Callback Detection Exclusions List
You can configure Sensors to perform detailed heuristic analyses of DNS packets for callback activities such as FFSN and DGA. However, such complex analyses consume considerable Sensor resources. Therefore, you can exclude domains, which you know are definitely safe from further analysis.
Important
Trellix strongly recommends that you add your organization's public and internal domain names to the Callback Detection Exclusions List. Excluding such domains from analysis preserves Sensor resources to analyze unknown domains.
You create the callback detection exclusions list by importing the list of exclusion domains into the Manager. The Sensor checks for these callback detection exclusions first in the DNS packets before checking for the C&C server domains defined in the callback detectors.
Note
In case you want to allow traffic to C&C server domains by the callback detectors, you can add them to the Callback Detection Exclusions List.
When the Sensor detects an excluded domain name in the DNS traffic, it excludes that DNS traffic from any further DNS-based callback detection. However, the Sensor inspects the subsequent L7 traffic from the same endpoint to the excluded domain for threats.
Note
By default, checking the Callback Detection Exclusions List is enabled when you enable any feature for advanced callback detection.
Inspection of DNS traffic for C&C server domains
The Sensor blocks the DNS traffic if the DNS response packet contains a C&C server domain according to callback detectors. If a host attempts to reach a C&C server domain, it is most likely infected and is now a bot. So, the Sensor sends a crafted DNS response back to sinkhole this bot traffic. The concept of sinkholing is explained in detail in the subsequent sections of this chapter.
Note
Even if the callback detectors file is present in the Sensor, you must configure the Sensor for inspecting DNS responses for C&C server domains.