New features and changes
This section describes new features in the Trellix Email Security - Server release 10.0.2
Introduced new virtual integrated EX appliance on VMWare infrastructure
Users can utilize the existing infrastructure to run a virtual integrated EX appliance on VMware for advanced threat detection without the need for additional hardware procurement or reliance on cloud-based services like AWS.
Email remediation on On-premise Exchange server
The retroactive remediation feature is enhanced. You can now remediate emails on On-premise Exchange servers allowing for the quarantine or deletion of emails marked as malicious from retro detection alerts.
QR code extraction extended to Doc/Docx files
EX supports URL extractions and analyses from QR codes for DOC and DOCX.
Domain wise email analysis and submission statistics summary
Adds domain filter to message detection and analysis data. This release has only CLI support for this feature.
WebUI support to add hash/URL/sha256sum for block list and allow lists
You can now add hash/URL/sha256sum for block list and allow lists using the Web UI.
Data streaming functionality extended to sensors
You can now use the EX sensors in integrated mode to stream submission metadata to the servers such as Splunk or Helix.
You can configure the EX sensor to send the submission to MVX for initial analysis. Post-analysis, MVX will send back the submission details to the EX sensor. The EX sensor can then stream the required data to the third-party servers.
Improved Email Campaign detection (ECD)
Improved campaign detection algorithm based on how the user views the email that captures all its properties. This algorithm is also language agnostic and works with all the languages including English. In addition to campaign detection, email screenshots are included in the artifacts for malicious emails.
Increased quarantine folder max size to 250 GB
The quarantine folder size can now be increased from default 50GB to a maximum of 250GB using CLI and Web UI.
General enhancement:
EX is enhanced to display both Filename or file path in rsyslogs and populate them in respective field. Earlier, it was UUID populated in filename and file path fields.
A new CLI has been introduced to configure alert retention period and deletion cron execution time.
A new CLI to search intel feed like hash/url/md5 has been introduced.
Triage bundle and Log archive password has been changed to "Trellix Customer Support Archive".
HTM file type is now enabled by default for pre-filtering. The CLI to disable it:
no filter-analysis filetype htm enable.
New, modified, or deprecated CLI commands
New commands
Use the following CLI to search for intel feeds like hash/url/md5:
show analysis intel url <url>— Display Intel information for URL.show analysis intel sha256 <sha265>— Display Intel information for sha256.show analysis intel md5 <mdsum>— Display Intel information for md5.
Use the following CLIs to obtain domain wise Email analysis and submission statistics summary:
show email-analysis statistics details— Dumps URL/attachment across all domains.show email-analysis statistics domain— Dumps show summary for each domain.show email-analysis statistics domain domain_name— Dumps show summary for a given domain.show email-analysis statistics domain domain_name details— Dumps all we have for a given domain, including attachments/URL stats.
Alert retention period and deletion cron execution time CLIs:
fedb data-retention alert duration-days <1 - 3650>— Configures Fedb data retention duration (in days).fedb data-retention alert schedule-time <00-23:00-59>— Configures Fedb data retention schedule time (HH:MM).show fedb data-retention alert configuration— View the data retention duration and purge schedule.
Use the following commands to configure Exchange On-prem remediation:
Note
Ensure that the MS Exchange user on your Exchange Server has been granted "Full Access" permission to all inboxes.
email-analysis remediation enable— Enables the remediation for Exchange On-prem users.email-analysis remediation exchange config server <server IP>— Use this CLI command to configure the Exchange On-prem server.email-analysis remediation exchange config username <username> password <password>— Use this CLI command to configure the username and password of Exchange server.email-analysis remediation policy {pull | quarantine}— Use this CLI command to configure an automatic remediation policy for retroactively detected malicious email.email-analysis remediation queue-id <queue-id>— Use this CLI command to add submission for manual remediation.show email-analysis remediation— Verify the configuration for Exchange remediation.email-analysis remediation mode exchange— Use this CLI command to set the mode to Exchange for remediation.email-analysis remediation mode cloud— Use this CLI command to set the mode to Cloud for remediation.
Improved Email Campaign Detection CLIs:
ecd enable— Enable ecd feature.no ecd enable— Disable ecd feature.show ecd status—Show if ecd is running or not.ecd campaign-lifetime <1 - 60> days— Set the number of days the email campaigns are visible from the WEBUI.ecd max-active-campaigns <0 - 100>— Set number of active campaigns.ecd max-email-lookback <3 - 90>— Set the email look back limit. This value determines how far to look back when considering mails for a campaign.ecd recluster-interval <600 - 3600> seconds— Set the DB poll period.
Use the following CLIs to enable inline html analysis:
email-analysis policy inline-html-extraction enable— Enables policy inline html extraction analysis.no email-analysis policy inline-html-extraction enable— Disables policy inline html extraction analysis.
Deprecated commands
O365 Remediation CLIs — Replaced by
email-analysis remediationCLIs instead.email-analysis o365 remediation enableemail-analysis o365 remediation policy {pull | quarantine
Resolved Issues
The following issues were resolved in the Email Security - Server 10.0.2 release.
Tracking Number | Summary |
|---|---|
CMS-17212 | Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted. |
COM-62368 | Fixes an issue where adding a root CA was failing in rare cases. |
COM-62263 | Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes. |
COM-62177 | Fixes an issue where the EX appliance was trying to reach 8.8.8.8 through the IP which was not configured as DNS Server. |
COM-62169 | Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx. |
COM-62147 | Fixes an issue where searching emails on the Web UI did not honor hours:min, only date. |
COM-31673 | Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx. |
COM-31326 | Fixes an issue with Mgmtd md_cert not accepting certificate bundle from the Web UI when MS-DOS <CR><LF> are present in the bundle file. |
EMPS-17694 | Fixes an issue with EX appliance displaying submission spikes and time-outs related to email with .htm submission file-type when the appliance was upgraded to 10.0.1. |
EMPS-17675 | Fixes an issue where EX appliance displayed an error "Request failed with status code 500" when the user tried to view a riskware quarantined email on the Alerts details page. |
EMPS-17643 | Fixes an issue where EX displayed the timezone as GMT even after configuring the timezone to UTC. |
EMPS-17631 | Source and source type can be skipped when reloading fqdn. |
EMPS-17561 | The download limit of 16kb for emails downloaded from Email Quarantine UI has been removed. |
EMPS-17537 | Fixes an issue that allows the user to configure max-size/buffer-size/output-type for rsyslog protocol. |
EMPS-17272 | Fixes an issue where the url field for riskware object was still showing http instead of hxxp in downloaded report. |
EMPS-16677 | Fixes an issue where "Download Email" is saved as queue ID of email instead as email.txt. |
WEBUI-14981 | Fixes an issue where Email Hourly Stat report should display the Total Duplicate in a more better way. |
WEBUI-14972 | The Allow option in the Settings > 3rd Party Feeds tab is enabled. |
WEBUI-14371 | Fixes an issue with the View Email window in the Email Quarantine tab having misalignment issues. |
Known issues
The following issues are known in the Email Security - Server 10.0.2 release.
Tracking number | Summary |
|---|---|
COM-30656 | The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list. |
COM-30655 | During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration. Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution. |
COM-31165 | The GI settings API does not currently enforce a limit of 10 inputs for a field. |
EMPS-17820 | The data entered in the Advanced Rule tab during the release 10.0.2 was not retained when the EX appliance was downgraded to the release 10.0.1. |
EMPS-17781 | Forward email list is empty for Exchange Remediation in 'the View Email page. |
EMPS-17780 | A mismatch of the remediation status is observed for deleted email in View Email tab for Exchange Remediation. |
EMPS-17729 | Remediation of emails sent to distribution lists or aliases is not supported. |
EMPS-17745 | Inconsistency output are generated when duplicate values of mdsum/sha256/url are added from Web UI and CLI for allowed and blocked list. |
EMPS-17730 | Under eAlerts > Riskware > Alert Details page, the filename field is missing. |
EMPS-17220 | There could be websocket connection breaks between the headless chrome and python library due to issues with headless chrome. This will be reconciled automatically and connection would be reestablished. |
EMPS-17213 | On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments. |
EMPS-17700 | The EX appliance displays the following error "Application server error occurred" after running the command "system cleanup profile temp-files all". |
WEBUI-29828 | In the Email Quarantine tab, Badges option check boxes are greyed out in light mode. |
WEBUI-29818 | A loading indicator/Icon should be displayed on the 3rd party feeds to avoid any confusions if the data is available or not in the Allowed/Blocked list. |
WEBUI-15060 | In the About > Create Log Archive page, logs are not displayed instantly after the success message. It requires a refresh of the UI to display them. |
WEBUI-14979 | The Service Health Statistics Trend displays incorrect date and time for week and month. |
WEBUI-14964 | Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI. |
Disable SAML in a Helix environment
SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.
For more information, see the Helix Integration Guide for Trellix devices.
In the Software Requirements section, see “HelixConnect Client Software Requirements”.
In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.
Upgrade support
The Trellix Email Security - Server 10.0.2 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 10.0.2 from release 9.0.0 or later.
After an upgrade to version 10.0.2, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
Created Log archive files will not be preserved on upgrade to 10.0.2. Please have a backup of logs before upgrade.
Important
When you upgrade an Email Security appliance to 10.0.2, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the
Email Security — Server Edition User Guide
.
Note
After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.
Downloading content from the DTI offline update portal
If you download Email Security - Server 10.0.2 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms
The EX 3500 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)
For detailed instructions about upgrading IPMI, see the System Administration Guide.
To upgrade IPMI to version 3.11:
Note
IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.
Do not shut down or remove power from the appliance during the upgrade.
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
ipmi firmware update latestConfirm the upgrade:
hostname (config) #
show ipmi
If the upgrade fails, try the steps again.
If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:
Stop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
To upgrade the BIOS to version 1.9:
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
system bios firmware update latestNote
Do not shut down or remove power from the appliance during the upgrade.
Confirm the upgrade:
hostname (config) #
show system biosStop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
YARA rules supported versions
YARA rules support version 4.3.2.
Important
Before you upgrade an Email Security - Server appliance to the 10.0.2 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.