Purpose-built network evidence

Generate the network traffic your test requires.Build the scenario, not the lab.

A detection rule, parser test, training exercise, or research project may require a very specific packet capture. Creating it usually means configuring hosts, services, routes, and capture tools first. That setup can take longer than the test itself.

NETMETRIA EXPLORER RELEASE TARGET
September 2026 Join the access list for release updates and evaluation opportunities.

NetMetria Explorer is for learning, evaluation, and teaching. NetMetria Workbench is the planned operational product for expanded content and visual authoring. NetMetria Enterprise adds organizational licensing, support, and services. Dataset quality does not change across the product line.

NO DEDICATED LABwhen the goal is a controlled packet dataset
FOCUSED SCOPEonly the hosts and interactions the scenario needs
PCAP + CONTEXTtraffic, timing, and expected results from the same run
15ATT&CK-aligned behaviors in the NetMetria Explorer launch scope

Why NetMetria exists

The hard part is often creating the right traffic, not opening the PCAP.

A team may need traffic for one detection rule, parser, exercise, or research question. Public captures may be close, but they rarely match the requirement exactly. A lab gives more control, but it also adds systems, configuration, maintenance, and reset work.

NetMetria was built for cases where the packet evidence is the objective.

It generates the traffic for a defined scenario and records what was supposed to happen. A live lab is still the right choice when the exercise depends on endpoint state, user actions, or actual system compromise.

THE USUAL OPTIONS

Use an existing capture, or build and run a lab.

  1. 01Build and maintain a physical or virtual lab
  2. 02Search for a PCAP that only approximates the question
  3. 03Replay fixed traffic that cannot be redefined
  4. 04Manually reconstruct what happened and when
  5. 05Reset and rerun the environment for another variation
THE NETMETRIA APPROACH

Start with the traffic you need.

  1. 01Identify the required hosts and their roles
  2. 02Arrange the behaviors in the order they should occur
  3. 03Generate the packet capture
  4. 04Review the PCAP with its timeline and ground truth
  5. 05Adjust the scenario and generate another dataset

How NetMetria works

Describe the scenario, generate the traffic, and check the result.

Each run keeps the scenario, generated traffic, timing, manifest, and ground truth together.

01

DECLARE

Include only the hosts the scenario needs.

Set the host roles, target relationships, behavior order, and timing for the test.

  • No full enterprise reconstruction
  • Clear roles for each host
  • A stated purpose for each behavior
02

GENERATE

Generate the traffic and output files.

NetMetria creates the network conversations and writes the PCAP and supporting files without running a complete live environment.

  • Standard PCAP output
  • Controlled timing
  • Repeatable generation runs
03

VALIDATE

Check the result against the scenario.

Compare detections, parser output, alerts, or analyst findings with the timeline, manifest, and ground truth.

  • Known packet locations
  • Expected behavior for each step
  • Quicker regression checks

Inspect the output

A sample capture with fifteen ordered behaviors.

The export below comes from a sample NetMetria PCAP. It shows the protocols, endpoints, timing, and behavior order planned for the initial NetMetria Explorer release.

Join the NetMetria Explorer access list →
181packets in the export
15ATT&CK-aligned behaviors
SMB2 · TCP · UDP · TLS · HTTPobservable protocol activity
KNOWN ORDERbehavior ranges mapped to the timeline
sample_pcap.txt · Wireshark packet-list export
SHOWING: ALL 181 PACKETS SELECT A BEHAVIOR ABOVE TO HIGHLIGHT ITS PACKET RANGE
No.  Time         Source        Destination   Protocol   Length  Info1    0.000000     192.168.1.10  192.168.1.20  TCP        74      49152 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728505099 TSecr=0 WS=2562    0.000213     192.168.1.20  192.168.1.10  TCP        74      445 → 49152 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672586938 TSecr=728505099 WS=1283    0.000356     192.168.1.10  192.168.1.20  TCP        54      49152 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=04    0.001876     192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$5    0.003109     192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response6    0.004147     192.168.1.10  192.168.1.20  SMB2       190     Create Request File: srvsvc7    0.006022     192.168.1.20  192.168.1.10  SMB2       210     Create Response File: srvsvc8    0.006848     192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc9    0.008511     192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc10   0.009083     192.168.1.10  192.168.1.20  SMB2       146     Close Request File: srvsvc11   0.010007     192.168.1.20  192.168.1.10  SMB2       182     Close Response12   0.010581     192.168.1.10  192.168.1.20  TCP        54      49152 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=013   0.010666     192.168.1.20  192.168.1.10  TCP        54      445 → 49152 [ACK] Seq=525 Ack=504 Win=8340480 Len=014   0.011288     192.168.1.20  192.168.1.10  TCP        54      445 → 49152 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=015   0.011384     192.168.1.10  192.168.1.20  TCP        54      49152 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=016   102.405724   192.168.1.10  192.168.1.20  TCP        74      49153 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728607504 TSecr=0 WS=25617   102.405984   192.168.1.20  192.168.1.10  TCP        74      445 → 49153 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672689344 TSecr=728607504 WS=12818   102.406064   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=019   102.407174   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$20   102.408137   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response21   102.409493   192.168.1.10  192.168.1.20  SMB2       190     Create Request File: srvsvc22   102.410722   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: srvsvc23   102.412334   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc24   102.414139   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: srvsvc25   102.415365   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: srvsvc26   102.416507   192.168.1.20  192.168.1.10  SMB2       182     Close Response27   102.416589   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [ACK] Seq=503 Ack=525 Win=16445440 Len=028   102.417409   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=029   102.417548   192.168.1.20  192.168.1.10  TCP        54      445 → 49153 [ACK] Seq=525 Ack=504 Win=8340480 Len=030   102.418488   192.168.1.20  192.168.1.10  TCP        54      445 → 49153 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=031   102.418562   192.168.1.10  192.168.1.20  TCP        54      49153 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=032   214.682241   192.168.1.10  192.168.1.20  TCP        74      49154 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728719781 TSecr=0 WS=25633   214.682484   192.168.1.20  192.168.1.10  TCP        74      445 → 49154 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672801620 TSecr=728719781 WS=12834   214.682557   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=035   214.683526   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$36   214.685388   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response37   214.685971   192.168.1.10  192.168.1.20  SMB2       186     Create Request File: samr38   214.688159   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: samr39   214.689184   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: samr40   214.690198   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: samr41   214.691489   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: samr42   214.693556   192.168.1.20  192.168.1.10  SMB2       182     Close Response43   214.693677   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [ACK] Seq=499 Ack=525 Win=16445440 Len=044   214.694484   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [FIN, ACK] Seq=499 Ack=525 Win=16445440 Len=045   214.694630   192.168.1.20  192.168.1.10  TCP        54      445 → 49154 [ACK] Seq=525 Ack=500 Win=8340480 Len=046   214.695157   192.168.1.20  192.168.1.10  TCP        54      445 → 49154 [FIN, ACK] Seq=525 Ack=500 Win=8340480 Len=047   214.695330   192.168.1.10  192.168.1.20  TCP        54      49154 → 445 [ACK] Seq=500 Ack=526 Win=16445440 Len=048   327.536659   192.168.1.10  192.168.1.20  TCP        74      49155 → 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728832635 TSecr=0 WS=25649   327.537014   192.168.1.20  192.168.1.10  TCP        74      80 → 49155 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672914475 TSecr=728832635 WS=12850   327.537591   192.168.1.10  192.168.1.20  TCP        54      49155 → 80 [RST] Seq=1 Win=16445440 Len=051   411.558516   192.168.1.10  192.168.1.20  TCP        74      49156 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=728916657 TSecr=0 WS=25652   411.558739   192.168.1.20  192.168.1.10  TCP        74      445 → 49156 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2672998496 TSecr=728916657 WS=12853   411.558820   192.168.1.10  192.168.1.20  TCP        54      49156 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=054   411.559737   192.168.1.10  192.168.1.20  SMB2       168     Negotiate Protocol Request55   411.560377   192.168.1.10  192.168.1.20  TCP        54      49156 → 445 [FIN, ACK] Seq=115 Ack=1 Win=16445440 Len=056   411.560476   192.168.1.20  192.168.1.10  TCP        54      445 → 49156 [ACK] Seq=1 Ack=116 Win=8340480 Len=057   411.561082   192.168.1.20  192.168.1.10  TCP        54      445 → 49156 [FIN, ACK] Seq=1 Ack=116 Win=8340480 Len=058   411.561212   192.168.1.10  192.168.1.20  TCP        54      49156 → 445 [ACK] Seq=116 Ack=2 Win=16445440 Len=059   532.899823   192.168.1.10  192.168.1.20  TCP        74      49157 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729037998 TSecr=0 WS=25660   532.900188   192.168.1.20  192.168.1.10  TCP        74      445 → 49157 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673119838 TSecr=729037998 WS=12861   532.900363   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=062   532.901843   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$63   532.903676   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response64   532.904402   192.168.1.10  192.168.1.20  SMB2       190     Create Request File: svcctl65   532.906589   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: svcctl66   532.907442   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl67   532.909084   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl68   532.910288   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: svcctl69   532.912740   192.168.1.20  192.168.1.10  SMB2       182     Close Response70   532.912892   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [ACK] Seq=503 Ack=525 Win=16445440 Len=071   532.913364   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=072   532.913441   192.168.1.20  192.168.1.10  TCP        54      445 → 49157 [ACK] Seq=525 Ack=504 Win=8340480 Len=073   532.914379   192.168.1.20  192.168.1.10  TCP        54      445 → 49157 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=074   532.914479   192.168.1.10  192.168.1.20  TCP        54      49157 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=075   631.527495   192.168.1.10  192.168.1.20  TCP        74      49158 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729136626 TSecr=0 WS=25676   631.527775   192.168.1.20  192.168.1.10  TCP        74      445 → 49158 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673218465 TSecr=729136626 WS=12877   631.527847   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=078   631.528486   192.168.1.10  192.168.1.20  SMB2       184     Tree Connect Request Tree: \\files.corp.example\ADMIN$79   631.530638   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response80   631.531955   192.168.1.10  192.168.1.20  SMB2       206     Create Request File: q4-summary.bin81   631.533065   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: q4-summary.bin82   631.533422   192.168.1.10  192.168.1.20  SMB2       266     Write Request Len:96 Off:083   631.535295   192.168.1.20  192.168.1.10  SMB2       138     Write Response84   631.535832   192.168.1.10  192.168.1.20  SMB2       146     Close Request85   631.537733   192.168.1.20  192.168.1.10  SMB2       182     Close Response86   631.537856   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [ACK] Seq=587 Ack=453 Win=16445440 Len=087   631.538733   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [FIN, ACK] Seq=587 Ack=453 Win=16445440 Len=088   631.538867   192.168.1.20  192.168.1.10  TCP        54      445 → 49158 [ACK] Seq=453 Ack=588 Win=8340480 Len=089   631.539222   192.168.1.20  192.168.1.10  TCP        54      445 → 49158 [FIN, ACK] Seq=453 Ack=588 Win=8340480 Len=090   631.539327   192.168.1.10  192.168.1.20  TCP        54      49158 → 445 [ACK] Seq=588 Ack=454 Win=16445440 Len=091   727.607329   192.168.1.10  192.168.1.20  TCP        74      49159 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729232706 TSecr=0 WS=25692   727.607549   192.168.1.20  192.168.1.10  TCP        74      445 → 49159 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673314545 TSecr=729232706 WS=12893   727.607677   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=094   727.608709   192.168.1.10  192.168.1.20  SMB2       180     Tree Connect Request Tree: \\files.corp.example\IPC$95   727.610158   192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response96   727.610836   192.168.1.10  192.168.1.20  SMB2       190     Create Request File: svcctl97   727.611807   192.168.1.20  192.168.1.10  SMB2       210     Create Response File: svcctl98   727.612725   192.168.1.10  192.168.1.20  SMB2       202     Ioctl Request FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl99   727.614736   192.168.1.20  192.168.1.10  SMB2       210     Ioctl Response FSCTL_QUERY_NETWORK_INTERFACE_INFO File: svcctl100  727.616356   192.168.1.10  192.168.1.20  SMB2       146     Close Request File: svcctl101  727.617592   192.168.1.20  192.168.1.10  SMB2       182     Close Response102  727.617682   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [ACK] Seq=503 Ack=525 Win=16445440 Len=0103  727.618506   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [FIN, ACK] Seq=503 Ack=525 Win=16445440 Len=0104  727.618641   192.168.1.20  192.168.1.10  TCP        54      445 → 49159 [ACK] Seq=525 Ack=504 Win=8340480 Len=0105  727.619137   192.168.1.20  192.168.1.10  TCP        54      445 → 49159 [FIN, ACK] Seq=525 Ack=504 Win=8340480 Len=0106  727.619315   192.168.1.10  192.168.1.20  TCP        54      49159 → 445 [ACK] Seq=504 Ack=526 Win=16445440 Len=0107  850.790822   192.168.1.10  192.168.1.30  TCP        74      49160 → 8443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729355889 TSecr=0 WS=256108  850.791125   192.168.1.30  192.168.1.10  TCP        74      8443 → 49160 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=1877069036 TSecr=729355889 WS=128109  850.791286   192.168.1.10  192.168.1.30  TCP        54      49160 → 8443 [ACK] Seq=1 Ack=1 Win=16445440 Len=0110  850.792091   192.168.1.10  192.168.1.30  TLSv1.3    191     Client Hello (SNI=assets.corp.example)111  850.792665   192.168.1.30  192.168.1.10  TLSv1.3    109     Server Hello112  850.793835   192.168.1.10  192.168.1.30  TLSv1.3    231     Application Data113  850.795173   192.168.1.30  192.168.1.10  TLSv1.3    145     Application Data114  850.795958   192.168.1.10  192.168.1.30  TCP        54      49160 → 8443 [FIN, ACK] Seq=315 Ack=147 Win=16445440 Len=0115  850.796042   192.168.1.30  192.168.1.10  TCP        54      8443 → 49160 [ACK] Seq=147 Ack=316 Win=8340480 Len=0116  850.796855   192.168.1.30  192.168.1.10  TCP        54      8443 → 49160 [FIN, ACK] Seq=147 Ack=316 Win=8340480 Len=0117  850.797025   192.168.1.10  192.168.1.30  TCP        54      49160 → 8443 [ACK] Seq=316 Ack=148 Win=16445440 Len=0118  955.700886   192.168.1.10  192.168.1.20  UDP        92      49161 → 8444 Len=50119  955.701797   192.168.1.20  192.168.1.10  UDP        106     8444 → 49161 Len=64120  955.703353   192.168.1.10  192.168.1.20  UDP        99      49161 → 8444 Len=57121  955.704710   192.168.1.20  192.168.1.10  UDP        117     8444 → 49161 Len=75122  955.706252   192.168.1.10  192.168.1.20  UDP        90      49161 → 8444 Len=48123  955.706755   192.168.1.20  192.168.1.10  UDP        102     8444 → 49161 Len=60124  1034.261722  192.168.1.10  192.168.1.20  TCP        74      49162 → 8445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729539360 TSecr=0 WS=256125  1034.261912  192.168.1.20  192.168.1.10  TCP        74      8445 → 49162 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673621199 TSecr=729539360 WS=128126  1034.262032  192.168.1.10  192.168.1.20  TCP        54      49162 → 8445 [ACK] Seq=1 Ack=1 Win=16445440 Len=0127  1034.262711  192.168.1.10  192.168.1.20  TLSv1.3    191     Client Hello (SNI=assets.corp.example)128  1034.263671  192.168.1.20  192.168.1.10  TLSv1.3    109     Server Hello129  1034.264210  192.168.1.10  192.168.1.20  TLSv1.3    155     Application Data130  1034.265129  192.168.1.10  192.168.1.20  TCP        54      49162 → 8445 [FIN, ACK] Seq=239 Ack=56 Win=16445440 Len=0131  1034.265215  192.168.1.20  192.168.1.10  TCP        54      8445 → 49162 [ACK] Seq=56 Ack=240 Win=8340480 Len=0132  1034.266158  192.168.1.20  192.168.1.10  TCP        54      8445 → 49162 [FIN, ACK] Seq=56 Ack=240 Win=8340480 Len=0133  1034.266247  192.168.1.10  192.168.1.20  TCP        54      49162 → 8445 [ACK] Seq=240 Ack=57 Win=16445440 Len=0134  1157.164158  192.168.1.10  192.168.1.30  TCP        74      49163 → 8444 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729662263 TSecr=0 WS=256135  1157.164386  192.168.1.30  192.168.1.10  TCP        74      8444 → 49163 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=1877375409 TSecr=729662263 WS=128136  1157.164524  192.168.1.10  192.168.1.30  TCP        54      49163 → 8444 [ACK] Seq=1 Ack=1 Win=16445440 Len=0137  1157.165140  192.168.1.10  192.168.1.30  TLSv1.3    191     Client Hello (SNI=assets.corp.example)138  1157.166091  192.168.1.30  192.168.1.10  TLSv1.3    109     Server Hello139  1157.166836  192.168.1.10  192.168.1.30  TLSv1.3    243     Application Data140  1157.168665  192.168.1.30  192.168.1.10  TLSv1.3    147     Application Data141  1157.169528  192.168.1.10  192.168.1.30  TCP        54      49163 → 8444 [FIN, ACK] Seq=327 Ack=149 Win=16445440 Len=0142  1157.169634  192.168.1.30  192.168.1.10  TCP        54      8444 → 49163 [ACK] Seq=149 Ack=328 Win=8340480 Len=0143  1157.170215  192.168.1.30  192.168.1.10  TCP        54      8444 → 49163 [FIN, ACK] Seq=149 Ack=328 Win=8340480 Len=0144  1157.170387  192.168.1.10  192.168.1.30  TCP        54      49163 → 8444 [ACK] Seq=328 Ack=150 Win=16445440 Len=0145  1239.352005  192.168.1.10  192.168.1.20  TCP        74      49164 → 445 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729744451 TSecr=0 WS=256146  1239.352300  192.168.1.20  192.168.1.10  TCP        74      445 → 49164 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673826290 TSecr=729744451 WS=128147  1239.352407  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [ACK] Seq=1 Ack=1 Win=16445440 Len=0148  1239.353387  192.168.1.10  192.168.1.20  SMB2       184     Tree Connect Request Tree: \\files.corp.example\ADMIN$149  1239.355808  192.168.1.20  192.168.1.10  SMB2       138     Tree Connect Response150  1239.356586  192.168.1.10  192.168.1.20  SMB2       206     Create Request File: q4-summary.bin151  1239.358001  192.168.1.20  192.168.1.10  SMB2       210     Create Response File: q4-summary.bin152  1239.358775  192.168.1.10  192.168.1.20  SMB2       266     Write Request Len:96 Off:0153  1239.361165  192.168.1.20  192.168.1.10  SMB2       138     Write Response154  1239.362565  192.168.1.10  192.168.1.20  SMB2       146     Close Request155  1239.363725  192.168.1.20  192.168.1.10  SMB2       182     Close Response156  1239.363889  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [ACK] Seq=587 Ack=453 Win=16445440 Len=0157  1239.364869  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [FIN, ACK] Seq=587 Ack=453 Win=16445440 Len=0158  1239.364982  192.168.1.20  192.168.1.10  TCP        54      445 → 49164 [ACK] Seq=453 Ack=588 Win=8340480 Len=0159  1239.365680  192.168.1.20  192.168.1.10  TCP        54      445 → 49164 [FIN, ACK] Seq=453 Ack=588 Win=8340480 Len=0160  1239.365756  192.168.1.10  192.168.1.20  TCP        54      49164 → 445 [ACK] Seq=588 Ack=454 Win=16445440 Len=0161  1366.301670  192.168.1.10  192.168.1.20  TCP        74      49165 → 8080 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729871400 TSecr=0 WS=256162  1366.301919  192.168.1.20  192.168.1.10  TCP        74      8080 → 49165 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=2673953239 TSecr=729871400 WS=128163  1366.302022  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [ACK] Seq=1 Ack=1 Win=16445440 Len=0164  1366.302639  192.168.1.10  192.168.1.20  HTTP       413     GET /assets/v2/health/check?rid=a20e HTTP/1.1 165  1366.304389  192.168.1.20  192.168.1.10  HTTP       232     HTTP/1.1 204 No Content 166  1366.304476  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [ACK] Seq=360 Ack=179 Win=16445440 Len=0167  1366.304748  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [FIN, ACK] Seq=360 Ack=179 Win=16445440 Len=0168  1366.304899  192.168.1.20  192.168.1.10  TCP        54      8080 → 49165 [ACK] Seq=179 Ack=361 Win=8340480 Len=0169  1366.305375  192.168.1.20  192.168.1.10  TCP        54      8080 → 49165 [FIN, ACK] Seq=179 Ack=361 Win=8340480 Len=0170  1366.305513  192.168.1.10  192.168.1.20  TCP        54      49165 → 8080 [ACK] Seq=361 Ack=180 Win=16445440 Len=0171  1465.903962  192.168.1.10  192.168.1.30  TCP        74      49166 → 8080 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM TSval=729971002 TSecr=0 WS=256172  1465.904224  192.168.1.30  192.168.1.10  TCP        74      8080 → 49166 [SYN, ACK] Seq=0 Ack=1 Win=65160 Len=0 MSS=1460 SACK_PERM TSval=1877684149 TSecr=729971002 WS=128173  1465.904304  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [ACK] Seq=1 Ack=1 Win=16445440 Len=0174  1465.905940  192.168.1.10  192.168.1.30  TCP        466     49166 → 8080 [PSH, ACK] Seq=1 Ack=1 Win=16445440 Len=412 [TCP segment of a reassembled PDU]175  1465.906929  192.168.1.10  192.168.1.30  HTTP/JSON  339     POST /files/v1/uploads/session/ee6723 HTTP/1.1 , JSON (application/json)176  1465.909354  192.168.1.30  192.168.1.10  HTTP/JSON  432     HTTP/1.1 200 OK , JSON (application/json)177  1465.909454  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [ACK] Seq=698 Ack=379 Win=16445440 Len=0178  1465.909864  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [FIN, ACK] Seq=698 Ack=379 Win=16445440 Len=0179  1465.909955  192.168.1.30  192.168.1.10  TCP        54      8080 → 49166 [ACK] Seq=379 Ack=699 Win=8340480 Len=0180  1465.910551  192.168.1.30  192.168.1.10  TCP        54      8080 → 49166 [FIN, ACK] Seq=379 Ack=699 Win=8340480 Len=0181  1465.910726  192.168.1.10  192.168.1.30  TCP        54      49166 → 8080 [ACK] Seq=699 Ack=380 Win=16445440 Len=0

Evaluate NetMetria Explorer

Use NetMetria Explorer to learn, evaluate, and teach.

NetMetria Explorer is a complete, non-expiring edition built for product evaluation, individual study, classroom instruction, and detection engineering labs.

Join the NetMetria Explorer access list

Start with the question

What question does the traffic need to answer?

NetMetria works best when the test begins with a specific question. A general request for realistic traffic is too vague to define a useful dataset.

Detection engineering

Will the rule detect the behavior it was written for?

Run detection logic against known packet activity, then compare the alert with the scenario.

Security product QA

Does the parser, sensor, or pipeline handle the traffic correctly?

Test ingestion, parsing, and extraction with traffic whose expected contents are known.

Analyst training

Can the analyst find and explain the expected activity?

Teach packet analysis with a scenario timeline and answer key available to the instructor.

Controlled research

How do two tools or methods perform on the same input?

Use the same scenario and input conditions for experiments, demonstrations, and comparisons.

NetMetria product lineup

One generation standard. Different scope and workflow.

NetMetria Explorer is the complete evaluation and learning product. NetMetria Workbench expands content breadth and authoring efficiency for day-to-day detection engineering. NetMetria Enterprise adds organizational licensing, support, training, and services. Every product uses the same generation core and produces the same quality of datasets.

NetMetria Explorer Planned September 2026

Learn. Evaluate. Teach.

A complete, non-expiring edition for product evaluation, individual study, classroom instruction, and detection engineering labs. NetMetria Explorer uses the same generation core and produces the same dataset quality as every other NetMetria product.

  • Linux command-line scenario-to-PCAP workflow
  • 15 ATT&CK-aligned behaviors at initial release
  • PCAP, timeline, manifest, and ground truth
  • Classroom exercises and instructor-led training
  • Repeatable, deterministic dataset generation
NetMetria Workbench In development

Build. Manage. Expand.

The planned operational product for sustained detection engineering work. NetMetria Workbench adds broader content libraries, reusable project workflows, and visual scenario and campaign authoring. It does not change the quality of the generated dataset.

  • Additional ATT&CK techniques, protocol families, and network profiles
  • Additional transferred objects, payload objects, scenarios, and campaign templates
  • Visual scenario and campaign editor targeted for Q1 2027
  • CLI and visual workflows for recurring dataset development
NetMetria Enterprise In development

Deploy. Support. Standardize.

The organizational offering built on NetMetria Workbench. NetMetria Enterprise adds licensing, support, training, deployment assistance, and services without creating a separate dataset-quality tier.

  • Organizational licensing
  • Priority support and training
  • Consulting and deployment assistance
  • Enterprise services
Every NetMetria product produces the same quality of datasets. NetMetria Workbench expands content and authoring workflow. NetMetria Enterprise expands organizational capabilities. Neither changes how well NetMetria models the declared scenario.

Product boundary

What NetMetria does, and what it does not do.

NetMetria is built to
  • Model scenario-relevant hosts and interactions
  • Generate network-observable behavior
  • Produce PCAP with timing and ground truth
  • Support controlled validation and comparison
NetMetria is not built to
  • Execute malware or payloads
  • Emulate complete endpoint state
  • Operate live command-and-control infrastructure
  • Replace a cyber range when live systems are required

NetMetria Explorer access list

Join the NetMetria Explorer access list.

Join for NetMetria Explorer release updates and possible pre-release evaluation opportunities. NetMetria Explorer is a complete, non-expiring evaluation and learning edition, not a time-limited trial. The list may also be used for NetMetria Workbench and NetMetria Enterprise announcements.

  1. 01
    Follow the NetMetria Explorer releaseReceive status, availability, and evaluation updates
  2. 02
    Describe your intended useDetection, testing, training, research, or lab development
  3. 03
    Follow the product lineupReceive NetMetria Workbench and NetMetria Enterprise announcements
This is an interest list. It is not a sales form. The form does not ask for a phone number. A confirmation email is sent after submission.
Join the NetMetria Explorer access listNetMetria Explorer release and product updates
Primary area of interest

A confirmation will be sent to the email address provided.

Technical evaluation

What to understand before joining the NetMetria Explorer list.

The answers below cover product boundaries, NetMetria Explorer, the product lineup, and the access list.

How is NetMetria different from replaying an existing PCAP?

Packet replay sends traffic from an existing capture. NetMetria creates a new capture from a scenario that defines the hosts, roles, behavior order, timing, and expected network results. The PCAP is delivered with the scenario timeline and ground truth for that run.

How is NetMetria different from a cyber range?

A cyber range runs real or virtual systems in a live environment. NetMetria does not recreate the full environment. It generates the network traffic needed for the scenario. Use a range when endpoint state, user interaction, live tools, or system compromise are part of the exercise.

What does “known-answer PCAP” mean?

The PCAP includes supporting information that describes the expected behavior sequence, timing, hosts, flows, and results. Analysts and engineers can compare tool output with what the scenario was designed to generate.

How are hosts selected for a scenario?

A host is included only when it has a role in the scenario. It may send traffic, receive traffic, support an intermediate step, or generate background activity. Unrelated systems are not added just to imitate a complete enterprise network.

Can background traffic be included?

Yes. Background traffic uses the same role-based model as the main scenario. Additional hosts or logical traffic sources can be added when their job is to create ambient activity. The sample on this page leaves background traffic out so the fifteen behavior groups are easier to inspect.

How repeatable is the generated traffic?

Using the same scenario and generation inputs produces comparable packet output, timing, manifests, and ground-truth records. That makes the dataset useful for rule development, parser testing, regression checks, training, and controlled comparisons.

How realistic is the generated traffic?

NetMetria represents the network behavior required by a test. It does not try to reproduce every detail of a live enterprise. Judge the result by whether the PCAP contains the packet structures, order, timing, endpoints, and protocol activity the test requires.

Does NetMetria execute malware or compromise endpoints?

No. NetMetria generates network traffic associated with the declared behaviors. It does not run malware, exploit systems, create live command infrastructure, or change endpoint state.

What is included in NetMetria Explorer?

NetMetria Explorer is planned for September 2026. The initial release includes the Linux command-line workflow, 15 ATT&CK-aligned network behaviors, and outputs for PCAP, timeline, manifest, and ground truth. It is designed for product evaluation, individual learning, classroom instruction, instructor-led training, and detection engineering labs.

Does NetMetria Explorer generate lower-quality or simplified traffic?

No. NetMetria Explorer uses the same core generation technology and modeling approach as NetMetria Workbench and NetMetria Enterprise. Dataset quality and traffic realism do not change across the product line. NetMetria Workbench expands content and authoring workflow; NetMetria Enterprise expands organizational capabilities.

Is NetMetria Explorer a trial or demonstration edition?

No. NetMetria Explorer is a complete, non-expiring evaluation and learning platform. It is not time-limited, deliberately degraded, or a demonstration build. NetMetria Workbench has broader content and authoring capabilities, but it does not produce higher-quality datasets.

How do NetMetria Workbench and NetMetria Enterprise relate to NetMetria Explorer?

NetMetria Workbench is the planned operational product for day-to-day detection engineering. It expands the available ATT&CK techniques, protocol families, network profiles, transferred objects, payload objects, scenarios, campaign templates, content libraries, and authoring workflow. NetMetria Enterprise builds on NetMetria Workbench with organizational licensing, priority support, training, consulting, deployment assistance, and enterprise services.

Will NetMetria include a visual editor?

Yes. Visual scenario and campaign authoring is planned for NetMetria Workbench, with the editor targeted for Q1 2027. The editor is intended to reduce authoring and project-management effort. It does not create a different traffic-realism or dataset-quality tier. The initial NetMetria Explorer release uses the Linux command-line workflow.

What does joining the NetMetria Explorer access list mean?

The list is used for NetMetria Explorer release updates and possible pre-release evaluation opportunities. It may also be used for NetMetria Workbench and NetMetria Enterprise announcements. The intended-use question helps shape examples and documentation. Joining does not guarantee early access or a place in an evaluation group.

NetMetria access list

Review the sample traffic and follow the NetMetria Explorer release.

Join the NetMetria Explorer access list →
Join NetMetria Explorer access list