DNS Tunneling Exfiltration Detector
Interactive 3D simulation of DNS-tunneling data exfiltration and Shannon-entropy-based detection: watch queries stream from a compromised host through a resolver toward a covert command server, tune the detector threshold, and see live true/false positive rates.
DNS tunneling smuggles stolen data out of a network inside ordinary-looking DNS queries, one of the quieter techniques behind real cyber-espionage campaigns because DNS traffic is rarely filtered at the firewall. This simulation streams two classes of query — legitimate hostnames and base32-style encoded exfiltration labels — from a compromised host through a resolver toward a covert command server in real 3D, computing each label's Shannon entropy live and testing it against an adjustable detection threshold. Tune the legit and tunnel traffic rates, the payload size per query, and the entropy cutoff to watch the true-positive, false-negative and false-positive rates respond exactly as they would for a real entropy-based DNS security control.
Interactive 3D simulation of DNS-tunneling data exfiltration: watch encoded queries stream from a compromised host through a resolver toward a covert server, tune a live Shannon-entropy detector threshold, and see true/false positive rates respond in real time.
3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install