SecondSight
Human threat hunters working the gray space your automated tools ignore.
Automated tools are good at surfacing weak signals but bad at judging intent — and attackers deliberately hide in the noise of legitimate admin activity. Trellix SecondSight is a premier threat hunting service where elite human hunters investigate the low-confidence "gray space" in your Trellix endpoint, network, or email telemetry. It is a force multiplier for your SOC, and it dovetails with how Faltrox runs your defence.
Overview
What SecondSight is
Trellix SecondSight is a premier threat hunting service where elite human hunters investigate the low-confidence "gray space" in your Trellix telemetry. Automated tools are good at surfacing weak signals but bad at judging intent — and attackers deliberately hide in the noise of legitimate administrative activity. SecondSight applies human judgement to that gray space to confirm whether a behaviour is admin activity or an active breach.
It covers endpoint, network, and email telemetry across Trellix EDR, NDR, and Email Security – Cloud. The Core tier, included with those products, delivers proactive alerts; the Enterprise tier adds custom and validation hunts you direct, front-of-line priority, and weekly reporting. It is a force multiplier for your SOC, not a replacement — and it dovetails with how Faltrox runs your defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Endpoint Telemetry
Hunters work the specialised signals from Trellix EDR to find active endpoint breaches.
Network Telemetry
Coverage extends to Trellix NDR telemetry, following the attacker across the network.
Email Telemetry
Trellix Email Security – Cloud telemetry is hunted for the email-borne stages of an attack.
Gray-Space Signals
Investigates the low-confidence signals that surface but never trigger a critical alert.
Admin-Activity Cover
Distinguishes genuine sophisticated intrusions from the legitimate admin activity attackers hide in.
Remediation Validation
Validation hunts confirm a remediation was 100% successful — that the attacker is truly gone.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Ingest
Hunters use the specialised telemetry from your Trellix EDR, NDR, and Email Security products as the catalyst for investigation.
- 02
Hunt
They dive into the low-confidence gray space of that telemetry — signals that never rise to a critical alert.
- 03
Confirm Intent
Human knowledge is applied to the data to determine whether a behaviour is an active, sophisticated breach or benign admin activity.
- 04
Task
Enterprise engagements direct four custom hunts and four validation hunts per quarter against specific concerns.
- 05
Report
Proactive alerts fire on discovered threats, with front-of-line prioritisation and weekly activity reports at the Enterprise tier.
Capabilities
Key capabilities
Gray-Space Hunting
Hunters dive into the low-confidence signals that surface but never trigger a critical alert, applying human judgement to confirm whether a behaviour is admin activity or an active breach.
Human-in-the-Loop
A "second set of eyes" on your product telemetry, running in parallel to your analysts so subtle, sophisticated movements do not slip past automated filters as background noise.
Multi-Product Coverage
Specialised hunting expertise across Trellix EDR, NDR, and Email Security – Cloud, so the service follows the attacker across endpoint, network, and email telemetry.
Custom Hunts
The Enterprise tier lets you task hunters with four custom hunts per quarter to investigate specific concerns within your telemetry — directed defence rather than passive monitoring.
Validation Hunts
Four validation hunts per quarter confirm a remediation effort was 100% successful, closing the "did we actually get all of it?" question that dogs incident cleanup.
Front-of-Line Priority
Enterprise engagements get prioritised, front-of-line investigations and notifications, so the highest-stakes concerns are worked first.
Proactive Notification
The Core tier, included with EDR, Email Security – Cloud, and NDR, delivers proactive alerts on the discovery of threats found through hunting.
Weekly Reporting
Enterprise engagements include weekly activity reports, so the hunting work is visible and auditable rather than a black box.
Specifications
Technical detail
- Core Tier
- Included with Trellix EDR, Email Security – Cloud, and/or NDR
- Enterprise Tier
- Annual subscription / add-on
- Custom Hunts
- Four requests per quarter (Enterprise)
- Validation Hunts
- Four requests per quarter (Enterprise)
- Reporting
- Weekly activity reports (Enterprise)
Works with
Part of the platform
Trellix products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Trellix SecondSight for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Does this replace our SOC?
No — it is explicitly a force multiplier, not a replacement. Your analysts keep managing and monitoring the environment; SecondSight hunters work in parallel as a second set of eyes on the telemetry, focused on the sophisticated gray-space activity that automated monitoring is not built to interpret.
02What is the "gray space" it hunts in?
The low-confidence signals your Trellix products generate that never rise to a critical alert — the noise attackers deliberately hide inside legitimate administrative activity. Automated filters often surface these signals but cannot judge intent; human hunters can.
03What is the difference between the Core and Enterprise tiers?
Core is included with EDR, Email Security – Cloud, and NDR and gives proactive alerts on discovered threats. Enterprise is a subscription that adds four custom hunts and four validation hunts per quarter, front-of-line prioritisation, and weekly reporting — so you can direct the hunting.
04What is a validation hunt?
A hunt tasked specifically to confirm that a remediation was completely successful — that the attacker is genuinely gone rather than dormant. It answers the hardest question in incident response, which is knowing when an incident is actually over.
05How does this fit a Faltrox managed engagement?
It complements our SOC work: where our team runs day-to-day detection and response, SecondSight adds Trellix’s own specialist hunters against your telemetry. We coordinate the tasking so custom and validation hunts target the concerns that matter for your environment.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us