datasets
Training and evaluation data, with the modality, task and licence stated up front. Listed live from the Hugging Face Hub.
mitre-attack-en
MITRE ATT&CK Enterprise - Complete English Dataset
Comprehensive dataset of the MITRE ATT&CK Enterprise framework on Hugging Face. Data extracted automatically from official STIX 2.1 sources.
Description
This dataset covers the entire MITRE ATT&CK Enterprise framework:
14 tactics with full descriptions
691 techniques and sub-techniques (216 techniques + 475 sub-techniques)
44 mitigations with associated techniques
172 threat groups (APTs) with their known techniques
30… See the full description on the dataset page: https://huggingface.co/datasets/AYI-NEDJIMI/mitre-attack-en.mitre-attack-synthetic-scenarios
MITRE ATT&CK Synthetic Scenario Logs v3.0
Expanded Dataset: 30 scenarios × 8 events = 240 synthetic events
Axis
Coverage
Environment
endpoint, cloud, SaaS, identity, CI/CD, OT/IoT
Actor Type
external_apt, ransomware, insider, compromised_vendor, careless_admin, automated_threat
Intent
exfiltration, impact, fraud, persistence, reconnaissance, cryptomining, espionage
Detection Source
EDR, IAM, SIEM, DLP, DNS, proxy, cloud_audit, email_gateway, CASB, NDR, PAM, firewall… See the full description on the dataset page: https://huggingface.co/datasets/koushikcs09/mitre-attack-synthetic-scenarios.mitre-attack-techniques-qa
MITRE ATT&CK Techniques QA
A question–answer dataset covering 475 MITRE ATT&CK Enterprise techniques and sub-techniques,
designed for training and evaluating security-focused language models, RAG assistants for SOC
analysts, and red/blue/purple-team education.
Dataset Summary
Property
Value
Records
475
Language
English
Techniques (parent) covered
222 / 222 (all non-deprecated Enterprise parents)
Sub-techniques covered
253 (selection across the… See the full description on the dataset page: https://huggingface.co/datasets/ismailtasdelen/mitre-attack-techniques-qa.security-attacks-MITREcyber_MITRE_attack_tactics-and-techniquesThe dataset is question answering for MITRE tactics and techniques for version 15. Data sources are:
Tactics
Techniques
Mitre_Attacks_Framework_Dataset
MITRE ATT&CK Enterprise Dataset
Overview
This dataset provides a comprehensive collection of MITRE ATT&CK Enterprise techniques (v14.1) in JSONL format, designed for cybersecurity professionals, red teams, and threat hunters.
Each entry maps to a specific ATT&CK technique, including its ID, name, description, real-world example, and source.
The dataset is structured for seamless integration into security tools such as SIEMs, threat intelligence platforms, or custom red… See the full description on the dataset page: https://huggingface.co/datasets/darkknight25/Mitre_Attacks_Framework_Dataset.mitre-attack-fr
MITRE ATT&CK Enterprise - Dataset Francophone Complet
Premier dataset francophone complet du framework MITRE ATT&CK Enterprise sur Hugging Face. Données extraites automatiquement des sources STIX 2.1 officielles avec traductions françaises professionnelles.
Description
Ce dataset couvre l'intégralité du framework MITRE ATT&CK Enterprise avec :
14 tactiques traduites en français avec descriptions détaillées
691 techniques et sous-techniques (216 techniques + 475… See the full description on the dataset page: https://huggingface.co/datasets/AYI-NEDJIMI/mitre-attack-fr.Mitre-ATTACK-reasoning-datasetcybersec_mitre_attack_tactics_techniques_instruction_datamitre-attack-commandsmitre-attack-ttp-labeled-instructions
MITRE ATT&CK TTP Mapping Dataset
Training and evaluation data for mapping adversarial behavior descriptions (CTI reports,
CTF writeups, CISA advisories) to MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs).
Built as my individual contribution to a research project conducted at LORIA (supervised by Jean-Yves Marion). This dataset was developed and used to fine-tune skyylord/qwen3-emb-0.6b-ttp with CachedMultipleNegativesRankingLoss and ANCE-style hard negative re-mining.… See the full description on the dataset page: https://huggingface.co/datasets/skyylord/mitre-attack-ttp-labeled-instructions.mitre-attack-groups
RelayShield MITRE ATT&CK Group-Technique Mapping
A structured slice of MITRE ATT&CK Enterprise data: 189 named threat actor groups, each mapped to its associated ATT&CK techniques and software, with descriptions and source citations.
This is a cleaned, machine-readable export of MITRE's public STIX bundle — useful if you want group→technique mappings without parsing STIX yourself.
Fields
Field
Type
Description
group_id
string
MITRE ATT&CK group ID (e.g.… See the full description on the dataset page: https://huggingface.co/datasets/relayshieldadmin/mitre-attack-groups.mitre_attackMitre_Attacks_Framework_Dataset
MITRE ATT&CK Enterprise Dataset
Overview
This dataset provides a comprehensive collection of MITRE ATT&CK Enterprise techniques (v14.1) in JSONL format, designed for cybersecurity professionals, red teams, and threat hunters.
Each entry maps to a specific ATT&CK technique, including its ID, name, description, real-world example, and source.
The dataset is structured for seamless integration into security tools such as SIEMs, threat intelligence platforms, or custom red… See the full description on the dataset page: https://huggingface.co/datasets/JR87/Mitre_Attacks_Framework_Dataset.MITRE_Attack_Commandsmitre_attackMitreAttackRecords
MitreAttackRecords
tags: Security, Log Analysis, Predictive Modeling
Note: This is an AI-generated dataset so its content may be inaccurate or false
Dataset Description:
The 'MitreAttackRecords' dataset is a compilation of security log entries from various systems that have been impacted by Mitre ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) attack patterns. Each log entry is associated with specific labels that indicate the presence of certain Mitre ATT&CK tactics… See the full description on the dataset page: https://huggingface.co/datasets/infinite-dataset-hub/MitreAttackRecords.mitre-attack-commandsmitreattackQAmitre-attackmitre-attack-datasetdefendable-pain-mitre-attack-pain-v0.1
MITRE ATT&CK Pain Receipt
"the taxonomy" — Mr. Defendable
A free pain-receipt dataset from the DefendableOS ecosystem. 29 rows · ready to read · all cited or graded · CC-BY-4.0.
Part of the 100-pack — 100 free pain-receipt datasets dropped from the Defendable Bakery to the open AI-trust community. Different theme per dataset. Same operator voice across all of them.
Tribunal begins before training. No proof, no honey. To the shed.
What's in here
29 pain receipts… See the full description on the dataset page: https://huggingface.co/datasets/SwarmandBee/defendable-pain-mitre-attack-pain-v0.1.synthetic_mitre_attack_code_testmitre-attack-datasetmitre-attack-command-generationattacks-MITRECSE132_MITRE_Attack_Commandscse132-mitre-attack-commandsmitre-attack-commandsCSE132_MITRE_ATTACK_Commands
