Download sample PCAPs
Three scenarios at increasing levels of complexity.
Each PCAP is a separate scenario, not one part of a larger incident. The samples progress from a smaller focused capture to denser traffic with more interactions and a longer observation window.
01Focused ScenarioStart with a smaller environment and a constrained set of scenario-driven interactions.
→
02Multi-Behavior ScenarioAdd more traffic relationships, timing context, and potentially related activity.
→
03Complex ScenarioWork through the longest and densest capture, with more competing network evidence.
All three samples begin after initial accessAll three public PCAPs are post-compromise scenarios. They begin after a foothold has been established and focus on the network activity that follows, not on the traffic used to gain initial access.
These samples do not include initial-access traffic. Future scenarios may cover network-visible activity around initial access, but NetMetria is not an exploit-execution system.
The descriptions below provide starting context without revealing the scenario answer. The public downloads do not include exact actor roles, ATT&CK mappings, event sequence, or ground-truth relationships.
NM-SAMPLE-001EASY
Focused Scenario
A compact, self-contained scenario intended as the starting point for independent inspection. It is designed for analysts who want a smaller capture in which significant activity can be separated from supporting network traffic without first reconstructing a large environment.
Scenario contextA small network is carrying routine supporting traffic while a limited set of scenario-driven interactions occurs among hosts and services. Expect DNS, web and TLS traffic, SMB, NTP, and general TCP/UDP exchanges. The useful starting question is not “which packet is malicious?” but “which relationships and changes in behavior deserve attention?”
- Packets
- 1,592
- Duration
- 11m 59s
- File size
- 230.2 KiB
- Format
- PCAP
DNSHTTPTLS/HTTPSSMBNTPTCPUDP
SHA-2569f5959202cc07f4b5d64549c5a352ca7a90cb0826550432735c25957e4924c2d
Short analyst guide
Start without external scenario context. Identify participating hosts, significant flows, service usage, changes in activity over time, and any traffic that could support a defensible detection hypothesis.
- Which hosts appear operationally significant?
- Which protocols and services deserve closer inspection?
- What activity is routine versus potentially scenario-driven?
- What evidence could be turned into an IDS or SIEM analytic?
NM-SAMPLE-002INTERMEDIATE
Multi-Behavior Scenario
A larger, self-contained scenario with more interacting activity and a longer observation window. It is intended to test whether an analysis approach still holds when meaningful behavior is distributed across more flows and there is more competing network evidence.
Scenario contextA busier network continues to generate routine service traffic while several scenario-driven interactions unfold over roughly 28 minutes. The same major protocol families are present, but the analyst has more timing relationships and more activity to correlate before deciding which flows belong together.
- Packets
- 4,134
- Duration
- 27m 59s
- File size
- 622.6 KiB
- Format
- PCAP
DNSHTTPTLS/HTTPSSMBNTPTCPUDP
SHA-256e5830a9672261b799cf1a6a259ae6078e976c6e5de06e898f0049a8b7b46db96
Short analyst guide
Reconstruct meaningful sequences instead of evaluating packets in isolation. Look for related behavior across flows and determine which observations would survive translation into a detection or validation workflow.
- Which flows appear related by timing or host role?
- Can you identify meaningful stages in the observed activity?
- Which indicators are strong enough to automate?
- What context would you want from ground truth after the blind review?
NM-SAMPLE-003ADVANCED
Complex Scenario
The largest self-contained public sample, with a substantially longer capture and more network interactions. It is intended for analysts evaluating traffic reconstruction, rule development, tool behavior, and workflow performance when the capture no longer offers an obvious starting point.
Scenario contextOver roughly 52 minutes, multiple hosts and services produce a denser mix of supporting and scenario-driven traffic. DNS, web and TLS traffic, SMB, NTP, and general TCP/UDP exchanges all contribute to the picture. The task is to build a defensible timeline, identify the relationships that matter, and separate useful detection evidence from ordinary network activity.
- Packets
- 6,109
- Duration
- 51m 59s
- File size
- 877.5 KiB
- Format
- PCAP
DNSHTTPTLS/HTTPSSMBNTPTCPUDP
SHA-256946998d7d8e9217d77892e780bf52d2994c5201c7dd850e25ccf0ddab7158eb0
Short analyst guide
Approach the capture as an unknown environment. Build a timeline, identify the most important traffic relationships, and determine which observations are useful for defensive analytics rather than merely interesting artifacts.
- Which hosts and services anchor the timeline?
- Which traffic patterns appear coordinated or sequential?
- Where would you place detection boundaries?
- How would you validate your conclusions if the ground truth were later revealed?