Real attack traffic. Labelled. And free.
Many teams build on our datasets because capturing and labelling real attack traffic is difficult, expensive, and risky. We create and maintain labelled captures of malware, botnet, IoT, and honeypot traffic. These datasets support detection development, independent evaluation, research, and education.
CTU-13
The reference botnet dataset of the field. Thirteen scenarios of real botnet traffic. Every flow was manually labeled: botnet, command and control, normal, or background.
Created at the Stratosphere Laboratory by Sebastián García and published with the paper "An empirical comparison of botnet detection methods" in Computers and Security in 2014. Cited in thousands of studies since, it is still the dataset new detection methods are measured against. Learn more
CTU-SME-11
A network security dataset in the setting of a small medium enterprise network. Includes 11 devices, 7 days, 99 million expert-labeled network flows with real benign and malicious traffic.
This dataset was created by Štěpán Bendl as part of his master's thesis at the Czech Technical University in Prague, in 2023, under the supervision of Sebastián García and Veronica Valeros.
-
Real IoT malware, captured live. Twenty captures of botnet infections executed on real devices with open internet access, including Mirai, Okiru, and Torii. Three more captures record the clean traffic of real consumer hardware: a smart lamp, an Amazon Echo, and a smart door lock. Every flow is labeled by behavior, from command and control to denial of service attacks.
Created by Sebastian García, Agustín Parmisano, and María José Erquiaga and published in 2020, with funding from Avast Software. It has since become one of the most widely used datasets in IoT security research.
-
Description tEight identical honeypots, eight cities, forty days. The cloud servers were deployed simultaneously across Europe, North America, and Asia and configured identically, so geography is the only variable. Each ran a real SSH service with no honeypot software, leaving attackers nothing to fingerprint. The result is a clean measurement of how location shapes the attacks a server receives, delivered as bidirectional NetFlows in three formats.
Created by Veronica Valeros and Sebastian García and published with a companion paper in Data in Brief in 2022.ext goes here
-
The Hornet experiment, extended. Nine identical honeypots ran for 65 days in 2024 across Europe, North America, Asia, and Oceania, adding Sydney to the original eight cities. The design is unchanged: real SSH servers, identical automated configuration, no honeypot software. Traffic is delivered as hourly Zeek logs, ready for detection pipelines. Together with Hornet 40, it lets you compare the internet's attack background across three years.
Created at the Stratosphere Laboratory and published with a companion paper in Data in Brief in 2025.
-
What does phone spyware look like on the wire? Real Android phones were infected with seven Remote Access Trojans, including DroidJack, SpyMAX, and AhMyth, then operated by hand from their control panels. Each capture pairs the network traffic with the RAT's APK, screenshots of both the victim phone and the controller, and a timestamped log of every action performed, down to the moment a picture was taken. You can trace each packet to the act that produced it.
Created at the Stratosphere Laboratory by Kamila Babayeva under the supervision of Sebastian Garcia, and first published in 2020.
