Go top
Paper information

COMISET: Dataset for the analysis of malicious events in Windows systems

A. Pérez-Sánchez, R. Palacios, G. López

Data in Brief Vol. 61, pp. 111723

Summary:

The evaluation of threat detection and prevention systems requires the use of datasets that are up-to-date and correctly designed according to the most common threats. Currently, the availability of event datasets containing sufficient information to perform these analyses on Microsoft Windows systems is practically non-existent. In the background section we summarize the existing datasets, highlighting their main limitations to conduct studies of threat detection. Following we present COMISET, the dataset we have generated through the collection of events in real time and updated according to the current threats and malware obfuscation techniques. The main advantage of using this dataset with respect to those already available is that it was developed specifically for the evaluation of threat detection and prevention systems, and the events were labelled according to techniques and tactics of the MITRE ATT&CK matrix. COMISET is freely available for research purposes and contains about 250 million events of both malicious and non-malicious types. To create the dataset the experiments have been performed in two different scenarios: a laboratory emulating the infrastructure of a small company, and a computer network commonly used by students at Comillas University. In the laboratory environment, real attacks were executed involving a variety of techniques and tactics commonly used by the adversaries. The monitoring system was able to capture the events and label them according to the MITRE ATT&CK matrix. Some of these events are shown in this paper as an example of the worthy information contained in the dataset. 


Spanish layman's summary:

COMISET es un dataset de eventos inofensivos y maliciosos recogidos en ordenadores Windows, durante utilización normal y durante pruebas de ciberataques reales realizadas en un entorno controlado. Este dataset es útil para desarrollar nuevas técnicas de detección basadas en eventos en lugar de análisis de código.

 


English layman's summary:

COMISET is a dataset of malicious and harmless events collected in Windows computers, during normal use and during experiments of real cyberattacks conducted in a controlled environment. This dataset is useful for developing new detections techniques based on system events instead of code analysis.


Keywords: Event-based threat detection; MITRE ATT&CK; Cyber kill chain; Advanced persistent threats


JCR-JIF Impact Factor and WoS quartile: 1,400 - Q3 (2024)

DOI reference: DOI icon https://doi.org/10.1016/j.dib.2025.111723

Published on paper: August 2025.

Published on-line: May 2025.



Citation:
A. Pérez-Sánchez, R. Palacios, G. López, "COMISET: Dataset for the analysis of malicious events in Windows systems", Data in Brief, Vol. 61, pp. 111723, August 2025. [Online: May 2025] doi: 10.1016/j.dib.2025.111723

    Research topics:
  • Safe, Trustworthy, Fair and Interpretable AI
  • Machine Learning and Advanced Analytics
    Research groups:
  • Instituto de Investigación Tecnológica (IIT)
    ODS:
  • Goal 9: Industry, innovation and infrastructure
  • Goal 8: Decent work and economic growth