Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

DGA-like Traffic

Cycling through algorithmically generated names

Research demonstration All scenarios

Some malware families compute a fresh list of domain names every day and try them in turn until one answers. Most fail. The resulting mix of pseudo-random names and heavy NXDOMAIN is one of the most recognisable shapes in DNS telemetry.

  • A DGA is a shared algorithm producing the same names for attacker and malware
  • Most generated names are never registered, so failures dominate
  • The pattern is recognisable, but benign lookalikes exist
Speed
1/83 queries

Queries/min

60

Allowed

1

Blocked

0

Findings

0

NXDOMAIN %

0.0%

Unique domains

1

TXT queries

0

Avg entropy

1.58

Query flow

How each simulated lookup is handled

  1. Device

    DEMO-NAS-05

  2. DNS query

    CNAME ntp.example

  3. DNS Daddy

    resolver + policy

  4. Signals

    0 of 4 firing

  5. Outcome

    Allow

Event stream

Synthetic queries. Select a row to inspect it.

TimeDeviceDNS queryResult
13:42:00DEMO-NAS-05192.0.2.91ntp.exampleAllowed

Devices on the simulated network

Per-device behaviour, measured over the run

  • DEMO-LAPTOP-01192.0.2.21

    Staff laptop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-DESKTOP-02192.0.2.32

    Reception desktop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-LAB-CLIENT192.0.2.42

    Isolated lab host

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-PHONE-04192.0.2.70

    Mobile device

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-NAS-05192.0.2.91

    File server

    queries
    1
    unique
    1
    entropy
    1.58
    nxdomain
    0%

Detection model

Signals accumulate as behaviour changes

Research demonstration

Risk score

0/68 needed

Confidence

0%

MITRE ATT&CK

T1568.002

Signals

  • Majority of lookups fail+0 of 25not yet observed
  • Pseudo-random name structure+0 of 22not yet observed
  • Large number of distinct second-level domains+0 of 23not yet observed
  • Rapid sequential attempts+0 of 15not yet observed

Simplified demonstration model. Each signal adds a fixed number of points; reaching 68 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.

Attack timeline

How the scenario unfolds

  1. 1Normal traffic across the labnow
  2. 2One client starts trying meaningless domain names
  3. 3NXDOMAIN ratio rises sharply for that client
  4. 4Entropy and domain-cardinality signals fire
  5. 5Risk score crosses the threshold
  6. 6One generated name resolves and is blocked by policy
  7. 7Analyst hunts the same names across other hosts

Threat hunting mode

Find the affected device before the model tells you

Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.

Keep going

Compare this against another pattern