Adaptive security requires real-time monitoring of all threat vectors, including fast, accurate assessments of potential cyber attacks tracked to endpoint activity. Endpoint Security (HX) xAgents protect your networks by monitoring each endpoint device or host, collecting real-time data of events occurring on the endpoint, and identifying threat activity and evidence on the host. Threat activity and evidence include:
Unauthorized use of valid accounts
Trace evidence and partial files
Command and control activity
Known and unknown malware
Suspicious network traffic
Valid programs used for malicious purposes
Unauthorized file access
Exploits and other online attacks (found using xAgent Exploit Guard functionality)
Commodity malware (found using xAgent malware protection functionality)
When the xAgent finds evidence of potential compromises, it reports this information to the Endpoint Security server. It also retrieves information and tasks (jobs) from the Endpoint Security (HX) server and performs them. Tasks include upgrading indicators of compromise, requests for forensic information (file, triage, and data requests), and requests to contain the host endpoint.
You can provision an Endpoint Security (HX) xAgent to an on-premises, virtual, or cloud Endpoint Security server. For more information about provisioning, installing, or uninstalling the xAgent, see the Endpoint Security Agent (HX) Deployment Guide.
This guide covers administration of Endpoint Security (HX) xAgent. This section summarizes the following agent features:
Note
Endpoint Security (HX) xAgent will still function if disconnected from a Trellix Endpoint Security (HX) server but still running on an endpoint. However, the content will not update, and no alerts will appear in the Endpoint Security (HX) controller.