Mora / Datasets / Orders / Lab FA30E2

Order from Lab FA30E2

Security incidents

Closed, real security incidents, each complete: raw endpoint and network logs, the alerts with their dispositions, the analyst's timed investigation timeline, and the root cause confirmed by forensics. The unit is the incident, with consistent pseudonymous host and user ids across sources and attacker addresses left intact.

How answering works

Any number of people fill one order. The lab receives one dataset, in its own columns.

  1. Your agent reads the order

    It looks at what you hold and says which columns you can fill, and what is missing.

  2. Mora checks what you send

    Every record: no copies, no personal data, not already public, not on Mora from someone else.

  3. The lab pays per record it accepts

    The lab named the price. You fill as much of the order as you can.

The columns the lab wants

You do not need every column. Mora says which ones each dataset fills.

ColumnTypeWhat it must hold
incident_id / org_id / sectorid, id, labelOne intrusion at one organisation; the organisation is an id, never a name
first_malicious_at, detected_at, contained_at, closed_attimestamp (UTC)The four dates of the case
endpoint_eventsrows (EVTX/Sysmon, EDR JSON, auditd; Parevent_id, host_id, event_time, source, process_guid, parent_process_guid, image, command_line, user_id, sha256, raw
network_eventsrows (Zeek, netflow, pcap where kept)flow_id, event_time, src_host_id, dst (external IPs and domains kept), port, proto, bytes, dns_query, http_host, ja3
alertsrowsrule_name, product, severity, fired_at, event_refs, disposition (true positive, false positive, benign), dispositioned_by
analyst_timelinerows (JSON Lines)at, analyst_id, action (query, pivot, containment, note), text, query_text, evidence_refs pointing to real events
root_causetext + labelsinitial_access_vector, root_cause, ATT&CK technique ids, patient_zero_host_id, first_malicious_event_id, confirmed_by
maliciouslabel per eventWhether the event is part of the intrusion or background

How much, in the lab's words

2,000 closed incidents from at least 50 organisations, 2023 to 2026, each with telemetry from 7 days before the first malicious event until containment (about 10 billion events, a few TB), plus 20,000 triaged alerts including false positives

  • incidents
  • endpoint-events
  • network-events
  • alerts
  • analyst-timeline
  • root-cause
  • labels
  • environment