Skip to main content
zenodoopen

SAPPAN: Advanced Threat Data

<p>The data were acquired from a simulated environment consisting of two Windows clients, a Windows server, a Linux host, and a Linux router whose connection diagram can be found in the <a href="https://zenodo.org/record/5547862/files/infrastructure.png">infrastructure.png</a> file. One attack scenario was performed in this environment, and data relevant to this attack are uploaded as this dataset.</p> <p>The advanced attack scenario follows our previous experiment (see <a href="https://zenodo.org/record/4159878">SAPPAN: Combined Network and Host Data</a>), where the initial compromise of a host from outside has already been carried out. The scenario starts by running the code on Workstation1 and extracting the data, followed by a lateral movement to Workstation2, where the data is also extracted. The scenario ends with the deactivation of all implants. A detailed description of the scenario can be found in the <a href="https://zenodo.org/record/5547862/files/test_protocol.xlsx">test_protocol.xlsx</a> file.</p> <p>The scenario is inspired by the first scenario described in <a href="https://attackevals.mitre-engenuity.org/enterprise/apt29/operational-flow">APT29 Evaluation: Operational Flow</a> and <a href="https://github.com/mitre-attack/attack-arsenal/tree/master/adversary_emulation/APT29/Emulation_Plan/Day%201">APT29 Day 1 (Steps 1 through 10)</a>. However, in order to better showcase analyses relevant to the SAPPAN project, we have chosen a different C2 framework (POshC2 instead of Pupy RAT) and performed certain steps concerning code execution, downloading and exfiltrating data differently.</p> <p>The dataset consists of the following data:</p> <ul> <li><a href="https://zenodo.org/record/5547862/files/infrastructure.png">infrastructure.png</a> - Schema of the artificial infrastructure</li> <li><a href="https://zenodo.org/record/5547862/files/test_protocol.xlsx">test-protocol.xlsx</a> - Detailed protocol of the captured attack</li> <li><a href="https://zenodo.org/record/5547862/files/network_traffic_capture.pcap">network_traffic_capture.pcap</a> - Full packet capture (PCAP format) of all network traffic passing through firewall host</li> <li><a href="https://zenodo.org/record/5547862/files/RDR-data.zip">RDR-data.zip</a> - Raw event data (JSON format) from all Windows host with the following attributes: <ul> <li>time - the time when the sensor recorded the event</li> <li>event_type - the type of the event</li> <li>host - info about the host machine (name and OS version)</li> <li>event - event type-specific payload</li> </ul> </li> </ul>

ShareScore

44/100

Overall dataset sharing score

Score breakdown

These five areas show where the dataset supports — or may limit — practical reuse.

Stewardship
4
Harmonization
4
Access
20
Reuse readiness
12
Engagement
4