Capture Client
AI-powered endpoint security with behavioural detection and rollback remediation.
SonicWall Capture Client is a powerful, affordable AI-powered endpoint security solution that combines behavioural threat detection with SonicWall’s patented Real-Time Deep Memory Inspection to stop known and unknown threats — and to roll back an endpoint to its pre-attack state after ransomware. It gives high-efficacy, actionable detection and response from a single agent. Faltrox deploys, tunes, and operates it as managed endpoint defence.
Overview
What Capture Client is
Organisations of every size — from SMBs to the largest enterprises — need endpoint security that is easy to deploy yet catches advanced threats. SonicWall Capture Client delivers exactly that: AI-powered endpoint protection and detection and response from a single agent, with high-efficacy, actionable threat detection through a powerful dual engine.
It combines behavioural, machine-learning threat detection with SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI) to stop known and unknown malware, including fileless and evasive attacks. Its rollback remediation restores an endpoint to its healthy pre-attack state after a ransomware attack, and it integrates with the SonicWall ecosystem (Capture ATP, firewalls) for shared intelligence. Faltrox deploys it, tunes the policy, and operates the detection and response as managed endpoint defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Endpoints
AI-powered protection for endpoints across SMBs to large enterprises.
Known & Unknown Malware
A dual engine stops known malware and never-before-seen threats.
Fileless & Evasive Attacks
RTDMI catches fileless and evasive attacks that behaviour-only tools miss.
Ransomware Rollback
Rollback remediation restores endpoints to their pre-attack state.
Behavioural Detection
Machine-learning behavioural detection identifies threats by what they do.
SonicWall Ecosystem
Integrates with Capture ATP and firewalls for shared intelligence.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Deploy
A single lightweight agent is deployed to endpoints and managed from the cloud.
- 02
Detect
A dual engine combines behavioural machine-learning detection with patented RTDMI to catch known and unknown threats.
- 03
Respond
Threats are contained and remediated, with actionable detection and response from the agent.
- 04
Roll Back
After a ransomware attack, rollback remediation restores the endpoint to its healthy pre-attack state.
- 05
Operate
Faltrox tunes the policy, runs the response, and integrates it with the SonicWall ecosystem as managed endpoint defence.
Capabilities
Key capabilities
Dual-Engine Detection
Combines behavioural machine-learning detection with patented RTDMI for high-efficacy protection.
RTDMI
Real-Time Deep Memory Inspection catches fileless and evasive attacks in memory.
Behavioural AI
Machine-learning behavioural detection identifies threats by what they do, not just signatures.
Rollback Remediation
Restores an endpoint to its healthy pre-attack state after ransomware.
Actionable Detection & Response
High-efficacy, actionable EDR from a single agent.
Easy Deployment
Powerful yet affordable and easy to deploy across any size organisation.
Ecosystem Integration
Integrates with Capture ATP and SonicWall firewalls for shared intelligence.
Cloud-Managed
Managed from the cloud for consistent operation across the endpoint estate.
Works with
Part of the platform
SonicWall products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes SonicWall Capture Client for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is the "dual engine"?
Capture Client combines two detection approaches — behavioural machine-learning detection that identifies threats by what they do, and SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI) that catches fileless and evasive attacks in memory. Together they give high-efficacy protection against both known and unknown threats.
02Can it recover from ransomware?
Yes — its rollback remediation restores an endpoint to its healthy pre-attack state after a ransomware attack, so a detonation becomes a recoverable event rather than a crisis. Faltrox operates that response.
03How does it catch fileless attacks?
Through RTDMI, which inspects what happens in memory in real time — catching fileless and evasive attacks that never write a malicious file to disk and that behaviour-only or signature-only tools miss.
04How does it relate to Capture Client MDR?
Capture Client is the endpoint security product; Capture Client MDR (SonicSentry MDR) adds a 24/7 managed detection and response service on top, operated by experts. Faltrox scopes whether you need the product operated by us or the fully-managed MDR service.
05How does Faltrox operate it?
We deploy and tune Capture Client, run the detection and response, operate rollback where needed, and integrate it with Capture ATP and your SonicWall firewalls — delivering managed endpoint defence rather than an agent your team runs.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us