Endpoint Security
Machine-learning endpoint protection that undoes the damage, not just the alert.
Trellix Endpoint Security (ENS) pairs machine-learning threat detection with automatic rollback remediation, so a compromised endpoint doesn't just get flagged, it gets restored to its last known-good state. Faltrox licenses, deploys, and tunes ENS for you, then operates it from our SOC around the clock.
Overview
What Endpoint Security is
Trellix Endpoint Security (ENS) is an integrated endpoint protection platform that replaces the reactive, signature-first model of traditional antivirus with layered machine-learning detection and automated recovery. Instead of matching a file against a list of known-bad definitions and hoping the list is current, ENS classifies behaviour in real time — which is what lets it stop malware it has never seen before.
It covers Windows desktops and servers, and manages the security controls already built into Windows — Defender Antivirus, Exploit Guard, and Firewall — from a single console rather than ripping them out. The result is one protection layer that spans signatureless detection, containment of unknown applications, an integrated reputation-scored firewall, and visibility into fileless and script-based attacks that never write a scannable file to disk.
The differentiator is what happens after detection. Rollback remediation reverts the changes malware made and returns the endpoint to its last known-good state automatically — no manual reimage, no ticket queue — while the Story Graph gives the SOC an evidence trail of exactly how the infection moved. Faltrox holds the ePO console, tunes the policies to your environment, and operates it around the clock.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Windows Desktops
Full protection for Windows desktop endpoints — the primary target surface for phishing payloads, drive-by malware, and ransomware.
Windows Servers
Server endpoints get the same signatureless detection and containment, protecting the systems that hold the data attackers move laterally to reach.
Zero-Day Malware
Behavioural machine learning catches never-before-seen exploits and malware without waiting on a signature to be written and distributed.
Fileless & Script Attacks
AMSI and PowerShell event logging surface fileless and script-based attacks that never touch disk — the class signature AV structurally cannot see.
Ransomware
Containment stops encryption at patient zero, and rollback reverts damage — turning a ransomware detonation into a recoverable event rather than a crisis.
Botnets & C2 Traffic
The integrated, reputation-scored firewall blocks botnet, DDoS, and command-and-control traffic using Trellix Global Threat Intelligence.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Classify
Real Protect analyses process behaviour in the cloud with machine learning and, together with reputation from Global Threat Intelligence, decides whether an unknown file is safe, suspicious, or malicious — no signature required.
- 02
Contain
Dynamic Application Containment boxes in greyware and emerging malware at patient zero, blocking the actions it would use to spread while deeper analysis runs, so an unknown binary cannot move laterally.
- 03
Remediate
If a file is convicted, rollback remediation automatically reverts every change it made and restores the endpoint to its last known-good state — recovery happens without waiting on a human.
- 04
Investigate
The Story Graph reconstructs exactly how the infection entered and moved through the system, so the Faltrox SOC starts an investigation from evidence rather than a blank terminal.
- 05
Harden
Trellix Insights predicts which threats target your industry and region and flags under-protected endpoints, so policy is tuned against the adversaries actually coming for you — before the next attack lands.
Capabilities
Key capabilities
Real Protect
Signatureless machine-learning behaviour classification that catches zero-day malware in near real time, without waiting on virus definitions to be written and pushed.
Rollback Remediation
Automatically reverts every change a piece of malware made and returns the endpoint to its last known-good state. No manual reimage, no ticket queue.
Dynamic Application Containment
Analyses and contains greyware and emerging malware at patient zero, so an unknown binary is boxed in before it has a chance to spread laterally.
Trellix Insights
Predicts which threats are actively targeting your industry and region, then flags which of your endpoints are under-protected against them before an attack lands.
Story Graph
A visual trace of exactly how an infection moved through a system, so investigation starts from evidence rather than a blank terminal.
Reputation-Scored Firewall
Uses Trellix Global Threat Intelligence to block botnets, DDoS, and APT traffic, and restricts a device to outbound-only while it boots off the corporate network.
AMSI & PowerShell Logging
Surfaces fileless and script-based attacks that never touch disk as a scannable file — the class of attack signature AV structurally cannot see.
Single-Console Defender Management
Manages Windows Defender Antivirus, Exploit Guard, and Firewall policy from the same console instead of replacing them, so nothing you already run gets ripped out.
Specifications
Technical detail
- Protected Endpoints
- Windows desktop and server systems
- Native Controls Managed
- Windows Defender Antivirus, Exploit Guard, and Windows Firewall
- Management
- Trellix ePolicy Orchestrator (ePO) — on-premises or SaaS single pane of glass
- Detection
- Real Protect ML (signatureless), Dynamic Application Containment, GTI reputation
- Recovery
- Automatic rollback remediation to last known-good state
- Attack Visibility
- Story Graph tracing, AMSI and PowerShell event logging
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Endpoint Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What does Trellix ENS actually protect?
Windows desktop and server endpoints — it's not a network or email product. Faltrox pairs it with Trellix's network and email security lines where those are also in scope.
02Is Real Protect the same as traditional antivirus?
No. Real Protect is signatureless — instead of matching known virus definitions, it classifies suspicious behaviour in the cloud using machine learning, which is what lets it catch zero-day malware traditional signature-based AV hasn't seen yet.
03What happens after ENS detects an infection?
Rollback remediation automatically reverts the changes the malware made and returns the endpoint to its last known-good state. Faltrox's SOC is notified through the Story Graph so a human reviews what happened, but recovery doesn't wait on that review.
04Do we need to replace Windows Defender to use this?
No. ENS manages Windows Defender Antivirus, Exploit Guard, and Firewall policies from the same console rather than replacing them, so nothing you already run gets ripped out.
05How does Faltrox operate this day to day?
We hold the Trellix ePO console, tune Real Protect and DAC policies to your environment, and our SOC acts on whatever the Story Graph or Trellix Insights surfaces — you get the protection without running a security console yourself.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us