ai-network-llms / datasets /llm2_input.jsonl
JoeiBanana's picture
Upload batch 5/8
8f9d821 verified
Raw
History Blame Contribute Delete
5.55 kB
{"instruction": "Analyze and correlate the following Wazuh alert with the Cisco running configuration. Determine which device, interface, VLAN, or ACL is related to the given indicators, and describe the affected network components.", "context_summary": "Incident type: port_scan. Severity: high, classification: suspicious. Indicators: none. Recommended actions: Block source IP 203.0.113.45 at firewall, Notify security team.", "wazuh_alert": {"incident_type": "port_scan", "classification": "suspicious", "severity": "high", "source_ip": "203.0.113.45", "destination_ip": "10.0.20.7", "ioc": ["203.0.113.45"], "recommended_actions": ["Block source IP 203.0.113.45 at firewall", "Notify security team"], "explanation": "A port scan is an attempt to probe multiple ports on a system, which can be indicative of malicious activity"}, "config_raw": ""}
{"instruction": "Analyze and correlate the following Wazuh alert with the Cisco running configuration. Determine which device, interface, VLAN, or ACL is related to the given indicators, and describe the affected network components.", "context_summary": "Incident type: data_exfiltration. Severity: high, classification: suspicious. Indicators: 10.1.1.15, 185.199.108.12. Recommended actions: Verify data transfer with network team, Review firewall rules and configurations.", "wazuh_alert": {"incident_type": "data_exfiltration", "classification": "suspicious", "severity": "high", "source_ip": "10.1.1.15", "destination_ip": "185.199.108.12", "iocs": ["10.1.1.15", "185.199.108.12"], "recommended_actions": ["Verify data transfer with network team", "Review firewall rules and configurations"], "explanation": "The event indicates a potential exfiltration of large amounts of data from the internal host to an external host over HTTPS"}, "config_raw": ""}
{"instruction": "Analyze and correlate the following Wazuh alert with the Cisco running configuration. Determine which device, interface, VLAN, or ACL is related to the given indicators, and describe the affected network components.", "context_summary": "Incident type: malware. Severity: high, classification: suspicious. Indicators: d41d8cd98f00b204e9800998ecf8427e. Recommended actions: Remove the malware, Run full system scan.", "wazuh_alert": {"incident_type": "malware", "classification": "suspicious", "severity": "high", "source_ip": null, "destination_ip": null, "iocs": ["d41d8cd98f00b204e9800998ecf8427e"], "recommended_actions": ["Remove the malware", "Run full system scan"], "explanation": "The Wazuh alert indicates that a malicious binary was detected on the system, which suggests potential malware activity. The recommended actions are to remove the malware and run a full system scan to ensure no further issues."}, "config_raw": ""}
{"instruction": "Analyze and correlate the following Wazuh alert with the Cisco running configuration. Determine which device, interface, VLAN, or ACL is related to the given indicators, and describe the affected network components.", "context_summary": "Incident type: bgp_route_table_anomaly. Severity: medium, classification: suspicious. Indicators: none. Recommended actions: Verify the BGP configuration on core-router-01, Check for any recent changes to the routing policy.", "wazuh_alert": {"incident_type": "bgp_route_table_anomaly", "classification": "suspicious", "severity": "medium", "source_ip": null, "destination_ip": "198.51.100.9", "ioc": ["10.0.0.0/8", "172.16.0.0/12"], "recommended_actions": ["Verify the BGP configuration on core-router-01", "Check for any recent changes to the routing policy"], "explanation": "The log indicates an unexpected prefix announcement from a peer router, which could be indicative of a potential security risk or misconfiguration."}, "config_raw": ""}
{"instruction": "Analyze and correlate the following Wazuh alert with the Cisco running configuration. Determine which device, interface, VLAN, or ACL is related to the given indicators, and describe the affected network components.", "context_summary": "Incident type: brute_force. Severity: high, classification: suspicious. Indicators: none. Recommended actions: Block source IP 192.0.2.111, Investigate further.", "wazuh_alert": {"incident_type": "brute_force", "classification": "suspicious", "severity": "high", "source_ip": "192.0.2.111", "destination_ip": null, "ioc_list": ["192.0.2.111"], "recommended_actions": ["Block source IP 192.0.2.111", "Investigate further"], "explanation": "This alert indicates a high volume of RDP authentication failures, which may indicate a brute force attack"}, "config_raw": ""}
{"instruction": "Analyze and correlate the following Wazuh alert with the Cisco running configuration. Determine which device, interface, VLAN, or ACL is related to the given indicators, and describe the affected network components.", "context_summary": "Incident type: suspicious. Severity: medium, classification: suspicious. Indicators: none. Recommended actions: Verify container logs for suspicious activity, Check for signs of unauthorized code execution.", "wazuh_alert": {"incident_type": "suspicious", "classification": "suspicious", "severity": "medium", "source_ip": "10.0.80.6", "destination_ip": "185.199.108.12", "ioc_list": ["185.199.108.12"], "recommended_actions": ["Verify container logs for suspicious activity", "Check for signs of unauthorized code execution"], "explanation": "This incident indicates that the container has been compromised by an external payload, which may lead to further malicious activity."}, "config_raw": ""}