Endpoint Security (HX) version 11 and version 20 or later perform real-time monitoring of your endpoint devices and collect forensic data from them.
The version 20 or later xAgent s provide the following enhancements over the version 11 xAgent s:
Real-time event data is stored in an encrypted database, making version 20 more secure than version 11.
The log files of version 11 xAgents are plain text files, readable using any text editor. The log files of version 20 xAgent s are stored in the encrypted database, making them more secure. They can only be reviewed by extracting them using the
xagt --log-exportcommand. See Command-Line Parameters .The version 20 or later xAgent uses a faster, more efficient matching engine. This improves the xAgent 's performance and the detail provided from the matched data. Newer version 11 xAgent s (version 11.8.5 and later) also use this faster, more efficient matching engine, but older versions do not.
The version 20 or later xAgent uses spawned processes to provide a more stable agent. Version 11 xAgent s use only a single process.
Version 20 xAgent s can use new audits to retrieve real-time event data on demand for Endpoint Security (HX) triage requests. These audits are used to fulfill Endpoint Security (HX) data acquisition requests.
Intelligence downloads to version 20 or later xAgent s are faster than to version 11 xAgent s. When intelligence downloads occur for version 20 (or later) xAgent s, only the changed intelligence is downloaded. For version 11 xAgent s, all intelligence is downloaded.
New agent policies allow you to dynamically configure version 20 or later xAgent functionality from the Web UI. These policies allow you to
Restrict resource usage of the xAgent on the host endpoint
Control real-time detection processing by the xAgent
Limit the number of hosts that run Endpoint Security (HX) tasks concurrently
Control xAgent logging
Control Exploit Guard (detection and prevention) processing by the xAgent .
Newer version 11 xAgent s (version 11.8.5 and later) can also enable and disable real-time event data collection, but older releases cannot.
Only version 20 or later xAgents are searched during an Enterprise Search attempt. Enterprise Search requests allow you to query all the host endpoints in your enterprise for specific indicators of compromise (IOCs). Exhaustive searches (a specific type of Enterprise Search) require the purchase of an Endpoint Security (HX) Power license. See "License Management" in the Endpoint Security (HX) System Administration Guide.
Only version 21 (or later) Windows xAgent s can perform exploit detection (a component of Exploit Guard) on your host endpoints. For more information about exploit detection, see Managing Exploit Guard .
Only version 22 (or later) Windows agents can perform exploit prevention (another component of Exploit Guard) on your host endpoints. For more information about exploit prevention, see Managing Exploit Guard.
Only version 23.10.0 xAgent s can run on macOS platforms. Only version 25.12.0 or later can run on Linux platforms. See "Operating System Requirements" in the Endpoint Security (HX) Server Deployment Guide for a full list of supported macOS versions.
Only version 24 (or later) Windows xAgent s can perform malware detection (a component of malware protection) on your host endpoints. For more information about malware detection, see Managing Malware ProtectionDetection.
Only version 26 (or later) Windows xAgent s can apply a removal protection password to prevent the unauthorized removal of the Trellix Endpoint Security (HX) xAgent software.