The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Known botnet detection

Prev Next

The Advanced Callback Detection framework also uses a deterministic botnet detection approach, targeted toward detection of known bots. As mentioned earlier, a bot lifecycle can be divided into exploitation, infection and the attack/propagation phases. Each phase has a corresponding attack signature to detect the phase. The framework monitors per source IP address the specified sequence of these attack IDs within a specified time to trigger a correlated attack. This provides a precise bot detection.

Consider the example of Kraken botnet. Kraken bot is known to have the following phases:

  1. Connectivity test to mx.google.com.

  2. Download Test: Front pages of popular news websites – www.nytimes.com, www.cbsnews.com, www.cnn.com, and www.google.com.

  3. Peer Lookup: DNS Queries for randomly generated URI based on dynamic DNS domains.

  4. Peer Connect & Update: Connect to peer bot (UDP dport 447/TCP dport 80/TCP dport 443) and download update.

  5. Download Payload (Spam template, Spam Payload, MX server addresses and so on).

  6. Send Spam.

Phases 1 and 2 are not malicious by themselves. However, when correlated with phases, 3,4,5 and 6, Kraken botnet can be detected effectively.