hypnonyx/traffico

TEXT GENERATIONPricing:Input $0.04 / Cached $0.008 / Output $0.08Concurrent Unit Cost:1Model Size:0.3BQuant:BF16Context Size:32kPublished:Mar 4, 2026License:otherArchitecture:Transformer Featherless Exclusive Cold

hypnonyx/traffico is a 0.3 billion parameter language model, fine-tuned from Google's Gemma 2.7B, specialized in cybersecurity. It analyzes TCP/IP network traffic to detect cyberattacks and maps network flow patterns to the MITRE ATT&CK framework. This model excels at classifying network flows as normal or malicious and providing ATT&CK-mapped threat classifications for security teams.

Loading preview...

Overview

hypnonyx/traffico is a specialized language model, fine-tuned from Google's Gemma 2.7B, designed for cybersecurity applications. It focuses on analyzing TCP/IP network traffic to identify cyberattacks and correlate them with the MITRE ATT&CK framework. The model was trained using a synthetic dataset derived from real-world network traffic (CIC-IDS2017 + UNSW-NB15) and enriched with MITRE ATT&CK techniques, enabling it to classify network flows and provide threat classifications.

Key Capabilities

  • Network Intrusion Detection: Classifies network flows as benign or malicious in real-time.
  • Threat Intelligence: Maps detected attacks to specific MITRE ATT&CK techniques and tactics.
  • Security Monitoring: Analyzes TCP/IP flows from network sensors and IDS systems.
  • Incident Response: Helps understand adversary behavior patterns from network telemetry.
  • ATT&CK Mapping: Provides classifications for various attack types, including DoS, DDoS, PortScan, Brute Force, Infiltration, Botnet, and Web attacks, linking them to MITRE ATT&CK categories like Reconnaissance, Initial Access, Lateral Movement, and Impact.

Good For

  • Security teams needing to understand adversary tactics from network behavior.
  • Researchers studying attack-to-technique mappings in security datasets.
  • Integrating into existing security monitoring and incident response workflows.

Limitations

  • The model is not exhaustive and may not cover all possible or novel adversary behaviors.
  • It is provided "as is" and requires validation against specific security requirements.
  • Comprehensive defensive coverage is not guaranteed solely by using this model.