Checking for botnet traffic comes down a bit to monitoring for common behaviour patterns. I highlight a few techniques to do just that
0:00-0:10 Intro
0:11-3:25 High Outbound
3:26:-7:33 Is the IP Suspicious?
7:34-9:08 Comm. with non standard ports
9:09-12:27 Using Ctrl F
12:28-13:26 Filtering for common strings