Real attack traffic. Labelled. And free.

Many teams build on our datasets because capturing and labelling real attack traffic is difficult, expensive, and risky. We create and maintain labelled captures of malware, botnet, IoT, and honeypot traffic. These datasets support detection development, independent evaluation, research, and education.

CTU-13

The reference botnet dataset of the field. Thirteen scenarios of real botnet traffic. Every flow was manually labeled: botnet, command and control, normal, or background.

Created at the Stratosphere Laboratory by Sebastián García and published with the paper "An empirical comparison of botnet detection methods" in Computers and Security in 2014. Cited in thousands of studies since, it is still the dataset new detection methods are measured against. Learn more

CTU-SME-11

A network security dataset in the setting of a small medium enterprise network. Includes 11 devices, 7 days, 99 million expert-labeled network flows with real benign and malicious traffic.

This dataset was created by Štěpán Bendl as part of his master's thesis at the Czech Technical University in Prague, in 2023, under the supervision of Sebastián García and Veronica Valeros.