The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the List of Zombies for an Active Botnet

Prev Next

This URL gets the list of zombies for an active botnet.

Resource URL

GET /domain/<domain_id>/activebotnetzombies/<bot_id>?includeChildDomain=<includeChildDomain>&&duration=<duration>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain_id Domain id Number Yes
includeChildDomain Should the child domains be included Boolean No
duration Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOUR
  • LAST_12_HOUR
  • LAST_24_HOUR
  • LAST_48_HOUR
  • LAST_7_DAYS
  • LAST_14_DAYS
String No

Response Parameters

Following fields are returned.

Field Name Description Data Type
zombiesDetailList List of zombies for the botnet ObjectList

Details of fields in zombiesDetailList:

Field Name Description Data Type
ipAddress IP address String
dnsName DNS name String
ccCommunication C&C communication String
events Number of events Number
lastEvent Time of last event String
comment Comment String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/activebotnetzombies/6

Response

 {
       "zombiesDetailList":
       [
           {
               "ipAddress": "192.168.2.2",
               "dnsName": "",
               "ccCommunication": "UN_BLOCKED",
               "events": 2,
               "lastEvent": "Jan 31 16:53 IST",
               "comment": ""
           }
       ]
    } 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1105 Invalid domain
2 404 4201 Invalid duration filter
3 404 4202 Invalid botnet id