TrellixEmail Security

    IVX for Enterprise Applications

    An API that drops sandbox detonation into any app that ingests files.

    Digital transformation has opened ERP, CRM, HR, and procurement systems to suppliers, vendors, and contractors — but those applications do not inspect files on ingest. Trellix Intelligent Virtual Execution (IVX) for Enterprise Applications exposes the IVX sandbox through an API so any built or bought application with an API can scan objects for threats at any point in its workflow. Faltrox integrates it into the applications that matter to your business.

    Overview

    What IVX for Enterprise Applications is

    Trellix Intelligent Virtual Execution (IVX) for Enterprise Applications exposes the IVX sandbox through an API so any built or bought application with an API can scan objects for threats at any point in its workflow. Digital transformation has opened ERP, CRM, HR, and procurement systems to suppliers, vendors, and contractors — but those applications do not inspect files on ingest, leaving a gap attackers exploit.

    It ships out-of-the-box support for dozens of applications — Salesforce, Webex, Slack, Teams — and the API covers anything else, including CIFS-compatible file shares. The same signature-less IVX engine detonates across 200+ execution environments and 200+ file types, returning contextual JSON verdicts with MITRE ATT&CK mapping. Faltrox integrates it into the applications and file-ingest points that carry real risk.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    ERP, CRM & HR Apps

    Adds file detonation to the business systems that ingest files but never inspect them.

    02

    Any Application with an API

    A simple API embeds sandbox scanning into any custom or third-party application.

    03

    CIFS File Shares

    Scans network file shares for weaponised Office files, images, PDFs, and archives.

    04

    Weaponised Files

    Detects advanced targeted attacks embedded in documents before they spread from a shared store.

    05

    200+ File Types

    Submissions are not limited to a narrow set of formats — over 200 file types are supported.

    06

    Zero-Day & APT

    Confirms true zero-day malware, targeted attacks, bots, and advanced persistent threats.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Integrate

      A RESTful API — or a prebuilt connector for apps like Salesforce, Webex, Slack, and Teams — embeds IVX into your applications.

    2. 02

      Submit

      Objects are submitted for inspection at any point in the workflow, or by a SOC analyst manually, or from CIFS file shares.

    3. 03

      Fast-Match

      Submissions are first fast-matched against Trellix Global Threat Intelligence from 40,000+ customers to pre-filter.

    4. 04

      Detonate

      The signature-less engine detonates across 200+ execution environments and file types to confirm the threat.

    5. 05

      Verdict

      A JSON verdict with file, registry, process, and network changes plus ATT&CK mapping flows into your workflow.

    Capabilities

    Key capabilities

    API-First Integration

    A simple API lets you integrate signature-less detonation into any enterprise application — built or bought — for continuous, frictionless protection at any point in the workflow.

    Out-of-the-Box App Support

    Prebuilt support for dozens of applications including Salesforce, Webex, Slack, Microsoft Teams, and more, with the API covering anything that lacks a native plug-in.

    File-Share Scanning

    Scans CIFS-compatible file shares to detect advanced targeted attacks embedded in weaponised Office files, images, PDFs, Flash, or archive files before they spread.

    Signature-Less Engine

    The same IVX hypervisor detonates against 200+ execution environments across operating systems and application versions, confirming true zero-day malware, targeted attacks, bots, and APTs.

    200+ File Types

    Supports over 200 file types for submission, so the applications you protect are not limited to a narrow set of formats.

    SOC Manual Submission

    Analysts can manually submit objects for inspection and insight, or wire submission into automated workflows — flexibility for both ad-hoc investigation and continuous protection.

    GTI Fast Match

    Begins by fast-matching submissions against Trellix Global Threat Intelligence from 40,000+ customers, pre-filtering before the heavier detonation stage for efficiency.

    Contextual JSON Verdicts

    Returns verdicts with file, registry, process, and network changes plus MITRE ATT&CK mapping in JSON, so results feed enterprise workflows and SOC tooling directly.

    Specifications

    Technical detail

    Integration Model
    RESTful API for any application with an API
    Prebuilt Apps
    Salesforce, Webex, Slack, Microsoft Teams, and more
    File Coverage
    200+ file types; CIFS-compatible file-share scanning
    Detonation Capacity
    200+ simultaneous executions per submission
    Deployment
    Cloud-native (Trellix or AWS Marketplace) or on-premises
    Output
    JSON verdict with ATT&CK mapping and contextual detail

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix IVX for Enterprise Applications for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Which applications can this protect?

    Any application that exposes an API. It ships with out-of-the-box support for dozens of apps — Salesforce, Webex, Slack, Teams and more — and the API covers everything else, so you can add file detonation to ERP, CRM, HR, or procurement systems that ingest files without inspecting them.

    02Why do enterprise apps need this?

    Digital transformation has granted external parties access to systems like ERP and CRM, but these applications do not inspect files on ingest to block threats before they enter the environment. IVX closes that gap by scanning objects wherever they enter the workflow.

    03How does it differ from the collaboration-platform version?

    Same IVX engine, different integration surface. The collaboration version targets Slack, Teams, and cloud storage out of the box; the enterprise-applications version is API-first, letting you embed detonation into any custom or third-party business application you run.

    04Can we scan existing network file shares?

    Yes. IVX can scan CIFS-compatible file shares to detect and stop weaponised Office files, images, PDFs, Flash, and archives — useful for the shared repositories that many organisations never inspect.

    05How does Faltrox implement it?

    We identify the applications and file-ingest points that carry real risk, integrate IVX through its API or a prebuilt connector, and wire the JSON verdicts into your SOC workflow — so protection is embedded in your business apps rather than bolted on.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us