Public dataset library

Download the PCAPs and inspect the traffic.

Three NetMetria-generated PCAPs are available without registration. Inspect them in Wireshark, tshark, tcpdump, an IDS/IPS platform, a SIEM pipeline, or your normal detection-engineering tools.

Download sample PCAPs

Three scenarios at increasing levels of complexity.

Each PCAP is a separate scenario, not one part of a larger incident. The samples progress from a smaller focused capture to denser traffic with more interactions and a longer observation window.

01Focused Scenario

Start with a smaller environment and a constrained set of scenario-driven interactions.

02Multi-Behavior Scenario

Add more traffic relationships, timing context, and potentially related activity.

03Complex Scenario

Work through the longest and densest capture, with more competing network evidence.

All three samples begin after initial access

All three public PCAPs are post-compromise scenarios. They begin after a foothold has been established and focus on the network activity that follows, not on the traffic used to gain initial access.

These samples do not include initial-access traffic. Future scenarios may cover network-visible activity around initial access, but NetMetria is not an exploit-execution system.

The descriptions below provide starting context without revealing the scenario answer. The public downloads do not include exact actor roles, ATT&CK mappings, event sequence, or ground-truth relationships.

NM-SAMPLE-001EASY

Focused Scenario

A compact, self-contained scenario intended as the starting point for independent inspection. It is designed for analysts who want a smaller capture in which significant activity can be separated from supporting network traffic without first reconstructing a large environment.

Scenario context

A small network is carrying routine supporting traffic while a limited set of scenario-driven interactions occurs among hosts and services. Expect DNS, web and TLS traffic, SMB, NTP, and general TCP/UDP exchanges. The useful starting question is not “which packet is malicious?” but “which relationships and changes in behavior deserve attention?”

Packets
1,592
Duration
11m 59s
File size
230.2 KiB
Format
PCAP
DNSHTTPTLS/HTTPSSMBNTPTCPUDP
SHA-2569f5959202cc07f4b5d64549c5a352ca7a90cb0826550432735c25957e4924c2d
Short analyst guide

Start without external scenario context. Identify participating hosts, significant flows, service usage, changes in activity over time, and any traffic that could support a defensible detection hypothesis.

  • Which hosts appear operationally significant?
  • Which protocols and services deserve closer inspection?
  • What activity is routine versus potentially scenario-driven?
  • What evidence could be turned into an IDS or SIEM analytic?
NM-SAMPLE-002INTERMEDIATE

Multi-Behavior Scenario

A larger, self-contained scenario with more interacting activity and a longer observation window. It is intended to test whether an analysis approach still holds when meaningful behavior is distributed across more flows and there is more competing network evidence.

Scenario context

A busier network continues to generate routine service traffic while several scenario-driven interactions unfold over roughly 28 minutes. The same major protocol families are present, but the analyst has more timing relationships and more activity to correlate before deciding which flows belong together.

Packets
4,134
Duration
27m 59s
File size
622.6 KiB
Format
PCAP
DNSHTTPTLS/HTTPSSMBNTPTCPUDP
SHA-256e5830a9672261b799cf1a6a259ae6078e976c6e5de06e898f0049a8b7b46db96
Short analyst guide

Reconstruct meaningful sequences instead of evaluating packets in isolation. Look for related behavior across flows and determine which observations would survive translation into a detection or validation workflow.

  • Which flows appear related by timing or host role?
  • Can you identify meaningful stages in the observed activity?
  • Which indicators are strong enough to automate?
  • What context would you want from ground truth after the blind review?
NM-SAMPLE-003ADVANCED

Complex Scenario

The largest self-contained public sample, with a substantially longer capture and more network interactions. It is intended for analysts evaluating traffic reconstruction, rule development, tool behavior, and workflow performance when the capture no longer offers an obvious starting point.

Scenario context

Over roughly 52 minutes, multiple hosts and services produce a denser mix of supporting and scenario-driven traffic. DNS, web and TLS traffic, SMB, NTP, and general TCP/UDP exchanges all contribute to the picture. The task is to build a defensible timeline, identify the relationships that matter, and separate useful detection evidence from ordinary network activity.

Packets
6,109
Duration
51m 59s
File size
877.5 KiB
Format
PCAP
DNSHTTPTLS/HTTPSSMBNTPTCPUDP
SHA-256946998d7d8e9217d77892e780bf52d2994c5201c7dd850e25ccf0ddab7158eb0
Short analyst guide

Approach the capture as an unknown environment. Build a timeline, identify the most important traffic relationships, and determine which observations are useful for defensive analytics rather than merely interesting artifacts.

  • Which hosts and services anchor the timeline?
  • Which traffic patterns appear coordinated or sequential?
  • Where would you place detection boundaries?
  • How would you validate your conclusions if the ground truth were later revealed?

Ground-truth availability

The public downloads are currently PCAP-only.

The downloadable samples are intended for blind analysis. A public ground-truth format is still under review because it must expose useful scenario attribution without disclosing proprietary implementation details.

Available

PCAP-only analysis

Download the PCAP and analyze the traffic without a scenario answer key or ATT&CK mapping.

Not yet public

Public ground truth

A separate public ground-truth format may be released later. The internal manifest will not be published as-is; any public format must be reviewed for proprietary implementation details first.

Evaluate NetMetria

If these PCAPs are relevant to your work, evaluate Explorer next.

Inspect the public PCAPs first. If the traffic is useful for your detection, analysis, training, research, or testing work, request Explorer evaluation information.

Evaluate NetMetria
Sample-use statement

These files are provided for technical evaluation, defensive-security research, detection engineering, training, and testing. Publication on this page does not grant rights to repackage or commercially redistribute the datasets as a separate dataset product. Contact contact@netmetria.com if your intended use requires clarification.