Trellix Endpoint Security (HX) products include one or more Endpoint Security (HX) Server working with Endpoint Security (HX) Agents installed on each device or host in your enterprise. Working together, these products monitor each endpoint device or host and identify threat activity and evidence on them.
Adaptive security requires real-time monitoring of all threat vectors, including fast, accurate assessments of potential cyber attacks tracked to endpoint activity. The Endpoint Security (HX) xAgent allows you to detect, analyze, and respond to targeted cyber attacks and zero-day exploits on the endpoint.
In Windows environments, the Endpoint Security (HX) products can use Exploit Guard to detect and prevent exploits and other online attacks that occur during the use of Adobe products such as Reader and Flash, Java, browsers such as Microsoft Edge, Google Chrome, and Mozilla Firefox, and Microsoft Office products such as Excel, Outlook, Powerpoint, and Word.
In Windows environments, the Endpoint Security (HX) products can detect and prevent commodity malware on your host endpoints. Malware includes viruses, trojans, worms, spyware, adware, key loggers, rootkits, phishing, and other potentially unwanted programs (PUP).
The Endpoint Security (HX) Server processes alerts from Indicators of Compromise (IOC), Exploit Guard (EXG), Anti-Virus (AV) and MalwareGuard (MG). Armed with this intelligence, the Endpoint Security (HX) xAgent monitors activity on each endpoint host, collecting real-time, exploit, and malware data from events occurring on the endpoint, and identifying activity that matches the real-time indicator rules and Trellix's exploit and malware intelligence. Matches are reported to the Endpoint Security (HX) as an alert for the affected host endpoint. The server compiles the data received from the agents across the enterprise and provides a holistic view of the data in the Endpoint Security (HX) Web UI. If a potential threat is detected, analysts and administrators can use the Endpoint Security (HX) software to quickly assess the situation and, if necessary, contain hosts and neutralize the threat across the enterprise. You can also use the Endpoint Security (HX) Server to acquire and investigate detailed data from the agent. If the threat is severe enough, you can use the server to contain the agent.
Generally, all Endpoint Security (HX) tasks are processed on a first-come, first-served basis. Because the server and the agent can process tasks in parallel, however, all tasks for an individual agent are not necessarily handled in order. Containment tasks are explicitly marked as high-priority tasks and preempt any data acquisition tasks, such as Enterprise Search and data acquisition requests.
The following diagram shows the flow of information between the server and the agent:
.jpg)
Dynamic Threat Intelligence (DTI) provides security content to the Endpoint Security (HX) Server.
The server distributes that security content to the agents.
The agent compares the security content with activity contained within the event storage.
The agent regularly checks for new security content with the Endpoint Security (HX) Server.
When an agent detects an incident, the agent alerts the server.
The agent prepares a triage collection and reports back to the server with both the new alert and the auto-generated triage collection.
The server receives and processes the triage collection.