The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get the List of Zombies for an Active Botnet

Prev Next

This URL gets the list of zombies for an active botnet.

Resource URL

GET /domain/<domain_id>/activebotnetzombies/<bot_id>?includeChildDomain=<includeChildDomain>&&duration=<duration>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domain_id

Domain id

Number

Yes

includeChildDomain

Should the child domains be included

Boolean

No

duration

Duration can be:

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOUR

  • LAST_12_HOUR

  • LAST_24_HOUR

  • LAST_48_HOUR

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

Response Parameters

Following fields are returned.

Field Name

Description

Data Type

zombiesDetailList

List of zombies for the botnet

ObjectList

Details of fields in zombiesDetailList:

Field Name

Description

Data Type

ipAddress

IP address

String

dnsName

DNS name

String

ccCommunication

C&C communication

String

events

Number of events

Number

lastEvent

Time of last event

String

comment

Comment

String

Example

Request

GET https://<NSM_IP>/sdkapi/domain/0/activebotnetzombies/6

Response

    {
       "zombiesDetailList":
       [
           {
               "ipAddress": "192.168.2.2",
               "dnsName": "",
               "ccCommunication": "UN_BLOCKED",
               "events": 2,
               "lastEvent": "Jan 31 16:53 IST",
               "comment": ""
           }
       ]
    }

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1105

Invalid domain

2

404

4201

Invalid duration filter

3

404

4202

Invalid botnet id