The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

1.1.3

Prev Next

The Forensics Bridge module 1.1.3 release includes new features, resolved issues and known issues.

New features

Support for macOS endpoints

This release introduces support for sending alerts from macOS endpoints to Trellix ePO.

Resolved Issues

Reference

Description

ENDPT-226006

Resolves an issue where Forensics Bridge module with Endpoint Security Agent (HX) v36.30.0 was unable to forward events to Trellix ePolicy Orchestrator - On-premises.

ENDPT-226561

Addresses an issue that prevented the MalwareProtection event from being parsed by Trellix ePO, which consistently displayed the error message: An error occurred while retrieving the requested data.

ENDPT-113163

Eliminates a problem where LogonTracker was unable to send failed logon attempts events to Trellix Endpoint Detection and Response.

ENDPT-225853

Fixes an issue where the deployment of Trellix Forensics (Endpoint Security Agent (HX)) from Trellix ePO was failing.

Known Issues

Reference

Description

ENDPT-226066

Upgrading the agent to an incompatible version through Endpoint Security Agent (HX) may cause the Forensics Bridge to fail to send events to Trellix ePO.

ENDPT-227292

Events without Actor process ID (PID) information are not forwarded to the Trellix EDR console.

ENDPT-226515

The Endpoint Security Agent (HX) is not uninstalled after running job for Endpoint Security Agent (HX) uninstallation from Trellix ePO.

Additional information

Prerequisites

This release requires the following Trellix product versions:

  • Trellix Agent 5.8.3.622 or later

  • EDR Client requirement:

    • Windows: 4.2.1.4528 or later

Product Compatibility

This release supports the following Trellix product versions:

  • Endpoint Security (HX) server 10.0.0 or later.

  • Endpoint Security Agent (HX) 36.30.0 is supported for the following operating systems:

    • Windows

    • Linux

    • macOS

      The Endpoint Security Agent (HX) v36.30.0 is supported across all three platforms—Windows, macOS, and Linux. However, event or alert routing to Trellix ePO is only supported on Windows and macOS, as the Forensics Bridge module v1.1.3 does not support the Linux operating system.

    Note

    The equivalent Trellix ePO package version for Endpoint Security Agent (HX) 36.30.0 is 36.30.0.13.

  • Trellix Forensics ePO Extension 36.0.0.146 or later.