TrellixNetwork Security

    Network Forensics

    Lossless full-packet capture at 20 Gbps, indexed so you can actually find the session.

    When an incident happens, the questions are: what exactly moved, when, and to where. Trellix Network Forensics answers them by pairing the industry’s fastest lossless packet capture with a centralised analysis workbench — capturing and indexing full packets at up to 20 Gbps, then reconstructing the sessions, files, and emails around an attack. Faltrox operates it as the evidence layer behind detection.

    Overview

    What Network Forensics is

    Trellix Network Forensics pairs the industry’s fastest lossless packet capture with a centralised analysis workbench. When an incident happens, the questions are: what exactly moved, when, and to where — and logs tell you an event happened while full packet capture tells you what actually crossed the wire. It captures and indexes full packets at up to 20 Gbps, then reconstructs the sessions, files, and emails around an attack.

    It covers web, email, FTP, DNS, chat, and SSL sessions across physical, next-generation, and virtual appliances scaling from hundreds of megabits to 20 Gbps and terabytes of storage. Patented indexing makes finding one session in terabytes of capture fast, and retrospective threat hunting applies new intelligence to old traffic. Faltrox operates it as the evidence layer behind detection.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Full Packet Capture

    Continuous lossless capture with time stamping preserves exactly what crossed the wire.

    02

    Session Protocols

    Decodes and searches web, email, FTP, DNS, chat, and SSL sessions and their file attachments.

    03

    Data Exfiltration

    Proprietary algorithms diagnose anomalous behaviour and identify data theft during and after an attack.

    04

    Retrospective IOCs

    Back-in-time IOC search alerts you to indicators that were present days or weeks earlier.

    05

    Physical & Virtual Appliances

    Scales from 500 Mbps to 20 Gbps across physical, next-gen, and virtual (Azure, ESXi, KVM) appliances.

    06

    Intelligent Filtering

    Selective filtering drops streaming video, large transfers, and encrypted payloads to focus storage.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Capture

      Lossless packet capture at up to 20 Gbps records every packet, indexing each in real time by time stamp and connection attributes.

    2. 02

      Store

      Intelligent filtering excludes low-value traffic so retention concentrates on what matters, across onboard and SAN-attached storage.

    3. 03

      Reconstruct

      Session decoders and one-click file reconstruction rebuild suspect files, web pages, and emails safely for analysis.

    4. 04

      Hunt

      Retrospective threat hunting integrates Threat Intelligence, STIX, and OpenIOC feeds with automated back-in-time search.

    5. 05

      Pivot

      The workbench aggregates Network Security, Email Security, and Endpoint Security alerts with one-click pivot to session data.

    Capabilities

    Key capabilities

    Lossless Packet Capture

    Continuous lossless capture with time stamping at recording speeds up to 20 Gbps, so the evidence exists to answer scope-and-impact questions rather than being reconstructed from partial logs.

    Patented Indexing

    Real-time indexing of every captured packet by time stamp and connection attributes enables ultrafast search and retrieval of target connections — the difference between a query returning in seconds and in hours.

    Session Reconstruction

    Session decoders view and search web, email, FTP, DNS, chat, and SSL connection details plus file attachments, and reconstruct suspect files, web pages, and emails safely for analysis.

    Retrospective Threat Hunting

    Integrates Trellix Threat Intelligence, STIX, and OpenIOC feeds with automated back-in-time IOC search, so you get alerted to indicators that were present in your network days or weeks earlier.

    IOC Aggregation Workbench

    Consolidates Network Security, Email Security, and Endpoint Security alerts with all network metadata in one workbench, with one-click pivot from an alert straight to its session data.

    Intelligent Capture Filtering

    Selective filtering drops streaming video, large file transfers, and encrypted payloads from capture, so storage and analysis focus on traffic that matters.

    Metadata Export

    Exports flow index and connection metadata in JSON, convertible to NetFlow v9, IPFIX, and SiLK formats for ingestion into your wider analytics stack.

    Flexible Appliances

    Physical, next-generation, and virtual (Azure, ESXi, KVM, AMI) capture appliances scale from 500 Mbps to 20 Gbps and 6 TB to 700+ TB, with distributed investigation-analysis nodes.

    Specifications

    Technical detail

    Max Record Speed
    Up to 20 Gbps lossless capture
    Physical Appliances
    PX 1004S-6 (6 TB) to next-gen 7600PX/5000SX (up to ~700 TB raw)
    Virtual Support
    Azure, ESXi, KVM, AMI — 25 Mbps to 1,000 Mbps by profile
    Indexed Protocols
    HTTP, SMTP, POP3, IMAP, SSL, TLS, DNS, FTP
    Analysis Ingestion
    Up to 50K events/second (2600IA-HW)
    Metadata Formats
    JSON; NetFlow v9, IPFIX, SiLK

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Network Forensics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why capture full packets when we already keep logs?

    Logs tell you an event happened; full packet capture tells you exactly what moved. During an incident that difference decides whether you can prove what data left, quantify impact for regulators, and reconstruct the attacker’s actions — none of which a summarised log supports.

    02How do you find one session in 20 Gbps of capture?

    That is what the patented indexing architecture is for. Every packet is indexed in real time by time stamp and connection attributes, so search and retrieval of a target connection is ultrafast rather than a linear scan of terabytes.

    03Can it find threats that were already in our network before we knew?

    Yes — retrospective threat hunting integrates Threat Intelligence, STIX, and OpenIOC feeds with automated back-in-time search, and alerts you to IOCs that were present days or weeks earlier. New intelligence gets applied to old captured traffic.

    04Will capturing everything overwhelm storage?

    Intelligent capture filtering lets you exclude streaming video, large file transfers, and encrypted payloads, so retention concentrates on traffic worth keeping. Appliances also scale to hundreds of terabytes of onboard and SAN-attached storage.

    05How does it fit the rest of our Trellix stack?

    It aggregates alerts from Network Security, Email Security, and Endpoint Security into one workbench with one-click pivot to the underlying session — so a detection anywhere in the portfolio drops you straight onto its packet-level evidence.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us