Skip to content

Demo: decoys

This mock home network runs Ward’s real decision path: decoys first, then the allowlist, then the blocklist, then forward. Look a name up, or simulate what a compromised device does when it explores a network: it tries common internal names until one answers.

Loading Ward (4.1 MB of WebAssembly, downloaded once)…

Decoys
  • nas-backup.home.arpa
  • printer-admin.lan
  • vault.internal.home.arpa
Blocklist
  • doubleclick.net
  • googlesyndication.com
  • wpad.home.arpa
  • wpad.lan
Allowlist
  • pagead2.googlesyndication.com

    Trigram statistics derived from the Majestic Million, CC BY 3.0.

    Decoys match exactly, so scanner.nas-backup.home.arpa is not a decoy hit. The Export config tab shows what ward config export would print for an equivalent ward.yaml. The export lists which blocklist and allowlist files you use, never the names inside them, and it has no field for decoys. The page counts decoy names in it to prove that. How decoys work has the details.