TrellixEndpoint Security

    Endpoint Forensics

    Forensic data from tens of thousands of endpoints, in minutes.

    Trellix Endpoint Forensics (HX) is a modular single-agent platform that protects, detects, investigates, and responds — then collects the forensic data needed to accurately scope an incident. Its detection logic is built from real-time indicators of compromise developed across thousands of front-line incident response engagements. Faltrox deploys it and runs the investigations.

    Overview

    What Endpoint Forensics is

    Trellix Endpoint Forensics (HX) is a modular, single-agent platform that protects, detects, investigates, and responds — then collects the forensic data needed to accurately scope an incident. Its detection logic is built from real-time indicators of compromise developed across thousands of front-line incident response engagements, so it recognises the techniques attackers actually use rather than only what a signature has already catalogued.

    It covers Windows, macOS, and Linux endpoints across hybrid environments including air-gapped networks, deployable as a physical, virtual, or cloud-hosted appliance. Where Endpoint Security is the protection layer and EDRF the SaaS-managed EDR line, Endpoint Forensics is the appliance-based investigation platform for organisations whose deployment constraints demand it. Faltrox deploys it, tunes the detection modules, and runs the scoping and timeline work when something fires.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Windows, macOS & Linux

    One lightweight agent covers desktops and servers across all three major operating systems.

    02

    Air-Gapped Networks

    Native visibility across hybrid environments including air-gapped networks, with offline collection.

    03

    Known & Unknown Threats

    Signature, machine-learning, and behavioural engines cover both catalogued and never-before-seen threats.

    04

    Browser & Software Exploits

    Behavioural analysis determines when an exploit is being used in common software and stops it executing.

    05

    Credential Theft

    Purpose-built mechanisms detect and stop the credential exfiltration that turns one host into domain access.

    06

    Enterprise-Scale Estates

    Searches and scopes across tens of thousands of endpoints in minutes during an active incident.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Deploy

      A single lightweight agent installs across the estate as a physical, virtual, or cloud-hosted appliance, including on air-gapped networks.

    2. 02

      Detect

      Three engines run in concert — a signature engine for known malware, machine learning trained on thousands of IR engagements, and behavioural analysis for exploits.

    3. 03

      Collect

      On demand or automatically, it captures salient forensic data — memory, files, and process state — remotely, without shell access to the endpoint.

    4. 04

      Scope

      Determines whether an attack occurred on a host, whether it persists, and how far it may have spread across the estate.

    5. 05

      Timeline & Respond

      Establishes the duration and sequence of the compromise and follows the incident through to containment and remediation.

    Capabilities

    Key capabilities

    Enterprise-Scale Collection

    Search for and investigate known and unknown threats across tens of thousands of endpoints in minutes, rather than triaging machine by machine.

    Three Detection Engines

    A signature engine for known malware, machine learning trained on thousands of IR engagements for threats with no signature yet, and behavioural analysis that stops browser and software exploits mid-execution.

    Attack Vector Identification

    Identifies and details the specific vectors an attack used to infiltrate an endpoint, so the entry path gets closed rather than just the payload removed.

    Scope and Persistence Analysis

    Determines whether an attack occurred on a given endpoint, whether it persists, and how far it may have spread — the questions that decide whether an incident is closed or ongoing.

    Incident Timeline

    Establishes the timeline and duration of endpoint compromises and follows the incident through, giving a defensible sequence of events for regulators and insurers.

    Credential Exfiltration Defence

    Purpose-built mechanisms detect and stop credential theft, the technique that turns a single compromised endpoint into domain-wide access.

    Enterprise Search & Rapid Acquisition

    Discover and investigate suspicious activity across the estate, and pull in-depth endpoint data for a specific timeframe when an investigation narrows to a window.

    One Lightweight Agent

    A single agent carries protection, detection, and forensics with minimal performance impact, and gains new capability through downloadable modules rather than new installs.

    Specifications

    Technical detail

    Windows
    7, 8, 8.1, 10, 11; Server 2008R2, 2012R2, 2016, 2019
    macOS
    10.9 – 10.15, 11, 12, 13
    Linux
    RHEL 6.8–8.3, CentOS 6.8–8.0, SUSE 11 SP3–15, Ubuntu 14.04–20.04 LTS, Amazon Linux, Oracle Linux
    Deployment
    Physical appliance, virtual appliance, or cloud-hosted appliance
    Compliance
    GDPR, PCI-DSS, HIPAA

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Endpoint Forensics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How does Endpoint Forensics differ from EDR with Forensics?

    Endpoint Forensics (HX) is the appliance-based platform with a modular architecture and its own deployment options, including air-gapped networks. EDRF is the SaaS-managed EDR line run through ePO. Which one fits depends on your deployment constraints — Faltrox scopes that with you rather than defaulting to one.

    02How quickly can it sweep our estate during an incident?

    Collection across tens of thousands of endpoints runs in minutes. That speed is the point: during an active incident, the question "which other machines have this?" needs an answer in the same hour, not the same week.

    03Does it work on air-gapped networks?

    Yes. It natively integrates with the Trellix Security Platform to give visibility across hybrid environments including air-gapped networks, and can be deployed as a physical, virtual, or cloud-hosted appliance.

    04Is this a replacement for antivirus?

    It includes a signature-based engine for malware prevention alongside the machine-learning and behavioural engines, so it both prevents and investigates. In practice Faltrox positions it as the investigation and response capability over your protection layer.

    05What does Faltrox do with it?

    We deploy the appliance, tune the detection modules, and run the search, scoping, and timeline work when something fires — so the forensic capability exists without you staffing a forensics team to use it.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us