The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Module overview

Prev Next

The Forensics Bridge module is a Trellix Endpoint Security Agent (HX) module responsible for routing alerts to Trellix EDR and Trellix ePO. The supported alerts are Logon Tracker, AMSI, and IOC. For each alert type, routing can be configured on Endpoint Security Agent (HX) for Trellix EDR and Trellix ePO using the policy configuration.

You can analyze and investigate the Agent (HX) data consisting of IOC, Logon Tracker, and AMSI alerts in Trellix EDR and Trellix ePO consoles to contain and remediate threats. For more information, see Analyze the Trellix Endpoint Forensics Bridge or Agent (HX) data.

The Forensics Bridge module is installed on the Endpoint Security (HX) server. This module includes a server portion and a client portion. The server side is tasked with establishing a secure content metadata channel and facilitating the configuration for endpoint client policies. The server side also includes configuration to set the extent of logging of its operation. The client segment is installed on computers within a specified host set upon the implementation of a policy that activates Forensics Bridge module. While in this active state, the Forensics Bridge client code subscribes to the security content metadata channel. It examines data transmitted through the alerter and message bus services. The client code maps the event data to ePO and/or EDR and adds relevant security content metadata.