Email Security - Server (EX) 10.0.2 Release Notes

Prev Next

New features and changes

This section describes new features in the Trellix Email Security - Server release 10.0.2

  • Introduced new virtual integrated EX appliance on VMWare infrastructure

    Users can utilize the existing infrastructure to run a virtual integrated EX appliance on VMware for advanced threat detection without the need for additional hardware procurement or reliance on cloud-based services like AWS.

  • Email remediation on On-premise Exchange server

    The retroactive remediation feature is enhanced. You can now remediate emails on On-premise Exchange servers allowing for the quarantine or deletion of emails marked as malicious from retro detection alerts.

  • QR code extraction extended to Doc/Docx files

    EX supports URL extractions and analyses from QR codes for DOC and DOCX.

  • Domain wise email analysis and submission statistics summary

    Adds domain filter to message detection and analysis data. This release has only CLI support for this feature.

  • WebUI support to add hash/URL/sha256sum for block list and allow lists

    You can now add hash/URL/sha256sum for block list and allow lists using the Web UI.

  • Data streaming functionality extended to sensors

    You can now use the EX sensors in integrated mode to stream submission metadata to the servers such as Splunk or Helix.

    You can configure the EX sensor to send the submission to MVX for initial analysis. Post-analysis, MVX will send back the submission details to the EX sensor. The EX sensor can then stream the required data to the third-party servers.

  • Improved Email Campaign detection (ECD)

    Improved campaign detection algorithm based on how the user views the email that captures all its properties. This algorithm is also language agnostic and works with all the languages including English. In addition to campaign detection, email screenshots are included in the artifacts for malicious emails.

  • Increased quarantine folder max size to 250 GB

    The quarantine folder size can now be increased from default 50GB to a maximum of 250GB using CLI and Web UI.

General enhancement:

  • EX is enhanced to display both Filename or file path in rsyslogs and populate them in respective field. Earlier, it was UUID populated in filename and file path fields.

  • A new CLI has been introduced to configure alert retention period and deletion cron execution time.

  • A new CLI to search intel feed like hash/url/md5 has been introduced.

  • Triage bundle and Log archive password has been changed to "Trellix Customer Support Archive".

  • HTM file type is now enabled by default for pre-filtering. The CLI to disable it: no filter-analysis filetype htm enable.

New, modified, or deprecated CLI commands

New commands

  • Use the following CLI to search for intel feeds like hash/url/md5:

    • show analysis intel url <url> — Display Intel information for URL.

    • show analysis intel sha256 <sha265> — Display Intel information for sha256.

    • show analysis intel md5 <mdsum> — Display Intel information for md5.

  • Use the following CLIs to obtain domain wise Email analysis and submission statistics summary:

    • show email-analysis statistics details — Dumps URL/attachment across all domains.

    • show email-analysis statistics domain — Dumps show summary for each domain.

    • show email-analysis statistics domain domain_name — Dumps show summary for a given domain.

    • show email-analysis statistics domain domain_name details — Dumps all we have for a given domain, including attachments/URL stats.

  • Alert retention period and deletion cron execution time CLIs:

    • fedb data-retention alert duration-days <1 - 3650> — Configures Fedb data retention duration (in days).

    • fedb data-retention alert schedule-time <00-23:00-59>— Configures Fedb data retention schedule time (HH:MM).

    • show fedb data-retention alert configuration — View the data retention duration and purge schedule.

  • Use the following commands to configure Exchange On-prem remediation:

    Note

    Ensure that the MS Exchange user on your Exchange Server has been granted "Full Access" permission to all inboxes.

    • email-analysis remediation enable — Enables the remediation for Exchange On-prem users.

    • email-analysis remediation exchange config server <server IP> — Use this CLI command to configure the Exchange On-prem server.

    • email-analysis remediation exchange config username <username> password <password> — Use this CLI command to configure the username and password of Exchange server.

    • email-analysis remediation policy {pull | quarantine} — Use this CLI command to configure an automatic remediation policy for retroactively detected malicious email.

    • email-analysis remediation queue-id <queue-id> — Use this CLI command to add submission for manual remediation.

    • show email-analysis remediation — Verify the configuration for Exchange remediation.

    • email-analysis remediation mode exchange — Use this CLI command to set the mode to Exchange for remediation.

    • email-analysis remediation mode cloud — Use this CLI command to set the mode to Cloud for remediation.

  • Improved Email Campaign Detection CLIs:

    • ecd enable — Enable ecd feature.

    • no ecd enable — Disable ecd feature.

    • show ecd status—Show if ecd is running or not.

    • ecd campaign-lifetime <1 - 60> days — Set the number of days the email campaigns are visible from the WEBUI.

    • ecd max-active-campaigns <0 - 100> — Set number of active campaigns.

    • ecd max-email-lookback <3 - 90> — Set the email look back limit. This value determines how far to look back when considering mails for a campaign.

    • ecd recluster-interval <600 - 3600> seconds — Set the DB poll period.

  • Use the following CLIs to enable inline html analysis:

    • email-analysis policy inline-html-extraction enable — Enables policy inline html extraction analysis.

    • no email-analysis policy inline-html-extraction enable — Disables policy inline html extraction analysis.

Deprecated commands
  • O365 Remediation CLIs — Replaced by email-analysis remediation CLIs instead.

  • email-analysis o365 remediation enable

  • email-analysis o365 remediation policy {pull | quarantine

Resolved Issues

The following issues were resolved in the Email Security - Server 10.0.2 release.

Tracking Number

Summary

CMS-17212

Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted.

COM-62368

Fixes an issue where adding a root CA was failing in rare cases.

COM-62263

Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes.

COM-62177

Fixes an issue where the EX appliance was trying to reach 8.8.8.8 through the IP which was not configured as DNS Server.

COM-62169

Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx.

COM-62147

Fixes an issue where searching emails on the Web UI did not honor hours:min, only date.

COM-31673

Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx.

COM-31326

Fixes an issue with Mgmtd md_cert not accepting certificate bundle from the Web UI when MS-DOS <CR><LF> are present in the bundle file.

EMPS-17694

Fixes an issue with EX appliance displaying submission spikes and time-outs related to email with .htm submission file-type when the appliance was upgraded to 10.0.1.

EMPS-17675

Fixes an issue where EX appliance displayed an error "Request failed with status code 500" when the user tried to view a riskware quarantined email on the Alerts details page.

EMPS-17643

Fixes an issue where EX displayed the timezone as GMT even after configuring the timezone to UTC.

EMPS-17631

Source and source type can be skipped when reloading fqdn.

EMPS-17561

The download limit of 16kb for emails downloaded from Email Quarantine UI has been removed.

EMPS-17537

Fixes an issue that allows the user to configure max-size/buffer-size/output-type for rsyslog protocol.

EMPS-17272

Fixes an issue where the url field for riskware object was still showing http instead of hxxp in downloaded report.

EMPS-16677

Fixes an issue where "Download Email" is saved as queue ID of email instead as email.txt.

WEBUI-14981

Fixes an issue where Email Hourly Stat report should display the Total Duplicate in a more better way.

WEBUI-14972

The Allow option in the Settings > 3rd Party Feeds tab is enabled.

WEBUI-14371

Fixes an issue with the View Email window in the Email Quarantine tab having misalignment issues.

Known issues

The following issues are known in the Email Security - Server 10.0.2 release.

Tracking number

Summary

COM-30656

The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list.

COM-30655

During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration.

Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution.

COM-31165

The GI settings API does not currently enforce a limit of 10 inputs for a field.

EMPS-17820

The data entered in the Advanced Rule tab during the release 10.0.2 was not retained when the EX appliance was downgraded to the release 10.0.1.

EMPS-17781

Forward email list is empty for Exchange Remediation in 'the View Email page.

EMPS-17780

A mismatch of the remediation status is observed for deleted email in View Email tab for Exchange Remediation.

EMPS-17729

Remediation of emails sent to distribution lists or aliases is not supported.

EMPS-17745

Inconsistency output are generated when duplicate values of mdsum/sha256/url are added from Web UI and CLI for allowed and blocked list.

EMPS-17730

Under eAlerts > Riskware > Alert Details page, the filename field is missing.

EMPS-17220

There could be websocket connection breaks between the headless chrome and python library due to issues with headless chrome. This will be reconciled automatically and connection would be reestablished.

EMPS-17213

On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments.

EMPS-17700

The EX appliance displays the following error "Application server error occurred" after running the command "system cleanup profile temp-files all".

WEBUI-29828

In the Email Quarantine tab, Badges option check boxes are greyed out in light mode.

WEBUI-29818

A loading indicator/Icon should be displayed on the 3rd party feeds to avoid any confusions if the data is available or not in the Allowed/Blocked list.

WEBUI-15060

In the About > Create Log Archive page, logs are not displayed instantly after the success message. It requires a refresh of the UI to display them.

WEBUI-14979

The Service Health Statistics Trend displays incorrect date and time for week and month.

WEBUI-14964

Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI.

Disable SAML in a Helix environment

SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.

For more information, see the Helix Integration Guide for Trellix devices.

  • In the Software Requirements section, see “HelixConnect Client Software Requirements”.

  • In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.

Upgrade support

The Trellix Email Security - Server 10.0.2 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 10.0.2 from release 9.0.0 or later.

After an upgrade to version 10.0.2, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

Created Log archive files will not be preserved on upgrade to 10.0.2. Please have a backup of logs before upgrade.

Important

When you upgrade an Email Security appliance to 10.0.2, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the

Email Security — Server Edition User Guide

.

Note

After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Email Security - Server 10.0.2 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

The EX 3500 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)

For detailed instructions about upgrading IPMI, see the System Administration Guide.

To upgrade IPMI to version 3.11:

Note

IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.

Do not shut down or remove power from the appliance during the upgrade.

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # ipmi firmware update latest

  3. Confirm the upgrade:

    hostname (config) # show ipmi

If the upgrade fails, try the steps again.

If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:

  1. Stop the reload process:

    hostname (config) # reload halt

  2. Disconnect all power cables for 2 minutes.

  3. After 2 minutes, reconnect power cables and restart the appliance.

To upgrade the BIOS to version 1.9:

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # system bios firmware update latest

    Note

    Do not shut down or remove power from the appliance during the upgrade.

  3. Confirm the upgrade:

    hostname (config) # show system bios

  4. Stop the reload process:

    hostname (config) # reload halt

  5. Disconnect all power cables for 2 minutes.

  6. After 2 minutes, reconnect power cables and restart the appliance.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Email Security - Server appliance to the 10.0.2 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.