Network Security
Signature-less MVX sandboxing that catches the zero-day the firewall waved through.
Trellix Network Security sits in the path of internet traffic behind your firewall, IPS, and secure web gateway to catch the advanced, targeted, and evasive attacks those miss. At its core is Multi-Vector Virtual Execution (MVX) — a signature-less dynamic analysis engine — plus machine-learning correlation engines built from thousands of hours of incident response. Faltrox deploys it clientless and operates the alerts.
Overview
What Network Security is
Trellix Network Security sits in the path of internet traffic — behind your firewall, IPS, and secure web gateway — to catch the advanced, targeted, and evasive attacks those defences miss. At its core is Multi-Vector Virtual Execution (MVX), a signature-less dynamic analysis engine that detonates suspicious traffic in a safe virtual environment, plus machine-learning correlation engines built from thousands of hours of incident response.
It detects zero-day, multi-flow, and other evasive attacks with high accuracy and few false positives, and the SmartVision engine extends that to east-west lateral movement across the network. It deploys clientless with no rules or tuning to get started, in integrated or distributed form, on-premises or in AWS and Azure. Faltrox deploys it and operates the alerts, so strong detection does not require standing up a large operations effort.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Internet Traffic
Inspects inbound and outbound internet traffic for exploits, malware, and callbacks in real time.
Multi-OS Endpoints
Consistent protection for Windows, macOS, and Linux across 160+ analysed file types.
Lateral Movement
SmartVision detects suspicious east-west traffic, data exfiltration, and web shells across the network.
Zero-Day & Evasive Attacks
The signature-less MVX sandbox catches never-before-seen exploits that signature defences wave through.
Encrypted Traffic
Built-in TLS 1.3 decryption on appliances gives visibility into encrypted traffic at no extra licence.
AWS & Azure
Available as virtual and public-cloud appliances for cloud internet-access points.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Position
Deployed behind existing firewall, IPS, and SWG appliances, it inspects the traffic those defences pass as clean.
- 02
Detonate
The signature-less MVX engine detonates suspicious files, objects, and URLs in a safe virtual environment for a definitive verdict.
- 03
Correlate
Machine-learning and correlation engines and the SmartVision analytics engine detect obfuscated, targeted, and lateral-movement attacks.
- 04
Validate
MVX validates alerts from conventional signature matching and applies riskware categorisation to prioritise genuine breaches.
- 05
Respond
Inline blocking stops attacks, and correlation with Email Security, Network Forensics, and Endpoint Security coordinates containment.
Capabilities
Key capabilities
MVX Engine
A signature-less, dynamic analysis engine detonates suspicious traffic in a safe virtual environment to catch zero-day, multiflow, and evasive attacks that signature- and policy-based defences never see.
ML Correlation Engines
Multiple machine-learning, AI, and correlation engines detect obfuscated and targeted attacks using contextual rules from front-line incident response — covering client-side, server-side, lateral movement, and post-exploitation traffic.
SmartVision Lateral-Movement Detection
Detects suspicious east-west traffic from the data centre to remote branches, with data-exfiltration detection, JA3 encrypted-communication identification, web shell detection, and full kill-chain coverage.
Alert Validation
MVX validates alerts raised by conventional signature matching and applies riskware categorisation, so genuine breach attempts are separated from adware and spyware and triaged first.
Built-In TLS 1.3 Decryption
Optional TLS 1.3 decryption is available on appliances with no additional licence fee, giving visibility into encrypted traffic without a separate purchase.
Flexible Deployment Modes
Out-of-band TAP/SPAN monitoring, inline monitoring, inline active blocking, or out-of-band TCP resets — plus active high-availability on selected models for network or device failure.
Distributed MVX Architecture
Integrated all-in-one appliances or distributed Smart Nodes with a shared MVX Smart Grid or Trellix Cloud MVX, scaling from one node to thousands with N+1 fault tolerance.
Portfolio Correlation
Central Management correlates with Email Security, Network Forensics adds packet capture per alert, and Endpoint Security contains the endpoints Network Security flags.
Specifications
Technical detail
- Prevention Throughput
- 250 Mbps to 10 Gbps inline blocking
- Integrated Appliances
- 50 Mbps to 5 Gbps
- Physical Smart Node
- 50 Mbps to 10 Gbps
- Virtual / Public Cloud
- 50 Mbps to 8 Gbps (AWS and Azure)
- File Type Analysis
- 160+ file types; up to 3,300 unique attachments/hour
- Certifications
- Common Criteria, FIPS 140-2, SOC 2, US DHS SAFETY Act
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix Network Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01We already have a next-gen firewall and IPS — why add this?
Network Security is designed to sit behind exactly those and catch what they miss. Firewalls and signature-based IPS stop known attacks; the MVX sandbox catches never-before-seen exploits and evasive malware by detonating suspicious traffic in a virtual environment. It is a different detection method, not a duplicate.
02Does it require agents or heavy tuning to deploy?
The integrated appliance is clientless and deploys quickly without rules, policies, or tuning to get started. That is one reason it suits organisations that want strong detection without standing up a large operations effort — which Faltrox then runs on top of.
03Can it catch attackers already inside the network?
Yes — the SmartVision engine is built for east-west, server-facing traffic, detecting lateral movement, data exfiltration, and web shells from the data centre out to branch offices, with full kill-chain coverage mapped to MITRE ATT&CK.
04How does it handle encrypted traffic?
It offers built-in TLS 1.3 decryption on appliances with no additional licence fee, and JA3 detection in SmartVision for identifying malicious encrypted communication without full decryption.
05Can we start small and grow without re-buying?
Yes. It supports cost-free migration from an integrated to a distributed deployment, and the shared MVX Smart Grid or Cloud MVX scales from a single node to thousands, so growth in branches or traffic does not mean replacing what you own.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us