EDR with Forensics
EDR that keeps the evidence, so the second wave never gets a foothold.
Sophisticated attackers hide the root cause of a breach inside trusted components, so containing the alert still leaves the exploit in place. Trellix EDR with Forensics (EDRF) adds always-on forensic collection and AI-guided investigation to standard EDR, giving analysts the context to eradicate an intrusion rather than just interrupt it. Faltrox runs the console and the investigations.
Overview
What EDR with Forensics is
Trellix Endpoint Detection and Response with Forensics (EDRF) extends standard EDR with always-on forensic collection and AI-guided investigation. Ordinary EDR captures endpoint behaviour and can contain a threat, but sophisticated attackers hide the initial compromise and root cause inside trusted components — so containing the alert leaves the intrusion in place. EDRF adds the depth of visibility needed to eradicate an attack rather than just interrupt it.
It covers the full investigation lifecycle: capturing process, memory, and disk-level evidence remotely; correlating alerts and attacker TTPs with Trellix Wise AI; and giving analysts of any level machine-generated insight into what happened. It runs on-premises, in the cloud, or fully air-gapped, and is managed through Trellix ePO. Faltrox operates the console and runs the investigations, so the forensic capability exists without you staffing a forensics team.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Windows Endpoints
Deep detection, response, and forensic capture across your Windows desktop and server estate.
Deeply Hidden Threats
Surfaces obfuscated and deeply rooted threats that hide within trusted components and evade standard EDR.
Patient-Zero Root Cause
Identifies the initial compromise and root cause, not just the symptom, so the intrusion is fully eradicated.
Fileless Attacks
Cloud and client analytics catch file-based and fileless attacks that slipped past other defences.
Air-Gapped Environments
Enhanced forensics for on-premises-only and air-gapped deployments with strict data-residency needs.
Post-Breach Persistence
Historical search across weeks or months reveals dormant footholds and indicators left behind.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Collect
Always-on collection streams process activity, file changes, network connections, DNS queries, and command lines from every monitored endpoint, and snapshots memory and disk on demand.
- 02
Detect
Endpoint telemetry is analysed on both the client and in the cloud across multiple analytic engines, mapping behaviour to the MITRE ATT&CK framework.
- 03
Investigate
Trellix Wise automatically correlates related breaches, artifacts, and attacker TTPs into a visual graph, and dynamic investigation guides adapt to each case.
- 04
Respond
Direct command-line access to impacted devices, automated containment, and one-click report generation close the incident fast.
- 05
Hunt
Analysts query a centralised repository of deep forensic data — historical and real-time — across tens of thousands of machines to find what automation missed.
Capabilities
Key capabilities
Always-On Forensic Capture
Snapshots active processes, process and driver memory, network connections, services, registry keys, and autorun entries — plus partial and full disk images — entirely remotely, with no shell access to the endpoint.
Trellix Wise AI Investigation
Automatically correlates related breaches, artifacts, and network connections into a visual graph, recommends next steps by threat severity, and generates the closing report in one click.
Dynamic Investigation Guides
Unlike playbooks that automate scripted tasks for known threats, these adjust to each case, combining strategies and re-gathering evidence as the investigation evolves.
MITRE ATT&CK Mapping
Behaviour-based detections map to ATT&CK, so the phase of a threat and its associated risk are read off a shared framework instead of being argued about per analyst.
Historical & Real-Time Search
Streams process activity, file changes, network connections, DNS queries, and command lines from every monitored system. Search back weeks or months, or query live endpoints across tens of thousands of machines.
Customisable IOCs
Collects indicators at the endpoint itself across six event types — process, file, image load, registry key, IP, DNS lookup, URL — with over 94 attributes available for tuning to your environment.
Air-Gapped Deployment
Full forensic capability in on-premises-only and air-gapped environments, for the data-residency and privacy constraints that rule out cloud-only EDR.
Offline Collection
A non-persistent collection tool captures snapshots on unmonitored and offline systems, so a machine that was off the network during the incident is still investigable.
Specifications
Technical detail
- Delivery
- SaaS application, managed through Trellix ePO (on-premises or cloud)
- Deployment Modes
- Cloud, on-premises only, air-gapped
- IOC Event Types
- Six types, 94+ customisable attributes
- Compliance
- Supports GDPR, PCI-DSS, and HIPAA evidence requirements
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix EDR with Forensics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How is this different from Trellix Endpoint Security (ENS)?
ENS is the protection layer — it blocks and rolls back. EDRF is the investigation layer that sits on top: it retains deep forensic data so you can answer how the attacker got in, what else they touched, and whether they are still there. Most customers run both.
02Does collecting forensic data require remote access to our machines?
No. All forensics actions are performed remotely through the agent without requiring remote shell access to the endpoint, which is what makes it usable at scale without opening an interactive path onto every device.
03Can it run without sending our data to the cloud?
Yes. EDRF supports on-premises-only and air-gapped deployments with enhanced forensics, specifically for organisations with data residency, GDPR, PCI-DSS, or HIPAA constraints that rule out cloud analysis.
04How far back can we search?
Always-on collection preserves activity history so the search window can span weeks or months, and it covers endpoints regardless of whether they are currently online. Deleted files remain discoverable in the collected data.
05Do we need our own senior analysts to get value from it?
That is the gap Faltrox fills. Trellix Wise lowers the expertise needed through guided investigation and alert correlation, and our SOC runs the investigations on top of that, so you are not hiring Tier 3 analysts to operate the tool.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us