Generate the traffic. Know the answer. Skip the full lab.
NetMetria models only the hosts, roles, and interactions required by a scenario. It generates repeatable network traffic, PCAP datasets, timelines, and ground truth without recreating the full network infrastructure. Community is the first public edition. Pro and Enterprise editions are also in development.
COMMUNITY RELEASE TARGET
September 2026Join the access list for release updates and evaluation opportunities.
Pro and Enterprise editions are also in development. Future edition details will be announced after capabilities are implemented and verified.
15supported ATT&CK-aligned behaviors
1declared scenario keeps the artifacts aligned
PCAP + GTpacket evidence with known context
PRODUCT ROADMAPCommunity first, with Pro and Enterprise in development
The actual bottleneck
The hard part is not opening a PCAP. It is producing the right traffic on purpose.
Purpose-built network traffic usually arrives after someone builds hosts, configures services, operates tools, captures packets, labels the result, and explains what happened. NetMetria starts with the evidence requirement instead.
CONVENTIONAL LAB WORKFLOW
Build the environment before the test can begin.
01Prepare hosts and network services
02Configure routes, tools, and capture points
03Operate the scenario and troubleshoot drift
04Capture, label, and explain the packet file
05Reset the environment before repeating it
NETMETRIA WORKFLOW
Define the network-observable behavior the test requires.
01Declare the relevant hosts and roles
02Sequence the required behaviors and timing
03Generate the packet dataset
04Validate against the attached answer key
05Repeat the declared scenario for comparison
Inspect the output
One capture. Fifteen behaviors. A packet-level story you can verify.
This Wireshark packet-list export shows traffic from a sample NetMetria PCAP. Use it to inspect the protocols, timing, endpoints, and behavior sequence represented in the initial Community release scope.
NetMetria keeps the scenario declaration, generated traffic, timing, and ground truth tied to the same run.
01
DECLARE
Model only the required hosts and roles.
Define the hosts, roles, target relationships, behavior sequence, and timing required by the validation question.
No unnecessary enterprise reconstruction
Defined scenario roles
Known behavior intent
02
GENERATE
Produce packet evidence directly.
Generate scenario-aligned network conversations and the associated dataset artifacts without operating a complete live lab.
Standard PCAP output
Controlled timing
Comparable generation runs
03
VALIDATE
Compare results with known answers.
Review detections, parser output, alerts, or analyst findings against the timeline, manifest, and ground truth.
Known evidence location
Known expected behavior
Faster regression review
Start with the question
What does your team need the traffic to prove?
The strongest NetMetria use cases begin with a specific validation question, not a generic request for “realistic traffic.”
Detection engineering
Will the rule fire on the behavior it was written to detect?
Test detection logic against known packet activity and compare the alert to the declared scenario.
Security product QA
Does the parser, sensor, or pipeline preserve the evidence correctly?
Exercise ingestion and extraction behavior using input with expected network activity.
Analyst training
Can the analyst find and explain what the scenario says is present?
Teach packet analysis with a trusted answer key available to the instructor.
Controlled research
Can two tools or methods be compared against the same input?
Use repeatable conditions for experiments, demonstrations, and comparative evaluation.
NetMetria editions
Community is the first public edition, not the end of the platform.
The initial Community release is planned for September 2026 and provides the core scenario-generation workflow with a defined 15-behavior launch scope. Pro and Enterprise editions are in development to extend NetMetria beyond the initial public release. Detailed capabilities and availability will be announced only after they are implemented and verified.
CommunityPlanned September 2026
Core scenario-to-PCAP generation.
Designed for technical users who want to evaluate NetMetria in detection, product-testing, training, research, and lab workflows.
Linux command-line workflow
15 ATT&CK-aligned behaviors at initial release
PCAP, timeline, manifest, and ground truth
Repeatable output from declared scenario input
ProIn development
Expanded technical workflows.
Pro is being developed for broader behavior coverage and more advanced scenario and dataset requirements.
Specific capabilities, packaging, and availability have not yet been announced.
EnterpriseIn development
Organizational deployment needs.
Enterprise is being developed for organizations that require additional deployment, management, and operational capabilities.
Specific capabilities, packaging, and availability have not yet been announced.
The current access list is centered on Community.Members may also receive future announcements about Pro and Enterprise as those editions are defined and verified.
Community access list
Be among the first to evaluate NetMetria Community.
Join for release updates and opportunities to try NetMetria Community, planned for September 2026. The list may also be used for future Pro and Enterprise announcements as those editions are defined.
01
Join the release listReceive Community status and availability updates
02
Describe your intended useDetection, testing, training, research, or lab development
03
Follow the product roadmapReceive future Pro and Enterprise announcements when verified
This is an interest list, not a sales inquiry.No phone number is requested. A confirmation is emailed after the form is submitted.
ACCESS LIST CONFIRMED
You are on the NetMetria Community access list.
A confirmation was sent to your email address. Community release updates and future edition announcements will come from contact@netmetria.com.
Product boundary
Focused network evidence for defined scenarios.
NetMetria is built to
Model scenario-relevant hosts and interactions
Generate network-observable behavior
Produce PCAP with timing and ground truth
Support controlled validation and comparison
NetMetria is not built to
Execute malware or payloads
Emulate complete endpoint state
Operate live command-and-control infrastructure
Replace a cyber range when live systems are required
Technical evaluation
What to understand before joining the Community list.
Technical boundaries, the initial Community scope, the edition roadmap, and what joining the access list means.
How is NetMetria different from replaying an existing PCAP?
Packet replay reproduces traffic that has already been captured. NetMetria generates a new dataset from a declared scenario: the relevant hosts, their roles, the ordered behaviors, timing, and intended network-visible results. The resulting PCAP remains tied to the scenario definition and its ground truth.
How is NetMetria different from a cyber range?
A cyber range operates real or virtual systems so activity can occur within a live environment. NetMetria does not recreate that environment. It models only the hosts, roles, and interactions needed to generate the scenario’s network-observable traffic. A range remains appropriate when endpoint state, user interaction, live tooling, or system compromise must be part of the exercise.
What does “known-answer PCAP” mean?
The packet capture is accompanied by information describing what the scenario was designed to produce: the behavior sequence, timing, participating hosts, generated flows, and expected results. Analysts and engineers can compare what their tools detected against what was intentionally placed in the dataset.
How are hosts selected for a scenario?
A host is included when it has a defined role in the scenario. That role may involve originating traffic, receiving traffic, supporting an intermediate step, or producing ambient activity. NetMetria does not model unrelated systems merely to make the scenario resemble a complete enterprise network.
Can background traffic be included?
Yes. Background traffic follows the same scenario-role model. Additional synthetic hosts or logical traffic sources can be included when their role is to generate ambient activity around the primary behavior. The sample shown on this page excludes background traffic so the 15 supported behaviors can be inspected without unrelated packets.
How repeatable is the generated traffic?
The same declared scenario and generation inputs produce comparable packet output, timing, manifests, and ground-truth records. This allows a dataset to be reused for rule development, parser testing, regression analysis, training, and controlled comparison.
How realistic is the generated traffic?
NetMetria is designed for controlled network-behavior representation, not unrestricted emulation of every implementation detail found in a live enterprise. Fidelity should be judged against the validation objective: whether the dataset contains the packet structures, ordering, timing, endpoints, and protocol activity required by the test.
Does NetMetria execute malware or compromise endpoints?
No. NetMetria generates network-observable traffic associated with declared behaviors. It does not execute malware, exploit systems, establish live command infrastructure, or modify endpoint state.
What is included in the initial NetMetria Community release?
Community is the first public edition and is planned for release in September 2026. Its initial release includes the Linux command-line workflow, 15 ATT&CK-aligned network behaviors, and dataset outputs that include PCAP, timeline, manifest, and ground truth. The 15-behavior set is the Community launch scope, not a permanent limit on the broader NetMetria platform.
How do Pro and Enterprise relate to Community?
Pro and Enterprise are additional NetMetria editions in development. Pro is intended to extend behavior coverage and advanced technical workflows. Enterprise is intended to address additional organizational deployment, management, and operational requirements. Detailed capabilities, packaging, and availability will be announced only after they are implemented and verified.
What does joining the Community access list mean?
The list is primarily used for Community release updates and opportunities to evaluate the first public edition. It may also be used for future Pro and Enterprise announcements. Information about intended use helps guide examples and documentation. Joining does not guarantee immediate access, a specific release date, or inclusion in every evaluation group.
NetMetria access list
Inspect the traffic. Understand the model. Start with Community.