Distributed Team Cybersecurity Incident Logs
This dataset contains detailed logs of simulated cybersecurity incidents affecting remote and distributed teams, capturing incident types, severity, affected endpoints, user roles, response times, and resolution details. It is ideal for developing, training, and benchmarking AI/ML models for security monitoring in hybrid or fully remote work environments, and supports incident trend analysis, response optimization, and compliance reporting.
Sample rows
preview · 8 of 80 rows · all 21 columns| incident_idstring | severity_levelstring | response_time_minutesfloat | external_notification_requiredboolean | user_rolestring | incident_datetimedatetime | incident_typestring | affected_endpoint_idstring | endpoint_typestring | endpoint_osstring | user_idstring | team_idstring | team_locationstring | detection_methodstring | response_initiated_datetimedatetime | incident_statusstring | resolution_datetimedatetime | data_compromisedboolean | data_types_affectedstring | resolution_summarystring | notesstring |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| INC-EX1A34B2 | medium | 11 | false | developer | 2024-04-10T08:43:00Z | phishing | ENDPT-0093 | laptop | Windows 11 | USR-2101 | TEAM-NEU-001 | Europe-Remote | user_report | 2024-04-10T08:54:00Z | investigating | blank | false | blank | blank | User reported suspicious email, initial investigation underway. |
| INC-4BDE27FC | high | 5 | false | analyst | 2024-04-12T16:10:00Z | malware | ENDPT-0238 | desktop | Windows 10 | USR-1187 | TEAM-USW-002 | US-West | automated_alert | 2024-04-12T16:15:00Z | contained | 2024-04-12T17:00:00Z | false | blank | Malware quarantined, endpoint scanned and cleaned. | Automated alert detected malware, incident contained quickly. |
| INC-7F21A9E4 | critical | 3 | true | sysadmin | 2024-04-13T11:25:00Z | unauthorized_access | ENDPT-0125 | server | Ubuntu 22.04 | USR-3210 | TEAM-ASIA-003 | Asia-Pacific | scheduled_scan | 2024-04-13T11:28:00Z | resolved | 2024-04-13T12:10:00Z | true | credentials,source_code | Access blocked, credentials reset, audit performed. | Critical unauthorized server access, regulator notified. |
| INC-2A9C8B1F | high | 37 | true | contractor | 2024-03-29T21:03:00Z | ransomware | ENDPT-0412 | cloud_instance | Amazon Linux 2 | USR-1782 | TEAM-UTC2-004 | UTC+2 | third_party_notification | 2024-03-29T21:40:00Z | investigating | blank | true | source_code,PII | blank | Third-party cloud monitoring reported ransomware on instance. |
| INC-ED45F7B3 | medium | 9 | false | blank | 2024-03-25T08:19:00Z | ddos | ENDPT-0200 | server | Windows Server 2019 | blank | TEAM-USE-005 | US-East | automated_alert | 2024-03-25T08:28:00Z | contained | 2024-03-25T09:05:00Z | false | blank | Traffic filtered, firewall rules updated. | DDoS mitigated, firewall strengthened. |
| INC-9C6B8A3E | critical | 19 | true | executive | 2024-03-27T14:01:00Z | data_leak | ENDPT-1099 | mobile | iOS 17 | USR-1390 | TEAM-EUR-006 | Europe-Remote | user_report | 2024-03-27T14:20:00Z | resolved | 2024-03-27T15:22:00Z | true | PII,financial_data | Device wiped, password resets, external notification sent. | Executive reported sensitive data leak; authorities informed. |
| INC-3A7F0CDB | low | 13 | false | contractor | 2024-03-23T18:17:00Z | insider_threat | ENDPT-0082 | desktop | Windows 10 | USR-1998 | TEAM-USW-002 | US-West | manual_review | 2024-03-23T18:30:00Z | open | blank | false | blank | blank | Suspicious file access logged, further review needed. |
| INC-6B12E479 | medium | 15 | false | developer | 2024-03-22T09:40:00Z | malware | ENDPT-1013 | laptop | macOS 13 | USR-1432 | TEAM-UTC3-007 | UTC+3 | scheduled_scan | 2024-03-22T09:55:00Z | contained | 2024-03-22T10:30:00Z | false | blank | Malicious file removed, endpoint monitoring increased. | Scheduled scan found malware, no data compromised. |
| INC-DB8F7C10 | low | 3 | false | manager | 2024-03-21T07:17:00Z | phishing | ENDPT-0311 | mobile | Android 14 | USR-1579 | TEAM-USE-005 | US-East | user_report | 2024-03-21T07:20:00Z | resolved | 2024-03-21T07:35:00Z | false | blank | Phishing link reported, no action required. | Manager reported phishing SMS, no compromise detected. |
| INC-892F4C7D | medium | 21 | false | blank | 2024-03-20T13:59:00Z | other | ENDPT-0407 | cloud_instance | Google Cloud VM | blank | TEAM-ASIA-003 | Asia-Pacific | third_party_notification | 2024-03-20T14:20:00Z | investigating | blank | false | blank | blank | Third-party vendor flagged unusual network traffic. |
| INC-EF5C8B13 | critical | 3 | true | sysadmin | 2024-03-19T11:05:00Z | ransomware | ENDPT-0712 | laptop | Windows 10 | USR-1111 | TEAM-EUR-006 | Europe-Remote | automated_alert | 2024-03-19T11:08:00Z | contained | 2024-03-19T12:00:00Z | true | credentials,PII | Endpoint isolated, restore from backup. | Sysadmin laptop hit by ransomware, external notification sent. |
| INC-ACB761E4 | low | 13 | false | analyst | 2024-03-18T15:22:00Z | phishing | ENDPT-0142 | desktop | Windows 11 | USR-1200 | TEAM-USW-002 | US-West | user_report | 2024-03-18T15:35:00Z | open | blank | false | blank | blank | Suspicious email link reported by analyst. |
| INC-F91D3B87 | medium | 12 | false | developer | 2024-03-17T19:48:00Z | malware | ENDPT-1181 | mobile | Android 14 | USR-1823 | TEAM-UTC2-004 | UTC+2 | automated_alert | 2024-03-17T20:00:00Z | resolved | 2024-03-17T20:40:00Z | false | blank | Malware cleaned, security app installed. | Malware detected and removed from developer's mobile. |
| INC-1E7B4F2C | high | 18 | true | sysadmin | 2024-03-16T12:22:00Z | insider_threat | ENDPT-0197 | server | Red Hat 8 | USR-1089 | TEAM-USE-005 | US-East | manual_review | 2024-03-16T12:40:00Z | investigating | blank | true | source_code,financial_data | blank | Insider accessed sensitive data on server. |
| INC-EC3D1F92 | medium | 12 | false | blank | 2024-03-15T07:55:00Z | ddos | ENDPT-0910 | cloud_instance | Azure VM | blank | TEAM-ASIA-003 | Asia-Pacific | automated_alert | 2024-03-15T08:07:00Z | contained | 2024-03-15T08:40:00Z | false | blank | Cloud provider mitigated attack. | Cloud instance targeted by DDoS, mitigated by provider. |
| INC-3B8C6E41 | low | 7 | false | manager | 2024-03-12T13:35:00Z | phishing | ENDPT-0511 | laptop | macOS 12 | USR-1012 | TEAM-EUR-006 | Europe-Remote | user_report | 2024-03-12T13:42:00Z | resolved | 2024-03-12T14:00:00Z | false | blank | User educated, no data compromised. | Manager clicked phishing link, no harm done. |
| INC-70F2EAC3 | medium | 14 | false | analyst | 2024-03-10T21:11:00Z | malware | ENDPT-0241 | desktop | Windows 10 | USR-1991 | TEAM-USW-002 | US-West | scheduled_scan | 2024-03-10T21:25:00Z | contained | 2024-03-10T22:00:00Z | false | blank | Infected file removed, desktop monitored. | Scheduled scan flagged malware, no data loss. |
| INC-9D7A31F8 | high | 17 | true | executive | 2024-03-09T10:38:00Z | data_leak | ENDPT-0672 | mobile | iOS 16 | USR-1312 | TEAM-UTC3-007 | UTC+3 | user_report | 2024-03-09T10:55:00Z | resolved | 2024-03-09T12:05:00Z | true | PII | Device locked, data container wiped. | Executive reported accidental data exposure. |
| INC-4E15C8B2 | medium | 14 | false | sysadmin | 2024-03-07T17:31:00Z | insider_threat | ENDPT-1001 | server | Ubuntu 20.04 | USR-1800 | TEAM-USE-005 | US-East | manual_review | 2024-03-07T17:45:00Z | investigating | blank | true | source_code | blank | Sysadmin suspected of unauthorized code access. |
| INC-59ACD4E1 | high | 8 | false | developer | 2024-03-06T08:22:00Z | malware | ENDPT-0243 | laptop | Windows 11 | USR-1442 | TEAM-UTC2-004 | UTC+2 | automated_alert | 2024-03-06T08:30:00Z | contained | 2024-03-06T09:15:00Z | false | blank | Malware cleaned, developer reimaged laptop. | Malware hit developer's laptop, cleaned promptly. |
What the 80 rows show
from the 80-row sampleCritical (severity level) stands out: 13 of its 14 rows have external_
- 25%external_
notification_ required = true - 7.0median response_
time_ minutes - 5endpoint types
- 5detection methods
- 5incident statuses
- 8incident types
Median 7.0, from 1.2 to 37.0.
- string 15
- float 1
- datetime 3
- boolean 2
Columns
21 columns in four groups| column | type | description | example |
|---|---|---|---|
| Text 15 columns | |||
incident_id | string | Unique identifier for each cybersecurity incident log entryunique | INC-EX1A34B2 |
incident_type | string | Type of cybersecurity incident (e.g., phishing, malware, unauthorized access, data leak)8 values | phishing |
severity_level | string | Severity classification of the incident (e.g., low, medium, high, critical)low · medium · high · critical | medium |
affected_endpoint_id | string | Unique identifier for the affected device or endpoint (e.g., laptop, server, mobile device) | ENDPT-0093 |
endpoint_type | string | Type of endpoint affected (e.g., laptop, desktop, server, mobile, cloud_instance)6 values | laptop |
endpoint_os | string | Operating system of the affected endpoint (e.g., Windows 10, macOS 12, Ubuntu 20.04)optional | Windows 11 |
user_id | string | Unique identifier for the user associated with the affected endpoint or incidentoptional | USR-2101 |
user_role | string | Role of the user involved in the incident (e.g., developer, manager, sysadmin, analyst, executive)7 values · optional | developer |
team_id | string | Unique identifier for the distributed or remote team involvedoptional | TEAM-NEU-001 |
team_location | string | Geographical location or time zone of the team (e.g., UTC+2, US-East, Europe-Remote)11 locations · optional | Europe-Remote |
detection_method | string | How the incident was detected (e.g., automated alert, user report, scheduled scan, third-party notification)6 values · optional | user_report |
incident_status | string | Current status of the incident (e.g., open, investigating, contained, resolved, false_positive)open · investigating · contained · resolved · false_positive | investigating |
resolution_summary | string | Brief summary of actions taken to resolve the incidentoptional | Phishing email blocked. |
data_types_affected | string | Comma-separated list of data types affected (e.g., credentials, PII, source_code, financial_data)optional | credentials,source_code |
notes | string | Additional notes or context about the incidentoptional | Minor UI bug reported. |
| Numbers 1 column | |||
response_time_minutes | float | Time in minutes between incident detection and response initiation0 or more · optional | 11 |
| Dates and times 3 columns | |||
incident_datetime | datetime | Date and time when the incident was first detected or reported | 2024-04-10T08:43:00Z |
response_initiated_datetime | datetime | Date and time when the incident response was initiatedoptional | 2024-04-10T08:54:00Z |
resolution_datetime | datetime | Date and time when the incident was resolved or closedoptional | 2024-04-12T17:00:00Z |
| True or false 2 columns | |||
data_compromised | boolean | Indicates whether sensitive data was compromised in the incidentoptional | false |
external_notification_required | boolean | Indicates if external notification (e.g., to regulators or customers) was requiredoptional | false |
Use it for
A technology dashboard
The external_
notification_ required rate, response_ time_ minutes by severity_ level and a breakdown of user_ role. Excel, Power BI or Tableau. Why do 20 of 80 rows have external_
notification_ required = true? A root-cause class exercise
Hand out the rows and one question. The answer is in the data, not in the brief.
- Incidents80INC-EX1A34B211mediumINC-7F21A9E43criticalINC-2A9C8B1F37high
A software demo
Believable incidents with incident_
datetime, incident_ type and severity_ level to fill a screen in front of a buyer.
blueprint · distributed-team-cybersecurity-incident-logs
Behind this dataset
Same schema. As many rows as you need.
These 80 rows came out of a blueprint — 21 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.
- Each incident must include timestamp, incident type, and affected endpoint.
- User roles (e.g., developer, manager) must be linked to each incident.
- Response time is measured in hours and cannot be negative.
- Incident severity must follow standardized classification (Low, Medium, High, Critical).
- No duplicate incidents (unique by timestamp and endpoint).
1 credit per row. New accounts start with 25 free credits.
- Exports
- CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
- Licence
- yours to use, including commercially
- API slug
- distributed-team-cybersecurity-incident-logs