Trellix Email Security - Cloud 2025.1 brings infrastructure and capacity enhancements to boost overall performance and threat detection.
New features
Performance and detection have been improved through infrastructure and capacity enhancements to Trellix Email Security - Cloud 2025.1.
You can now access Email Security - Cloud on the Trellix XConsole platform.
Trellix XConsole provides a centralized and streamlined user interface that makes navigating between various Trellix products easier. You can log in once and gain access to available Trellix products such as Trellix IVX or Trellix Email Security - Cloud.
Accessing Trellix Email Security - Cloud through XConsole provides the following user experience-related features:
For more information see, Logging in using XConsole.
Product switcher: You can switch between the products you have access to, gaining you access to products within the XConsole window.
Main menu: You can use the main menu button to display the menu based on the selected product.
You can now use the Google Security Operations (Google SecOps) platform (formerly known as Chronicle) to compile security events, create reports and dashboards related to security incidents.
You need to create a Google SIEM account and integrate it with the Email Security - Cloud appliance to transfer alerts and events to the SecOps instance and analyse them using the Google Ingestion APIs.
For more details, see Google Security Operations integration.
The Trellix Wise (Beta) chat support feature is now available on the Gov instance. You can ask questions and queries related to any alert. The chat support will return relevant answers. Your chat history will be retained for 7 days.
For more details, see Advanced threat alert details in the Administration Guide.
Enhancements
You can now identify retroactive emails by seeing the newly added alert type icon, Retroactive, on the top-right of the Alerts table.
In both Alerts and Riskware pages, delivered (retroactive) emails will now have their status displayed as delivered and dropped (OOB retroactive) emails will have their status displayed as dropped (OOB).
You can still search for emails on the Email Trace page using the filter, Has retroactive alert.
For more details, see Advanced Threats and Riskware.
You can now search for emails by using the Released tag in the Email Trace page as well as the Email Trace request API.
For more details, see Email Trace Filters and Email Trace Request.
You can now select Virus and Riskware options for SMTP remediation policies under Policy actions.
For more details, see Remediation policies.
The Education page now has a mandatory placeholder for education content.
The Template design page now has two mandatory placeholders for name and URL.
In the Template design page, you can now flag phishing indicators using the Red Flag option.
For more details, see Phishing simulator.
You can now view the process graph of the email URL or attachment in the Overview section of Advanced threat alert details page.
The process graph displays the graph of the URL or attachment found in the email and processes spawned. For each spawned process, the graph displays the process ID, process name, and command line.
For more details, see Alert Details.
The new FAQ section enlists a number of questions which can help you to know the processes better. You can also rate the received answers using the Like and Dislike buttons.
You can use the Reset button to clear the existing conversation and start a new one.
The Feedback form enables you to rate the quality and accuracy of the Wise chatbot and add your suggestions.
You can also view the total and remaining quota of queries you can make daily and monthly.
For more details, see Trellix Wise (Beta).
You can now enable or disable non-mandatory policies like Advanced Threat Engine Configuration, Riskware Rules and Remediation.
You can now configure new journal rules using the Microsoft Purview platform.
For detailed steps, see Message analysis policies.
Resolved issue
Tracking number | Description |
|---|---|
ETP-70923 | Fixes an issue on the Email trace page where searching for outbound emails using local and domain parts (@domain) was not fetching any results. |