Normal DNS
The baseline every detection is measured against
A small office network going about its day. Short, meaningful hostnames, a handful of repeated destinations, and mostly A and AAAA lookups. Watch this first so the suspicious scenarios have something to look abnormal against.
- A DNS query is a device asking a resolver to turn a name into an address
- Ordinary names are short, human-readable and heavily repeated
- Almost everything resolves successfully
Queries/minRate across all simulated clients in this scenario.
60
AllowedLookups the simulated resolver answered normally.
1
BlockedLookups a policy or feed prevented.
0
FindingsDetections raised by the simplified demonstration model.
0
NXDOMAIN %Share of lookups for names that do not exist.
0.0%
Unique domainsDistinct names seen — high cardinality is itself a signal.
1
TXT queriesTXT and NULL lookups. Normal in small amounts.
0
Avg entropyBits per character of the leftmost label. Readable names sit near 2.5.
2.75
Query flow
How each simulated lookup is handled
Device
DEMO-LAPTOP-01
DNS query
AAAA packages.example.net
DNS Daddy
resolver + policy
Signals
nothing above threshold
Outcome
Allow
Event stream
Synthetic queries. Select a row to inspect it.
| Time | Device | Type | DNS query | Result |
|---|---|---|---|---|
| 13:42:00 | DEMO-LAPTOP-01192.0.2.21 | packages.example.net | Allowed |
Devices on the simulated network
Per-device behaviour, measured over the run
DEMO-LAPTOP-01192.0.2.21
Staff laptop
- queries
- 1
- unique
- 1
- entropy
- 2.75
- nxdomain
- 0%
DEMO-DESKTOP-02192.0.2.32
Reception desktop
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-LAB-CLIENT192.0.2.42
Isolated lab host
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-PHONE-04192.0.2.70
Mobile device
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
DEMO-NAS-05192.0.2.91
File server
- queries
- 0
- unique
- 0
- entropy
- 0.00
- nxdomain
- 0%
Detection model
Nothing to report
No signals above threshold
This is what a healthy baseline looks like: short readable names, heavy reuse, almost everything resolving. Every other scenario is measured against activity like this.
Simplified demonstration model. The scoring used across this simulation is written for teaching and does not mirror the real DNS Daddy engine.
Attack timeline
How the scenario unfolds
- 1Devices come online and resolve routine destinationsnow
- 2Names repeat as caches expire — low unique-domain count
- 3Query rate stays flat and unremarkable
- 4No signal crosses a threshold — nothing to report
Keep going
Compare this against another pattern