Capture Security Appliance
On-premises, memory-based malware analysis with RTDMI for data residency.
SonicWall Capture Security appliance (CSa) brings fast, accurate on-premises, memory-based file analysis and malware detection — the same patented Real-Time Deep Memory Inspection as Capture ATP, but running on-site for organisations with data-residency or privacy requirements. It keeps files and analysis within your walls while catching evasive and fileless threats. Faltrox deploys and operates it as managed on-premises sandboxing.
Overview
What Capture Security Appliance is
Some organisations cannot send files to a cloud sandbox for analysis — compliance, data residency, or privacy requirements demand that files stay on-site. The SonicWall Capture Security appliance (CSa) answers this: it brings the same fast, accurate, memory-based malware detection as Capture ATP, running on-premises so files and analysis never leave your environment.
It uses SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI) to force malware to reveal its weaponry in memory in real time, catching evasive, fileless, and chip-based threats that behaviour-based sandboxes miss — with the speed to block at the gateway. It integrates with SonicWall firewalls and endpoints just like the cloud service, but keeps everything on-site. Faltrox deploys the appliance, integrates it, and operates the detections as managed on-premises sandboxing.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
On-Premises Analysis
Memory-based malware analysis that runs on-site, keeping files within your walls.
Data Residency
For organisations with compliance, residency, or privacy requirements.
Unknown Malware
Catches never-before-seen malware with multi-technique analysis.
Evasive & Fileless Attacks
RTDMI catches fileless, evasive, and chip-based attacks in memory.
Real-Time Verdicts
Delivers verdicts fast enough to block at the gateway.
SonicWall Ecosystem
Integrates with SonicWall firewalls and endpoints on-site.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Submit
Suspicious files from SonicWall firewalls and endpoints are submitted to the on-premises appliance.
- 02
Analyse On-Site
The appliance analyses files locally, so files and analysis never leave your environment.
- 03
Deep Memory Inspection
Patented RTDMI forces malware to reveal its weaponry in memory in real time.
- 04
Block
A real-time verdict lets the gateway block the threat before it enters the network.
- 05
Operate
Faltrox deploys the appliance, integrates it, and operates its detections as managed on-premises sandboxing.
Capabilities
Key capabilities
On-Premises Sandboxing
Fast, accurate memory-based file analysis that runs on-site for data residency.
Real-Time Deep Memory Inspection
Patented RTDMI forces malware to expose its weaponry in memory in real time.
Evasive & Fileless Coverage
Catches fileless, evasive, and chip-based attacks that behaviour-based sandboxes miss.
Real-Time Block
Delivers verdicts fast enough to block threats at the gateway.
Data-Residency Compliance
Keeps files and analysis on-site for compliance, residency, and privacy requirements.
Ecosystem Integration
Integrates with SonicWall firewalls and endpoints just like the cloud service.
Multi-Technique Analysis
Analyses files across several detection techniques for high efficacy.
Accurate Detection
Fast and accurate detection of known and unknown malware.
Works with
Part of the platform
SonicWall products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes SonicWall Capture Security Appliance for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why choose the appliance over cloud Capture ATP?
Data residency, compliance, or privacy. If you cannot send files to a cloud sandbox for analysis, the Capture Security appliance runs the same RTDMI-based, memory-based analysis on-premises — so files and analysis never leave your environment while you still catch evasive and fileless threats.
02Does it use the same detection as Capture ATP?
Yes — it uses SonicWall’s patented Real-Time Deep Memory Inspection (RTDMI), the same technology in cloud Capture ATP, forcing malware to reveal its weaponry in memory in real time to catch evasive, fileless, and chip-based attacks.
03Does it block threats in real time?
Yes — like the cloud service, it delivers verdicts fast enough for the gateway to block a threat before it enters the network, rather than only detecting it after the fact.
04Does it integrate with our SonicWall firewalls?
Yes — it integrates with SonicWall firewalls and endpoints just like the cloud service, but keeps everything on-site. Suspicious files are submitted to the appliance for local analysis. Faltrox designs that integration.
05How does Faltrox operate it?
We deploy the appliance, integrate it with your firewalls and endpoints, tune the analysis policy, and operate its detections — delivering managed on-premises sandboxing for organisations that need files kept on-site.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us