SonicWallThreat Protection

    Capture Security Appliance

    On-premises, memory-based malware analysis with RTDMI for data residency.

    SonicWall Capture Security appliance (CSa) brings fast, accurate on-premises, memory-based file analysis and malware detection — the same patented Real-Time Deep Memory Inspection as Capture ATP, but running on-site for organisations with data-residency or privacy requirements. It keeps files and analysis within your walls while catching evasive and fileless threats. Faltrox deploys and operates it as managed on-premises sandboxing.

    Overview

    What Capture Security Appliance is

    Some organisations cannot send files to a cloud sandbox for analysis — compliance, data residency, or privacy requirements demand that files stay on-site. The SonicWall Capture Security appliance (CSa) answers this: it brings the same fast, accurate, memory-based malware detection as Capture ATP, running on-premises so files and analysis never leave your environment.

    It uses SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI) to force malware to reveal its weaponry in memory in real time, catching evasive, fileless, and chip-based threats that behaviour-based sandboxes miss — with the speed to block at the gateway. It integrates with SonicWall firewalls and endpoints just like the cloud service, but keeps everything on-site. Faltrox deploys the appliance, integrates it, and operates the detections as managed on-premises sandboxing.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    On-Premises Analysis

    Memory-based malware analysis that runs on-site, keeping files within your walls.

    02

    Data Residency

    For organisations with compliance, residency, or privacy requirements.

    03

    Unknown Malware

    Catches never-before-seen malware with multi-technique analysis.

    04

    Evasive & Fileless Attacks

    RTDMI catches fileless, evasive, and chip-based attacks in memory.

    05

    Real-Time Verdicts

    Delivers verdicts fast enough to block at the gateway.

    06

    SonicWall Ecosystem

    Integrates with SonicWall firewalls and endpoints on-site.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Submit

      Suspicious files from SonicWall firewalls and endpoints are submitted to the on-premises appliance.

    2. 02

      Analyse On-Site

      The appliance analyses files locally, so files and analysis never leave your environment.

    3. 03

      Deep Memory Inspection

      Patented RTDMI forces malware to reveal its weaponry in memory in real time.

    4. 04

      Block

      A real-time verdict lets the gateway block the threat before it enters the network.

    5. 05

      Operate

      Faltrox deploys the appliance, integrates it, and operates its detections as managed on-premises sandboxing.

    Capabilities

    Key capabilities

    On-Premises Sandboxing

    Fast, accurate memory-based file analysis that runs on-site for data residency.

    Real-Time Deep Memory Inspection

    Patented RTDMI forces malware to expose its weaponry in memory in real time.

    Evasive & Fileless Coverage

    Catches fileless, evasive, and chip-based attacks that behaviour-based sandboxes miss.

    Real-Time Block

    Delivers verdicts fast enough to block threats at the gateway.

    Data-Residency Compliance

    Keeps files and analysis on-site for compliance, residency, and privacy requirements.

    Ecosystem Integration

    Integrates with SonicWall firewalls and endpoints just like the cloud service.

    Multi-Technique Analysis

    Analyses files across several detection techniques for high efficacy.

    Accurate Detection

    Fast and accurate detection of known and unknown malware.

    Works with

    Part of the platform

    SonicWall products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes SonicWall Capture Security Appliance for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why choose the appliance over cloud Capture ATP?

    Data residency, compliance, or privacy. If you cannot send files to a cloud sandbox for analysis, the Capture Security appliance runs the same RTDMI-based, memory-based analysis on-premises — so files and analysis never leave your environment while you still catch evasive and fileless threats.

    02Does it use the same detection as Capture ATP?

    Yes — it uses SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI), the same technology in cloud Capture ATP, forcing malware to reveal its weaponry in memory in real time to catch evasive, fileless, and chip-based attacks.

    03Does it block threats in real time?

    Yes — like the cloud service, it delivers verdicts fast enough for the gateway to block a threat before it enters the network, rather than only detecting it after the fact.

    04Does it integrate with our SonicWall firewalls?

    Yes — it integrates with SonicWall firewalls and endpoints just like the cloud service, but keeps everything on-site. Suspicious files are submitted to the appliance for local analysis. Faltrox designs that integration.

    05How does Faltrox operate it?

    We deploy the appliance, integrate it with your firewalls and endpoints, tune the analysis policy, and operate its detections — delivering managed on-premises sandboxing for organisations that need files kept on-site.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us