This Trellix EDR with Forensics - December 2024 release includes an enhanced capability for Trellix EDR and Endpoint Security (HX).
Release details
Component | Version |
|---|---|
Trellix EDR with Forensics for Windows | 50.0.1.135 |
Trellix EDR with Forensics for Linux | 50.0.1.166 |
Trellix EDR with Forensics for macOS | 50.0.1.133 |
For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
Advanced Trellix EDR and Endpoint Security (HX) capabilities with Trellix EDR with Forensics
Trellix EDR with Forensics integrates Trellix EDR and Trellix Endpoint Security (HX) workspaces with the ePO platform, providing a unified and enhanced endpoint security solution. This unified solution combines the capabilities of Trellix EDR with core Endpoint Security (HX) features, including IOC detections, Custom IOCs, Acquisitions, Enterprise Search, and Enrichment. It can be deployed and managed through either ePO - On-prem or ePO - SaaS platforms.
Trellix EDR with Forensics enables the following capabilities:
Single-phase deployment — You can deploy Trellix Agent, Trellix EDR with Forensics, and other components individually or through combined deployment tasks using ePO - On-prem or ePO - SaaS platforms. You can also deploy them using the Smart Installer. Use the Product Deployment page in the ePO console to deploy the Trellix EDR with Forensics Client and Agent packages.
Unified Policy Catalog — Trellix EDR with Forensics provides a unified Policy Catalog in the ePO environment, where various configurations pertaining to Trellix EDR and Endpoint Security (HX) can be configured. You can utilize ePO as the centralized platform to configure policies for Trellix EDR and Endpoint Security (HX). For more information on Trellix EDR with Forensics policy catalog, see Trellix EDR with Forensics Product Guide.
Integrated detection, response, and containment — You can utilize the integrated capabilities of Trellix EDR with Forensics to detect, investigate, respond, and contain potential threats on your endpoints.
Trellix EDR enables you to visualize additional context for threats and their associated endpoints. You can drill into detailed data and telemetry, such as threat behavior, process activity, and the sequence of events leading to the compromise.
With Trellix EDR, you can detect and analyze threats in real time, investigate security incidents using in-depth forensic tools, and automate responses to contain and mitigate risks quickly. It allows users to visualize attack paths, uncover hidden threats, and gain actionable insights through advanced analytics and reporting.
Endpoint Security (HX) enhances endpoint security through capabilities such as scanning endpoints for potential threats and vulnerabilities. It enables efficient IOC management, allowing you to detect and respond to malicious activity. With Acquisitions, you can collect and analyze forensic data from endpoints, while Enterprise Search provides search capabilities across the environment for threat identification. Additionally,Endpoint Security (HX) supports data enrichment.
ePO allows you to manage the functionalities of Trellix EDR and Endpoint Security (HX) through the ePO platform. Additionally, you can configure alerts from Endpoint Security (HX) to be displayed in ePO. You can also utilize the built-in reports, dashboards, and monitors to track various product features.
Product compatibility
For more information about supported platforms, environments, and operating systems, see the Trellix Knowledge Base article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
Component versions
Trellix EDR with Forensics requires the installation of the following components:
Component | Version |
|---|---|
ePO - On-prem | 5.10 Service Pack 1 Update 3 or later |
Trellix Agent Extension | 5.8.2.929 or later |
DXL Data Exchange Layer (DXL) | 6.0.3 RTW or later |
Trellix EDR with Forensics Extension | 2.0.0.1310 or later |
Trellix EDR with Forensics | 2.2.0.89 or later |
Trellix EDR Client Extension | 4.2.1.85 or later |
Trellix EDR Endpoint Snapshot Tool | 6.6.0.10 or later |
Trellix EDR Cloud Endpoint | 23.10.410.1 or later |
Trellix EDR with Forensics Client | Windows: 50.0.1.135 macOS: 50.0.1.133 Linux: 50.0.1.166 |
Endpoint Security (HX) Server | 10.0.2 1 |
1 - Version 10.0.1 is also supported. However, the containment feature is not supported for XClient on this version. Upgrade to version 10.0.2 to use the containment feature.
For ePO - SaaS, the components are preconfigured. However, you must deploy the Trellix Agent and the Trellix EDR with Forensics packages. For details, see Trellix EDR with Forensics Installation Guide.
Installation information
For details about installation, configuration, and usage of Trellix EDR with Forensics, see Trellix EDR with Forensics Installation Guide.
Known issues
For a list of known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.