TrellixEndpoint Security

    Mobile Threat Defense

    Mobile threat defence that secures BYOD without reading the employee’s phone.

    Trellix Mobile Threat Defense (MTD) is a privacy-first application that protects corporate-owned and BYO devices from advanced threats across the full mobile kill chain — device, network, phishing, and app. Its machine-learning Dynamic Detection Engine runs on-device in real time. Faltrox deploys it and integrates its signal into your existing SOC workflows.

    Overview

    What Mobile Threat Defense is

    Trellix Mobile Threat Defense (MTD) is a privacy-first application that protects corporate-owned and BYO devices from advanced threats across the full mobile kill chain — device, network, phishing, and app. Its machine-learning Dynamic Detection Engine runs on-device in real time, so protection does not depend on a cloud round trip and works wherever the device is.

    Mobile is usually the blind spot in a security programme: access decisions are made on identity and managed laptops while phones with the same access go unassessed. MTD closes that gap without harvesting the employee’s personal data — the design choice that lets a BYOD rollout survive its own consent conversation. It integrates with existing SIEM, IAM, UEM, and XDR workflows, and Faltrox wires its signal into your SOC.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Apple iOS

    Full threat defence for iOS 12 and higher, corporate-owned or BYO.

    02

    Android

    Coverage for Android 6 and higher across the fragmented Android device landscape.

    03

    ChromeOS

    Protection for ChromeOS systems that support Android apps.

    04

    Mobile Phishing

    Dynamic content filtering blocks phishing arriving through channels beyond corporate email.

    05

    Malicious Apps

    Advanced app analysis identifies both security and privacy risks in installed applications.

    06

    Network Attacks

    Detects malicious networks and man-in-the-middle attacks on the untrusted networks phones live on.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Activate

      Zero-touch activation enrols devices with no manual step, so a BYOD or corporate fleet is protected without a friction-heavy rollout.

    2. 02

      Detect

      The on-device Dynamic Detection Engine uses machine learning to detect threats across device, network, phishing, and app vectors in real time.

    3. 03

      Analyse

      Advanced app analysis inspects installed applications for the permissions and data flows a store listing never discloses.

    4. 04

      Respond

      Mobile forensics on the device, its connections, and malicious apps let the SOC scope and stop a compromise before it becomes an outbreak.

    5. 05

      Integrate

      Detections flow into existing SIEM, IAM, UEM, and XDR platforms through a full-featured API, so mobile alerts land where humans review them.

    Capabilities

    Key capabilities

    Full Kill-Chain Detection

    Machine learning detects threats across all four mobile attack surfaces — device compromise, malicious networks, phishing, and hostile apps — rather than covering only app reputation.

    Privacy-First Architecture

    Secures BYOD alongside corporate-owned endpoints without harvesting the end user’s personal data, which is what makes a BYOD rollout survive its own consent conversation.

    On-Device Real-Time Protection

    Protection runs locally on the device rather than depending on a cloud round trip, so risk is reduced and advanced threats stopped even off-network.

    Advanced App Analysis

    Identifies both security and privacy risks in installed applications — the permissions and data flows that a store listing does not disclose.

    Mobile Forensics

    Forensic data on the device, its network connections, and malicious applications lets a SOC scope an incident and stop one compromised phone becoming an outbreak.

    Dynamic Content Filtering

    Blocks malicious or risky web activity on the device, covering the phishing paths that arrive through channels other than corporate email.

    Vulnerability Detection

    Flags outdated or non-compliant operating systems and applications, turning an unmanaged fleet into a patchable inventory.

    Zero-Touch Activation

    Frictionless deployment with no manual enrolment step, plus a full-featured API and integrations into SIEM, IAM, UEM, and XDR workflows.

    Specifications

    Technical detail

    Apple iOS
    iOS 12 or higher
    Android
    Android 6 or higher
    ChromeOS
    Systems supporting Android apps
    Deployment
    Cloud, on-premises, or air-gapped
    Integrations
    SIEM, IAM, UEM, and XDR platforms; full-featured API

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Mobile Threat Defense for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Can employees see what we can see on their personal phones?

    The privacy-first design is the product’s central claim: it secures BYO devices without collecting personal data. This matters practically, not just ethically — a mobile security rollout that employees believe is surveillance does not get adopted.

    02Does it work if the phone is off the corporate network?

    Yes. Real-time protection runs on-device rather than requiring a cloud round trip, which is essential given that mobile devices spend most of their time on networks you do not control.

    03How does this fit a Zero Trust programme?

    It supplies device posture and risk signal for mobile, which is usually the blind spot in a Zero Trust rollout — access decisions are made on identity and managed laptops while phones with the same access go unassessed.

    04Do we need to replace our MDM or UEM?

    No. MTD integrates with existing UEM, IAM, SIEM, and XDR platforms. MDM manages the device; MTD detects threats on it. They are complementary layers.

    05What does Faltrox handle?

    Deployment and policy configuration across teams, groups, and apps, plus wiring the detections into your SOC workflow so mobile alerts land somewhere a human actually reviews them.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us