Mora / Datasets / Orders / Lab FA30E2
Order from Lab FA30E2
Security incidents
Closed, real security incidents, each complete: raw endpoint and network logs, the alerts with their dispositions, the analyst's timed investigation timeline, and the root cause confirmed by forensics. The unit is the incident, with consistent pseudonymous host and user ids across sources and attacker addresses left intact.
How answering works
Any number of people fill one order. The lab receives one dataset, in its own columns.
- Your agent reads the order
It looks at what you hold and says which columns you can fill, and what is missing.
- Mora checks what you send
Every record: no copies, no personal data, not already public, not on Mora from someone else.
- The lab pays per record it accepts
The lab named the price. You fill as much of the order as you can.
The columns the lab wants
You do not need every column. Mora says which ones each dataset fills.
| Column | Type | What it must hold |
|---|---|---|
incident_id / org_id / sector | id, id, label | One intrusion at one organisation; the organisation is an id, never a name |
first_malicious_at, detected_at, contained_at, closed_at | timestamp (UTC) | The four dates of the case |
endpoint_events | rows (EVTX/Sysmon, EDR JSON, auditd; Par | event_id, host_id, event_time, source, process_guid, parent_process_guid, image, command_line, user_id, sha256, raw |
network_events | rows (Zeek, netflow, pcap where kept) | flow_id, event_time, src_host_id, dst (external IPs and domains kept), port, proto, bytes, dns_query, http_host, ja3 |
alerts | rows | rule_name, product, severity, fired_at, event_refs, disposition (true positive, false positive, benign), dispositioned_by |
analyst_timeline | rows (JSON Lines) | at, analyst_id, action (query, pivot, containment, note), text, query_text, evidence_refs pointing to real events |
root_cause | text + labels | initial_access_vector, root_cause, ATT&CK technique ids, patient_zero_host_id, first_malicious_event_id, confirmed_by |
malicious | label per event | Whether the event is part of the intrusion or background |
How much, in the lab's words
2,000 closed incidents from at least 50 organisations, 2023 to 2026, each with telemetry from 7 days before the first malicious event until containment (about 10 billion events, a few TB), plus 20,000 triaged alerts including false positives
- incidents
- endpoint-events
- network-events
- alerts
- analyst-timeline
- root-cause
- labels
- environment