Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

High-Entropy Subdomains

api.example.test versus aj39DKsl20ZmQ8.example.test

Research demonstration All scenarios

Entropy measures how random a string looks. Human hostnames are predictable; generated ones are not. This scenario puts the two side by side so you can see what the measurement actually captures — and why on its own it proves nothing.

  • Entropy is a statistical property of the name, nothing more
  • Plenty of legitimate infrastructure uses random-looking hostnames
  • One signal is a lead; a finding needs corroboration
Speed
1/75 queries

Queries/min

60

Allowed

1

Blocked

0

Findings

0

NXDOMAIN %

0.0%

Unique domains

1

TXT queries

0

Avg entropy

2.81

Query flow

How each simulated lookup is handled

  1. Device

    DEMO-LAPTOP-01

  2. DNS query

    AAAA storage.example.net

  3. DNS Daddy

    resolver + policy

  4. Signals

    0 of 4 firing

  5. Outcome

    Allow

Event stream

Synthetic queries. Select a row to inspect it.

TimeDeviceDNS queryResult
13:42:00DEMO-LAPTOP-01192.0.2.21storage.example.netAllowed

Devices on the simulated network

Per-device behaviour, measured over the run

  • DEMO-LAPTOP-01192.0.2.21

    Staff laptop

    queries
    1
    unique
    1
    entropy
    2.81
    nxdomain
    0%
  • DEMO-DESKTOP-02192.0.2.32

    Reception desktop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-LAB-CLIENT192.0.2.42

    Isolated lab host

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-PHONE-04192.0.2.70

    Mobile device

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-NAS-05192.0.2.91

    File server

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%

Detection model

Signals accumulate as behaviour changes

Research demonstration

Risk score

0/60 needed

Confidence

0%

Signals

  • Average label entropy well above baseline+0 of 30not yet observed
  • Labels longer than typical hostnames+0 of 15not yet observed
  • Very little name reuse+0 of 20not yet observed
  • Concentrated under one parent domain+0 of 15not yet observed

Simplified demonstration model. Each signal adds a fixed number of points; reaching 60 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.

Attack timeline

How the scenario unfolds

  1. 1Readable, low-entropy names across the labnow
  2. 2One client begins requesting random-looking labels
  3. 3Average entropy for that client separates from the baseline
  4. 4Length and cardinality signals corroborate
  5. 5Risk score crosses a deliberately low threshold
  6. 6Low-severity finding generated
  7. 7Analyst rules out known providers before acting

Threat hunting mode

Find the affected device before the model tells you

Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.

Keep going

Compare this against another pattern