The Cyber4OT dataset contains prepared in the test-bed environment packet traces from normal activity of OT network, as well as, full network attack. During recorded activity, the attacker performs full network reconnaissance, later disconnects legal Modbus TCP connection and performs PLC device hijacking.
The dataset contains 96 files with more than 4,25 millions of packets.
Detailed description of the dataset and conducted simulated attack is provided in the article:
K. Cabaj, S. Plamowski, P, Chaber, M. Ławryńczuk, P. Marusak, R. Nebeluk, A. Wojtulewicz, K. Zarzycki, Cyber4OT dataset: Network traces for cyber-security vulnerability evaluation in industrial control systems, SoftwareX, Volume 31, 2025, ISSN 2352-7110, doi.org/10.1016/j.softx.2025.102196.
Detailed description of the test bed, where data was prepared, is provided in the Cyber4OT_testbed_description.pdf file.
The most recent version of dataset (currently version 1.0.3) is also available from Zenodo - doi.org/10.5281/zenodo.15005190
Krzysztof Cabaj, Sebastian Plamowski, Patryk Chaber, Maciej Ławryńczuk, Piotr Marusak, Robert Nebeluk, Andrzej Wojtulewicz, Krzysztof Zarzycki.
This work was financed by the grant no. CYBERSECIDENT/488240/IV/NCBR/2021 Laboratory for Vulnerability Analysis (LaVA) of stationary and mobile IT devices and algorithms and software.