New features and changes
This section describes new features in the Trellix Email Security - Server release 11.0.0
Support OS Upgrade to Alma Linux 9.2
The Email Security - Server platform has undergone a base upgrade from CentOS 7 to Alma Linux 9.2 to ensure continuous support and deliver improved stability, security, and performance.
Support the analysis of all URLs present within the email body, even when operating in bypass mode
Now, even in bypass mode, Email Security - Server appliance analyzes all URLs within the email body, irrespective of queue status, and executes actions based on the resulting verdicts.
Support release of quarantined Emails based on MD5 Hash and URL identifiers
The Email Security - Server can now release quarantined Emails matching the specified MD5 checksum or URL criteria and deliver them to recipients. This applies even if the Emails contain other attachments or URLs.
Enhanced QR-code extraction and support to provide statistics on QR code attacks
EX now includes the analysis of QR codes within PDF attachments, in addition to existing keyword analysis in email content (body, subject, and attachment filename).
Previously, EX could only extract QR codes from .png files within zip archives. This update expands the functionality to support QR code extraction from all file types, not just .png.
New statistical tracking for QR code-based attacks enables security administrators to monitor the volume of these attacks detected within their environment over specified timeframes.
Enhanced Remediation for Microsoft Exchange Server (On-premises)
When a retro alert identifies a malicious or suspicious email, users can now configure or manually trigger quarantine or deletion of the email directly from the affected user's mailbox on their on-premises Exchange server. This feature integrates with Email Security - Server existing automatic and manual remediation workflows. .
Upgraded OpenSSL to the 3.1.x full release
The OpenSSL library has been upgraded to 3.1.x full release to enhance security measures, improve performance efficiency, and expand cryptographic capabilities.
Implemented Sender-based tracking protection
When enabled, this feature removes tracking URLs embedded in emails. These URLs, often concealed due to their small size (0-1 pixels), gather data on end-user interactions, including email opens, location, and actions taken.
Configurable Retention for clean Emails
The Email Security - Server now provides configurable retention periods and storage for clean emails. This enhancement enables administrators to perform detailed analysis, conduct troubleshooting, and implement policy modifications. If retro alerts are generated for these clean emails, users can now view the previously missed emails using the Web UI.
Custom URL rules now support regex pattern matching
Regular expression pattern matching is now supported for custom blocklists and allowlists, enhancing the ability to define URL rules. This enhancement provides increased flexibility for improved threat management via both the Command Line Interface (CLI) and the Web User Interface (WebUI).
Integration of external threat intelligence feeds through the TAXII protocol
Email Security - Server now integrates third-party threat intelligence feeds from TAXII servers using STIX 2.x/TAXII 2.1 via the web UI and CLI. Upon configuration, the system automatically retrieves feeds, including URLs and file hashes, at scheduled intervals based on the configured synchronization frequency. Currently, Email Security - Server supports the configuration of a single TAXII server, with customizable API roots, credentials, CA certificates, synchronization frequency, and STIX indicator types.
Important
For more details, see "Managing threat intel feeds using TAXII".
Integration with private Global Threat Intelligence (pGTI)
The Email Security - Server appliance now supports Private Global Threat Intelligence (pGTI) integration, enabling it to leverage Trellix's private cloud server for URL and file reputation verdicts. pGTI, which uses REST APIs and certificate-based authentication, maintains reputations based on Trellix security platform submissions. Email Security - Server can now query pGTI for file and URL reputation assessments during analysis.
Improved Third-Party Feed management capabilities
The 3rd Party Feeds page, formerly exclusive to Email Security - Server, is now extended to the Central Management System. This enhancement allows users to add, view, and download feeds from the Web UI of either product. Additionally, new Allowed Lists and Blocked Lists sub-tabs are implemented in both products. These tabs enable the management of entries, including the ability to add, view, update, and delete based on URL, MD5sum, SHA256, and Regex URL criteria.
Capability to rescan the quarantined emails
This release introduces enhanced capabilities for the handling of emails containing encrypted attachments. Previously, these attachments posed challenges for analysis upon initial receipt. The system now includes the ability to identify and automatically isolate these emails based on customizable riskware protocols. Authorized personnel can then conduct further analysis of the quarantined emails by providing the necessary decryption parameters. Sources and related content.
Enhanced postfix debugging
A new command-line interface (CLI) is available to add debug_peer_list = <next hop IP> to the main Postfix configuration file (main.cf). This enhancement improves logging capabilities, enabling better diagnosis of connection status, cipher usage, communication failure points, and error messages.
New, modified, or deprecated CLI commands
New commands
Regex pattern matching in custom URL rules CLIs
[no] analysis custom blacklist regex url <pattern>: Adds a rule to a custom blacklist based on the regex URL with specified pattern.[no] analysis custom whitelist regex url <pattern>: Adds a rule to a custom whitelist based on the regex URL with specified pattern.show analysis custom blacklist regex urls: Displays the custom blacklist containing all the regex URLs.show analysis custom whitelist regex urls: Displays the custom whitelist containing all the regex URLs.
CLIs for managing threat intel feeds - TAXII
[no] taxii server <TAXII server name> api-root: Configures the API root for the TAXII server.[no] taxii server <TAXII server name>: Configures a TAXII server.[no] taxii server <TAXII server name> api-root collection-id: Configures the API root with a collection ID for the TAXII server.[no] taxii server<TAXII server name> api-root username password: Configures the API root username and password for the TAXII server.[no] taxii server <TAXII server name> discovery-url: Configures the TAXII server discovery URL.[no] taxii server <TAXII server name>enable: Enables the TAXII server.[no] taxii server <TAXII server name> pagination-limit: Configures the pagination limit for the TAXII server.[no] taxii server<TAXII server name> root-ca: Configures the root CA for the TAXII server.[no] taxii server <server name> root-ca ca-chain: Configures the root CA and CA chain for the TAXII server.[no] taxii server <TAXII server name> sync-frequency: Set the TAXII server sync frequency in minutes (10-1440).[no] taxii server <TAXII server name> username password: Configure the TAXII server username and password.[no] taxii server <TAXII server name> validate config: Validates the TAXII server configuration.[no] show taxii server: Displays the configuration of a TAXII server.[no]analysis custom stix indicator-type <type> enable: Enables the indicator type for STIX format intel feeds. Only the configured indicator patterns with indicator-type configured are synced.
CLIs for managing threat intel feeds - STIX format
[no]analysis custom stix indicator-type <type> enable: Enables the indicator type for STIX format intel feeds.show analysis custom stix indicator-types: Displays the indicator types for STIX format intel feeds.
CLIs for pGTI integration
analysis pgti baseurl <pgti_url>: Configures the URL address of the pGTI serverno analysis pgti baseurl: Deletes the URL address of the pGTI serveranalysis pgti apikey certificate <cert_name> ca-list <ca-chain-cert_name>: Generates the API key for communicating with the pGTI server using the APIno analysis pgti apikey: Deletes the pGTI API key and the corresponding certificate name and ca_chain name config used for generating the certificates[no] analysis pgti enable: Enables/disables the integration with the pGTI servershow analysis pgti: Displays the configuration details regarding the pGTI integration
Email analysis quarantine email release file CLIs
email-analysis quarantine email release file md5: Releases quarantine emails in bulk, specifically those that contain attachments with md5sum files.email-analysis quarantine email release file url: Releases quarantine emails in bulk for URL.Show email-analysis quarantine email release status: Displays quarantine Email status.
CLIs to configure retention for clean emails
[no] email-analysis clean-emails keep enable: Enables or disables the clean email retention feature.Default: Disabled
email-analysis clean-emails keep days <1–90>: Specifies the number of days to retain clean emails.Range: 1 to 90 days.
email-analysis clean-emails keep size <1–250>: Sets the maximum storage limit (in GB) for retaining clean emails.Range: 1 to 250 GB.
Advance url defense rewrite rules CLIs:
email-analysis adv-url-defense rewrite url-whitelist regex <pattern>: Adds regex pattern for URL whitelist matching.no email-analysis adv-url-defense rewrite whitelist <UUID>: Removes the regex pattern for URL as well as domain whitelist.show email-analysis adv-url-defense rewrite whitelist: Displays advance url defense rewrite rules.
Sender-based tracking protection CLIs
[no] email-analysis policy tracking-protection enable: Enables the feature globally.[no] email-analysis policy tracking-protection dry-run enable: Enables dry run.[no] email-analysis policy tracking-protection content-lists enable: To enable/disable based on the patterns identified by Trellix Research team.[no] email-analysis policy tracking-protection pixel-pattern enable:To enable/disable based on the pixel size[no] no email-analysis policy user-policy <policy-name>: Creates a policy.[no] email-analysis policy user-policy <policy-name> tracking-protection enable: Enables the feature at policy level.show email-analysis policy user-policy and show email-analysis policy user-policy <policy-name>: View policies.[no] email-analysis recipient domain <recipient-domain> policy <policy-name>: Associates a policy to a domain.[no] email-analysis recipient address <recipient-address> policy <policy-name>: Associates a policy to a recipient.show email-analysis recipient policy: Displays the associated polices to domain/recipient address.email-analysis policy tracking-protection adblock-pattern <rule>: Creates custom patterns.show email-analysis policy tracking-protection adblock-patterns: Displays the custom patterns created.no email-analysis policy tracking-protection adblock-pattern <Rule number>: Removes custom patterns.
CLIs for postfix debugging
[no] email-analysis mta options debug-peer-ip <IP>: Temporarily adds an IP address to the debug_peer_list in Postfix's main.cf for one hour to enable detailed diagnostic logging of connectivity, cipher usage, and communication errors.
Exchange remediation CLIs
email-analysis remediation exchange config server <exchange server configuration>: Configures the exchange server's IP.email-analysis remediation exchange config username <user_with full_delegation_rights> password <password>: Configures username and password for the exchange server.email-analysis remediation mode <exchange/cloud>: Configures the selection between o365 and exchange modes.email-analysis remediation policy <quarantine|pull>: Configure the remediation action, whether to delete or quarantine the email which triggers a retro active alert
Note
The Exchange user configured here needs full delegation rights for all Exchange Server inboxes.
Resolved Issues
The following issues were resolved in the Email Security - Server 11.0.0 release.
Tracking number | Summary |
|---|---|
COM-62823 | In the latest OS version, the 'ping' command response for non-registered hosts has changed from "unknown host" to the more generic "system error" to improve security hardening. |
COM-62752 | Vulnerability Validation for CVE-2024-10979 The reported vulnerability for CVE-2024-10979 is addressed by removing the plperlu extension reference and dependencies. |
COM-62576 | When a URL is added to the custom blacklist, EX now automatically considers both HTTP and HTTPS versions of the URL. This ensures consistent behavior by handling both protocol variations during subsequent blacklist processing. |
COM-62384 | Addresses an issue wherein EX appliances, subsequent to upgrading from version 9.1.5, exhibit unforeseen alterations in alert notification logs, necessitating modifications to SIEM/QRadar parsing rules due to the inclusion of supplementary fields and a divergent format. |
COM-62287 | The JAR versions have been updated to the latest to address multiple CVEs. |
COM-31572 | Version 11.0.0 incorporates an update to OpenSSH 9.8p1, addressing the security vulnerability detailed by the associated CVE identifier. It is imperative to acknowledge that the complete mitigation of this vulnerability necessitates corresponding updates to all connecting SSH clients, in accordance with the publicly documented remediation procedures for the aforementioned CVE. |
COM-31520, COM-31516 | Vulnerability Validation for CVE-2023-5869 Resolution for the vulnerability designated as CVE-2023-5869 was implemented in PostgreSQL 14.10 binaries. In the present release, version 11.0.0, PostgreSQL 14.11 is deployed, thereby incorporating the necessary fixes from version 14.10 and effectively mitigating the aforementioned vulnerability. |
COM-31445 | Email Security - Server is not vulnerable for CVE-2023-38545 and CVE-2023-38546. |
EMPS-18200 | A problem was identified where URLs containing extended %20 sequences followed by an @ symbol were not correctly extracted. This issue has been resolved, and such URLs are now properly identified and handled during URL extraction. |
EMPS-18170 | An issue affecting the CSV export functionality has been resolved. Previously, Email Security - Server failed to accurately export filtered results to a CSV file or reports when users applied a URL filter in the "processed emails" section. |
EMPS-18162 | Advanced Rules configuration instructions are updated:
For example, "\\\\.pdf$" checks for .pdf attachments. |
EMPS-18119 | Fixes an issue where the FEDeployment URL within RTF sample attachments was not accurately extracted and processed, which impacted detection capabilities. |
EMPS-18071 | The Alerts Summary widget on the dashboard has been updated to accurately display the malicious record count in the "Unverified/Total malicious Campaigns" section. This resolves a prior issue with incorrect counts. |
EMPS-18019 | Addresses the "Rows per page" functionality in eQuarantine. After the initial TAP was applied, the feature failed to work correctly from the second TAP onward. |
EMPS-18018 | Fixes an issue in eQuarantine > Search Emails function where the email subject failed to correspond with the original email's subject. |
EMPS-17997 | Fixes an issue where daily digest emails were not being dispatched to recipients after an upgrade from version 9.1.5. The emails are now being correctly sent as expected. |
EMPS-17927 | Fixes an issue identified in release 10.0.2 in which parsing of attached messages/rfc822 was malfunctioning, This caused attachments to fail extraction from emails. |
EMPS-17848 | Fixes an issue where emails and alerts were not displayed when the appliance's timezone differed from UTC. |
EMPS-17870 | An issue has been resolved where the "show email-analysis" CLI command was misspelled. |
EMPS-17841 | The Top Emails by URL widget now excludes protect2.fireeye.com to provide more accurate count of re-written URLs, improving the precision of monitoring data. |
EMPS-17730 | Fixes an issue where the filename field was missing on the Analysis Details page for riskware alerts. |
EMPS-17700 | Fixes the 'Application server error' occured in the Email Security - Server WEBUI while cleaning up temp files. |
EMPS-17666 | Fixes an issue with the Queue Emails section displaying date/time information in UTC, even when the system was set to KST, after upgrading to release 11.0.0. |
EMPS-17432 | Fixes an issue that prevented the the addition of URLs or MD5 checksums to the Allowed/Blocked list of the Email Security - Server appliance. |
Known issues
The following issues are known in the Email Security - Server 11.0.0 release.
Tracking number | Summary |
|---|---|
COM-30656 | The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list. |
COM-30655 | During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration. Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution. |
COM-31165 | The GI settings API does not currently enforce a limit of 10 inputs for a field. |
COM-63527 | Instead of originating from the designated live interface (ether2), the sandbox analysis traffic is incorrectly originating from the management interface (ether1). |
EMPS-17820 | The downgrade of Email Security - Server to a previous release resulted in the loss of data configured on the "Advanced Rule" tab of the current release. |
EMPS-17745 | Submitting duplicate mdsum, sha256, or URL values to allowed and blocked lists via the Web UI and CLI results in inconsistent output. |
EMPS-17213 | On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments. |
WEBUI-29818 | Introduced a loading indicator for third-party feeds within the Allow/Block lists to enhance user comprehension of data availability status. |
WEBUI-15060 | On the About > Create Log Archive page, logs do not appear after the success message. It requires a refresh of the UI to be visible. |
WEBUI-14979 | The Service Health Statistics Trend incorrectly displays date and time for weekly and monthly reports. |
WEBUI-14964 | Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI. |
Disable SAML in a Helix environment
SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.
For more information, see the Helix Integration Guide for Trellix devices.
In the Software Requirements section, see “HelixConnect Client Software Requirements”.
In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.
Upgrade support
The Trellix Email Security - Server 11.0.1 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 11.0.1 from release 9.1.0 or later.
Created Log archive files on 9.1.x will not be preserved on upgrade to 11.0,0. Please have a backup of logs before upgrade.
Important
When you upgrade an Email Security appliance to 11.0.0, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the
Email Security — Server Edition User Guide
.
Note
After an upgrade to version 11.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.0.
Downloading content from the DTI offline update portal
If you download Email Security - Server 11.0.0 security content from the DTI Offline Update Portal, use the SCNET-9.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
YARA rules supported versions
YARA rules support version 4.5.0.
Important
Before you upgrade an Email Security - Server appliance to the 11.0.0 release, modify any custom YARA rules to YARA 4.5.0. For details about YARA 4.5.0, see YARA's Documentation, Release 4.5.0 by Victor Alvarez.