The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

0-day botnet detection

Prev Next

The Advanced Callback Detection framework uses a probabilistic 0-day botnet detection approach, targeted toward detection of 0-day bots. It consists of multiple heuristics identified during the research and analysis of various bots. Heuristics cover a wide range of checks such as the following:

  • Anomalies in protocols being used for communication such as HTTP and SSL

  • Response errors in protocols such as DNS, SMTP

  • Suspicious behavior such as port scan and stealth scan

  • Cloud based detection such as GTI File Reputation and IP Reputation

The Advanced Callback Detection framework monitors for such heuristics being exhibited by a particular source IP address within a specified amount of time. This allows the framework to determine if the source IP address has been compromised and is exhibiting bot behavior.

The framework has capabilities to correlate attacks across different communication protocols.

The following are some of the currently implemented heuristics:

  • SSL: Invalid SSL Flow Detected

  • SSL: Invalid SSL Flow Detected Due to Wrong Hello Record Type

  • SSL: Invalid SSL Flow Detected Due to wrong Record Version

  • SSL: Invalid SSL Flow Detected Due to Wrong Handshake Type

  • Heuristic DNS: Too Many Type A Query Response Errors Found

  • Heuristic DNS: Too Many Type MX Query Response Errors Found

  • DNS: Recursive Query To Root Servers Found

  • BOT Heuristic: Spam Bot Activity - Multiple Block list Responses from SMTP server

  • BOT Heuristic: Potential Bot Activity - Multiple Resets from SMTP receiver

  • Heuristic SMTP: Multiple Emails sent without Authentication

  • IRC: IRC Client Activity Detected

  • HTTP: Executable Files Found in Zip Files

  • HTTP: Password Protected Zip File Found

  • HTTP: Invalid Flow Detected

  • Bot: Potential Stealth Scanner Detected

  • Malware: Potential Malicious File Transfer Detected by GTI File Reputation (Artemis)

  • BOT: HTran Connection Bouncer Error Message Detected