The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Inspection of DNS response packets for advanced callback detection

Prev Next

Sensors can inspect DNS response packets to detect known and zero-day callback activities.

  • For the known botnets, Sensors inspect the DNS response packets for C&C server domains according to the callback detectors.

  • For the detection of zero-day callback activities, Sensors perform complex heuristic analyses of DNS response traffic. This way, Sensors can detect the following types of callback activities:

    • IP addresses and domains related to a Fast Flux Service Network (FFSN).

    • Domain names generated by bots infected with Domain Generation Algorithm (DGA).

Note

You can edit the attack definitions related to DNS inspection in the required IPS policies. Alternatively, you can edit the attack definitions in Master Attack Repository to affect all IPS policies.