ICS Cybersecurity Events and Intrusion Detection
This dataset provides detailed records of cybersecurity events and intrusion detection incidents within industrial control systems, including unauthorized access attempts, malware infections, configuration changes, and network anomalies. Each event is enriched with asset, network, user, and response details, enabling robust security monitoring, threat analysis, and compliance reporting for operational technology environments.
Sample rows
preview · 8 of 100 rows · all 18 columns| event_idstring | event_typestring | is_false_positiveboolean | config_change_typestring | event_datetimedatetime | severitystring | source_ipstring | destination_ipstring | device_idstring | device_typestring | user_idstring | malware_namestring | network_protocolstring | location_sitestring | location_zonestring | response_actionstring | response_datetimedatetime | descriptionstring |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EVT-1001 | unauthorized_access | false | blank | 2024-06-10T07:18:45Z | critical | 198.51.100.23 | 10.10.2.15 | PLC-0021 | PLC | user_admin | blank | Modbus | Plant A | Production | blocked | 2024-06-10T07:19:04Z | Multiple failed login attempts detected from external IP. |
| EVT-1002 | malware_detection | false | blank | 2024-06-11T15:22:03Z | high | 172.16.5.88 | 192.168.1.17 | RTU-0045 | RTU | tech_jones | Industroyer | DNP3 | Plant B | Control | quarantined | 2024-06-11T15:25:10Z | Detected malware signature on RTU device. |
| EVT-1003 | config_change | true | firmware_update | 2024-06-09T09:12:28Z | medium | 10.10.3.60 | 10.10.3.10 | SCADA-0008 | SCADA | eng_rsmith | blank | OPC-UA | Plant C | Engineering | investigated | 2024-06-09T10:01:12Z | Firmware upgrade performed on SCADA device. |
| EVT-1004 | network_anomaly | false | blank | 2024-06-10T03:24:19Z | medium | 10.10.1.42 | 10.10.1.100 | SENSOR-0054 | sensor | blank | blank | Modbus | Plant A | Field | investigated | 2024-06-10T03:55:14Z | Spike in traffic detected on sensor subnet. |
| EVT-1005 | malware_detection | false | blank | 2024-06-08T18:14:36Z | critical | 192.168.2.38 | 192.168.2.41 | HMI-0012 | HMI | user_davis | Stuxnet | OPC-UA | Plant D | Operator | blocked | 2024-06-08T18:16:44Z | Malware detected on HMI workstation. |
| EVT-1006 | config_change | false | network_settings_change | 2024-06-11T06:45:00Z | low | 10.10.3.99 | 10.10.3.20 | RTU-0042 | RTU | net_kelly | blank | DNP3 | Plant C | Control | none | 2024-06-11T06:50:21Z | Network settings changed on RTU. |
| EVT-1007 | unauthorized_access | false | blank | 2024-06-12T14:29:58Z | high | 203.0.113.44 | 10.10.2.11 | PLC-0030 | PLC | unknown | blank | Modbus | Plant B | Production | blocked | 2024-06-12T14:30:07Z | Attempted access to PLC from unknown user. |
| EVT-1008 | network_anomaly | true | blank | 2024-06-07T22:16:11Z | medium | 10.10.4.16 | 10.10.4.255 | SCADA-0011 | SCADA | blank | blank | OPC-UA | Plant D | Engineering | none | 2024-06-07T22:19:33Z | Unusual broadcast traffic on SCADA network. |
| EVT-1009 | unauthorized_access | false | blank | 2024-06-10T12:02:09Z | medium | 198.51.100.19 | 10.10.2.22 | SCADA-0025 | SCADA | ssh_guest | blank | OPC-UA | Plant A | Control | investigated | 2024-06-10T12:07:55Z | Unauthorized SSH attempt detected on SCADA. |
| EVT-1010 | malware_detection | false | blank | 2024-06-06T17:41:25Z | critical | 172.16.5.77 | 192.168.3.20 | HMI-0022 | HMI | op_martin | LockerGoga | OPC-UA | Plant B | Operator | quarantined | 2024-06-06T17:42:41Z | Ransomware detected on HMI. |
| EVT-1011 | config_change | false | parameter_change | 2024-06-11T13:10:44Z | medium | 10.10.2.16 | 10.10.2.18 | PLC-0018 | PLC | tech_jones | blank | Modbus | Plant C | Production | investigated | 2024-06-11T13:12:22Z | Device parameter changed by technician. |
| EVT-1012 | network_anomaly | false | blank | 2024-06-09T20:47:03Z | low | 10.10.1.56 | 10.10.1.17 | SENSOR-0039 | sensor | blank | blank | DNP3 | Plant B | Field | none | 2024-06-09T20:47:59Z | Unexpected protocol traffic detected on sensor. |
| EVT-1013 | unauthorized_access | false | blank | 2024-06-12T19:05:16Z | high | 203.0.113.89 | 192.168.3.60 | HMI-0034 | HMI | unknown | blank | OPC-UA | Plant D | Operator | blocked | 2024-06-12T19:05:41Z | Invalid card swipe attempt at HMI. |
| EVT-1014 | malware_detection | true | blank | 2024-06-07T11:32:14Z | medium | 192.168.1.77 | 10.10.2.17 | PLC-0049 | PLC | eng_rsmith | BlackEnergy | Modbus | Plant A | Production | investigated | 2024-06-07T12:11:09Z | Suspicious executable found on PLC. |
| EVT-1015 | config_change | false | access_rights_change | 2024-06-08T09:45:16Z | low | 10.10.4.41 | 10.10.4.12 | SCADA-0032 | SCADA | sec_brown | blank | OPC-UA | Plant C | Engineering | none | 2024-06-08T09:46:54Z | Access rights modified for SCADA user. |
| EVT-1016 | unauthorized_access | false | blank | 2024-06-12T08:29:42Z | critical | 198.51.100.90 | 172.16.5.22 | RTU-0073 | RTU | admin | blank | DNP3 | Plant D | Control | blocked | 2024-06-12T08:30:21Z | Brute force attempt on RTU admin account. |
| EVT-1017 | malware_detection | false | blank | 2024-06-11T02:11:37Z | high | 172.16.5.44 | 10.10.1.52 | SENSOR-0071 | sensor | tech_jones | Duqu | Modbus | Plant B | Field | quarantined | 2024-06-11T02:13:15Z | Worm detected on sensor device. |
| EVT-1018 | config_change | false | parameter_change | 2024-06-09T16:30:04Z | medium | 10.10.2.80 | 192.168.2.30 | HMI-0040 | HMI | eng_rsmith | blank | OPC-UA | Plant A | Operator | investigated | 2024-06-09T16:32:25Z | Parameter adjustment on HMI device. |
| EVT-1019 | network_anomaly | false | blank | 2024-06-07T05:20:36Z | low | 10.10.2.22 | 10.10.4.11 | PLC-0041 | PLC | blank | blank | Modbus | Plant C | Production | none | 2024-06-07T05:22:00Z | High latency detected between PLC and SCADA. |
| EVT-1020 | unauthorized_access | false | blank | 2024-06-08T12:55:13Z | medium | 203.0.113.61 | 10.10.1.70 | SENSOR-0084 | sensor | unknown | blank | DNP3 | Plant B | Field | investigated | 2024-06-08T12:58:09Z | Unauthorized login detected on sensor. |
What the 100 rows show
from the 100-row sample- 11%is_
false_ positive = true - 4severities
- 4response actions
- 5device types
- 5network protocols
- 10location sites
- string 15
- datetime 2
- boolean 1
Columns
18 columns in three groups| column | type | description | example |
|---|---|---|---|
| Text 15 columns | |||
event_id | string | Unique identifier for each cybersecurity eventunique | EVT-1001 |
event_type | string | Type of security event (e.g., unauthorized_access, malware_detection, config_change, network_anomaly)4 values | unauthorized_access |
severity | string | Severity level of the event (e.g., low, medium, high, critical)low · medium · high · critical | critical |
description | string | Detailed description of the eventoptional | Multiple failed login att… |
source_ip | string | IP address from which the event originatedoptional | 198.51.100.23 |
destination_ip | string | IP address targeted by the eventoptional | 10.10.2.15 |
device_id | string | Unique identifier for the OT device involved in the eventoptional | PLC-0021 |
device_type | string | Type of OT device (e.g., PLC, SCADA, RTU, HMI, sensor)PLC · SCADA · RTU · HMI · sensor · optional | PLC |
user_id | string | Identifier of the user involved in the event (if applicable)optional | user_admin |
malware_name | string | Name of detected malware (if event_type is malware_detection)optional | Industroyer |
config_change_type | string | Type of configuration change (if event_type is config_change)4 values · optional | firmware_update |
network_protocol | string | Network protocol involved in the event (e.g., Modbus, DNP3, OPC-UA)5 protocols · optional | Modbus |
location_site | string | Physical site or facility where the event occurred10 sites · optional | Plant A |
location_zone | string | Network or security zone within the siteoptional | Production |
response_action | string | Action taken in response to the event (e.g., blocked, quarantined, investigated, none)blocked · quarantined · investigated · none · optional | blocked |
| Dates and times 2 columns | |||
event_datetime | datetime | Timestamp when the event occurred | 2024-06-10T07:18:45Z |
response_datetime | datetime | Timestamp when the response action was takenoptional | 2024-06-10T07:19:04Z |
| True or false 1 column | |||
is_false_positive | boolean | Indicates if the event was later determined to be a false positiveoptional | false |
Use it for
A manufacturing dashboard
The is_
false_ positive rate, is_ false_ positive by event_ type and a breakdown of config_ change_ type. Excel, Power BI or Tableau. Why do 11 of 100 rows have is_
false_ positive = true? A class exercise
Hand out the rows and one question. Everyone works from the same 100 rows.
- Events100EVT-1001unauthor…EVT-1003config_c…EVT-1008network_…
A software demo
Believable events with event_
type, event_ datetime and severity to fill a screen in front of a buyer.
blueprint · ics-cybersecurity-events-and-intrusion-detection
Behind this dataset
Same schema. As many rows as you need.
These 100 rows came out of a blueprint — 18 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.
- Security event ID unique
- Event type: login attempt, malware, config change, network scan, DOS attack
- Source IP address and destination
- User account involved
- Severity: critical, high, medium, low
- IDS/IPS signature match
- Whitelist violations for known-good baseline
- Anomaly detection for unusual traffic patterns
1 credit per row. New accounts start with 25 free credits.
- Exports
- CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
- Licence
- yours to use, including commercially
- API slug
- ics-cybersecurity-events-and-intrusion-detection