The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure DNS-based domain name exceptions and C&C server domain detection

Prev Next

Follow these high-level steps to configure the Sensor to detect domain name exceptions and C&C server domains in the DNS response packets.

  1. Import the Domain Name Exceptions into the Manager. See Manage domain name exceptions.

  2. Make sure that the latest callback detector file is deployed on the required Sensors. See Manage Botnet Detectors.

  3. Optionally, configure the TTL for the crafted DNS response packet as well as the sinkhole IPv4 address. See Configure TTL and IP address for DNS sinkholing.

  4. Enable Domain Name Exceptions detection, DNS Sinkholing, and other advanced callback detection options in the inspection option policies. See Define Advanced Botnet Detection in a Protection Option policy.

  5. Apply the inspection option policies to the Sensor resources. See Assign a protection option policy to Sensor resources.