Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

DNS Tunnelling

Data smuggled inside query names

Experimental concept All scenarios

One lab host starts sending long, encoded-looking subdomains under a single parent domain. Because the resolver answers the query, the name itself becomes a covert channel. Signals accumulate until the demonstration model raises a finding.

  • Query names can carry data outbound even when web traffic is blocked
  • Detection comes from behaviour over time, not one bad-looking name
  • Unique-subdomain count under one parent is the strongest single clue
Speed
1/92 queries

Queries/min

60

Allowed

1

Blocked

0

Findings

0

NXDOMAIN %

0.0%

Unique domains

1

TXT queries

0

Avg entropy

2.00

Query flow

How each simulated lookup is handled

  1. Device

    DEMO-LAPTOP-01

  2. DNS query

    A auth.example.com

  3. DNS Daddy

    resolver + policy

  4. Signals

    0 of 5 firing

  5. Outcome

    Allow

Event stream

Synthetic queries. Select a row to inspect it.

TimeDeviceDNS queryResult
13:42:00DEMO-LAPTOP-01192.0.2.21auth.example.comAllowed

Devices on the simulated network

Per-device behaviour, measured over the run

  • DEMO-LAPTOP-01192.0.2.21

    Staff laptop

    queries
    1
    unique
    1
    entropy
    2.00
    nxdomain
    0%
  • DEMO-DESKTOP-02192.0.2.32

    Reception desktop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-LAB-CLIENT192.0.2.42

    Isolated lab host

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-PHONE-04192.0.2.70

    Mobile device

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-NAS-05192.0.2.91

    File server

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%

Detection model

Signals accumulate as behaviour changes

Experimental concept

Risk score

0/70 needed

Confidence

0%

MITRE ATT&CK

T1071.004

Signals

  • High unique-subdomain count+0 of 25not yet observed
  • Unusually long query labels+0 of 15not yet observed
  • High average label entropy+0 of 20not yet observed
  • Sustained elevated query rate+0 of 17not yet observed
  • Unusual TXT usage+0 of 10not yet observed

Simplified demonstration model. Each signal adds a fixed number of points; reaching 70 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.

Attack timeline

How the scenario unfolds

  1. 1Client behaves normally alongside the rest of the labnow
  2. 2Behaviour changes: long encoded labels appear under one parent
  3. 3Unique-subdomain count begins climbing with no cache reuse
  4. 4Entropy and label-length signals fire
  5. 5Query rate signal fires — risk score crosses the threshold
  6. 6Finding generated with its supporting evidence attached
  7. 7Analyst reviews evidence and false-positive candidates

Threat hunting mode

Find the affected device before the model tells you

Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.

Keep going

Compare this against another pattern