Behavioural detections alert only. They do not automatically block DNS traffic.
Each detector observes, scores and explains — blocking stays with threat intelligence and policy. All six detectors are experimental: the thresholds are calibrated against synthetic traffic, not a production network, so no real-world false-positive rate has been measured. These are statistical measurements, not machine-learning models.
High
1
Medium
3
Low
2
Detectors
6
All alert-only, all experimental
Findings
Select a finding to see the evidence behind it.
Detectors
The six behavioural detectors and what each one measures.
- DNS tunnellingdns_tunnelExperimental
High-volume encoded subdomain traffic under a single parent domain.
Measures: Unique subdomains, label length, label entropy, TXT/NULL share.
- DGA-like domainsdga_likeExperimental
Algorithmic-looking names, often spread across several TLDs.
Measures: Character distribution, label randomness, distinct parent domains.
- NXDOMAIN anomalynxdomain_anomalyExperimental
An unusual proportion of names that do not exist, versus the client's own baseline.
Measures: NXDOMAIN ratio, distinct failing names, per-client baseline.
- TXT anomalytxt_anomalyExperimental
An unusual share of TXT lookups for a client, or unusually large TXT answers.
Measures: TXT share of queries, answer size, distinct TXT names.
- DNS beaconingdns_beaconingExperimental
Highly regular query intervals to a single name.
Measures: Mean interval, coefficient of variation, distinct names.
- Resolution failureresolution_failureExperimental
Repeated SERVFAIL or timeout responses for a client or upstream.
Measures: SERVFAIL rate, timeout rate, affected upstream.
Want to watch these patterns build up in simulated traffic query by query?
Open the detection lab