Trellix Data Loss Prevention – SaaS 2410 Release Notes

Prev Next

Trellix DLP – SaaS 2410 is supported on a new platform and includes minor fixes, and resolved issues.

Trellix DLP – SaaS release information

Release Date - October 23, 2024

This release of Trellix DLP – SaaS is identified as version 2410, where the version identifier follows a YYMM convention. Trellix DLP – SaaS 2410 release, which includes minor enhancements and resolved issues.

Trellix DLP – SaaS is a unified solution that includes the following products:

Product

Supported versions

Trellix DLP Discover

11.10.600.23

Trellix DLP Endpoint for macOS

11.10.200.329

Trellix DLP Endpoint for Windows

11.10.300.1432

Trellix DLP Network Monitor appliance installation images

11.10.700

  • For VMware vSphere virtual appliance — Trellix-MS-11.10.700-3675.100.ms.hw10.hdd.ova

  • For hardware appliance — Trellix-MS-11.10.700-3675.100.iso

Trellix DLP Network Prevent appliance installation images

11.10.700

  • For VMware vSphere virtual appliance — Trellix-PS-11.10.700-3675.100.ps.hw10.hdd.ova

  • For Windows Hyper-V — Trellix-PS-11.10.700-3675.100.HyperV_ps.zip

  • For hardware appliance — Trellix-PS-11.10.700-3675.100.iso

  • For AWS — Trellix DLP Network Prevent AMI

    Trellix-PS-11.10.700-3675.100.AWS_ps.zip

Every update release is cumulative and includes all features and fixes from the previous release. For the previous release information, see here.

For more information about using Trellix DLP – SaaS, see the Trellix DLP – SaaS Product Guide.

Updated platform, environment, or operating system support

You can get the latest information about supported platforms, environments, and operating systems from these KB articles:

  • For Trellix DLP Discover – SaaS: 000010983

  • For Trellix DLP Endpoint - SaaS: 000006700

  • For Trellix DLP Network Monitor – SaaS: 000010052

  • For Trellix DLP Network Prevent – SaaS: 000010052

As part of our ongoing security enhancements, we have upgraded the following third-party libraries to address vulnerabilities. For detailed information on the previous versions and changes, please refer to the respective vendor Release Notes.

Libraries

Versions

zlib

1.3.1

KeyView

24.3

Microsoft Information Protection (MIP)

1.14.146

OpenSSL

3.3.1

Berkeley DB

5.3.28

7-Zip

23.01

libde265

1.0.15

libxml2

2.12.5

Minor update or fixes

This release improves existing features:

Enhanced S3 bucket registration - To secure the S3 bucket registration, you need to provide both the S3 Bucket Name and the Role ARN values. The Role ARN (Amazon Resource Name) is a unique identifier used to grant specific permissions for accessing AWS resources. For detailed instructions on how to obtain and download the Role ARN values, see KB: 000013848.

Note

The Role ARN value is optional. This approach is designed to maintain backward compatibility that allows you to continue using the current setup without requiring the Role ARN value. The requirement becomes mandatory in future releases.

Manually Resolve DFS - Using this option, you can manually resolve network share paths of all the child nodes of DFS shares and enter them individually in the network definitions. Alternatively, if you unchecked this option, Trellix DLP Endpoint for Windows - SaaS resolves all child nodes' share paths of the DFS share paths mentioned in the network definition. To enable Manual DFS Share navigate to Policy CatalogData Loss Prevention <version>Windowsedit a policySettingsAdvanced Configuration.

Support for the Turkish letter ‘İ’ - Trellix DLP Endpoint for Windows - SaaS now supports Turkish characters with case insensitivity for dictionary and keyword. For example, when a classification is created using a keyword containing the uppercase letter "İ", Trellix DLP converts it to the lowercase letter "i" allowing the rule to trigger.

Note

Trellix DLP Endpoint for Windows - SaaS can not convert to lowercase Turkish letter "ı" Ascii character code (305). However, you can create an entry in the Dictionary tab for both "ı" Ascii character code (305) and "i" Ascii character code (105) or you can create an advanced pattern to detect all "iıİ".

Application File Access Protection (AFAP) Rule enhancements - AFAP rule hooks are now injected only into processes configured for inspection in the AFAP rule, enhancing the overall performance of the product.

Advance parameter - The Advanced Parameters option in Windows client Configuration allow you to enable or disable experimental features and specify parameter values directly from the Trellix ePO console. This functionality eliminates the need to restart endpoint services when modifying or applying feature parameter values. For more information, see article 000013738

Addition to Ignored Processes - The list of ignored processes and file paths related to Trellix products is updated in Windows Client ConfigurationContent TrackingIgnored Processes. These changes are designed to prevent race conditions and enhance overall performance.

Note

Customized policies and rules do not update automatically. You must manually copy the new entries from the Trellix Default policy and incorporate them into your customized policies. For more information on the list of added processes, see article 000013942

Spreadsheet cell delimiter - The Respect Cell Boundaries in Spreadsheets checkbox in Content TrackingText Extractor prevents the incorrect identification of random 16-digit numbers. By default, this checkbox remains unchecked.

Resolved issues

This release resolves known issues and customer reported issues.

Resolved issues in DLP Extension

Reference

Resolution

DLPO-16950

Fixed an issue where the Run Query function in the Queries & Reports page did not work when Bar ChartChartBar Values was set to Number of for any query type.



Resolved issues in DLP Endpoint for Windows

Reference

Resolution

DLPW-8631

Fixed an issue where the Removable Storage File Access Device rule failed to block file access for CD/DVD devices even when the Device Type was set to CD/DVD and the True File Type was set to Actual File Type.

DLPW-8867

Fixed an issue where Trellix DLP Endpoint for Windows - SaaS moved blocked files to Quarantine folder in plain text when Removable Storage Protection rule's reaction was set to Block.

DLPW-10013

Fixed an issue in Windows 11 where the Plug and Play Device rule failed to block UAS (SCSI) storage devices.

DLPW-10122

Fixed an issue where the USB device was redirected from the host machine to the Citrix virtual machine. This allowed users to access or write to the device even when the Citrix VAD Device Rule (formerly the Citrix XenApp Rule) was applied.

DLPW-10287

Fixed an issue where sensitive files were not blocked when a folder containing sensitive files was dragged and dropped onto Microsoft Teams.

DLPW-10501

Fixed an issue where the Endpoint discovery scan incorrectly identified random 16-digit numbers that did not pass the Luhn check. As a fix, Respect cell boundaries in spreadsheets checkbox is provided in Content TrackingText Extractor page.

To use the Respect cell boundaries in spreadsheets option:

  1. Upgrade the extension.

  2. Select the WCC → Content Tracking option.

  3. Upgrade Trellix DLP Endpoint for Windows - SaaS

DLPW-10517

Fixed an issue in which the Application File Access Protection rule failed to block files when copied to removable media.

DLPW-10518

Fixed an issue that caused delays when opening .txt files in a Virtual Desktop Infrastructure (VDI) environment.

DLPW-10528

Fixed an issue where Microsoft Outlook displayed the following error message when sending an email: "The Send operation failed because the item was deleted before it was sent".

DLPW-11137

Fixed an issue in which evidence files in .pdf format were automatically appended with the .txt extension.

DLPW-11163

An issue that prevented updating to the latest version of Trellix DLP Endpoint 11.10.x has been resolved.

DLPW-11186

Fixed an issue where the Plug and Play Device rule failed to block files printed via USB devices.

DLPW-11269

Fixed an issue where the cloud protection rule did not prevent the files from being uploaded to Microsoft OneDrive.

DLPW-11392

Fixed an issue where false positives were generated when the application file access protection rule was configured on Microsoft Teams.

DLPW-11657

Fixed a localization issue that occurred after updating Trellix DLP Endpoint for Windows - SaaS to the latest version.

DLPW-11688

Fixed an issue where the RegDocDB.dat file in the WebDAV evidence share path was not downloading to endpoints.

DLPW-12632

Fixed an issue where incidents were generated for Microsoft 365 Business even if the Office 365 option was unchecked in Cloud Service settings.

DLPW-12634

Fixed an issue that caused the Microsoft sign-in dialog box to appear unexpectedly after updating Trellix DLP Endpoint for Windows - SaaS to the latest version.

DLPW-12773

Fixed an issue where the web protection rule failed to block the upload of sensitive text in the body of web-based emails.

DLPW-13679

Fixed an issue where the IsActionTriggered value was inconsistent in the email protection rule when using a recipient threshold condition.

DLPW-13816

Fixed an issue where fcnm.exe was crashing due to heap corruption.



Known issues

For a list of current known issues, see: Trellix Data Loss Prevention - SaaS Known Issues.

Comparison of Trellix DLP – SaaS with Trellix DLP on-premises

Trellix is working toward feature parity with the on-premises Trellix DLP product. To know more about the options not available in this release, see article 000012803.