New features and changes

Prev Next

This section describes new features in the Trellix Email Security - Server release 10.0.0.

Automated generation of artifacts

All the supported artifacts are now generated for malware-object and riskware-object alerts if the display of static information is enabled on the Email Security - Server appliance. These can be downloaded from API as well as from the Web UI. From this release, the display of static information is enabled by default. Furthermore, you can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.

Integration with Helix and HelixConnect

You can now integrate your Email Security - Server appliance with Helix through the Email Security - Server Web UI.

The HelixConnect client is automatically enabled when the Helix mode is enabled on the appliance. The appliance also automatically registers with Helix through the HelixConnect client. The HelixConnect client can be independently enabled or disabled even when the Helix mode is disabled.

For information about establishing connectivity with the HelixConnect client and enabling the functionality it offers, see the Helix Integration Guide.

Show submission CLI enhancement

md5sum and sha256 values are now populated in the show submission command output.

Datastreaming submission data to third-party SIEM

You can now configure datastreaming to Splunk servers.

Metadata streaming through an HTTP proxy

Metadata streaming through an HTTP proxy is now supported.

Termination of support for x400 appliances

Upgrade to release version 10.0.0 will not be supported on Email Security - Server 4th generation appliances.

MUSE Web UI improvements

The Email Security - Server appliance Web UI has adopted the MUSE design for UX improvements on eQuarantine and Search Email tabs for this release.

New data retention and purging policy

You can now set the number of days to retain alert data in the database using the Email Security - Server appliance Web UI. Data will be purged after the retention period. You can change the frequency and time of the data purge.

IPv6 support on the IPMI for x600 appliances

IPMI on the Email Security - Server 6th generation appliances is now compatible with IPv6 management network.

Advanced custom rules support on Email Security - Server appliances

Support for creating advanced custom rules has been provided. The Advanced Rules page allows you to create custom rules, combine these rules with different criteria using “AND” operation, and choose to match or not match the criteria with the defined values.

The Health Services tab

The Health Services tab allows you to configure health monitoring parameters for all the available health services on the appliance.

Restoring the database from a backup file

You can now restore a backup database belonging to a different appliance model of the same release version. This feature is useful when upgrading from one appliance model to another on the same release.

List of ciphers modified

The existing FIPS and CC high-security cipher lists have been updated. For more details, refer to Email Security - Server User Guide.

New format for alert URLs

All notification and API alert traceback URLs now use the new common format. The new URL format is https://%s/detection/objects?uuid=%s.

Import custom feeds into the Email Security-Server appliance

Offers both APIs and a UI that facilitate the seamless uploading of third-party intel feeds containing file hashes and URLs. It also supports uploading of custom intel in the widely used STIX format.

Support for ssh 'AllowUsers' and 'DenyUsers' by source IP address

Support for ssh 'AllowUsers' and 'DenyUsers' by source IP address has been added.

Detection enhancement

Enhanced object extraction from dynamic HTML pages using Headless Chrome.

General Enhancements
  • The retroactive remediation feature is enhanced. You can manually remediate emails even if they are marked as clean by the Email Security - Server appliance.

  • The HTTP events generated on the appliance can now be sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.

  • Log-management functionality has been improved.

  • The malware artifacts data downloaded as a zip file for any specified alert now includes OS Change Graph data as well.

  • SMTP authentication is now supported for both incoming and outgoing emails.

  • The total submission number of DUA now gets added to the hourly status report.

  • Emails containing non-malicious URLs are now released before the FAUDE delay timer expires.

  • The Service Health Statistics Trend widget on the Email Security - Server appliance Web UI dashboard highlights the health level of the most critical service in each category tile.

  • All the supported formats for Rsyslog notifications are now displayed in the Email Security - Server Web UI.

  • Factory default certificate generation key size is changed to 3072 bits.

  • The signature for hash/URL added to the block list is changed to Custom.Blocklist.

  • The Postfix version is upgraded to release 3.5.9.

  • The description on the Processed Emails page is removed.

  • The time zone information is removed from eQuarantine and Search Email tabs.

  • The FAUDE URL screenshot is now generated along with other artifacts after successful submission.

  • If you download security content from the DTI Offline Update Portal, you now use the SCNET-8.0 channel of the portal.

  • You can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.

  • Alert type 'Riskware-Object' has been added for the report type 'Riskware Details' for both Static and Scheduled Reports in the Reports option on the Email Security - Server Web UI.

  • Enhancements to the Email Hourly Stats report have been introduced. In addition to the existing data, the report now provides details on total number of submitted attachments, total number of objects fetched and submitted by DUA, and total number of VMs launched. Furthermore, a new table has been added to the Email Hourly Report, offering insights into the number of emails that have spent time in the email hold queue.

  • When the "FAUDE Delay" feature is enabled and if the email is determined to be clean after email analysis completion, the status is rechecked with FAUDE (if required). If FAUDE check confirms that the URLs are clean, the email is released immediately without waiting for the FAUDE delay period to expire. Additionally, FAUDE delay is now supported in Monitor Mode as well.