IEC 60870-5-104 Intrusion Detection Dataset — Smart Grid Cyberattacks [1.1 GB]
Smart-grid IDS dataset with labelled IEC 60870-5-104 and TCP/IP flow statistics plus PCAP files across 12 cyberattack scenarios. CSV and PCAP formats.
View DatasetShowing 12 of 17 datasets
Smart-grid IDS dataset with labelled IEC 60870-5-104 and TCP/IP flow statistics plus PCAP files across 12 cyberattack scenarios. CSV and PCAP formats.
View DatasetIndustrial IoT IDS dataset with labelled TCP/IP and DNP3 flow statistics plus PCAP files for 9 SCADA cyberattacks. CSV and PCAP formats for ML/DL IDS research.
View DatasetMQTT IoT IDS dataset from a simulated network with 12 sensors, broker, camera, and attacker. PCAP and CSV features support MQTT intrusion detection research.
View DatasetIoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.
View DatasetIoT IDS dataset for distinguishing normal and malicious ICMP/Ping traffic generated from an ESP-01s embedded device. PCAP, Zeek logs, and labelled CSV files.
View DatasetLarge-scale distributed IoT IDS benchmark with traffic captured at individual device interfaces across 78 heterogeneous smart city IoT devices using the Gotham testbed. PCAP and CSV. Published January 2026 on Zenodo. Designed for federated learning and decentralised IDS research.
View DatasetFirst open Zigbee IoT dataset with fully decrypted payloads, captured from a real smart home with 15 Zigbee devices over 20 days. Distributed as a single archive (dataset.tar.gz, 663.4 MB) of pcap captures with the network key included. Published October 2024 on Zenodo under CC BY 4.0.
View DatasetLarge-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.
View DatasetReal IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.
View DatasetRealistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.
View DatasetA large-scale dataset (245GB) collected from real-world industrial control systems for advanced threat detection.
View DatasetNetwork-traffic dataset on Mendeley Data documenting DDoS attacks against the Fibaro Home Center 3 smart-home controller; PCAP and CSV formats are provided. [page:4][web:52]
View Dataset