SonicWallThreat Protection

    Capture ATP with RTDMI

    Cloud sandboxing that forces malware to reveal its weaponry in memory.

    SonicWall Capture Advanced Threat Protection (ATP) is a cloud-based multi-engine sandbox that catches never-before-seen threats — powered by patented Real-Time Deep Memory Inspection (RTDMI), which forces malware to expose its weaponry in memory in real time. It catches evasive, fileless, and chip-based attacks that traditional sandboxes miss, and blocks them at the gateway. Faltrox enables and operates it across your SonicWall estate.

    Overview

    What Capture ATP with RTDMI is

    Traditional sandboxes watch a file’s behaviour over time and can be evaded by malware that stays dormant or detects the sandbox. SonicWall Capture ATP takes a different approach with patented Real-Time Deep Memory Inspection (RTDMI): it forces malware to reveal its weaponry in memory in real time, catching evasive, fileless, and even chip-based attacks that behaviour-based sandboxes miss — and doing it fast enough to block at the gateway.

    Capture ATP is a cloud-based multi-engine sandbox that suspicious files from SonicWall firewalls, endpoints, and other sources are submitted to for analysis. RTDMI delivers a verdict in real time, and new protections are shared across the SonicWall ecosystem. It is the advanced-threat engine behind the TZ, NSa, NSsp, and NSv firewalls and Capture Client. Faltrox enables Capture ATP across your estate, tunes it, and operates the detections it produces as managed defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Unknown Malware

    A cloud multi-engine sandbox catches never-before-seen malware.

    02

    Evasive & Fileless Attacks

    RTDMI catches fileless, evasive, and chip-based attacks traditional sandboxes miss.

    03

    Chip-Based Attacks

    Real-time memory inspection detects side-channel and chip-based threats.

    04

    Firewalls & Endpoints

    Analyses files from SonicWall firewalls, endpoints, and other sources.

    05

    Real-Time Verdicts

    RTDMI delivers verdicts in real time, fast enough to block at the gateway.

    06

    SonicWall Ecosystem

    Shares new protections across firewalls and endpoints.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Submit

      Suspicious files from SonicWall firewalls, Capture Client endpoints, and other sources are submitted to the cloud sandbox.

    2. 02

      Multi-Engine Analysis

      A multi-engine sandbox analyses the file across several detection techniques.

    3. 03

      Deep Memory Inspection

      Patented RTDMI forces malware to reveal its weaponry in memory in real time, catching evasive and fileless attacks.

    4. 04

      Block

      A real-time verdict lets the gateway block the threat before it enters the network.

    5. 05

      Operate

      Faltrox enables Capture ATP across the estate, tunes it, and operates the detections as managed defence.

    Capabilities

    Key capabilities

    Real-Time Deep Memory Inspection

    Patented RTDMI forces malware to expose its weaponry in memory in real time.

    Multi-Engine Sandbox

    A cloud multi-engine sandbox analyses files across several detection techniques.

    Evasive & Fileless Coverage

    Catches fileless, evasive, and chip-based attacks that behaviour-based sandboxes miss.

    Real-Time Block

    Delivers verdicts fast enough to block threats at the gateway, not just detect them.

    Broad Source Coverage

    Analyses files from SonicWall firewalls, endpoints, and other sources.

    Ecosystem Protection Sharing

    Shares new protections across the SonicWall firewall and endpoint ecosystem.

    Cloud-Delivered

    A cloud service integrated across the SonicWall platform.

    Behind the Portfolio

    The advanced-threat engine behind the TZ, NSa, NSsp, NSv firewalls and Capture Client.

    Works with

    Part of the platform

    SonicWall products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes SonicWall Capture ATP with RTDMI for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is RTDMI and how is it different from a normal sandbox?

    A traditional sandbox watches a file’s behaviour over time and can be evaded by malware that stays dormant or detects the sandbox. Real-Time Deep Memory Inspection forces malware to reveal its weaponry in memory in real time, catching evasive, fileless, and even chip-based attacks that behaviour-based analysis misses — and fast enough to block at the gateway.

    02Where do the files it analyses come from?

    From across the SonicWall ecosystem — the TZ, NSa, NSsp, and NSv firewalls, Capture Client endpoints, and other sources submit suspicious files to Capture ATP for analysis, and new protections are shared back across the ecosystem.

    03Does it block threats or just detect them?

    It blocks them — RTDMI delivers a verdict in real time, fast enough for the gateway to block a threat before it enters the network, rather than only detecting it after the fact like slower sandboxes.

    04Is there an on-premises option?

    Capture ATP is the cloud service; for on-premises, memory-based analysis SonicWall offers the Capture Security Appliance (CSa), which brings the same RTDMI-based detection on-site for data-residency needs. Faltrox scopes the right model.

    05How does Faltrox operate it?

    We enable Capture ATP across your SonicWall firewalls and endpoints, tune submission and analysis policy, and operate its detections — folding them into the managed network and endpoint defence we run.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us