Adaptive security requires monitoring of all threat vectors, including fast, accurate assessments of potential cyber attacks tracked to endpoint activity. The Trellix Endpoint Security (HX) product allows you to detect, analyze, and respond to targeted cyber attacks and zero-day exploits on the endpoint.
Note
In this guide, you will see the Endpoint Security (HX) server and DMZ server referred to as an Endpoint Security (HX) appliance or HXD appliance, respectively. These terms refer to the same products.
Using Endpoint Security (HX) servers, you can continuously monitor endpoints for advanced malware and indicators of compromise (IOCs) that routinely bypass signature-based and defense-in-depth security systems. The Endpoint Security (HX) servers and DMZ servers allow you to:
Search for advanced attackers and advanced persistent threats (APTs)
Investigate alerts from network devices, automatically creating IOCs and alerting users
Extend Trellix detection services seamlessly to your endpoints
Use Agent Anywhere technology to analyze remote endpoints outside the corporate network, regardless of their Internet connection type
Acquire files, data, and triage collections from endpoints and analyze these collections
Confirm whether alerts seen on the network actually compromise endpoints
Contain endpoints, isolating devices when they become compromised
This chapter covers the following topics: