Network Forensics
Lossless full-packet capture at 20 Gbps, indexed so you can actually find the session.
When an incident happens, the questions are: what exactly moved, when, and to where. Trellix Network Forensics answers them by pairing the industry’s fastest lossless packet capture with a centralised analysis workbench — capturing and indexing full packets at up to 20 Gbps, then reconstructing the sessions, files, and emails around an attack. Faltrox operates it as the evidence layer behind detection.
Overview
What Network Forensics is
Trellix Network Forensics pairs the industry’s fastest lossless packet capture with a centralised analysis workbench. When an incident happens, the questions are: what exactly moved, when, and to where — and logs tell you an event happened while full packet capture tells you what actually crossed the wire. It captures and indexes full packets at up to 20 Gbps, then reconstructs the sessions, files, and emails around an attack.
It covers web, email, FTP, DNS, chat, and SSL sessions across physical, next-generation, and virtual appliances scaling from hundreds of megabits to 20 Gbps and terabytes of storage. Patented indexing makes finding one session in terabytes of capture fast, and retrospective threat hunting applies new intelligence to old traffic. Faltrox operates it as the evidence layer behind detection.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Full Packet Capture
Continuous lossless capture with time stamping preserves exactly what crossed the wire.
Session Protocols
Decodes and searches web, email, FTP, DNS, chat, and SSL sessions and their file attachments.
Data Exfiltration
Proprietary algorithms diagnose anomalous behaviour and identify data theft during and after an attack.
Retrospective IOCs
Back-in-time IOC search alerts you to indicators that were present days or weeks earlier.
Physical & Virtual Appliances
Scales from 500 Mbps to 20 Gbps across physical, next-gen, and virtual (Azure, ESXi, KVM) appliances.
Intelligent Filtering
Selective filtering drops streaming video, large transfers, and encrypted payloads to focus storage.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Capture
Lossless packet capture at up to 20 Gbps records every packet, indexing each in real time by time stamp and connection attributes.
- 02
Store
Intelligent filtering excludes low-value traffic so retention concentrates on what matters, across onboard and SAN-attached storage.
- 03
Reconstruct
Session decoders and one-click file reconstruction rebuild suspect files, web pages, and emails safely for analysis.
- 04
Hunt
Retrospective threat hunting integrates Threat Intelligence, STIX, and OpenIOC feeds with automated back-in-time search.
- 05
Pivot
The workbench aggregates Network Security, Email Security, and Endpoint Security alerts with one-click pivot to session data.
Capabilities
Key capabilities
Lossless Packet Capture
Continuous lossless capture with time stamping at recording speeds up to 20 Gbps, so the evidence exists to answer scope-and-impact questions rather than being reconstructed from partial logs.
Patented Indexing
Real-time indexing of every captured packet by time stamp and connection attributes enables ultrafast search and retrieval of target connections — the difference between a query returning in seconds and in hours.
Session Reconstruction
Session decoders view and search web, email, FTP, DNS, chat, and SSL connection details plus file attachments, and reconstruct suspect files, web pages, and emails safely for analysis.
Retrospective Threat Hunting
Integrates Trellix Threat Intelligence, STIX, and OpenIOC feeds with automated back-in-time IOC search, so you get alerted to indicators that were present in your network days or weeks earlier.
IOC Aggregation Workbench
Consolidates Network Security, Email Security, and Endpoint Security alerts with all network metadata in one workbench, with one-click pivot from an alert straight to its session data.
Intelligent Capture Filtering
Selective filtering drops streaming video, large file transfers, and encrypted payloads from capture, so storage and analysis focus on traffic that matters.
Metadata Export
Exports flow index and connection metadata in JSON, convertible to NetFlow v9, IPFIX, and SiLK formats for ingestion into your wider analytics stack.
Flexible Appliances
Physical, next-generation, and virtual (Azure, ESXi, KVM, AMI) capture appliances scale from 500 Mbps to 20 Gbps and 6 TB to 700+ TB, with distributed investigation-analysis nodes.
Specifications
Technical detail
- Max Record Speed
- Up to 20 Gbps lossless capture
- Physical Appliances
- PX 1004S-6 (6 TB) to next-gen 7600PX/5000SX (up to ~700 TB raw)
- Virtual Support
- Azure, ESXi, KVM, AMI — 25 Mbps to 1,000 Mbps by profile
- Indexed Protocols
- HTTP, SMTP, POP3, IMAP, SSL, TLS, DNS, FTP
- Analysis Ingestion
- Up to 50K events/second (2600IA-HW)
- Metadata Formats
- JSON; NetFlow v9, IPFIX, SiLK
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Network Forensics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why capture full packets when we already keep logs?
Logs tell you an event happened; full packet capture tells you exactly what moved. During an incident that difference decides whether you can prove what data left, quantify impact for regulators, and reconstruct the attacker’s actions — none of which a summarised log supports.
02How do you find one session in 20 Gbps of capture?
That is what the patented indexing architecture is for. Every packet is indexed in real time by time stamp and connection attributes, so search and retrieval of a target connection is ultrafast rather than a linear scan of terabytes.
03Can it find threats that were already in our network before we knew?
Yes — retrospective threat hunting integrates Threat Intelligence, STIX, and OpenIOC feeds with automated back-in-time search, and alerts you to IOCs that were present days or weeks earlier. New intelligence gets applied to old captured traffic.
04Will capturing everything overwhelm storage?
Intelligent capture filtering lets you exclude streaming video, large file transfers, and encrypted payloads, so retention concentrates on traffic worth keeping. Appliances also scale to hundreds of terabytes of onboard and SAN-attached storage.
05How does it fit the rest of our Trellix stack?
It aggregates alerts from Network Security, Email Security, and Endpoint Security into one workbench with one-click pivot to the underlying session — so a detection anywhere in the portfolio drops you straight onto its packet-level evidence.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us