Trellix EDRF provides two distinct historical search features depending on the deployment environment:
Historical Search for EDRF Cloud: Access from the EDR user interface via the Monitoring and Device Search dashboards.
Historical Search for EDRF On-Prem: Use the Historical Search Module, which is installed on the Endpoint Security (HX) server.
The Historical Search capability enables analysts to investigate past endpoint activity and perform detailed forensic searches across managed endpoints within an on-premises environment. It is deployed as a module on the Endpoint Security (HX) On-prem server and utilizes the telemetry data collected from endpoints running EDRF.
The feature queries a centralized EDR Telemetry Store that continuously receives endpoint telemetry through the Data Exchange Layer (DXL) and ePolicy Orchestrator (ePO). This capability allows security teams to identify hidden threats, analyze attack timelines, and understand the complete scope of an incident without affecting endpoint performance.
Key capabilities
Comprehensive telemetry collection
Continuously collects and indexes detailed endpoint telemetry such as process executions, file and registry modifications, DNS queries, and network connections. The collected data remains available even if devices are offline, reimaged, or decommissioned, ensuring complete visibility during investigations.
Centralized data storage and query execution
All telemetry is stored and indexed in the EDR Telemetry Store. Analysts can query the centralized data store directly, eliminating the need to access endpoints. This approach ensures scalability across thousands of systems and avoids performance impact on active devices.
Flexible querying and retention options
Supports extended data retention and a powerful search syntax for precise filtering and analysis. Analysts can use fields, operators, and logical expressions to narrow or expand search results. Long-term retention provides historical context, allowing investigations to track the evolution and spread of attacks.
Integrated threat hunting and validation
Enables analysts to search for hidden indicators of compromise, apply new threat intelligence to past data, and test detection logic against stored telemetry. This supports proactive threat hunting and retrospective analysis.
Efficient incident investigation and response
Accelerates investigations by correlating data from multiple endpoints to identify patterns, impacted systems, and root causes. By reducing manual correlation and investigation time, Historical Search improves mean time to detect (MTTD) and mean time to respond (MTTR), strengthening the overall SOC workflow.