Trellix EDR allows you to continuously monitor, detect, investigate, and contain potential threats on your devices in real time.
Continuous real-time monitoring — Event information from devices is sent to the cloud providing the context and visibility needed to uncover stealthy threats. This information is available for immediate inspection and historical search.
Cloud-based analytics — Analytic engines inspect device activity to uncover a broad spectrum of suspicious behavior and detect threats that might have slipped by other security defenses. Cloud-based deployment enables rapid adoption of new analytic engines and techniques.
MITRE ATT&CK™ mapping — Behavior-based detection results map to the MITRE ATT&CK™ framework, supporting a consistent process to prioritize response by determining the phase of a threat and its associated risk.
Artificial intelligence guided investigation — Trellix EDR uses investigation guides built by combining the experience and expertise from Trellix Foundstone® forensic investigators with artificial intelligence (AI). These investigation guides force–multiply the investigation process and explore many hypotheses in parallel for maximum speed and accuracy. Investigation guides dynamically adjust to the case at hand, combining different strategies and data. Trellix EDR automatically asks and answers questions to prove or disprove the hypotheses. It automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves.
Broad data collection and local relevancy — The AI-powered investigation engine gathers and processes artifacts to make sense of alerts. These artifacts are collected from devices, security information and event management (SIEM) systems, and ePO - On-prem or ePO - SaaS. Trellix EDR compares evidence against known normal activity unique to each organization and threat intelligence sources including Global Threat Intelligence. This improves local relevancy and reduces false positives triggered against normal activity. Investigations can originate from either Trellix EDR or Security Information and Event Management (SIEM) alerts.
Flexible data display — You can toggle between different views of the same data, from graph views to table views. This enables users with different levels of experience to quickly understand how artifacts and events are connected without moving through multiple screens.
Search — In addition to guided investigation, you can use the Trellix EDR search and data collection capabilities to expand inquiries and look deeply into and across systems.
Historical search capability — Comprehensive, always-on data collection streams device event information from all monitored systems to the cloud. Analysts can search this centralized data to find indicators of compromise (IoCs) and indicators of attack (IoAs) that can be present with deleted files. You can perform the search regardless of current online or offline status of each device. The following are the historical search dashboards:
Historical Search — Introduces the capability to search historically across multiple devices.
Device Search — Introduces the capability to search historically against a specific endpoint.
Real-time search — For active incident inquiries, real-time search can quickly query for up-to-the-moment information from devices. Flexible syntax enables a range of capabilities from simple queries to more complex searches.
On-demand data collection — To support investigations, Trellix EDR can take a snapshot of a device on-demand, capturing a comprehensive view of active processes, network connections, services, and autorun entries. Enabled by a non-persistence data collection tool, snapshots can be captured on both monitored and non-monitored systems.