TrellixThreat Intelligence

    SecondSight

    Human threat hunters working the gray space your automated tools ignore.

    Automated tools are good at surfacing weak signals but bad at judging intent — and attackers deliberately hide in the noise of legitimate admin activity. Trellix SecondSight is a premier threat hunting service where elite human hunters investigate the low-confidence "gray space" in your Trellix endpoint, network, or email telemetry. It is a force multiplier for your SOC, and it dovetails with how Faltrox runs your defence.

    Overview

    What SecondSight is

    Trellix SecondSight is a premier threat hunting service where elite human hunters investigate the low-confidence "gray space" in your Trellix telemetry. Automated tools are good at surfacing weak signals but bad at judging intent — and attackers deliberately hide in the noise of legitimate administrative activity. SecondSight applies human judgement to that gray space to confirm whether a behaviour is admin activity or an active breach.

    It covers endpoint, network, and email telemetry across Trellix EDR, NDR, and Email Security – Cloud. The Core tier, included with those products, delivers proactive alerts; the Enterprise tier adds custom and validation hunts you direct, front-of-line priority, and weekly reporting. It is a force multiplier for your SOC, not a replacement — and it dovetails with how Faltrox runs your defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Endpoint Telemetry

    Hunters work the specialised signals from Trellix EDR to find active endpoint breaches.

    02

    Network Telemetry

    Coverage extends to Trellix NDR telemetry, following the attacker across the network.

    03

    Email Telemetry

    Trellix Email Security – Cloud telemetry is hunted for the email-borne stages of an attack.

    04

    Gray-Space Signals

    Investigates the low-confidence signals that surface but never trigger a critical alert.

    05

    Admin-Activity Cover

    Distinguishes genuine sophisticated intrusions from the legitimate admin activity attackers hide in.

    06

    Remediation Validation

    Validation hunts confirm a remediation was 100% successful — that the attacker is truly gone.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Ingest

      Hunters use the specialised telemetry from your Trellix EDR, NDR, and Email Security products as the catalyst for investigation.

    2. 02

      Hunt

      They dive into the low-confidence gray space of that telemetry — signals that never rise to a critical alert.

    3. 03

      Confirm Intent

      Human knowledge is applied to the data to determine whether a behaviour is an active, sophisticated breach or benign admin activity.

    4. 04

      Task

      Enterprise engagements direct four custom hunts and four validation hunts per quarter against specific concerns.

    5. 05

      Report

      Proactive alerts fire on discovered threats, with front-of-line prioritisation and weekly activity reports at the Enterprise tier.

    Capabilities

    Key capabilities

    Gray-Space Hunting

    Hunters dive into the low-confidence signals that surface but never trigger a critical alert, applying human judgement to confirm whether a behaviour is admin activity or an active breach.

    Human-in-the-Loop

    A "second set of eyes" on your product telemetry, running in parallel to your analysts so subtle, sophisticated movements do not slip past automated filters as background noise.

    Multi-Product Coverage

    Specialised hunting expertise across Trellix EDR, NDR, and Email Security – Cloud, so the service follows the attacker across endpoint, network, and email telemetry.

    Custom Hunts

    The Enterprise tier lets you task hunters with four custom hunts per quarter to investigate specific concerns within your telemetry — directed defence rather than passive monitoring.

    Validation Hunts

    Four validation hunts per quarter confirm a remediation effort was 100% successful, closing the "did we actually get all of it?" question that dogs incident cleanup.

    Front-of-Line Priority

    Enterprise engagements get prioritised, front-of-line investigations and notifications, so the highest-stakes concerns are worked first.

    Proactive Notification

    The Core tier, included with EDR, Email Security – Cloud, and NDR, delivers proactive alerts on the discovery of threats found through hunting.

    Weekly Reporting

    Enterprise engagements include weekly activity reports, so the hunting work is visible and auditable rather than a black box.

    Specifications

    Technical detail

    Core Tier
    Included with Trellix EDR, Email Security – Cloud, and/or NDR
    Enterprise Tier
    Annual subscription / add-on
    Custom Hunts
    Four requests per quarter (Enterprise)
    Validation Hunts
    Four requests per quarter (Enterprise)
    Reporting
    Weekly activity reports (Enterprise)

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix SecondSight for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Does this replace our SOC?

    No — it is explicitly a force multiplier, not a replacement. Your analysts keep managing and monitoring the environment; SecondSight hunters work in parallel as a second set of eyes on the telemetry, focused on the sophisticated gray-space activity that automated monitoring is not built to interpret.

    02What is the "gray space" it hunts in?

    The low-confidence signals your Trellix products generate that never rise to a critical alert — the noise attackers deliberately hide inside legitimate administrative activity. Automated filters often surface these signals but cannot judge intent; human hunters can.

    03What is the difference between the Core and Enterprise tiers?

    Core is included with EDR, Email Security – Cloud, and NDR and gives proactive alerts on discovered threats. Enterprise is a subscription that adds four custom hunts and four validation hunts per quarter, front-of-line prioritisation, and weekly reporting — so you can direct the hunting.

    04What is a validation hunt?

    A hunt tasked specifically to confirm that a remediation was completely successful — that the attacker is genuinely gone rather than dormant. It answers the hardest question in incident response, which is knowing when an incident is actually over.

    05How does this fit a Faltrox managed engagement?

    It complements our SOC work: where our team runs day-to-day detection and response, SecondSight adds Trellix’s own specialist hunters against your telemetry. We coordinate the tasking so custom and validation hunts target the concerns that matter for your environment.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us