The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show botnet-alertstats

Prev Next

The show botnet-alertstats command displays the statistics related to advanced botnet detection by a Sensor.

This command has no parameters.

Syntax:

show botnet-alertstats

Information displayed by the show botnet-alertstats command includes the following:

  • The count of domains, IP addresses, and URLs detected based on the callback detectors

  • The count of DGA bots detected

  • The count of suspected DGA command and control servers detected

  • The count of communications from your network to DGA command and control servers

  • The count of activities monitored for FFSN

  • The count of communications from your network to the flux agents of FFSN

  • The count of command and control domains detected based on heuristics, such as protocol anomalies and DNS response failures

Sample Output:

Callback detector matches : 306

DGA Zombie detected : 5

DGA CnC Server Suspects detected : 25

DGA Zombie to CnC Server callbacks detected : 50

Ip Flux botnet activity detected : 30

IP Flux agent callback detected : 60

Other Zero day botnets detected : 25

Applicable to:

NS-series and Virtual IPS Sensors