DNS Tunnelling
Data smuggled inside query names
One lab host starts sending long, encoded-looking subdomains under a single parent domain. Because the resolver answers the query, the name itself becomes a covert channel. Signals accumulate until the demonstration model raises a finding.
- Query names can carry data outbound even when web traffic is blocked
- Detection comes from behaviour over time, not one bad-looking name
- Unique-subdomain count under one parent is the strongest single clue
Queries/minRate across all simulated clients in this scenario.
60
AllowedLookups the simulated resolver answered normally.
1
BlockedLookups a policy or feed prevented.
0
FindingsDetections raised by the simplified demonstration model.
0
NXDOMAIN %Share of lookups for names that do not exist.
0.0%
Unique domainsDistinct names seen — high cardinality is itself a signal.
1
TXT queriesTXT and NULL lookups. Normal in small amounts.
0
Avg entropyBits per character of the leftmost label. Readable names sit near 2.5.
2.00
Query flow
How each simulated lookup is handled
Device
DEMO-LAPTOP-01
DNS query
A auth.example.com
DNS Daddy
resolver + policy
Signals
0 of 5 firing
Outcome
Allow
Event stream
Synthetic queries. Select a row to inspect it.
| Time | Device | Type | DNS query | Result |
|---|---|---|---|---|
| 13:42:00 | DEMO-LAPTOP-01192.0.2.21 | auth.example.com | Allowed |
Devices on the simulated network
Per-device behaviour, measured over the run
DEMO-LAPTOP-01192.0.2.21
Staff laptop
- queries
- 1
- unique
- 1
- entropy
- 2.00
- nxdomain
- 0%
DEMO-DESKTOP-02192.0.2.32
Reception desktop
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-LAB-CLIENT192.0.2.42
Isolated lab host
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-PHONE-04192.0.2.70
Mobile device
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-NAS-05192.0.2.91
File server
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
Detection model
Signals accumulate as behaviour changes
Signals
- High unique-subdomain count+0 of 25not yet observed
- Unusually long query labels+0 of 15not yet observed
- High average label entropy+0 of 20not yet observed
- Sustained elevated query rate+0 of 17not yet observed
- Unusual TXT usage+0 of 10not yet observed
Simplified demonstration model. Each signal adds a fixed number of points; reaching 70 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.
Attack timeline
How the scenario unfolds
- 1Client behaves normally alongside the rest of the labnow
- 2Behaviour changes: long encoded labels appear under one parent
- 3Unique-subdomain count begins climbing with no cache reuse
- 4Entropy and label-length signals fire
- 5Query rate signal fires — risk score crosses the threshold
- 6Finding generated with its supporting evidence attached
- 7Analyst reviews evidence and false-positive candidates
Threat hunting mode
Find the affected device before the model tells you
Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.
Keep going
Compare this against another pattern