DGA-like Traffic
Cycling through algorithmically generated names
Some malware families compute a fresh list of domain names every day and try them in turn until one answers. Most fail. The resulting mix of pseudo-random names and heavy NXDOMAIN is one of the most recognisable shapes in DNS telemetry.
- A DGA is a shared algorithm producing the same names for attacker and malware
- Most generated names are never registered, so failures dominate
- The pattern is recognisable, but benign lookalikes exist
Queries/minRate across all simulated clients in this scenario.
60
AllowedLookups the simulated resolver answered normally.
1
BlockedLookups a policy or feed prevented.
0
FindingsDetections raised by the simplified demonstration model.
0
NXDOMAIN %Share of lookups for names that do not exist.
0.0%
Unique domainsDistinct names seen — high cardinality is itself a signal.
1
TXT queriesTXT and NULL lookups. Normal in small amounts.
0
Avg entropyBits per character of the leftmost label. Readable names sit near 2.5.
1.58
Query flow
How each simulated lookup is handled
Device
DEMO-NAS-05
DNS query
CNAME ntp.example
DNS Daddy
resolver + policy
Signals
0 of 4 firing
Outcome
Allow
Event stream
Synthetic queries. Select a row to inspect it.
| Time | Device | Type | DNS query | Result |
|---|---|---|---|---|
| 13:42:00 | DEMO-NAS-05192.0.2.91 | ntp.example | Allowed |
Devices on the simulated network
Per-device behaviour, measured over the run
DEMO-LAPTOP-01192.0.2.21
Staff laptop
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-DESKTOP-02192.0.2.32
Reception desktop
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-LAB-CLIENT192.0.2.42
Isolated lab host
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-PHONE-04192.0.2.70
Mobile device
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-NAS-05192.0.2.91
File server
- queries
- 1
- unique
- 1
- entropy
- 1.58
- nxdomain
- 0%
Detection model
Signals accumulate as behaviour changes
Signals
- Majority of lookups fail+0 of 25not yet observed
- Pseudo-random name structure+0 of 22not yet observed
- Large number of distinct second-level domains+0 of 23not yet observed
- Rapid sequential attempts+0 of 15not yet observed
Simplified demonstration model. Each signal adds a fixed number of points; reaching 68 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.
Attack timeline
How the scenario unfolds
- 1Normal traffic across the labnow
- 2One client starts trying meaningless domain names
- 3NXDOMAIN ratio rises sharply for that client
- 4Entropy and domain-cardinality signals fire
- 5Risk score crosses the threshold
- 6One generated name resolves and is blocked by policy
- 7Analyst hunts the same names across other hosts
Threat hunting mode
Find the affected device before the model tells you
Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.
Keep going
Compare this against another pattern