High-Entropy Subdomains
api.example.test versus aj39DKsl20ZmQ8.example.test
Entropy measures how random a string looks. Human hostnames are predictable; generated ones are not. This scenario puts the two side by side so you can see what the measurement actually captures — and why on its own it proves nothing.
- Entropy is a statistical property of the name, nothing more
- Plenty of legitimate infrastructure uses random-looking hostnames
- One signal is a lead; a finding needs corroboration
Queries/minRate across all simulated clients in this scenario.
60
AllowedLookups the simulated resolver answered normally.
1
BlockedLookups a policy or feed prevented.
0
FindingsDetections raised by the simplified demonstration model.
0
NXDOMAIN %Share of lookups for names that do not exist.
0.0%
Unique domainsDistinct names seen — high cardinality is itself a signal.
1
TXT queriesTXT and NULL lookups. Normal in small amounts.
0
Avg entropyBits per character of the leftmost label. Readable names sit near 2.5.
2.81
Query flow
How each simulated lookup is handled
Device
DEMO-LAPTOP-01
DNS query
AAAA storage.example.net
DNS Daddy
resolver + policy
Signals
0 of 4 firing
Outcome
Allow
Event stream
Synthetic queries. Select a row to inspect it.
| Time | Device | Type | DNS query | Result |
|---|---|---|---|---|
| 13:42:00 | DEMO-LAPTOP-01192.0.2.21 | storage.example.net | Allowed |
Devices on the simulated network
Per-device behaviour, measured over the run
DEMO-LAPTOP-01192.0.2.21
Staff laptop
- queries
- 1
- unique
- 1
- entropy
- 2.81
- nxdomain
- 0%
DEMO-DESKTOP-02192.0.2.32
Reception desktop
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-LAB-CLIENT192.0.2.42
Isolated lab host
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-PHONE-04192.0.2.70
Mobile device
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-NAS-05192.0.2.91
File server
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
Detection model
Signals accumulate as behaviour changes
Risk score
0/60 needed
Confidence
0%
Signals
- Average label entropy well above baseline+0 of 30not yet observed
- Labels longer than typical hostnames+0 of 15not yet observed
- Very little name reuse+0 of 20not yet observed
- Concentrated under one parent domain+0 of 15not yet observed
Simplified demonstration model. Each signal adds a fixed number of points; reaching 60 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.
Attack timeline
How the scenario unfolds
- 1Readable, low-entropy names across the labnow
- 2One client begins requesting random-looking labels
- 3Average entropy for that client separates from the baseline
- 4Length and cardinality signals corroborate
- 5Risk score crosses a deliberately low threshold
- 6Low-severity finding generated
- 7Analyst rules out known providers before acting
Threat hunting mode
Find the affected device before the model tells you
Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.
Keep going
Compare this against another pattern