ICS Cybersecurity Events and Intrusion Detection

This dataset provides detailed records of cybersecurity events and intrusion detection incidents within industrial control systems, including unauthorized access attempts, malware infections, configuration changes, and network anomalies. Each event is enriched with asset, network, user, and response details, enabling robust security monitoring, threat analysis, and compliance reporting for operational technology environments.

  • last updated 2 Nov 2025
  • by GoMask
The brief that made it

Real-time monitoring and alerting for OT cybersecurity incidents

Sample rows

preview · 8 of 100 rows · all 18 columns
event_idstringevent_typestringis_false_positivebooleanconfig_change_typestringevent_datetimedatetimeseveritystringsource_ipstringdestination_ipstringdevice_idstringdevice_typestringuser_idstringmalware_namestringnetwork_protocolstringlocation_sitestringlocation_zonestringresponse_actionstringresponse_datetimedatetimedescriptionstring
EVT-1001unauthorized_accessfalseblank2024-06-10T07:18:45Zcritical198.51.100.2310.10.2.15PLC-0021PLCuser_adminblankModbusPlant AProductionblocked2024-06-10T07:19:04ZMultiple failed login attempts detected from external IP.
EVT-1002malware_detectionfalseblank2024-06-11T15:22:03Zhigh172.16.5.88192.168.1.17RTU-0045RTUtech_jonesIndustroyerDNP3Plant BControlquarantined2024-06-11T15:25:10ZDetected malware signature on RTU device.
EVT-1003config_changetruefirmware_update2024-06-09T09:12:28Zmedium10.10.3.6010.10.3.10SCADA-0008SCADAeng_rsmithblankOPC-UAPlant CEngineeringinvestigated2024-06-09T10:01:12ZFirmware upgrade performed on SCADA device.
EVT-1004network_anomalyfalseblank2024-06-10T03:24:19Zmedium10.10.1.4210.10.1.100SENSOR-0054sensorblankblankModbusPlant AFieldinvestigated2024-06-10T03:55:14ZSpike in traffic detected on sensor subnet.
EVT-1005malware_detectionfalseblank2024-06-08T18:14:36Zcritical192.168.2.38192.168.2.41HMI-0012HMIuser_davisStuxnetOPC-UAPlant DOperatorblocked2024-06-08T18:16:44ZMalware detected on HMI workstation.
EVT-1006config_changefalsenetwork_settings_change2024-06-11T06:45:00Zlow10.10.3.9910.10.3.20RTU-0042RTUnet_kellyblankDNP3Plant CControlnone2024-06-11T06:50:21ZNetwork settings changed on RTU.
EVT-1007unauthorized_accessfalseblank2024-06-12T14:29:58Zhigh203.0.113.4410.10.2.11PLC-0030PLCunknownblankModbusPlant BProductionblocked2024-06-12T14:30:07ZAttempted access to PLC from unknown user.
EVT-1008network_anomalytrueblank2024-06-07T22:16:11Zmedium10.10.4.1610.10.4.255SCADA-0011SCADAblankblankOPC-UAPlant DEngineeringnone2024-06-07T22:19:33ZUnusual broadcast traffic on SCADA network.

What the 100 rows show

from the 100-row sample
  • 11%is_false_positive = true
  • 4severities
  • 4response actions
  • 5device types
  • 5network protocols
  • 10location sites
event_type100 rows by value
0153024unauthor…24%26malware_…26%27config_c…27%23network_…23%
config_change_type27 rows with a value · 73 left blank
  1. firmware_update8
  2. network_settings_change7
  3. parameter_change7
  4. access_rights_change5
18 columns by typefrom the column list below
  • string 15
  • datetime 2
  • boolean 1

Columns

18 columns in three groups
blueprint · 18 columns
columntypedescriptionexample
Text 15 columns
event_idstringUnique identifier for each cybersecurity eventuniqueEVT-1001
event_typestringType of security event (e.g., unauthorized_access, malware_detection, config_change, network_anomaly)4 valuesunauthorized_access
severitystringSeverity level of the event (e.g., low, medium, high, critical)low · medium · high · criticalcritical
descriptionstringDetailed description of the eventoptionalMultiple failed login att…
source_ipstringIP address from which the event originatedoptional198.51.100.23
destination_ipstringIP address targeted by the eventoptional10.10.2.15
device_idstringUnique identifier for the OT device involved in the eventoptionalPLC-0021
device_typestringType of OT device (e.g., PLC, SCADA, RTU, HMI, sensor)PLC · SCADA · RTU · HMI · sensor · optionalPLC
user_idstringIdentifier of the user involved in the event (if applicable)optionaluser_admin
malware_namestringName of detected malware (if event_type is malware_detection)optionalIndustroyer
config_change_typestringType of configuration change (if event_type is config_change)4 values · optionalfirmware_update
network_protocolstringNetwork protocol involved in the event (e.g., Modbus, DNP3, OPC-UA)5 protocols · optionalModbus
location_sitestringPhysical site or facility where the event occurred10 sites · optionalPlant A
location_zonestringNetwork or security zone within the siteoptionalProduction
response_actionstringAction taken in response to the event (e.g., blocked, quarantined, investigated, none)blocked · quarantined · investigated · none · optionalblocked
Dates and times 2 columns
event_datetimedatetimeTimestamp when the event occurred2024-06-10T07:18:45Z
response_datetimedatetimeTimestamp when the response action was takenoptional2024-06-10T07:19:04Z
True or false 1 column
is_false_positivebooleanIndicates if the event was later determined to be a false positiveoptionalfalse

Use it for

  • is false posit…11%11 of 100 rowsrows by event type24unau…26malw…27conf…23netw…

    A manufacturing dashboard

    The is_false_positive rate, is_false_positive by event_type and a breakdown of config_change_type. Excel, Power BI or Tableau.

  • Why do 11 of 100 rows have is_false_positive = true?

    A class exercise

    Hand out the rows and one question. Everyone works from the same 100 rows.

  • A software demo

    Believable events with event_type, event_datetime and severity to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 18 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset100 rows18 columns
Yours10,000 rows18 columnslocation_site: UK only

blueprint · ics-cybersecurity-events-and-intrusion-detection

Behind this dataset

Same schema. As many rows as you need.

These 100 rows came out of a blueprint — 18 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Security event ID unique
  • Event type: login attempt, malware, config change, network scan, DOS attack
  • Source IP address and destination
  • User account involved
  • Severity: critical, high, medium, low
  • IDS/IPS signature match
  • Whitelist violations for known-good baseline
  • Anomaly detection for unusual traffic patterns
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
ics-cybersecurity-events-and-intrusion-detection

What should your data show?

Preview 20 rows free
No signup. No card.