Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

Beaconing

The same lookup, almost exactly on schedule

Experimental concept All scenarios

Volume is not the only tell. Here one client asks for a single name every few seconds with machine-like regularity. Nothing about the name is unusual — the timing is the signal.

  • Regular intervals are a behavioural signal independent of the name itself
  • Implants check in on a timer, sometimes with deliberate jitter
  • Plenty of legitimate software also polls on a schedule
Speed
1/53 queries

Queries/min

60

Allowed

1

Blocked

0

Findings

0

NXDOMAIN %

0.0%

Unique domains

1

TXT queries

0

Avg entropy

2.00

Query flow

How each simulated lookup is handled

  1. Device

    DEMO-DESKTOP-02

  2. DNS query

    CNAME chat.example.com

  3. DNS Daddy

    resolver + policy

  4. Signals

    0 of 4 firing

  5. Outcome

    Allow

Event stream

Synthetic queries. Select a row to inspect it.

TimeDeviceDNS queryResult
13:42:00DEMO-DESKTOP-02192.0.2.32chat.example.comAllowed

Devices on the simulated network

Per-device behaviour, measured over the run

  • DEMO-LAPTOP-01192.0.2.21

    Staff laptop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-DESKTOP-02192.0.2.32

    Reception desktop

    queries
    1
    unique
    1
    entropy
    2.00
    nxdomain
    0%
  • DEMO-LAB-CLIENT192.0.2.42

    Isolated lab host

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-PHONE-04192.0.2.70

    Mobile device

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-NAS-05192.0.2.91

    File server

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%

Detection model

Signals accumulate as behaviour changes

Experimental concept

Risk score

0/65 needed

Confidence

0%

MITRE ATT&CK

T1071.004

Signals

  • Highly regular query interval+0 of 32not yet observed
  • Same name repeatedly, defeating cache expectations+0 of 18not yet observed
  • Pattern sustained over time+0 of 20not yet observed
  • Periodic TXT lookups within the pattern+0 of 12not yet observed

Simplified demonstration model. Each signal adds a fixed number of points; reaching 65 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.

Attack timeline

How the scenario unfolds

  1. 1Normal, irregular traffic across the labnow
  2. 2One client begins resolving a single name on a timer
  3. 3Interval consistency becomes measurable
  4. 4Regularity and repetition signals fire
  5. 5Pattern persistence pushes risk over the threshold
  6. 6Finding generated
  7. 7Analyst identifies the responsible process

Threat hunting mode

Find the affected device before the model tells you

Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.

Keep going

Compare this against another pattern