About the Endpoint Security (HX) server

Prev Next

Adaptive security requires monitoring of all threat vectors, including fast, accurate assessments of potential cyber attacks tracked to endpoint activity. The Trellix Endpoint Security (HX) product allows you to detect, analyze, and respond to targeted cyber attacks and zero-day exploits on the endpoint.

Note

In this guide, you will see the Endpoint Security (HX) server and DMZ server referred to as an Endpoint Security (HX) appliance or HXD appliance, respectively. These terms refer to the same products.

Using Endpoint Security (HX) servers, you can continuously monitor endpoints for advanced malware and indicators of compromise (IOCs) that routinely bypass signature-based and defense-in-depth security systems. The Endpoint Security (HX) servers and DMZ servers allow you to:

  • Search for advanced attackers and advanced persistent threats (APTs)

  • Investigate alerts from network devices, automatically creating IOCs and alerting users

  • Extend Trellix detection services seamlessly to your endpoints

  • Use Agent Anywhere technology to analyze remote endpoints outside the corporate network, regardless of their Internet connection type

  • Acquire files, data, and triage collections from endpoints and analyze these collections

  • Confirm whether alerts seen on the network actually compromise endpoints

  • Contain endpoints, isolating devices when they become compromised

This chapter covers the following topics: