> For the complete documentation index, see [llms.txt](https://sirogy.gitbook.io/trellix-epolicy-orchestrator-on-prem-5.1/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sirogy.gitbook.io/trellix-epolicy-orchestrator-on-prem-5.1/product-overview/epo-overview/how-it-works.md).

# How it Works

rellix security software and ePO work together to stop malware attacks on your systems and notify you when they occur. During an attack, ePO components and processes stop an attack, notify you when it occurs, and record the incident.

Click on the numbers below to see what happens during an attack.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FABGfbQY55ZRYRR3k52rg%2Fimage.png?alt=media&amp;token=aca0cfa9-0a8b-4c84-9936-dd56f5dc3fc9" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FHbos2yh3k3avYMrL7GBV%2Fimage.png?alt=media&amp;token=73dce2bc-ae32-4f8e-ba0b-5b85f7fae24c" alt=""><figcaption></figcaption></figure>
