Distributed Team Cybersecurity Incident Logs

This dataset contains detailed logs of simulated cybersecurity incidents affecting remote and distributed teams, capturing incident types, severity, affected endpoints, user roles, response times, and resolution details. It is ideal for developing, training, and benchmarking AI/ML models for security monitoring in hybrid or fully remote work environments, and supports incident trend analysis, response optimization, and compliance reporting.

  • last updated 25 Jan 2026
  • by GoMask
The brief that made it

Training and benchmarking AI/ML models for cybersecurity incident detection

Sample rows

preview · 8 of 80 rows · all 21 columns
incident_idstringseverity_levelstringresponse_time_minutesfloatexternal_notification_requiredbooleanuser_rolestringincident_datetimedatetimeincident_typestringaffected_endpoint_idstringendpoint_typestringendpoint_osstringuser_idstringteam_idstringteam_locationstringdetection_methodstringresponse_initiated_datetimedatetimeincident_statusstringresolution_datetimedatetimedata_compromisedbooleandata_types_affectedstringresolution_summarystringnotesstring
INC-EX1A34B2medium11falsedeveloper2024-04-10T08:43:00ZphishingENDPT-0093laptopWindows 11USR-2101TEAM-NEU-001Europe-Remoteuser_report2024-04-10T08:54:00ZinvestigatingblankfalseblankblankUser reported suspicious email, initial investigation underway.
INC-4BDE27FChigh5falseanalyst2024-04-12T16:10:00ZmalwareENDPT-0238desktopWindows 10USR-1187TEAM-USW-002US-Westautomated_alert2024-04-12T16:15:00Zcontained2024-04-12T17:00:00ZfalseblankMalware quarantined, endpoint scanned and cleaned.Automated alert detected malware, incident contained quickly.
INC-7F21A9E4critical3truesysadmin2024-04-13T11:25:00Zunauthorized_accessENDPT-0125serverUbuntu 22.04USR-3210TEAM-ASIA-003Asia-Pacificscheduled_scan2024-04-13T11:28:00Zresolved2024-04-13T12:10:00Ztruecredentials,source_codeAccess blocked, credentials reset, audit performed.Critical unauthorized server access, regulator notified.
INC-2A9C8B1Fhigh37truecontractor2024-03-29T21:03:00ZransomwareENDPT-0412cloud_instanceAmazon Linux 2USR-1782TEAM-UTC2-004UTC+2third_party_notification2024-03-29T21:40:00Zinvestigatingblanktruesource_code,PIIblankThird-party cloud monitoring reported ransomware on instance.
INC-ED45F7B3medium9falseblank2024-03-25T08:19:00ZddosENDPT-0200serverWindows Server 2019blankTEAM-USE-005US-Eastautomated_alert2024-03-25T08:28:00Zcontained2024-03-25T09:05:00ZfalseblankTraffic filtered, firewall rules updated.DDoS mitigated, firewall strengthened.
INC-9C6B8A3Ecritical19trueexecutive2024-03-27T14:01:00Zdata_leakENDPT-1099mobileiOS 17USR-1390TEAM-EUR-006Europe-Remoteuser_report2024-03-27T14:20:00Zresolved2024-03-27T15:22:00ZtruePII,financial_dataDevice wiped, password resets, external notification sent.Executive reported sensitive data leak; authorities informed.
INC-3A7F0CDBlow13falsecontractor2024-03-23T18:17:00Zinsider_threatENDPT-0082desktopWindows 10USR-1998TEAM-USW-002US-Westmanual_review2024-03-23T18:30:00ZopenblankfalseblankblankSuspicious file access logged, further review needed.
INC-6B12E479medium15falsedeveloper2024-03-22T09:40:00ZmalwareENDPT-1013laptopmacOS 13USR-1432TEAM-UTC3-007UTC+3scheduled_scan2024-03-22T09:55:00Zcontained2024-03-22T10:30:00ZfalseblankMalicious file removed, endpoint monitoring increased.Scheduled scan found malware, no data compromised.

What the 80 rows show

from the 80-row sample

Critical (severity level) stands out: 13 of its 14 rows have external_notification_required = true, against 7 of 66 for the rest.

  • 25%external_notification_required = true
  • 7.0median response_time_minutes
  • 5endpoint types
  • 5detection methods
  • 5incident statuses
  • 8incident types
External notification required rate by severity_levelexternal_notification_required = true
0%50%100%0%low0 of 137%medium2 of 2921%high5 of 2493%critical13 of 14
response_time_minutes80 rows, in bands of 5
020403227145100102040response_time_minutes →

Median 7.0, from 1.2 to 37.0.

user_role72 rows with a value · 8 left blank
  1. analyst16
  2. sysadmin16
  3. developer14
  4. contractor11
  5. manager10
  6. executive4
  7. other1
21 columns by typefrom the column list below
  • string 15
  • float 1
  • datetime 3
  • boolean 2

Columns

21 columns in four groups
blueprint · 21 columns
columntypedescriptionexample
Text 15 columns
incident_idstringUnique identifier for each cybersecurity incident log entryuniqueINC-EX1A34B2
incident_typestringType of cybersecurity incident (e.g., phishing, malware, unauthorized access, data leak)8 valuesphishing
severity_levelstringSeverity classification of the incident (e.g., low, medium, high, critical)low · medium · high · criticalmedium
affected_endpoint_idstringUnique identifier for the affected device or endpoint (e.g., laptop, server, mobile device)ENDPT-0093
endpoint_typestringType of endpoint affected (e.g., laptop, desktop, server, mobile, cloud_instance)6 valueslaptop
endpoint_osstringOperating system of the affected endpoint (e.g., Windows 10, macOS 12, Ubuntu 20.04)optionalWindows 11
user_idstringUnique identifier for the user associated with the affected endpoint or incidentoptionalUSR-2101
user_rolestringRole of the user involved in the incident (e.g., developer, manager, sysadmin, analyst, executive)7 values · optionaldeveloper
team_idstringUnique identifier for the distributed or remote team involvedoptionalTEAM-NEU-001
team_locationstringGeographical location or time zone of the team (e.g., UTC+2, US-East, Europe-Remote)11 locations · optionalEurope-Remote
detection_methodstringHow the incident was detected (e.g., automated alert, user report, scheduled scan, third-party notification)6 values · optionaluser_report
incident_statusstringCurrent status of the incident (e.g., open, investigating, contained, resolved, false_positive)open · investigating · contained · resolved · false_positiveinvestigating
resolution_summarystringBrief summary of actions taken to resolve the incidentoptionalPhishing email blocked.
data_types_affectedstringComma-separated list of data types affected (e.g., credentials, PII, source_code, financial_data)optionalcredentials,source_code
notesstringAdditional notes or context about the incidentoptionalMinor UI bug reported.
Numbers 1 column
response_time_minutesfloatTime in minutes between incident detection and response initiation0 or more · optional11
Dates and times 3 columns
incident_datetimedatetimeDate and time when the incident was first detected or reported2024-04-10T08:43:00Z
response_initiated_datetimedatetimeDate and time when the incident response was initiatedoptional2024-04-10T08:54:00Z
resolution_datetimedatetimeDate and time when the incident was resolved or closedoptional2024-04-12T17:00:00Z
True or false 2 columns
data_compromisedbooleanIndicates whether sensitive data was compromised in the incidentoptionalfalse
external_notification_requiredbooleanIndicates if external notification (e.g., to regulators or customers) was requiredoptionalfalse

Use it for

  • external notif…25%20 of 80 rowsmean response time mi…6.9low8.7medi…7.3high6.3crit…

    A technology dashboard

    The external_notification_required rate, response_time_minutes by severity_level and a breakdown of user_role. Excel, Power BI or Tableau.

  • Why do 20 of 80 rows have external_notification_required = true?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable incidents with incident_datetime, incident_type and severity_level to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 21 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset80 rows21 columns
Yours10,000 rows21 columnsteam_location: UK only

blueprint · distributed-team-cybersecurity-incident-logs

Behind this dataset

Same schema. As many rows as you need.

These 80 rows came out of a blueprint — 21 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Each incident must include timestamp, incident type, and affected endpoint.
  • User roles (e.g., developer, manager) must be linked to each incident.
  • Response time is measured in hours and cannot be negative.
  • Incident severity must follow standardized classification (Low, Medium, High, Critical).
  • No duplicate incidents (unique by timestamp and endpoint).
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
distributed-team-cybersecurity-incident-logs

What should your data show?

Preview 20 rows free
No signup. No card.