Why NetMetria

The lab can become most of the work.

NetMetria is for teams that need attack-related network traffic and ground truth without building a complete live environment for every dataset.

Conventional dataset creation

The capture is often the last step in a much larger setup.

Before useful traffic exists, a conventional workflow may require hosts, services, network configuration, attacker systems, tools, capture infrastructure, and scenario execution.

BEFORE THE CAPTURE
  1. Provision virtual or physical infrastructure
  2. Install and configure operating systems
  3. Configure services and network segmentation
  4. Prepare attacker systems and tools
  5. Build and execute the scenario
AFTER THE CAPTURE
  1. Determine which traffic belongs to which action
  2. Label and attribute the evidence
  3. Map activity to ATT&CK
  4. Reset the environment
  5. Repeat for the next test or variation

Network evidence without the full environment

Generate the traffic required for the test without rebuilding every system behind it each time you need a new dataset.

NetMetria generates the packet-level result of a defined scenario and keeps that traffic tied to its ground truth.

Less environment setup

Avoid building endpoint and attacker infrastructure that exists only to produce the test traffic.

Ground truth kept with the dataset

Keep expected activity and packet attribution with the generated dataset instead of reconstructing them afterward.

Defined test conditions

Create related datasets from defined scenario conditions for comparison, regression testing, and evaluation.

ATT&CK to network evidence

Generate inspectable packet evidence for supported ATT&CK-aligned behavior and retain the corresponding scenario context.

No malware required to produce the dataset

Produce supported attack-related network traffic without running real malware solely to create an analysis or training capture.

Lower cost of scenario variation

Change supported scenario or environment inputs and generate another dataset without rebuilding a separate live environment for each test.

What NetMetria produces

NetMetria produces PCAPs, but the dataset is more than the packet file.

A NetMetria dataset combines scenario-driven network traffic with the context needed to explain what that traffic represents. It can be generated when a detection, parser, exercise, or analysis task needs traffic built for a specific question.

Network-focused testing

Generate the evidence the network sensor needs to see.

NetMetria is designed for tests built around packet captures, flows, protocol behavior, service interactions, timing, and scenario context. The dataset stays focused on the network-observable activity required by the test.

Built for network evidence

Detection engineers, security-product teams, trainers, and researchers can work from defined scenario traffic without first constructing every system that would normally be involved in producing it.

Assess your current process

How much work stands between your question and the packet evidence?

The assessment identifies where infrastructure setup, scenario execution, labeling, dataset reproduction, and validation consume time in your current process.

Run the assessment →