The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Advanced callback detection

Prev Next

Bot is defined as malware running on a compromised system that is designed to participate in a centrally managed network of compromised computers known as a botnet. Single botnets have been known to consist of over a million compromised computers, and are arguably the most significant threats to the global Internet today.

Bot herders are moving away from massive botnets consisting of hundreds of thousands of zombies in favor of smaller and more targeted ones. Also, the IRC protocol for command and control (C&C) is being phased out in favor of more covert protocols, such as HTTP and non-SSL encrypted traffic over port 443.

The bot-like behavior is usually identified in several phases (each identified by a single attack ID), such as exploitation and infection, download of dropper files, download of configuration files, and attack and propagation. Each of the phases is typically carried out in a single network session. In some of the cases, such network sessions might look benign too. Traditionally, an attack signature can detect attack in a single flow except reconnaissance attacks. Trellix IPS supports advanced callback detection by correlating multiple attacks across different flows. Attacks are correlated by observing a host for a given period.

Advanced callback detection provides detailed information retrieved from different attack phases at the end of a successful correlation. Trellix IPS also forwards the attack information to the NTBA Appliance for doing similar correlation.