The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Conduct searches

Prev Next

EDRF allows you to query endpoint and enterprise data to investigate threats, validate security posture, and support forensic analysis. Depending on the type of search, you can retrieve data in real time, review historical records, or search across the enterprise for specific artifacts.

The search options include:

  • Real-time Search — Collects live data from endpoints. Use this when you need current information, such as active processes, registry values, or network connections.

  • Historical Search — Queries data that has already been collected and stored in the EDRF repository. This search is useful for analyzing past activity and correlating events over time.

  • Device Search — Searches for a specific endpoint by attributes such as hostname, IP address, or user. Use this option to quickly isolate or investigate a single endpoint.

  • Enterprise Search — Runs searches across the entire enterprise to identify the presence of files, processes, or indicators of compromise (IOCs) on multiple endpoints.