Cybersecurity network dataset generation

Generate adversary network datasets without building the attack lab.

NetMetria creates ATT&CK-aligned network traffic and ground truth for detection engineering, security-tool testing, training, and research. Generate the traffic you need for a specific test without recreating every system involved in the scenario.

Inspect the output first

Inspect the traffic before reading further.

Three NetMetria-generated PCAPs are available without registration. Open one in Wireshark, tshark, tcpdump, or your normal analysis stack and judge the traffic directly.

NM-SAMPLE-001EASY

Focused Scenario

A compact scenario for quickly identifying hosts, relationships, services, and scenario-driven activity.

Download PCAP ↓
NM-SAMPLE-002INTERMEDIATE

Multi-Behavior Scenario

More activity, more flows, and a longer observation window for correlation and detection work.

Download PCAP ↓
NM-SAMPLE-003ADVANCED

Complex Scenario

The densest public sample, with more competing evidence and a longer sequence to reconstruct.

Download PCAP ↓
Want the scenario context and hashes?

The full Samples page explains each capture, its scope, integrity hash, and suggested analyst starting points.

Open sample library

The problem

Producing the traffic can require far more work than capturing it.

Conventional dataset creation may require hosts, services, network configuration, attacker tooling, scenario execution, capture setup, packet attribution, labeling, and environment reset. The packet capture itself is only one step in the process.

CONVENTIONAL WORKFLOW
  1. Build hosts and services
  2. Configure networking and segmentation
  3. Prepare attacker tooling and scenario
  4. Execute the activity
  5. Capture and isolate relevant traffic
  6. Label and map the activity
  7. Reset and repeat for the next test
NETMETRIA
  1. Define the scenario
  2. Generate the network dataset
  3. Analyze against known context

The target is network-observable evidence tied to a defined scenario.

The NetMetria approach

Define the scenario, generate the traffic, and keep the ground truth with it.

NetMetria generates network datasets from defined scenarios. It models the hosts, services, and interactions required for the network evidence instead of requiring a complete live environment.

01

Define the scenario

Specify the roles, environment, and supported network behavior required for the test.

02

Generate the dataset

Generate the protocol traffic associated with the defined scenario.

03

Review with ground truth

Use the accompanying ground truth to identify the expected activity, roles, timing, and ATT&CK attribution represented in the dataset.

ObservationWhat the sensor sees: packets, flows, services, timing, conversations.
Ground truthWhat the dataset represents: scenario actions, roles, behavior, timing, and ATT&CK attribution.
How ground truth fits →

Why NetMetria

NetMetria is built to create test datasets, not isolated packets.

Use NetMetria when you need scenario-specific network traffic for a test, a detection change, a training exercise, or an analysis task.

Reduce lab-building burden

Avoid constructing a complete attack environment when the desired output is network evidence.

Preserve ground truth

Keep packet attribution tied to the scenario instead of rebuilding it manually after capture.

Create comparable datasets

Generate related datasets from defined scenario conditions for regression testing, rule evaluation, and before-and-after comparisons.

Connect ATT&CK behavior to packet evidence

Generate inspectable network traffic for supported ATT&CK-aligned behavior.

Use cases

Built for teams that test network-visible security behavior.

The primary audience is detection engineering. The same datasets can also support security-product testing, training, research, regression testing, and benchmarking.

Detection engineering

Generate traffic while developing or changing detections, then compare the result against known expected activity.

Security-product testing

Generate scenario-driven traffic when testing IDS, IPS, NDR, SIEM, firewall, parser, or analytics changes.

Training

Prepare scenario-driven packet exercises without building and resetting a full lab each time.

Research and QA

Create fresh datasets and scenario variations for regression checks, comparative analysis, and benchmarking.

Realism and validation

Realism requires more than packets that decode correctly.

Validation checks packet structure, protocol behavior, conversation coherence, endpoint characteristics, timing, identifiers, and known synthetic-generator artifacts. Automated validation is in place; independent expert review of the final public captures is still pending.

Protocol framingTCP behaviorChecksumsDNS / SMB / HTTP behaviorTiming and conversation structureSynthetic fingerprint checks

NetMetria Explorer

NetMetria Explorer is the current release.

Explorer is a Linux-based release with 15 currently supported ATT&CK-aligned network behaviors. It generates PCAP datasets with ground truth. The 15-behavior count describes Explorer today; it is not a platform-wide coverage claim.