TrellixEndpoint Security

    EDR with Forensics

    EDR that keeps the evidence, so the second wave never gets a foothold.

    Sophisticated attackers hide the root cause of a breach inside trusted components, so containing the alert still leaves the exploit in place. Trellix EDR with Forensics (EDRF) adds always-on forensic collection and AI-guided investigation to standard EDR, giving analysts the context to eradicate an intrusion rather than just interrupt it. Faltrox runs the console and the investigations.

    Overview

    What EDR with Forensics is

    Trellix Endpoint Detection and Response with Forensics (EDRF) extends standard EDR with always-on forensic collection and AI-guided investigation. Ordinary EDR captures endpoint behaviour and can contain a threat, but sophisticated attackers hide the initial compromise and root cause inside trusted components — so containing the alert leaves the intrusion in place. EDRF adds the depth of visibility needed to eradicate an attack rather than just interrupt it.

    It covers the full investigation lifecycle: capturing process, memory, and disk-level evidence remotely; correlating alerts and attacker TTPs with Trellix Wise AI; and giving analysts of any level machine-generated insight into what happened. It runs on-premises, in the cloud, or fully air-gapped, and is managed through Trellix ePO. Faltrox operates the console and runs the investigations, so the forensic capability exists without you staffing a forensics team.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Windows Endpoints

    Deep detection, response, and forensic capture across your Windows desktop and server estate.

    02

    Deeply Hidden Threats

    Surfaces obfuscated and deeply rooted threats that hide within trusted components and evade standard EDR.

    03

    Patient-Zero Root Cause

    Identifies the initial compromise and root cause, not just the symptom, so the intrusion is fully eradicated.

    04

    Fileless Attacks

    Cloud and client analytics catch file-based and fileless attacks that slipped past other defences.

    05

    Air-Gapped Environments

    Enhanced forensics for on-premises-only and air-gapped deployments with strict data-residency needs.

    06

    Post-Breach Persistence

    Historical search across weeks or months reveals dormant footholds and indicators left behind.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Collect

      Always-on collection streams process activity, file changes, network connections, DNS queries, and command lines from every monitored endpoint, and snapshots memory and disk on demand.

    2. 02

      Detect

      Endpoint telemetry is analysed on both the client and in the cloud across multiple analytic engines, mapping behaviour to the MITRE ATT&CK framework.

    3. 03

      Investigate

      Trellix Wise automatically correlates related breaches, artifacts, and attacker TTPs into a visual graph, and dynamic investigation guides adapt to each case.

    4. 04

      Respond

      Direct command-line access to impacted devices, automated containment, and one-click report generation close the incident fast.

    5. 05

      Hunt

      Analysts query a centralised repository of deep forensic data — historical and real-time — across tens of thousands of machines to find what automation missed.

    Capabilities

    Key capabilities

    Always-On Forensic Capture

    Snapshots active processes, process and driver memory, network connections, services, registry keys, and autorun entries — plus partial and full disk images — entirely remotely, with no shell access to the endpoint.

    Trellix Wise AI Investigation

    Automatically correlates related breaches, artifacts, and network connections into a visual graph, recommends next steps by threat severity, and generates the closing report in one click.

    Dynamic Investigation Guides

    Unlike playbooks that automate scripted tasks for known threats, these adjust to each case, combining strategies and re-gathering evidence as the investigation evolves.

    MITRE ATT&CK Mapping

    Behaviour-based detections map to ATT&CK, so the phase of a threat and its associated risk are read off a shared framework instead of being argued about per analyst.

    Historical & Real-Time Search

    Streams process activity, file changes, network connections, DNS queries, and command lines from every monitored system. Search back weeks or months, or query live endpoints across tens of thousands of machines.

    Customisable IOCs

    Collects indicators at the endpoint itself across six event types — process, file, image load, registry key, IP, DNS lookup, URL — with over 94 attributes available for tuning to your environment.

    Air-Gapped Deployment

    Full forensic capability in on-premises-only and air-gapped environments, for the data-residency and privacy constraints that rule out cloud-only EDR.

    Offline Collection

    A non-persistent collection tool captures snapshots on unmonitored and offline systems, so a machine that was off the network during the incident is still investigable.

    Specifications

    Technical detail

    Delivery
    SaaS application, managed through Trellix ePO (on-premises or cloud)
    Deployment Modes
    Cloud, on-premises only, air-gapped
    IOC Event Types
    Six types, 94+ customisable attributes
    Compliance
    Supports GDPR, PCI-DSS, and HIPAA evidence requirements

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix EDR with Forensics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How is this different from Trellix Endpoint Security (ENS)?

    ENS is the protection layer — it blocks and rolls back. EDRF is the investigation layer that sits on top: it retains deep forensic data so you can answer how the attacker got in, what else they touched, and whether they are still there. Most customers run both.

    02Does collecting forensic data require remote access to our machines?

    No. All forensics actions are performed remotely through the agent without requiring remote shell access to the endpoint, which is what makes it usable at scale without opening an interactive path onto every device.

    03Can it run without sending our data to the cloud?

    Yes. EDRF supports on-premises-only and air-gapped deployments with enhanced forensics, specifically for organisations with data residency, GDPR, PCI-DSS, or HIPAA constraints that rule out cloud analysis.

    04How far back can we search?

    Always-on collection preserves activity history so the search window can span weeks or months, and it covers endpoints regardless of whether they are currently online. Deleted files remain discoverable in the collected data.

    05Do we need our own senior analysts to get value from it?

    That is the gap Faltrox fills. Trellix Wise lowers the expertise needed through guided investigation and alert correlation, and our SOC runs the investigations on top of that, so you are not hiring Tier 3 analysts to operate the tool.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us