IoT Emulated ICMP/Ping Dataset — Normal and Malicious Traffic [3.2 GB PCAP]
IoT IDS dataset for distinguishing normal and malicious ICMP/Ping traffic generated from an ESP-01s embedded device. PCAP, Zeek logs, and labelled CSV files.
Labelled attack traffic for intrusion detection research: DDoS and botnet captures, MQTT and protocol abuse, malware traces and federated IDS benchmarks.
IoT IDS dataset for distinguishing normal and malicious ICMP/Ping traffic generated from an ESP-01s embedded device. PCAP, Zeek logs, and labelled CSV files.
IoT botnet IDS dataset using 83 real and emulated devices with Mirai, BashLite, and Torii traffic. Raw PCAP files support botnet and anomaly detection research.
MQTT IoT IDS dataset from a simulated network with 12 sensors, broker, camera, and attacker. PCAP and CSV features support MQTT intrusion detection research.
Free CC0 synthetic dataset: 4,000 rows of Modbus, OPC UA and DNP3 flows labelled for SCADA intrusion detection. 21% Attacks. Reproducible from its seed.
Real IoT botnet traffic dataset from 9 commercial devices (webcams, routers, thermostats) authentically infected by Mirai and BASHLITE. Over 7M records, 115 statistical features. CSV format. Benchmark for deep-learning-based IoT anomaly and botnet detection.
Free CC0 synthetic dataset: 10,000 rows of Modbus, OPC UA and DNP3 flows labelled for SCADA intrusion detection. 29% Attacks. Reproducible from its seed.
Realistic IoT/IIoT cybersecurity dataset supporting centralized and federated learning with 15 attack types across network, application, and protocol layers. CSV and PCAP formats (~12 GB). Available via IEEE Dataport and Kaggle. Designed for edge computing IDS research.
Smart-home-derived IoT botnet dataset with 625,783 labeled flow records and 83 network features. Covers DoS, Mirai, MITM, and Scan attacks from EZVIZ and SKT NGU Wi-Fi cameras. CSV format. Supports binary, category, and sub-category IDS classification tasks.
Real-time IoT network security dataset from a live IoT infrastructure with 41 bidirectional flow features. Includes ThingSpeak-LED, Wipro-Bulb, and MQTT-Temp devices with SSH brute force, DDoS (Hping/Slowloris), and Nmap attack scenarios. CSV format. Used for adaptive IDS development.
Real IoT malware traffic dataset with 325M labeled network flows from 20 malware and 3 benign device captures over 500+ hours. PCAP and Zeek conn.log formats. Used for IoT botnet detection, malware traffic classification, and ML security research.
Heterogeneous IoT/IIoT dataset from UNSW Canberra Cyber Range with network traffic, Windows/Linux OS traces, and IoT sensor telemetry. Labeled for 9 attack types including DoS, DDoS, ransomware, and XSS. CSV and PCAP formats. Benchmark for AI-based IDS evaluation.
Large-scale IoT cybersecurity dataset with 47M+ labeled network flows from 105 real IoT devices across 33 attack types in 7 categories. PCAP and CSV formats. Built for IDS/IPS development and ML-based IoT traffic classification research.
Free CC0 synthetic dataset: 10,000 rows of Modbus, OPC UA and DNP3 flows labelled for SCADA intrusion detection. 16% Attacks. Reproducible from its seed.
Free CC0 synthetic dataset: 10,000 rows of Modbus, OPC UA and DNP3 flows labelled for SCADA intrusion detection. 15% Attacks. Reproducible from its seed.
Free CC0 synthetic dataset: 500 rows of labelled network flows covering DoS, DDoS, botnet and reconnaissance traffic. 18% Attacks.
Latest 2026 IoT malware dataset from the Canadian Institute for Cybersecurity (CIC) and Yunnan University, featuring comprehensive malware samples and behavioral analysis data for IoT threat detection research.
Reproducible large-scale IoT network dataset from 78 emulated devices using MQTT, CoAP, and RTSP protocols. Includes benign and malicious traffic with DoS, brute force, scanning, and C&C attacks in PCAP and CSV formats.
Comprehensive IoT attack dataset for device identification and anomaly detection in security analytics applications.
Comprehensive synthetic dataset designed for analyzing DDoS attacks in Internet of Things environments.
A comprehensive dataset derived from real-time IoT infrastructure, designed for intrusion detection research and network security analysis.
A large-scale, reproducible network dataset for evaluating modern IoT intrusion detection systems.
A comprehensive and realistic IoT dataset generated by the Canadian Institute for Cybersecurity (CIC) for profiling, detecting, and characterizing multi-vector IoT attacks in a real network topology.
Dataset documents replay attacks targeting MQTT communications in water distribution system with 4.8 MB CSV file containing original and replayed messages for temporal sequence analysis.
Network-traffic dataset on Mendeley Data documenting DDoS attacks against the Fibaro Home Center 3 smart-home controller; PCAP and CSV formats are provided. [page:4][web:52]