Trellix DLP – SaaS 2410 is supported on a new platform and includes minor fixes, and resolved issues.
Trellix DLP – SaaS release information
Release Date - October 23, 2024
This release of Trellix DLP – SaaS is identified as version 2410, where the version identifier follows a YYMM convention. Trellix DLP – SaaS 2410 release, which includes minor enhancements and resolved issues.
Trellix DLP – SaaS is a unified solution that includes the following products:
Product | Supported versions |
|---|---|
Trellix DLP Discover | 11.10.600.23 |
Trellix DLP Endpoint for macOS | 11.10.200.329 |
Trellix DLP Endpoint for Windows | 11.10.300.1432 |
Trellix DLP Network Monitor appliance installation images | 11.10.700
|
Trellix DLP Network Prevent appliance installation images | 11.10.700
|
Every update release is cumulative and includes all features and fixes from the previous release. For the previous release information, see here.
For more information about using Trellix DLP – SaaS, see the Trellix DLP – SaaS Product Guide.
Updated platform, environment, or operating system support
You can get the latest information about supported platforms, environments, and operating systems from these KB articles:
As part of our ongoing security enhancements, we have upgraded the following third-party libraries to address vulnerabilities. For detailed information on the previous versions and changes, please refer to the respective vendor Release Notes.
Libraries | Versions |
|---|---|
zlib | 1.3.1 |
KeyView | 24.3 |
Microsoft Information Protection (MIP) | 1.14.146 |
OpenSSL | 3.3.1 |
Berkeley DB | 5.3.28 |
7-Zip | 23.01 |
libde265 | 1.0.15 |
libxml2 | 2.12.5 |
Minor update or fixes
This release improves existing features:
Enhanced S3 bucket registration - To secure the S3 bucket registration, you need to provide both the S3 Bucket Name and the Role ARN values. The Role ARN (Amazon Resource Name) is a unique identifier used to grant specific permissions for accessing AWS resources. For detailed instructions on how to obtain and download the Role ARN values, see KB: 000013848.
Note
The Role ARN value is optional. This approach is designed to maintain backward compatibility that allows you to continue using the current setup without requiring the Role ARN value. The requirement becomes mandatory in future releases.
Manually Resolve DFS - Using this option, you can manually resolve network share paths of all the child nodes of DFS shares and enter them individually in the network definitions. Alternatively, if you unchecked this option, Trellix DLP Endpoint for Windows - SaaS resolves all child nodes' share paths of the DFS share paths mentioned in the network definition. To enable Manual DFS Share navigate to Policy Catalog → Data Loss Prevention <version> → Windows → edit a policy → Settings → Advanced Configuration.
Support for the Turkish letter ‘İ’ - Trellix DLP Endpoint for Windows - SaaS now supports Turkish characters with case insensitivity for dictionary and keyword. For example, when a classification is created using a keyword containing the uppercase letter "İ", Trellix DLP converts it to the lowercase letter "i" allowing the rule to trigger.
Note
Trellix DLP Endpoint for Windows - SaaS can not convert to lowercase Turkish letter "ı" Ascii character code (305). However, you can create an entry in the Dictionary tab for both "ı" Ascii character code (305) and "i" Ascii character code (105) or you can create an advanced pattern to detect all "iıİ".
Application File Access Protection (AFAP) Rule enhancements - AFAP rule hooks are now injected only into processes configured for inspection in the AFAP rule, enhancing the overall performance of the product.
Advance parameter - The Advanced Parameters option in Windows client Configuration allow you to enable or disable experimental features and specify parameter values directly from the Trellix ePO console. This functionality eliminates the need to restart endpoint services when modifying or applying feature parameter values. For more information, see article 000013738
Addition to Ignored Processes - The list of ignored processes and file paths related to Trellix products is updated in Windows Client Configuration → Content Tracking → Ignored Processes. These changes are designed to prevent race conditions and enhance overall performance.
Note
Customized policies and rules do not update automatically. You must manually copy the new entries from the Trellix Default policy and incorporate them into your customized policies. For more information on the list of added processes, see article 000013942
Spreadsheet cell delimiter - The Respect Cell Boundaries in Spreadsheets checkbox in Content Tracking → Text Extractor prevents the incorrect identification of random 16-digit numbers. By default, this checkbox remains unchecked.
Resolved issues
This release resolves known issues and customer reported issues.
Reference | Resolution |
|---|---|
DLPO-16950 | Fixed an issue where the Run Query function in the Queries & Reports page did not work when Bar Chart → Chart → Bar Values was set to Number of for any query type. |
Reference | Resolution |
|---|---|
DLPW-8631 | Fixed an issue where the Removable Storage File Access Device rule failed to block file access for CD/DVD devices even when the Device Type was set to CD/DVD and the True File Type was set to Actual File Type. |
DLPW-8867 | Fixed an issue where Trellix DLP Endpoint for Windows - SaaS moved blocked files to Quarantine folder in plain text when Removable Storage Protection rule's reaction was set to Block. |
DLPW-10013 | Fixed an issue in Windows 11 where the Plug and Play Device rule failed to block UAS (SCSI) storage devices. |
DLPW-10122 | Fixed an issue where the USB device was redirected from the host machine to the Citrix virtual machine. This allowed users to access or write to the device even when the Citrix VAD Device Rule (formerly the Citrix XenApp Rule) was applied. |
DLPW-10287 | Fixed an issue where sensitive files were not blocked when a folder containing sensitive files was dragged and dropped onto Microsoft Teams. |
DLPW-10501 | Fixed an issue where the Endpoint discovery scan incorrectly identified random 16-digit numbers that did not pass the Luhn check. As a fix, Respect cell boundaries in spreadsheets checkbox is provided in Content Tracking → Text Extractor page. To use the Respect cell boundaries in spreadsheets option:
|
DLPW-10517 | Fixed an issue in which the Application File Access Protection rule failed to block files when copied to removable media. |
DLPW-10518 | Fixed an issue that caused delays when opening .txt files in a Virtual Desktop Infrastructure (VDI) environment. |
DLPW-10528 | Fixed an issue where Microsoft Outlook displayed the following error message when sending an email: "The Send operation failed because the item was deleted before it was sent". |
DLPW-11137 | Fixed an issue in which evidence files in .pdf format were automatically appended with the .txt extension. |
DLPW-11163 | An issue that prevented updating to the latest version of Trellix DLP Endpoint 11.10.x has been resolved. |
DLPW-11186 | Fixed an issue where the Plug and Play Device rule failed to block files printed via USB devices. |
DLPW-11269 | Fixed an issue where the cloud protection rule did not prevent the files from being uploaded to Microsoft OneDrive. |
DLPW-11392 | Fixed an issue where false positives were generated when the application file access protection rule was configured on Microsoft Teams. |
DLPW-11657 | Fixed a localization issue that occurred after updating Trellix DLP Endpoint for Windows - SaaS to the latest version. |
DLPW-11688 | Fixed an issue where the RegDocDB.dat file in the WebDAV evidence share path was not downloading to endpoints. |
DLPW-12632 | Fixed an issue where incidents were generated for Microsoft 365 Business even if the Office 365 option was unchecked in Cloud Service settings. |
DLPW-12634 | Fixed an issue that caused the Microsoft sign-in dialog box to appear unexpectedly after updating Trellix DLP Endpoint for Windows - SaaS to the latest version. |
DLPW-12773 | Fixed an issue where the web protection rule failed to block the upload of sensitive text in the body of web-based emails. |
DLPW-13679 | Fixed an issue where the IsActionTriggered value was inconsistent in the email protection rule when using a recipient threshold condition. |
DLPW-13816 | Fixed an issue where |
Known issues
For a list of current known issues, see: Trellix Data Loss Prevention - SaaS Known Issues.
Comparison of Trellix DLP – SaaS with Trellix DLP on-premises
Trellix is working toward feature parity with the on-premises Trellix DLP product. To know more about the options not available in this release, see article 000012803.