Trellix Attack Path Discovery (APD) is a cloud-based security solution that identifies and visualizes how attackers can reach your critical systems by correlating data from vulnerabilities, assets, identities, and configurations.
Trellix APD helps you move beyond isolated vulnerability scores by showing how individual weaknesses combine into dangerous attack chains.
Key capabilities
Automatic attack path mapping: Shows you how different security weaknesses in your environment connect to form a path that leads to your most important targets.
Contextual risk prioritization: Ranks your security risks based on technical feasibility and business impact rather than CVSS scores alone.
Real-time exposure visibility: Automatically updates your attack maps whenever your systems change, new configurations are made, or new security threats are discovered.
Integrated exposure context: Combines Trellix scan results with data from other third-party security tools to give you a single, complete view of potential attack chains.
Scoping: Allows you to focus your security analysis specifically on the systems that have the highest impact on your business.
Prerequisites
Before you begin, ensure you have the following:
Licensing: Trellix APD is available as an add-on SKU for ePO SaaS deployments. To use it, you must have one of the following base product bundles:
Trellix Endpoint Core
Trellix Endpoint Essentials
Trellix Endpoint Enterprise
Provisioning and Activation: You will receive activation emails based on your account status:
If you are a new customer, you will receive two separate activation emails (one for your Trellix ePO - SaaS account and one for your tenancy).
If you already have an active Trellix ePO - SaaS account, you will only receive the Trellix APD tenancy activation email.
System requirements: Target endpoints must run a supported version of Windows (Windows 10 or Windows 11).