As part of advanced callback detection, Sensors can protect your network from attacks effected through Domain Generation Algorithm technique. DGA is triggered for an infected host (bot) to communicate with the command and control (C&C) server. Some infamous malware which are known to use the DGA technique are Conficker, Pushdo, and Gameover ZeuS.
Sensors use a heuristics-based detection mechanism to identify the following:
Bots employing DGA technique
The IP address of the C&C server of the DGA botnet
Hosts attempting to communicate with the C&C server domain
Because it is a heuristics-based detection mechanism, DGA detection is equally effective in SPAN, tap, and inline modes.