Advanced Threat Landscape Analysis System
Global situational awareness of malicious files, domains, and IPs from a billion sensors.
Trellix Advanced Threat Landscape Analysis System (ATLAS) gives customers a unique global view of the malicious file, domain, and IP detections seen worldwide across Trellix’s billions of sensors — correlated with campaign research from the Advanced Research Center. It turns raw global telemetry into situational awareness you can query and filter. Faltrox uses it to keep your defence aligned to what is actually active in the wild.
Overview
What Advanced Threat Landscape Analysis System is
Trellix Advanced Threat Landscape Analysis System (ATLAS) gives customers a unique global view of the malicious file, domain, and IP detections seen worldwide across Trellix’s billions of sensors. It turns raw global telemetry into situational awareness you can query and filter — enriched with industry sector and geolocation so you can see the threats hitting your sector and region.
It correlates those detections with campaign research from the Advanced Research Center and Threat Intelligence Group — events, dates, threat actors, and IOCs — and lets you pivot between prevalence and campaign data in either direction. Analysts query it with familiar KQL and Lucene syntaxes and export findings as CSV. Faltrox uses it to keep your defence aligned to what is actually active in the wild.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Global Detections
Malicious file, domain, and IP detections seen worldwide across billions of Trellix sensors.
Threat Campaigns
Campaign dashboards of events, dates, threat actors, and IOCs from Advanced Research Center research.
Threat Actors
Dedicated threat-actor views connect indicators to the groups running the campaigns.
Industry & Geo Enrichment
Detections enriched with industry sector and geolocation to spotlight threats to your sector.
Indicators of Compromise
Prevalence dashboards for malicious IPs, files, and URLs updated daily from all Trellix products.
Your Sector's Threats
See threats trending in your industry and region before they reach your own network.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Aggregate
Data from multiple Trellix sources — Repper, REST, Real Protect, JCM — is aggregated from billions of sensors worldwide.
- 02
Enrich
Detections are enriched with industry sector and geolocation for comprehensive situational awareness.
- 03
Correlate
Threats are correlated with campaign data — events, dates, threat actors, and IOCs — from the Advanced Research Center.
- 04
Query
Analysts search with KQL and Lucene, add filters from visualisations, and pivot between prevalence and campaigns.
- 05
Export
Detailed detection and visualisation data export as CSV to feed your own dashboards and reporting.
Capabilities
Key capabilities
Prevalence Dashboards
Dedicated dashboards for malicious file, URL, and IP prevalence, populated daily from the full range of Trellix products, giving comprehensive situational awareness of the global threat landscape.
Campaign Correlation
Correlates detections with campaign data — events, dates, threat actors, and IOCs — researched by the Advanced Research Center and Threat Intelligence Group, plus open-source data.
Enriched Detection Data
Aggregates data from multiple Trellix sources and enriches it with industry sector and geolocation, so you can see which threats are hitting your sector and region.
Flexible Query Languages
Supports both KQL and Lucene query languages with terms queries, free-text search, ranges, boolean queries, and wildcards for precise investigation.
Cross-Reference Workflows
Pivot between prevalence and campaign data — from a prevalent IOC to the campaigns using it, or from a campaign to the prevalence of its indicators.
Filtering & Visualisation
Add filters directly from visualisations and drill into threat actors, campaigns, and IOCs across dashboards that share consistent design and workflows.
Data Export
Export detailed detection data and visualisation data in CSV, so global intelligence flows into your own analytics and reporting.
Reputation-to-Trust Mapping
Maps reputation to trust scores, connecting the global prevalence picture back to the trust decisions your protection layer makes.
Specifications
Technical detail
- Data Scope
- Malicious file, domain, and IP detections worldwide
- Sources
- Repper, REST, Real Protect, JCM and other Trellix data sources
- Enrichment
- Industry sector and geolocation
- Query Languages
- KQL and Lucene
- Dashboards
- File, URL, and IP prevalence; campaigns; threat actors
- Export
- CSV (detection and visualisation data)
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Trellix products
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Advanced Threat Landscape Analysis System for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What does ATLAS give us that our own tools do not?
A global vantage point. It shows the malicious files, domains, and IPs seen across Trellix’s billions of sensors worldwide — enriched by industry and geolocation — so you can see threats trending in your sector before they reach you, rather than only what has already hit your own network.
02How does it connect detections to real campaigns?
It correlates prevalence data with campaign research from the Advanced Research Center and Threat Intelligence Group — events, dates, threat actors, and IOCs — and lets you pivot between a prevalent indicator and the campaigns using it in either direction.
03Do we need to learn a special query language?
It supports both KQL and Lucene, with free-text search, ranges, boolean queries, and wildcards — so analysts familiar with common search syntaxes can query it without a steep learning curve. Faltrox analysts drive it on your behalf regardless.
04Can we get the data out for our own reporting?
Yes. ATLAS exports detailed detection data and visualisation data in CSV, so the global intelligence can feed your own dashboards, analytics, and executive reporting.
05How does Faltrox use it for us?
We use ATLAS to keep your defence aligned to what is active in the wild — watching prevalence and campaigns for your industry and geography, and feeding that back into detection tuning and threat hunting.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us