TrellixThreat Intelligence

    Advanced Threat Landscape Analysis System

    Global situational awareness of malicious files, domains, and IPs from a billion sensors.

    Trellix Advanced Threat Landscape Analysis System (ATLAS) gives customers a unique global view of the malicious file, domain, and IP detections seen worldwide across Trellix’s billions of sensors — correlated with campaign research from the Advanced Research Center. It turns raw global telemetry into situational awareness you can query and filter. Faltrox uses it to keep your defence aligned to what is actually active in the wild.

    Overview

    What Advanced Threat Landscape Analysis System is

    Trellix Advanced Threat Landscape Analysis System (ATLAS) gives customers a unique global view of the malicious file, domain, and IP detections seen worldwide across Trellix’s billions of sensors. It turns raw global telemetry into situational awareness you can query and filter — enriched with industry sector and geolocation so you can see the threats hitting your sector and region.

    It correlates those detections with campaign research from the Advanced Research Center and Threat Intelligence Group — events, dates, threat actors, and IOCs — and lets you pivot between prevalence and campaign data in either direction. Analysts query it with familiar KQL and Lucene syntaxes and export findings as CSV. Faltrox uses it to keep your defence aligned to what is actually active in the wild.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Global Detections

    Malicious file, domain, and IP detections seen worldwide across billions of Trellix sensors.

    02

    Threat Campaigns

    Campaign dashboards of events, dates, threat actors, and IOCs from Advanced Research Center research.

    03

    Threat Actors

    Dedicated threat-actor views connect indicators to the groups running the campaigns.

    04

    Industry & Geo Enrichment

    Detections enriched with industry sector and geolocation to spotlight threats to your sector.

    05

    Indicators of Compromise

    Prevalence dashboards for malicious IPs, files, and URLs updated daily from all Trellix products.

    06

    Your Sector's Threats

    See threats trending in your industry and region before they reach your own network.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Aggregate

      Data from multiple Trellix sources — Repper, REST, Real Protect, JCM — is aggregated from billions of sensors worldwide.

    2. 02

      Enrich

      Detections are enriched with industry sector and geolocation for comprehensive situational awareness.

    3. 03

      Correlate

      Threats are correlated with campaign data — events, dates, threat actors, and IOCs — from the Advanced Research Center.

    4. 04

      Query

      Analysts search with KQL and Lucene, add filters from visualisations, and pivot between prevalence and campaigns.

    5. 05

      Export

      Detailed detection and visualisation data export as CSV to feed your own dashboards and reporting.

    Capabilities

    Key capabilities

    Prevalence Dashboards

    Dedicated dashboards for malicious file, URL, and IP prevalence, populated daily from the full range of Trellix products, giving comprehensive situational awareness of the global threat landscape.

    Campaign Correlation

    Correlates detections with campaign data — events, dates, threat actors, and IOCs — researched by the Advanced Research Center and Threat Intelligence Group, plus open-source data.

    Enriched Detection Data

    Aggregates data from multiple Trellix sources and enriches it with industry sector and geolocation, so you can see which threats are hitting your sector and region.

    Flexible Query Languages

    Supports both KQL and Lucene query languages with terms queries, free-text search, ranges, boolean queries, and wildcards for precise investigation.

    Cross-Reference Workflows

    Pivot between prevalence and campaign data — from a prevalent IOC to the campaigns using it, or from a campaign to the prevalence of its indicators.

    Filtering & Visualisation

    Add filters directly from visualisations and drill into threat actors, campaigns, and IOCs across dashboards that share consistent design and workflows.

    Data Export

    Export detailed detection data and visualisation data in CSV, so global intelligence flows into your own analytics and reporting.

    Reputation-to-Trust Mapping

    Maps reputation to trust scores, connecting the global prevalence picture back to the trust decisions your protection layer makes.

    Specifications

    Technical detail

    Data Scope
    Malicious file, domain, and IP detections worldwide
    Sources
    Repper, REST, Real Protect, JCM and other Trellix data sources
    Enrichment
    Industry sector and geolocation
    Query Languages
    KQL and Lucene
    Dashboards
    File, URL, and IP prevalence; campaigns; threat actors
    Export
    CSV (detection and visualisation data)

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Advanced Threat Landscape Analysis System for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What does ATLAS give us that our own tools do not?

    A global vantage point. It shows the malicious files, domains, and IPs seen across Trellix’s billions of sensors worldwide — enriched by industry and geolocation — so you can see threats trending in your sector before they reach you, rather than only what has already hit your own network.

    02How does it connect detections to real campaigns?

    It correlates prevalence data with campaign research from the Advanced Research Center and Threat Intelligence Group — events, dates, threat actors, and IOCs — and lets you pivot between a prevalent indicator and the campaigns using it in either direction.

    03Do we need to learn a special query language?

    It supports both KQL and Lucene, with free-text search, ranges, boolean queries, and wildcards — so analysts familiar with common search syntaxes can query it without a steep learning curve. Faltrox analysts drive it on your behalf regardless.

    04Can we get the data out for our own reporting?

    Yes. ATLAS exports detailed detection data and visualisation data in CSV, so the global intelligence can feed your own dashboards, analytics, and executive reporting.

    05How does Faltrox use it for us?

    We use ATLAS to keep your defence aligned to what is active in the wild — watching prevalence and campaigns for your industry and geography, and feeding that back into detection tuning and threat hunting.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us