Capture ATP with RTDMI
Cloud sandboxing that forces malware to reveal its weaponry in memory.
SonicWall Capture Advanced Threat Protection (ATP) is a cloud-based multi-engine sandbox that catches never-before-seen threats — powered by patented Real-Time Deep Memory Inspection (RTDMI), which forces malware to expose its weaponry in memory in real time. It catches evasive, fileless, and chip-based attacks that traditional sandboxes miss, and blocks them at the gateway. Faltrox enables and operates it across your SonicWall estate.
Overview
What Capture ATP with RTDMI is
Traditional sandboxes watch a file’s behaviour over time and can be evaded by malware that stays dormant or detects the sandbox. SonicWall Capture ATP takes a different approach with patented Real-Time Deep Memory Inspection (RTDMI): it forces malware to reveal its weaponry in memory in real time, catching evasive, fileless, and even chip-based attacks that behaviour-based sandboxes miss — and doing it fast enough to block at the gateway.
Capture ATP is a cloud-based multi-engine sandbox that suspicious files from SonicWall firewalls, endpoints, and other sources are submitted to for analysis. RTDMI delivers a verdict in real time, and new protections are shared across the SonicWall ecosystem. It is the advanced-threat engine behind the TZ, NSa, NSsp, and NSv firewalls and Capture Client. Faltrox enables Capture ATP across your estate, tunes it, and operates the detections it produces as managed defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Unknown Malware
A cloud multi-engine sandbox catches never-before-seen malware.
Evasive & Fileless Attacks
RTDMI catches fileless, evasive, and chip-based attacks traditional sandboxes miss.
Chip-Based Attacks
Real-time memory inspection detects side-channel and chip-based threats.
Firewalls & Endpoints
Analyses files from SonicWall firewalls, endpoints, and other sources.
Real-Time Verdicts
RTDMI delivers verdicts in real time, fast enough to block at the gateway.
SonicWall Ecosystem
Shares new protections across firewalls and endpoints.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Submit
Suspicious files from SonicWall firewalls, Capture Client endpoints, and other sources are submitted to the cloud sandbox.
- 02
Multi-Engine Analysis
A multi-engine sandbox analyses the file across several detection techniques.
- 03
Deep Memory Inspection
Patented RTDMI forces malware to reveal its weaponry in memory in real time, catching evasive and fileless attacks.
- 04
Block
A real-time verdict lets the gateway block the threat before it enters the network.
- 05
Operate
Faltrox enables Capture ATP across the estate, tunes it, and operates the detections as managed defence.
Capabilities
Key capabilities
Real-Time Deep Memory Inspection
Patented RTDMI forces malware to expose its weaponry in memory in real time.
Multi-Engine Sandbox
A cloud multi-engine sandbox analyses files across several detection techniques.
Evasive & Fileless Coverage
Catches fileless, evasive, and chip-based attacks that behaviour-based sandboxes miss.
Real-Time Block
Delivers verdicts fast enough to block threats at the gateway, not just detect them.
Broad Source Coverage
Analyses files from SonicWall firewalls, endpoints, and other sources.
Ecosystem Protection Sharing
Shares new protections across the SonicWall firewall and endpoint ecosystem.
Cloud-Delivered
A cloud service integrated across the SonicWall platform.
Behind the Portfolio
The advanced-threat engine behind the TZ, NSa, NSsp, NSv firewalls and Capture Client.
Works with
Part of the platform
SonicWall products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes SonicWall Capture ATP with RTDMI for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is RTDMI and how is it different from a normal sandbox?
A traditional sandbox watches a file’s behaviour over time and can be evaded by malware that stays dormant or detects the sandbox. Real-Time Deep Memory Inspection forces malware to reveal its weaponry in memory in real time, catching evasive, fileless, and even chip-based attacks that behaviour-based analysis misses — and fast enough to block at the gateway.
02Where do the files it analyses come from?
From across the SonicWall ecosystem — the TZ, NSa, NSsp, and NSv firewalls, Capture Client endpoints, and other sources submit suspicious files to Capture ATP for analysis, and new protections are shared back across the ecosystem.
03Does it block threats or just detect them?
It blocks them — RTDMI delivers a verdict in real time, fast enough for the gateway to block a threat before it enters the network, rather than only detecting it after the fact like slower sandboxes.
04Is there an on-premises option?
Capture ATP is the cloud service; for on-premises, memory-based analysis SonicWall offers the Capture Security Appliance (CSa), which brings the same RTDMI-based detection on-site for data-residency needs. Faltrox scopes the right model.
05How does Faltrox operate it?
We enable Capture ATP across your SonicWall firewalls and endpoints, tune submission and analysis policy, and operate its detections — folding them into the managed network and endpoint defence we run.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us