Skip to content

Learn on security datathat behaves like production.

Large, messy, production-sized security datasets. The open-source tools to analyze them, installed and configured.

The problem

Most security research starts with a procurement form.

Useful datasets are sold under vendor contracts. Useful tooling assumes you already have a cluster and someone to run it. If you have neither, you learn on small synthetic samples and hope the lessons transfer to production.

We think the data and the tools should be public, so that's what Seacurity is.

What's here
01

Data

Logs, packet captures, threat intelligence feeds, and recorded attack traces, at the volumes you'd see in a real environment. Each dataset has a schema, a version history, and a license. Download it or query it where it sits.

02

Tools

Open-source detection engines, parsers, hunting notebooks, and visualizers, installed and configured. The same code is on GitHub if you'd rather run it yourself.

AB
03

Compute

Hosted workspaces with the datasets already mounted. You can run a query over a few billion events without provisioning anything first.

About

The people with the least access to real security data are the ones who could use it most.

Graduate students, small security teams, independent researchers, people teaching the subject. The data exists. Most of it is under contract.

Seacurity is an attempt to fix that by collecting what can be released, cleaning it, and hosting it with the tools needed to use it.

Funded by

Self-funding and donations.

No grants, sponsors, or institutional backers. The code and data are licensed so the project can continue even if we can't.

How it works

Pick a dataset.
Open a workspace. Work.

data-card.yaml
1dataset: win-auth-lab/v3
2source: instrumented lab network
3hosts: 400
4span: 90 days
5labels: 14 lateral-movement sequences
6license: CC-BY-NC-4.0
7covers: 4624, 4625, 4648, 4672
8excludes: Kerberos pre-auth failures
Reviewed for personal data
Catalog

What a dataset
looks like.

Full catalog opens at launch.

Example — not yet downloadable

win-auth-lab/v3

90 days of Windows authentication events from a 400-host instrumented lab network, with 14 labelled lateral-movement sequences.

Source
Instrumented lab network we run
Span
90 days · 400 hosts
Event IDs
4624, 4625, 4648, 4672
License
CC-BY-NC-4.0

Every card says what the data isn't.

Gaps, synthetic portions and anonymisation are stated on the card, not discovered halfway through an analysis.

Excludes
Kerberos pre-authentication failures.
Provenance
Which of the three sources it came from — a contributed corpus, a lab environment we instrument, or synthetic generation.
Personal data
How the release was reviewed, and what was dropped or replaced with synthetic values where anonymisation wasn't confident.

Download and query-in-place unlock when the catalog opens.

Principles

How we
operate.

Nothing is paid. There are no usage tiers or trial periods, and nothing on the site requires talking to a salesperson.

No paid tierNo trialsNo sales callsOpen sourceLicensed data

Everything is documented

Datasets carry a license. Tools are open source. The collection and cleaning methods are written up so you can reproduce them.

We publish data the way it actually looks

Large, noisy, inconsistently formatted. Cleaning that up is part of the work, and you should get to practice it.

Personal data is removed before release

Every dataset is reviewed. Where we can't anonymize confidently, we generate synthetic data or leave the field out.

Contributors set direction

Roadmap decisions are made in the open, and contributions are credited by name.

Contribute

Seacurity runs on
contributed data and code.

If you have a dataset that could be released, a tool worth adding, or a tutorial to write, the contributor guide explains how to submit it and what review looks like.

Data

A dataset that could be released, with a data card.

Tools

Open-source software worth installing for everyone.

Tutorials

A walkthrough that teaches with real data.

Review

Every submission is reviewed and credited by name.

# datacard.yaml
name: your-dataset
source: contributed | lab | synthetic
collection: how it was gathered
coverage: what it includes
excludes: what it does not
license: CC-BY-NC-4.0
pii_review: required before publish

Contributor guide and discussion forum open before launch.

FAQ

Questions,
answered.

Nothing here requires talking to a salesperson. If it isn't covered, get in touch.

Yes. Seacurity is self-funded, plus donations — no grants, sponsors, or institutional backers. There is no paid tier and no plan to add one.

No. The data is free for research, education, and training — not for commercial use. The exact license terms are on each data card.

Three sources: corpora contributed by organizations, instrumented lab environments we run, and synthetic generation. The data card for each dataset says which.

It shouldn't be. Every release is reviewed and personal data is anonymized or removed. If you find something we missed, report it and we'll pull the affected version.

Not to browse or download. Workspaces and contributions require one so we can save your work and attribute it.

Get in touch with a description of the project. We extend resources for research groups, courses, and open-source work on a case-by-case basis.

Yes. Everything is on GitHub with packaging for self-hosting. The hosted version exists to skip setup, not to lock you in.

Newsletter

Release
notes.

One email when we publish new datasets or tools. Roughly monthly.

No account needed. Unsubscribe in one click.