Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

NXDOMAIN Anomaly

A client asking for names that do not exist

Research demonstration All scenarios

Traffic starts normally, then one host begins generating a steady stream of NXDOMAIN responses — the resolver's way of saying 'no such name'. A rising NXDOMAIN rate is one of the cheapest, most useful DNS signals a defender has.

  • NXDOMAIN means the name does not exist, not that it was blocked
  • A low background NXDOMAIN rate is completely normal
  • Sustained high NXDOMAIN from one client is worth a look
Speed
1/84 queries

Queries/min

60

Allowed

1

Blocked

0

Findings

0

NXDOMAIN %

0.0%

Unique domains

1

TXT queries

0

Avg entropy

2.00

Query flow

How each simulated lookup is handled

  1. Device

    DEMO-NAS-05

  2. DNS query

    A chat.example.com

  3. DNS Daddy

    resolver + policy

  4. Signals

    0 of 4 firing

  5. Outcome

    Allow

Event stream

Synthetic queries. Select a row to inspect it.

TimeDeviceDNS queryResult
13:42:00DEMO-NAS-05192.0.2.91chat.example.comAllowed

Devices on the simulated network

Per-device behaviour, measured over the run

  • DEMO-LAPTOP-01192.0.2.21

    Staff laptop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-DESKTOP-02192.0.2.32

    Reception desktop

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-LAB-CLIENT192.0.2.42

    Isolated lab host

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-PHONE-04192.0.2.70

    Mobile device

    queries
    0
    unique
    0
    entropy
    0.00
    nxdomain
    0%
  • DEMO-NAS-05192.0.2.91

    File server

    queries
    1
    unique
    1
    entropy
    2.00
    nxdomain
    0%

Detection model

Signals accumulate as behaviour changes

Research demonstration

Risk score

0/65 needed

Confidence

0%

MITRE ATT&CK

T1568.002

Signals

  • High NXDOMAIN ratio+0 of 30not yet observed
  • Sustained failure volume+0 of 20not yet observed
  • Failures spread across many distinct names+0 of 20not yet observed
  • Elevated query rate+0 of 12not yet observed

Simplified demonstration model. Each signal adds a fixed number of points; reaching 65 generates a finding. Real detection engines weigh signals dynamically — this version is written to be readable, and is not production telemetry.

Attack timeline

How the scenario unfolds

  1. 1Baseline traffic: nearly all lookups succeednow
  2. 2One client starts requesting names that do not resolve
  3. 3NXDOMAIN ratio for that client climbs past the background rate
  4. 4Volume and unique-name signals fire
  5. 5Risk score crosses the threshold
  6. 6Finding generated
  7. 7Analyst separates misconfiguration from probing

Threat hunting mode

Find the affected device before the model tells you

Hunting mode hides the finding and the highlighted device. You read the raw stream and per-device measurements, then name the device you think is compromised.

Keep going

Compare this against another pattern