Endpoint Forensics
Forensic data from tens of thousands of endpoints, in minutes.
Trellix Endpoint Forensics (HX) is a modular single-agent platform that protects, detects, investigates, and responds — then collects the forensic data needed to accurately scope an incident. Its detection logic is built from real-time indicators of compromise developed across thousands of front-line incident response engagements. Faltrox deploys it and runs the investigations.
Overview
What Endpoint Forensics is
Trellix Endpoint Forensics (HX) is a modular, single-agent platform that protects, detects, investigates, and responds — then collects the forensic data needed to accurately scope an incident. Its detection logic is built from real-time indicators of compromise developed across thousands of front-line incident response engagements, so it recognises the techniques attackers actually use rather than only what a signature has already catalogued.
It covers Windows, macOS, and Linux endpoints across hybrid environments including air-gapped networks, deployable as a physical, virtual, or cloud-hosted appliance. Where Endpoint Security is the protection layer and EDRF the SaaS-managed EDR line, Endpoint Forensics is the appliance-based investigation platform for organisations whose deployment constraints demand it. Faltrox deploys it, tunes the detection modules, and runs the scoping and timeline work when something fires.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Windows, macOS & Linux
One lightweight agent covers desktops and servers across all three major operating systems.
Air-Gapped Networks
Native visibility across hybrid environments including air-gapped networks, with offline collection.
Known & Unknown Threats
Signature, machine-learning, and behavioural engines cover both catalogued and never-before-seen threats.
Browser & Software Exploits
Behavioural analysis determines when an exploit is being used in common software and stops it executing.
Credential Theft
Purpose-built mechanisms detect and stop the credential exfiltration that turns one host into domain access.
Enterprise-Scale Estates
Searches and scopes across tens of thousands of endpoints in minutes during an active incident.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Deploy
A single lightweight agent installs across the estate as a physical, virtual, or cloud-hosted appliance, including on air-gapped networks.
- 02
Detect
Three engines run in concert — a signature engine for known malware, machine learning trained on thousands of IR engagements, and behavioural analysis for exploits.
- 03
Collect
On demand or automatically, it captures salient forensic data — memory, files, and process state — remotely, without shell access to the endpoint.
- 04
Scope
Determines whether an attack occurred on a host, whether it persists, and how far it may have spread across the estate.
- 05
Timeline & Respond
Establishes the duration and sequence of the compromise and follows the incident through to containment and remediation.
Capabilities
Key capabilities
Enterprise-Scale Collection
Search for and investigate known and unknown threats across tens of thousands of endpoints in minutes, rather than triaging machine by machine.
Three Detection Engines
A signature engine for known malware, machine learning trained on thousands of IR engagements for threats with no signature yet, and behavioural analysis that stops browser and software exploits mid-execution.
Attack Vector Identification
Identifies and details the specific vectors an attack used to infiltrate an endpoint, so the entry path gets closed rather than just the payload removed.
Scope and Persistence Analysis
Determines whether an attack occurred on a given endpoint, whether it persists, and how far it may have spread — the questions that decide whether an incident is closed or ongoing.
Incident Timeline
Establishes the timeline and duration of endpoint compromises and follows the incident through, giving a defensible sequence of events for regulators and insurers.
Credential Exfiltration Defence
Purpose-built mechanisms detect and stop credential theft, the technique that turns a single compromised endpoint into domain-wide access.
Enterprise Search & Rapid Acquisition
Discover and investigate suspicious activity across the estate, and pull in-depth endpoint data for a specific timeframe when an investigation narrows to a window.
One Lightweight Agent
A single agent carries protection, detection, and forensics with minimal performance impact, and gains new capability through downloadable modules rather than new installs.
Specifications
Technical detail
- Windows
- 7, 8, 8.1, 10, 11; Server 2008R2, 2012R2, 2016, 2019
- macOS
- 10.9 – 10.15, 11, 12, 13
- Linux
- RHEL 6.8–8.3, CentOS 6.8–8.0, SUSE 11 SP3–15, Ubuntu 14.04–20.04 LTS, Amazon Linux, Oracle Linux
- Deployment
- Physical appliance, virtual appliance, or cloud-hosted appliance
- Compliance
- GDPR, PCI-DSS, HIPAA
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Endpoint Forensics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How does Endpoint Forensics differ from EDR with Forensics?
Endpoint Forensics (HX) is the appliance-based platform with a modular architecture and its own deployment options, including air-gapped networks. EDRF is the SaaS-managed EDR line run through ePO. Which one fits depends on your deployment constraints — Faltrox scopes that with you rather than defaulting to one.
02How quickly can it sweep our estate during an incident?
Collection across tens of thousands of endpoints runs in minutes. That speed is the point: during an active incident, the question "which other machines have this?" needs an answer in the same hour, not the same week.
03Does it work on air-gapped networks?
Yes. It natively integrates with the Trellix Security Platform to give visibility across hybrid environments including air-gapped networks, and can be deployed as a physical, virtual, or cloud-hosted appliance.
04Is this a replacement for antivirus?
It includes a signature-based engine for malware prevention alongside the machine-learning and behavioural engines, so it both prevents and investigates. In practice Faltrox positions it as the investigation and response capability over your protection layer.
05What does Faltrox do with it?
We deploy the appliance, tune the detection modules, and run the search, scoping, and timeline work when something fires — so the forensic capability exists without you staffing a forensics team to use it.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us