Database Security
Protect the database even when the vendor patch isn’t an option.
Databases hold the data an attacker is actually after, yet they are often the hardest systems to patch on schedule. Trellix Database Security finds, classifies, and defends sensitive information across leading database types — and keeps them protected even when vendor patches are unavailable, through virtual patching. Faltrox runs the monitoring and turns the alert stream into prioritised action.
Overview
What Database Security is
Trellix Database Security finds, classifies, and defends sensitive information across leading database types — and keeps them protected even when vendor patches are unavailable. Databases hold the data an attacker is actually after, yet they are often the hardest systems to patch on schedule, because production databases cannot be taken down on the vendor’s timetable.
It covers Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona on-premises, plus MariaDB, MySQL, and PostgreSQL on AWS RDS, across IPv4, IPv6, and dual-stack environments. Virtual patching stops exploits before they breach the database without impacting availability, and advanced analytics rank every database by real exposure. Faltrox runs the monitoring and turns the alert stream into prioritised action.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Leading Databases
Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona.
AWS RDS
Covers managed MariaDB, MySQL, and PostgreSQL instances on AWS RDS alongside on-premises.
Unpatchable Databases
Virtual patching protects databases the vendor no longer patches or that cannot be taken down.
Sensitive Data
Blocks unauthorised access to the sensitive and proprietary information held inside databases.
Shadow Databases
Discovers unknown databases spun up and forgotten — a common and invisible breach path.
Multiple Operating Systems
Runs across Windows, Linux, Solaris, AIX, and HP-UX for heterogeneous database estates.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Discover
Automated scanning finds supported databases across the environment and locates the sensitive data inside them, including databases you had lost track of.
- 02
Assess
Vulnerability Manager identifies and prioritises known vulnerabilities, and analytics calculate a risk level per database by correlating exposure with activity.
- 03
Protect
Virtual patches apply automatically without impacting availability, adding protection where a vendor patch is unavailable or cannot be applied.
- 04
Monitor
Database Activity Monitoring logs and detects access and irregularities in real time, preemptively blocking potential threats.
- 05
Report
A unified command centre turns raw alerts into prioritised insight and streamlines compliance audits through centralised dashboards.
Capabilities
Key capabilities
Database Activity Monitoring
Actively monitors, logs, and detects database access and irregularities, and preemptively blocks potential threats before they impact the environment.
Virtual Patching
Stops intrusions and exploits before they breach the database. Virtual patches apply automatically without impacting availability, and add protection when a vendor patch is unavailable or the database cannot be updated.
Vulnerability Manager
Automates scanning to find supported databases and their sensitive information across the environment, then identifies and prioritises known vulnerabilities for remediation.
Sensitive Data Discovery
Discovers unknown databases and locates sensitive and proprietary information across your environment — you cannot protect the database you did not know was there.
Advanced Analytics & Risk Scoring
Automatically calculates a risk level for every database by correlating active vulnerabilities with sensitive-data activity, surfaced on dashboards that make anomalies and audit prep legible.
Unified Command Center
Transforms raw alert data into actionable insight so the team focuses on the most critical threats first, rather than triaging a flat log.
Broad Database Support
Covers Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona on-premises, plus MariaDB, MySQL, and PostgreSQL on AWS RDS.
IPv4/IPv6/Dual-Stack
Seamless protection across IPv4, IPv6, and dual-stack environments, so the modern network topology is not a coverage gap.
Specifications
Technical detail
- On-Premises Databases
- Oracle, Microsoft SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, Percona
- AWS RDS
- MariaDB, MySQL, PostgreSQL
- Operating Systems
- Windows, Linux, Solaris, AIX, HP-UX
- Network
- IPv4, IPv6, and dual-stack
- Core Modules
- Activity Monitoring, Virtual Patching, Vulnerability Manager, Advanced Analytics
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Database Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What does virtual patching actually do for us?
It protects a database against a known vulnerability without applying the vendor patch — which matters because production databases often cannot be taken down for patching on the vendor’s schedule, or run versions the vendor no longer patches. Virtual patches apply automatically without impacting availability.
02Which databases does it cover?
Oracle, SQL Server, MySQL, PostgreSQL, MariaDB, Sybase, DB2, SAP HANA, and Percona on-premises, and MariaDB, MySQL, and PostgreSQL on AWS RDS — across Windows, Linux, Solaris, AIX, and HP-UX.
03Can it find databases we have lost track of?
Yes. It discovers unknown databases and locates the sensitive data inside them. Shadow databases spun up by a project and forgotten are a common breach path, and discovery is the first step to closing it.
04How does it decide what to alert on first?
Advanced Analytics calculates a risk level per database by correlating active vulnerabilities with sensitive-data activity, so the dashboard ranks by real exposure rather than raw event volume. Faltrox tunes this ranking to your environment.
05Is this separate from the rest of Trellix Data Security?
It is an add-on to the broader Data Security Suite. Most organisations combine it with DLP and encryption so the data is protected at the endpoint, in transit, and inside the database it lives in.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us