How NetMetria works

NetMetria generates the network side of a cybersecurity scenario.

NetMetria is a Linux-based cybersecurity network dataset generation platform. It produces scenario-driven PCAP traffic and machine-readable ground truth without requiring the full endpoint environment that would normally produce the traffic.

Workflow

From scenario definition to PCAP and ground truth.

NetMetria models the network interactions required by the scenario. It does not execute malware, compromise systems, or reproduce full endpoint state.

01

Define the scenario

Describe the roles, environment, and supported network behavior needed for the dataset.

02

Generate the network dataset

Generate protocol traffic representing the defined activity.

03

Analyze with ground truth

Inspect the PCAP and use the accompanying ground truth to identify the scenario activity represented by the traffic.

Ground truth

The PCAP shows the traffic. Ground truth records what the generated traffic represents.

With an ordinary capture, analysts may have to reconstruct attribution afterward. NetMetria keeps the generated traffic linked to scenario actions, roles, behaviors, timing, and ATT&CK attribution.

PACKETFLOWSTEPBEHAVIORATT&CKACTOR

What NetMetria is designed to test

Use NetMetria when the test question is on the wire.

NetMetria is designed for packet evidence, network relationships, sensor visibility, detections, and analytics. It is not an endpoint-emulation or exploit-execution system.

Scenario-specific datasets

Generate traffic around the test question you actually have instead of adapting an unrelated capture.

Comparable test datasets

Re-run defined scenario conditions when a rule, parser, analytic, or product changes and you need another dataset for comparison.

Expected activity recorded

Keep packet evidence associated with the scenario activity it represents.

Reduced infrastructure dependency

Represent the network roles required by the scenario without building a full physical or virtual environment for every case.

Product scope

NetMetria focuses on the network evidence a scenario should produce.

NetMetria generates supported network traffic and associated ground truth for defined cybersecurity scenarios. Its scope is the packet-level evidence used for detection, analysis, testing, training, and research.

Current edition

NetMetria Explorer

Explorer is the current Linux command-line release focus. Its present scope includes 15 ATT&CK-aligned network behaviors and generation of PCAP datasets with associated ground truth. It is intended for hands-on generation and analysis work; Workbench and Enterprise remain future directions.