Scenario → packets → known answers

Generate the traffic.
Know the answer.
Skip the full lab.

NetMetria models only the hosts, roles, and interactions required by a scenario. It generates repeatable network traffic, PCAP datasets, timelines, and ground truth without recreating the full network infrastructure. Community is the first public edition. Pro and Enterprise editions are also in development.

COMMUNITY RELEASE TARGET
September 2026 Join the access list for release updates and evaluation opportunities.

Pro and Enterprise editions are also in development. Future edition details will be announced after capabilities are implemented and verified.

15supported ATT&CK-aligned behaviors
1declared scenario keeps the artifacts aligned
PCAP + GTpacket evidence with known context
PRODUCT ROADMAPCommunity first, with Pro and Enterprise in development

The actual bottleneck

The hard part is not opening a PCAP. It is producing the right traffic on purpose.

Purpose-built network traffic usually arrives after someone builds hosts, configures services, operates tools, captures packets, labels the result, and explains what happened. NetMetria starts with the evidence requirement instead.

CONVENTIONAL LAB WORKFLOW

Build the environment before the test can begin.

  1. 01Prepare hosts and network services
  2. 02Configure routes, tools, and capture points
  3. 03Operate the scenario and troubleshoot drift
  4. 04Capture, label, and explain the packet file
  5. 05Reset the environment before repeating it
NETMETRIA WORKFLOW

Define the network-observable behavior the test requires.

  1. 01Declare the relevant hosts and roles
  2. 02Sequence the required behaviors and timing
  3. 03Generate the packet dataset
  4. 04Validate against the attached answer key
  5. 05Repeat the declared scenario for comparison

Inspect the output

One capture. Fifteen behaviors. A packet-level story you can verify.

This Wireshark packet-list export shows traffic from a sample NetMetria PCAP. Use it to inspect the protocols, timing, endpoints, and behavior sequence represented in the initial Community release scope.

Join the Community access list →
181packets in the export
15ATT&CK-aligned behaviors
SMB2 · TCP · UDP · TLS · HTTPobservable protocol activity
KNOWN ORDERbehavior ranges mapped to the timeline
sample_pcap.txt · Wireshark packet-list export
SHOWING: ALL 181 PACKETS SELECT A BEHAVIOR ABOVE TO HIGHLIGHT ITS PACKET RANGE
No.  Time         Source        Destination   Protocol   Length  Info1    0.000000     192.168.1.10  192.168.1.20  TCP        74      49152 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728505099 TSecr=0 WS=2562    0.000213     192.168.1.20  192.168.1.10  TCP        74      445 → 49152 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672586938 TSecr=728505099 WS=1283    0.000356     192.168.1.10  192.168.1.20  TCP        54      49152 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=04    0.001876     192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$5    0.003109     192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response6    0.004147     192.168.1.10  192.168.1.20  SMB2       190     Create Request File: srvsvc7    0.006022     192.168.1.20  192.168.1.10  SMB2       210     Create Response File: srvsvc8    0.006848     192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc9    0.008511     192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc10   0.009083     192.168.1.10  192.168.1.20  SMB2       146     Close Request File: srvsvc11   0.010007     192.168.1.20  192.168.1.10  SMB2       182     Close Response12   0.010581     192.168.1.10  192.168.1.20  TCP        54      49152 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=013   0.010666     192.168.1.20  192.168.1.10  TCP        54      445 → 49152 [ACK] Seq=525 Ack=504 Win=8340480 Len=014   0.011288     192.168.1.20  192.168.1.10  TCP        54      445 → 49152 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=015   0.011384     192.168.1.10  192.168.1.20  TCP        54      49152 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=016   102.405724   192.168.1.10  192.168.1.20  TCP        74      49153 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728607504 TSecr=0 WS=25617   102.405984   192.168.1.20  192.168.1.10  TCP        74      445 → 49153 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672689344 TSecr=728607504 WS=12818   102.406064   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=019   102.407174   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$20   102.408137   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response21   102.409493   192.168.1.10  192.168.1.20  SMB2       190     Create Request File: srvsvc22   102.410722   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: srvsvc23   102.412334   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc24   102.414139   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc25   102.415365   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: srvsvc26   102.416507   192.168.1.20  192.168.1.10  SMB2       182     Close Response27   102.416589   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [ACK] Seq=503 Ack=525 Win=16445440 Len=028   102.417409   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=029   102.417548   192.168.1.20  192.168.1.10  TCP        54      445 → 49153 [ACK] Seq=525 Ack=504 Win=8340480 Len=030   102.418488   192.168.1.20  192.168.1.10  TCP        54      445 → 49153 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=031   102.418562   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=032   214.682241   192.168.1.10  192.168.1.20  TCP        74      49154 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728719781 TSecr=0 WS=25633   214.682484   192.168.1.20  192.168.1.10  TCP        74      445 → 49154 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672801620 TSecr=728719781 WS=12834   214.682557   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=035   214.683526   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$36   214.685388   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response37   214.685971   192.168.1.10  192.168.1.20  SMB2       186     Create Request File: samr38   214.688159   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: samr39   214.689184   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: samr40   214.690198   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: samr41   214.691489   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: samr42   214.693556   192.168.1.20  192.168.1.10  SMB2       182     Close Response43   214.693677   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [ACK] Seq=499 Ack=525 Win=16445440 Len=044   214.694484   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [FIN, ACK] Seq=499 Ack=525 Win=16445440 Len=045   214.694630   192.168.1.20  192.168.1.10  TCP        54      445 → 49154 [ACK] Seq=525 Ack=500 Win=8340480 Len=046   214.695157   192.168.1.20  192.168.1.10  TCP        54      445 → 49154 [FIN, ACK] Seq=525 Ack=500 Win=8340480 Len=047   214.695330   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [ACK] Seq=500 Ack=526 Win=16445440 Len=048   327.536659   192.168.1.10  192.168.1.20  TCP        74      49155 → 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728832635 TSecr=0 WS=25649   327.537014   192.168.1.20  192.168.1.10  TCP        74      80 → 49155 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672914475 TSecr=728832635 WS=12850   327.537591   192.168.1.10  192.168.1.20  TCP        54      49155 → 80 [RST] Seq=1 Win=16445440 Len=051   411.558516   192.168.1.10  192.168.1.20  TCP        74      49156 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728916657 TSecr=0 WS=25652   411.558739   192.168.1.20  192.168.1.10  TCP        74      445 → 49156 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672998496 TSecr=728916657 WS=12853   411.558820   192.168.1.10  192.168.1.20  TCP        54      49156 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=054   411.559737   192.168.1.10  192.168.1.20  SMB2       168     Negotiate Protocol Request55   411.560377   192.168.1.10  192.168.1.20  TCP        54      49156 → 445 [FIN, ACK] Seq=115 Ack=1 Win=16445440 Len=056   411.560476   192.168.1.20  192.168.1.10  TCP        54      445 → 49156 [ACK] Seq=1 Ack=116 Win=8340480 Len=057   411.561082   192.168.1.20  192.168.1.10  TCP        54      445 → 49156 [FIN, ACK] Seq=1 Ack=116 Win=8340480 Len=058   411.561212   192.168.1.10  192.168.1.20  TCP        54      49156 → 445 [ACK] Seq=116 Ack=2 Win=16445440 Len=059   532.899823   192.168.1.10  192.168.1.20  TCP        74      49157 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729037998 TSecr=0 WS=25660   532.900188   192.168.1.20  192.168.1.10  TCP        74      445 → 49157 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673119838 TSecr=729037998 WS=12861   532.900363   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=062   532.901843   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$63   532.903676   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response64   532.904402   192.168.1.10  192.168.1.20  SMB2       190     Create Request File: svcctl65   532.906589   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: svcctl66   532.907442   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl67   532.909084   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl68   532.910288   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: svcctl69   532.912740   192.168.1.20  192.168.1.10  SMB2       182     Close Response70   532.912892   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [ACK] Seq=503 Ack=525 Win=16445440 Len=071   532.913364   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=072   532.913441   192.168.1.20  192.168.1.10  TCP        54      445 → 49157 [ACK] Seq=525 Ack=504 Win=8340480 Len=073   532.914379   192.168.1.20  192.168.1.10  TCP        54      445 → 49157 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=074   532.914479   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=075   631.527495   192.168.1.10  192.168.1.20  TCP        74      49158 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729136626 TSecr=0 WS=25676   631.527775   192.168.1.20  192.168.1.10  TCP        74      445 → 49158 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673218465 TSecr=729136626 WS=12877   631.527847   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=078   631.528486   192.168.1.10  192.168.1.20  SMB2       184     Tree Connect Request Tree: \\files.corp.example\ADMIN$79   631.530638   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response80   631.531955   192.168.1.10  192.168.1.20  SMB2       206     Create Request File: q4-summary.bin81   631.533065   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: q4-summary.bin82   631.533422   192.168.1.10  192.168.1.20  SMB2       266     Write Request Len:96 Off:083   631.535295   192.168.1.20  192.168.1.10  SMB2       138     Write Response84   631.535832   192.168.1.10  192.168.1.20  SMB2       146     Close Request85   631.537733   192.168.1.20  192.168.1.10  SMB2       182     Close Response86   631.537856   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [ACK] Seq=587 Ack=453 Win=16445440 Len=087   631.538733   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [FIN, ACK] Seq=587 Ack=453 Win=16445440 Len=088   631.538867   192.168.1.20  192.168.1.10  TCP        54      445 → 49158 [ACK] Seq=453 Ack=588 Win=8340480 Len=089   631.539222   192.168.1.20  192.168.1.10  TCP        54      445 → 49158 [FIN, ACK] Seq=453 Ack=588 Win=8340480 Len=090   631.539327   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [ACK] Seq=588 Ack=454 Win=16445440 Len=091   727.607329   192.168.1.10  192.168.1.20  TCP        74      49159 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729232706 TSecr=0 WS=25692   727.607549   192.168.1.20  192.168.1.10  TCP        74      445 → 49159 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673314545 TSecr=729232706 WS=12893   727.607677   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=094   727.608709   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$95   727.610158   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response96   727.610836   192.168.1.10  192.168.1.20  SMB2       190     Create Request File: svcctl97   727.611807   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: svcctl98   727.612725   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl99   727.614736   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl100  727.616356   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: svcctl101  727.617592   192.168.1.20  192.168.1.10  SMB2       182     Close Response102  727.617682   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [ACK] Seq=503 Ack=525 Win=16445440 Len=0103  727.618506   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=0104  727.618641   192.168.1.20  192.168.1.10  TCP        54      445 → 49159 [ACK] Seq=525 Ack=504 Win=8340480 Len=0105  727.619137   192.168.1.20  192.168.1.10  TCP        54      445 → 49159 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=0106  727.619315   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=0107  850.790822   192.168.1.10  192.168.1.30  TCP        74      49160 → 8443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729355889 TSecr=0 WS=256108  850.791125   192.168.1.30  192.168.1.10  TCP        74      8443 → 49160 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=1877069036 TSecr=729355889 WS=128109  850.791286   192.168.1.10  192.168.1.30  TCP        54      49160 → 8443 [ACK] Seq=1 Ack=1 Win=16445440 Len=0110  850.792091   192.168.1.10  192.168.1.30  TLSv1.3    191     Client Hello (SNI=assets.corp.example)111  850.792665   192.168.1.30  192.168.1.10  TLSv1.3    109     Server Hello112  850.793835   192.168.1.10  192.168.1.30  TLSv1.3    231     Application Data113  850.795173   192.168.1.30  192.168.1.10  TLSv1.3    145     Application Data114  850.795958   192.168.1.10  192.168.1.30  TCP        54      49160 → 8443 [FIN, ACK] Seq=315 Ack=147 Win=16445440 Len=0115  850.796042   192.168.1.30  192.168.1.10  TCP        54      8443 → 49160 [ACK] Seq=147 Ack=316 Win=8340480 Len=0116  850.796855   192.168.1.30  192.168.1.10  TCP        54      8443 → 49160 [FIN, ACK] Seq=147 Ack=316 Win=8340480 Len=0117  850.797025   192.168.1.10  192.168.1.30  TCP        54      49160 → 8443 [ACK] Seq=316 Ack=148 Win=16445440 Len=0118  955.700886   192.168.1.10  192.168.1.20  UDP        92      49161 → 8444 Len=50119  955.701797   192.168.1.20  192.168.1.10  UDP        106     8444 → 49161 Len=64120  955.703353   192.168.1.10  192.168.1.20  UDP        99      49161 → 8444 Len=57121  955.704710   192.168.1.20  192.168.1.10  UDP        117     8444 → 49161 Len=75122  955.706252   192.168.1.10  192.168.1.20  UDP        90      49161 → 8444 Len=48123  955.706755   192.168.1.20  192.168.1.10  UDP        102     8444 → 49161 Len=60124  1034.261722  192.168.1.10  192.168.1.20  TCP        74      49162 → 8445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729539360 TSecr=0 WS=256125  1034.261912  192.168.1.20  192.168.1.10  TCP        74      8445 → 49162 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673621199 TSecr=729539360 WS=128126  1034.262032  192.168.1.10  192.168.1.20  TCP        54      49162 → 8445 [ACK] Seq=1 Ack=1 Win=16445440 Len=0127  1034.262711  192.168.1.10  192.168.1.20  TLSv1.3    191     Client Hello (SNI=assets.corp.example)128  1034.263671  192.168.1.20  192.168.1.10  TLSv1.3    109     Server Hello129  1034.264210  192.168.1.10  192.168.1.20  TLSv1.3    155     Application Data130  1034.265129  192.168.1.10  192.168.1.20  TCP        54      49162 → 8445 [FIN, ACK] Seq=239 Ack=56 Win=16445440 Len=0131  1034.265215  192.168.1.20  192.168.1.10  TCP        54      8445 → 49162 [ACK] Seq=56 Ack=240 Win=8340480 Len=0132  1034.266158  192.168.1.20  192.168.1.10  TCP        54      8445 → 49162 [FIN, ACK] Seq=56 Ack=240 Win=8340480 Len=0133  1034.266247  192.168.1.10  192.168.1.20  TCP        54      49162 → 8445 [ACK] Seq=240 Ack=57 Win=16445440 Len=0134  1157.164158  192.168.1.10  192.168.1.30  TCP        74      49163 → 8444 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729662263 TSecr=0 WS=256135  1157.164386  192.168.1.30  192.168.1.10  TCP        74      8444 → 49163 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=1877375409 TSecr=729662263 WS=128136  1157.164524  192.168.1.10  192.168.1.30  TCP        54      49163 → 8444 [ACK] Seq=1 Ack=1 Win=16445440 Len=0137  1157.165140  192.168.1.10  192.168.1.30  TLSv1.3    191     Client Hello (SNI=assets.corp.example)138  1157.166091  192.168.1.30  192.168.1.10  TLSv1.3    109     Server Hello139  1157.166836  192.168.1.10  192.168.1.30  TLSv1.3    243     Application Data140  1157.168665  192.168.1.30  192.168.1.10  TLSv1.3    147     Application Data141  1157.169528  192.168.1.10  192.168.1.30  TCP        54      49163 → 8444 [FIN, ACK] Seq=327 Ack=149 Win=16445440 Len=0142  1157.169634  192.168.1.30  192.168.1.10  TCP        54      8444 → 49163 [ACK] Seq=149 Ack=328 Win=8340480 Len=0143  1157.170215  192.168.1.30  192.168.1.10  TCP        54      8444 → 49163 [FIN, ACK] Seq=149 Ack=328 Win=8340480 Len=0144  1157.170387  192.168.1.10  192.168.1.30  TCP        54      49163 → 8444 [ACK] Seq=328 Ack=150 Win=16445440 Len=0145  1239.352005  192.168.1.10  192.168.1.20  TCP        74      49164 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729744451 TSecr=0 WS=256146  1239.352300  192.168.1.20  192.168.1.10  TCP        74      445 → 49164 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673826290 TSecr=729744451 WS=128147  1239.352407  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=0148  1239.353387  192.168.1.10  192.168.1.20  SMB2       184     Tree Connect Request Tree: \\files.corp.example\ADMIN$149  1239.355808  192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response150  1239.356586  192.168.1.10  192.168.1.20  SMB2       206     Create Request File: q4-summary.bin151  1239.358001  192.168.1.20  192.168.1.10  SMB2       210     Create Response File: q4-summary.bin152  1239.358775  192.168.1.10  192.168.1.20  SMB2       266     Write Request Len:96 Off:0153  1239.361165  192.168.1.20  192.168.1.10  SMB2       138     Write Response154  1239.362565  192.168.1.10  192.168.1.20  SMB2       146     Close Request155  1239.363725  192.168.1.20  192.168.1.10  SMB2       182     Close Response156  1239.363889  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [ACK] Seq=587 Ack=453 Win=16445440 Len=0157  1239.364869  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [FIN, ACK] Seq=587 Ack=453 Win=16445440 Len=0158  1239.364982  192.168.1.20  192.168.1.10  TCP        54      445 → 49164 [ACK] Seq=453 Ack=588 Win=8340480 Len=0159  1239.365680  192.168.1.20  192.168.1.10  TCP        54      445 → 49164 [FIN, ACK] Seq=453 Ack=588 Win=8340480 Len=0160  1239.365756  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [ACK] Seq=588 Ack=454 Win=16445440 Len=0161  1366.301670  192.168.1.10  192.168.1.20  TCP        74      49165 → 8080 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729871400 TSecr=0 WS=256162  1366.301919  192.168.1.20  192.168.1.10  TCP        74      8080 → 49165 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673953239 TSecr=729871400 WS=128163  1366.302022  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [ACK] Seq=1 Ack=1 Win=16445440 Len=0164  1366.302639  192.168.1.10  192.168.1.20  HTTP       413     GET /assets/v2/health/check?rid=a20e HTTP/1.1 165  1366.304389  192.168.1.20  192.168.1.10  HTTP       232     HTTP/1.1 204 No Content 166  1366.304476  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [ACK] Seq=360 Ack=179 Win=16445440 Len=0167  1366.304748  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [FIN, ACK] Seq=360 Ack=179 Win=16445440 Len=0168  1366.304899  192.168.1.20  192.168.1.10  TCP        54      8080 → 49165 [ACK] Seq=179 Ack=361 Win=8340480 Len=0169  1366.305375  192.168.1.20  192.168.1.10  TCP        54      8080 → 49165 [FIN, ACK] Seq=179 Ack=361 Win=8340480 Len=0170  1366.305513  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [ACK] Seq=361 Ack=180 Win=16445440 Len=0171  1465.903962  192.168.1.10  192.168.1.30  TCP        74      49166 → 8080 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729971002 TSecr=0 WS=256172  1465.904224  192.168.1.30  192.168.1.10  TCP        74      8080 → 49166 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=1877684149 TSecr=729971002 WS=128173  1465.904304  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [ACK] Seq=1 Ack=1 Win=16445440 Len=0174  1465.905940  192.168.1.10  192.168.1.30  TCP        466     49166 → 8080 [PSH, ACK] Seq=1 Ack=1 Win=16445440 Len=412 [TCP segment of a reassembled PDU]175  1465.906929  192.168.1.10  192.168.1.30  HTTP/JSON  339     POST /files/v1/uploads/session/ee6723 HTTP/1.1 , JSON (application/json)176  1465.909354  192.168.1.30  192.168.1.10  HTTP/JSON  432     HTTP/1.1 200 OK , JSON (application/json)177  1465.909454  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [ACK] Seq=698 Ack=379 Win=16445440 Len=0178  1465.909864  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [FIN, ACK] Seq=698 Ack=379 Win=16445440 Len=0179  1465.909955  192.168.1.30  192.168.1.10  TCP        54      8080 → 49166 [ACK] Seq=379 Ack=699 Win=8340480 Len=0180  1465.910551  192.168.1.30  192.168.1.10  TCP        54      8080 → 49166 [FIN, ACK] Seq=379 Ack=699 Win=8340480 Len=0181  1465.910726  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [ACK] Seq=699 Ack=380 Win=16445440 Len=0

Evaluate the public release

Join the list for NetMetria Community.

Receive release updates and an opportunity to evaluate the initial public version against your own detection, testing, training, or research workflow.

Join the access list

From intent to validation

Three stages. One linked dataset.

NetMetria keeps the scenario declaration, generated traffic, timing, and ground truth tied to the same run.

01

DECLARE

Model only the required hosts and roles.

Define the hosts, roles, target relationships, behavior sequence, and timing required by the validation question.

  • No unnecessary enterprise reconstruction
  • Defined scenario roles
  • Known behavior intent
02

GENERATE

Produce packet evidence directly.

Generate scenario-aligned network conversations and the associated dataset artifacts without operating a complete live lab.

  • Standard PCAP output
  • Controlled timing
  • Comparable generation runs
03

VALIDATE

Compare results with known answers.

Review detections, parser output, alerts, or analyst findings against the timeline, manifest, and ground truth.

  • Known evidence location
  • Known expected behavior
  • Faster regression review

Start with the question

What does your team need the traffic to prove?

The strongest NetMetria use cases begin with a specific validation question, not a generic request for “realistic traffic.”

Detection engineering

Will the rule fire on the behavior it was written to detect?

Test detection logic against known packet activity and compare the alert to the declared scenario.

Security product QA

Does the parser, sensor, or pipeline preserve the evidence correctly?

Exercise ingestion and extraction behavior using input with expected network activity.

Analyst training

Can the analyst find and explain what the scenario says is present?

Teach packet analysis with a trusted answer key available to the instructor.

Controlled research

Can two tools or methods be compared against the same input?

Use repeatable conditions for experiments, demonstrations, and comparative evaluation.

NetMetria editions

Community is the first public edition, not the end of the platform.

The initial Community release is planned for September 2026 and provides the core scenario-generation workflow with a defined 15-behavior launch scope. Pro and Enterprise editions are in development to extend NetMetria beyond the initial public release. Detailed capabilities and availability will be announced only after they are implemented and verified.

Community Planned September 2026

Core scenario-to-PCAP generation.

Designed for technical users who want to evaluate NetMetria in detection, product-testing, training, research, and lab workflows.

  • Linux command-line workflow
  • 15 ATT&CK-aligned behaviors at initial release
  • PCAP, timeline, manifest, and ground truth
  • Repeatable output from declared scenario input
Pro In development

Expanded technical workflows.

Pro is being developed for broader behavior coverage and more advanced scenario and dataset requirements.

Specific capabilities, packaging, and availability have not yet been announced.

Enterprise In development

Organizational deployment needs.

Enterprise is being developed for organizations that require additional deployment, management, and operational capabilities.

Specific capabilities, packaging, and availability have not yet been announced.

The current access list is centered on Community. Members may also receive future announcements about Pro and Enterprise as those editions are defined and verified.

Community access list

Be among the first to evaluate NetMetria Community.

Join for release updates and opportunities to try NetMetria Community, planned for September 2026. The list may also be used for future Pro and Enterprise announcements as those editions are defined.

  1. 01
    Join the release listReceive Community status and availability updates
  2. 02
    Describe your intended useDetection, testing, training, research, or lab development
  3. 03
    Follow the product roadmapReceive future Pro and Enterprise announcements when verified
This is an interest list, not a sales inquiry. No phone number is requested. A confirmation is emailed after the form is submitted.
Join the Community access listCommunity access and product updates
Primary area of interest

A confirmation will be sent to the email address provided.

Product boundary

Focused network evidence for defined scenarios.

NetMetria is built to
  • Model scenario-relevant hosts and interactions
  • Generate network-observable behavior
  • Produce PCAP with timing and ground truth
  • Support controlled validation and comparison
NetMetria is not built to
  • Execute malware or payloads
  • Emulate complete endpoint state
  • Operate live command-and-control infrastructure
  • Replace a cyber range when live systems are required

Technical evaluation

What to understand before joining the Community list.

Technical boundaries, the initial Community scope, the edition roadmap, and what joining the access list means.

How is NetMetria different from replaying an existing PCAP?

Packet replay reproduces traffic that has already been captured. NetMetria generates a new dataset from a declared scenario: the relevant hosts, their roles, the ordered behaviors, timing, and intended network-visible results. The resulting PCAP remains tied to the scenario definition and its ground truth.

How is NetMetria different from a cyber range?

A cyber range operates real or virtual systems so activity can occur within a live environment. NetMetria does not recreate that environment. It models only the hosts, roles, and interactions needed to generate the scenario’s network-observable traffic. A range remains appropriate when endpoint state, user interaction, live tooling, or system compromise must be part of the exercise.

What does “known-answer PCAP” mean?

The packet capture is accompanied by information describing what the scenario was designed to produce: the behavior sequence, timing, participating hosts, generated flows, and expected results. Analysts and engineers can compare what their tools detected against what was intentionally placed in the dataset.

How are hosts selected for a scenario?

A host is included when it has a defined role in the scenario. That role may involve originating traffic, receiving traffic, supporting an intermediate step, or producing ambient activity. NetMetria does not model unrelated systems merely to make the scenario resemble a complete enterprise network.

Can background traffic be included?

Yes. Background traffic follows the same scenario-role model. Additional synthetic hosts or logical traffic sources can be included when their role is to generate ambient activity around the primary behavior. The sample shown on this page excludes background traffic so the 15 supported behaviors can be inspected without unrelated packets.

How repeatable is the generated traffic?

The same declared scenario and generation inputs produce comparable packet output, timing, manifests, and ground-truth records. This allows a dataset to be reused for rule development, parser testing, regression analysis, training, and controlled comparison.

How realistic is the generated traffic?

NetMetria is designed for controlled network-behavior representation, not unrestricted emulation of every implementation detail found in a live enterprise. Fidelity should be judged against the validation objective: whether the dataset contains the packet structures, ordering, timing, endpoints, and protocol activity required by the test.

Does NetMetria execute malware or compromise endpoints?

No. NetMetria generates network-observable traffic associated with declared behaviors. It does not execute malware, exploit systems, establish live command infrastructure, or modify endpoint state.

What is included in the initial NetMetria Community release?

Community is the first public edition and is planned for release in September 2026. Its initial release includes the Linux command-line workflow, 15 ATT&CK-aligned network behaviors, and dataset outputs that include PCAP, timeline, manifest, and ground truth. The 15-behavior set is the Community launch scope, not a permanent limit on the broader NetMetria platform.

How do Pro and Enterprise relate to Community?

Pro and Enterprise are additional NetMetria editions in development. Pro is intended to extend behavior coverage and advanced technical workflows. Enterprise is intended to address additional organizational deployment, management, and operational requirements. Detailed capabilities, packaging, and availability will be announced only after they are implemented and verified.

What does joining the Community access list mean?

The list is primarily used for Community release updates and opportunities to evaluate the first public edition. It may also be used for future Pro and Enterprise announcements. Information about intended use helps guide examples and documentation. Joining does not guarantee immediate access, a specific release date, or inclusion in every evaluation group.

NetMetria access list

Inspect the traffic. Understand the model. Start with Community.

Join the Community access list →
Join Community access list