-
Continual Anomaly Detection with pyCLAD
Continual anomaly detection is gaining attention in many domains where the notion of normality evolves over time and models must adapt without forgetting previously learned... -
SOC4Academia Toolbox
SOC4Academia Toolbox is a collection of practical materials and resources supporting the development and operation of Security Operations Centres (SOCs) in academic... -
CESNET Models
Pre-trained neural networks for traffic classification. The package provides two network architectures, 30pktTCNET and Multi-modal CESNET v2. See a related project CESNET... -
CESNET DataZoo (dataset collection)
A collection of datasets for network traffic classification and a set of tools to work with them. The cesnet-datazoo package currently provides four datasets: CESNET-TLS22... -
Network Entity Reputation Database (NERD)
IP reputation database - aggregates data about malicious IP addresses from multiple sources. Developed and run as a public service by CESNET. -
URL Evaluator
A system to gather suspicious URLs from multiple SSH honeynets and to semi-automatically evaluate whether they are malicious or not. Run by CESNET, results cotributed to URLhaus... -
Idle OS toolset
A toolset for capturing network traffic of various operating systems in idle state, whach was used to create the CESNET Idle OS traffic dataset. The toolset allows you to create... -
CESNET-TimeSeries24: Time Series Dataset for Network Traffic Anomaly...
A scientific paper and a dataest - timeseries describing network traffic of 275,000 active IP addresses in the CESNET3 network over a period of 40 weeks. Koumar, J., Hynek, K.,... -
HUGO Honeypot
CESNET runs a community project - a network of honeypots (HUGO Honeynet) which share captured data for centralized analysis. Project participants run an instance of the honeypot... -
CESNET Idle OS Traffic: A Dataset of Idle Traffic of Various Operating Systems
A dataset (and a scientific paper describing it) containing captured network traffic generated by various operating systems in an idle state, i.e. without any user interaction.... -
Attacks on Honeypots (June 2025 - January 2026)
This dataset contains network attack logs captured by a honeypot system between June 2025 and January 2026. It consists of four main CSV files providing different perspectives... -
Attacks on Honeypots (October 2024 - April 2025)
This dataset contains network attack logs captured by a honeypot system between November 2024 and April 2025. It consists of four main CSV files providing different perspectives...