Focused Scenario
A compact scenario for quickly identifying hosts, relationships, services, and scenario-driven activity.
Download PCAP ↓Cybersecurity network dataset generation
NetMetria creates ATT&CK-aligned network traffic and ground truth for detection engineering, security-tool testing, training, and research. Generate the traffic you need for a specific test without recreating every system involved in the scenario.
Inspect the output first
Three NetMetria-generated PCAPs are available without registration. Open one in Wireshark, tshark, tcpdump, or your normal analysis stack and judge the traffic directly.
A compact scenario for quickly identifying hosts, relationships, services, and scenario-driven activity.
Download PCAP ↓More activity, more flows, and a longer observation window for correlation and detection work.
Download PCAP ↓The densest public sample, with more competing evidence and a longer sequence to reconstruct.
Download PCAP ↓The full Samples page explains each capture, its scope, integrity hash, and suggested analyst starting points.
The problem
Conventional dataset creation may require hosts, services, network configuration, attacker tooling, scenario execution, capture setup, packet attribution, labeling, and environment reset. The packet capture itself is only one step in the process.
The target is network-observable evidence tied to a defined scenario.
The NetMetria approach
NetMetria generates network datasets from defined scenarios. It models the hosts, services, and interactions required for the network evidence instead of requiring a complete live environment.
Specify the roles, environment, and supported network behavior required for the test.
Generate the protocol traffic associated with the defined scenario.
Use the accompanying ground truth to identify the expected activity, roles, timing, and ATT&CK attribution represented in the dataset.
Why NetMetria
Use NetMetria when you need scenario-specific network traffic for a test, a detection change, a training exercise, or an analysis task.
Avoid constructing a complete attack environment when the desired output is network evidence.
Keep packet attribution tied to the scenario instead of rebuilding it manually after capture.
Generate related datasets from defined scenario conditions for regression testing, rule evaluation, and before-and-after comparisons.
Generate inspectable network traffic for supported ATT&CK-aligned behavior.
Use cases
The primary audience is detection engineering. The same datasets can also support security-product testing, training, research, regression testing, and benchmarking.
Generate traffic while developing or changing detections, then compare the result against known expected activity.
Generate scenario-driven traffic when testing IDS, IPS, NDR, SIEM, firewall, parser, or analytics changes.
Prepare scenario-driven packet exercises without building and resetting a full lab each time.
Create fresh datasets and scenario variations for regression checks, comparative analysis, and benchmarking.
Realism and validation
Validation checks packet structure, protocol behavior, conversation coherence, endpoint characteristics, timing, identifiers, and known synthetic-generator artifacts. Automated validation is in place; independent expert review of the final public captures is still pending.
NetMetria Explorer
Explorer is a Linux-based release with 15 currently supported ATT&CK-aligned network behaviors. It generates PCAP datasets with ground truth. The 15-behavior count describes Explorer today; it is not a platform-wide coverage claim.