Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

Normal DNS

The baseline every detection is measured against

A small office network going about its day. Short, meaningful hostnames, a handful of repeated destinations, and mostly A and AAAA lookups. Watch this first so the suspicious scenarios have something to look abnormal against.

  • A DNS query is a device asking a resolver to turn a name into an address
  • Ordinary names are short, human-readable and heavily repeated
  • Almost everything resolves successfully
Speed
1/70 queries

Queries/min

60

Allowed

1

Blocked

0

Findings

0

NXDOMAIN %

0.0%

Unique domains

1

TXT queries

0

Avg entropy

2.75

Query flow

How each simulated lookup is handled

  1. Device

    DEMO-LAPTOP-01

  2. DNS query

    AAAA packages.example.net

  3. DNS Daddy

    resolver + policy

  4. Signals

    nothing above threshold

  5. Outcome

    Allow

Event stream

Synthetic queries. Select a row to inspect it.

TimeDeviceDNS queryResult
13:42:00DEMO-LAPTOP-01192.0.2.21packages.example.netAllowed

Devices on the simulated network

Per-device behaviour, measured over the run

  • DEMO-LAPTOP-01192.0.2.21

    Staff laptop

    queries
    1
    unique
    1
    entropy
    2.75
    nxdomain
    0%
  • DEMO-DESKTOP-02192.0.2.32

    Reception desktop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-LAB-CLIENT192.0.2.42

    Isolated lab host

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-PHONE-04192.0.2.70

    Mobile device

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-NAS-05192.0.2.91

    File server

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%

Detection model

Nothing to report

No signals above threshold

This is what a healthy baseline looks like: short readable names, heavy reuse, almost everything resolving. Every other scenario is measured against activity like this.

Simplified demonstration model. The scoring used across this simulation is written for teaching and does not mirror the real DNS Daddy engine.

Attack timeline

How the scenario unfolds

  1. 1Devices come online and resolve routine destinationsnow
  2. 2Names repeat as caches expire — low unique-domain count
  3. 3Query rate stays flat and unremarkable
  4. 4No signal crosses a threshold — nothing to report

Keep going

Compare this against another pattern