TrellixData Security

    Database Security

    Protect the database even when the vendor patch isn’t an option.

    Databases hold the data an attacker is actually after, yet they are often the hardest systems to patch on schedule. Trellix Database Security finds, classifies, and defends sensitive information across leading database types — and keeps them protected even when vendor patches are unavailable, through virtual patching. Faltrox runs the monitoring and turns the alert stream into prioritised action.

    Overview

    What Database Security is

    Trellix Database Security finds, classifies, and defends sensitive information across leading database types — and keeps them protected even when vendor patches are unavailable. Databases hold the data an attacker is actually after, yet they are often the hardest systems to patch on schedule, because production databases cannot be taken down on the vendor’s timetable.

    It covers Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona on-premises, plus MariaDB, MySQL, and PostgreSQL on AWS RDS, across IPv4, IPv6, and dual-stack environments. Virtual patching stops exploits before they breach the database without impacting availability, and advanced analytics rank every database by real exposure. Faltrox runs the monitoring and turns the alert stream into prioritised action.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Leading Databases

    Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona.

    02

    AWS RDS

    Covers managed MariaDB, MySQL, and PostgreSQL instances on AWS RDS alongside on-premises.

    03

    Unpatchable Databases

    Virtual patching protects databases the vendor no longer patches or that cannot be taken down.

    04

    Sensitive Data

    Blocks unauthorised access to the sensitive and proprietary information held inside databases.

    05

    Shadow Databases

    Discovers unknown databases spun up and forgotten — a common and invisible breach path.

    06

    Multiple Operating Systems

    Runs across Windows, Linux, Solaris, AIX, and HP-UX for heterogeneous database estates.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Discover

      Automated scanning finds supported databases across the environment and locates the sensitive data inside them, including databases you had lost track of.

    2. 02

      Assess

      Vulnerability Manager identifies and prioritises known vulnerabilities, and analytics calculate a risk level per database by correlating exposure with activity.

    3. 03

      Protect

      Virtual patches apply automatically without impacting availability, adding protection where a vendor patch is unavailable or cannot be applied.

    4. 04

      Monitor

      Database Activity Monitoring logs and detects access and irregularities in real time, preemptively blocking potential threats.

    5. 05

      Report

      A unified command centre turns raw alerts into prioritised insight and streamlines compliance audits through centralised dashboards.

    Capabilities

    Key capabilities

    Database Activity Monitoring

    Actively monitors, logs, and detects database access and irregularities, and preemptively blocks potential threats before they impact the environment.

    Virtual Patching

    Stops intrusions and exploits before they breach the database. Virtual patches apply automatically without impacting availability, and add protection when a vendor patch is unavailable or the database cannot be updated.

    Vulnerability Manager

    Automates scanning to find supported databases and their sensitive information across the environment, then identifies and prioritises known vulnerabilities for remediation.

    Sensitive Data Discovery

    Discovers unknown databases and locates sensitive and proprietary information across your environment — you cannot protect the database you did not know was there.

    Advanced Analytics & Risk Scoring

    Automatically calculates a risk level for every database by correlating active vulnerabilities with sensitive-data activity, surfaced on dashboards that make anomalies and audit prep legible.

    Unified Command Center

    Transforms raw alert data into actionable insight so the team focuses on the most critical threats first, rather than triaging a flat log.

    Broad Database Support

    Covers Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona on-premises, plus MariaDB, MySQL, and PostgreSQL on AWS RDS.

    IPv4/IPv6/Dual-Stack

    Seamless protection across IPv4, IPv6, and dual-stack environments, so the modern network topology is not a coverage gap.

    Specifications

    Technical detail

    On-Premises Databases
    Oracle, Microsoft SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, Percona
    AWS RDS
    MariaDB, MySQL, PostgreSQL
    Operating Systems
    Windows, Linux, Solaris, AIX, HP-UX
    Network
    IPv4, IPv6, and dual-stack
    Core Modules
    Activity Monitoring, Virtual Patching, Vulnerability Manager, Advanced Analytics

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Database Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What does virtual patching actually do for us?

    It protects a database against a known vulnerability without applying the vendor patch — which matters because production databases often cannot be taken down for patching on the vendor’s schedule, or run versions the vendor no longer patches. Virtual patches apply automatically without impacting availability.

    02Which databases does it cover?

    Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona on-premises, and MariaDB, MySQL, and PostgreSQL on AWS RDS — across Windows, Linux, Solaris, AIX, and HP-UX.

    03Can it find databases we have lost track of?

    Yes. It discovers unknown databases and locates the sensitive data inside them. Shadow databases spun up by a project and forgotten are a common breach path, and discovery is the first step to closing it.

    04How does it decide what to alert on first?

    Advanced Analytics calculates a risk level per database by correlating active vulnerabilities with sensitive-data activity, so the dashboard ranks by real exposure rather than raw event volume. Faltrox tunes this ranking to your environment.

    05Is this separate from the rest of Trellix Data Security?

    It is an add-on to the broader Data Security Suite. Most organisations combine it with DLP and encryption so the data is protected at the endpoint, in transit, and inside the database it lives in.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us