Demo: decoys
This mock home network runs Ward’s real decision path: decoys first, then the allowlist, then the blocklist, then forward. Look a name up, or simulate what a compromised device does when it explores a network: it tries common internal names until one answers.
Loading Ward (4.1 MB of WebAssembly, downloaded once)…
- nas-backup.home.arpa
- printer-admin.lan
- vault.internal.home.arpa
- doubleclick.net
- googlesyndication.com
- wpad.home.arpa
- wpad.lan
- pagead2.googlesyndication.com
What ward config export would print for a ward.yaml equivalent to this demo. The export names each blocklist and allowlist file by id and path but never copies the names inside it, and it has no field for decoys at all. Decoys are left out by construction.
The live demo runs Ward's real decision path in your browser: decoys first, then the allowlist, then the blocklist, then forward. A decoy lookup raises an alert naming the client that asked, and an exported config never contains decoy names. Run the real thing with the Quickstart.
Trigram statistics derived from the Majestic Million, CC BY 3.0.
Decoys match exactly, so scanner.nas-backup.home.arpa is not a decoy hit. The Export config tab shows what ward config export would print for an equivalent ward.yaml. The export lists which blocklist and allowlist files you use, never the names inside them, and it has no field for decoys. The page counts decoy names in it to prove that. How decoys work has the details.