EDRF 50.0.1

Prev Next

This Trellix EDR with Forensics - December 2024 release includes an enhanced capability for Trellix EDR and Endpoint Security (HX).

Release details

Component

Version

Trellix EDR with Forensics for Windows

50.0.1.135

Trellix EDR with Forensics for Linux

50.0.1.166

Trellix EDR with Forensics for macOS

50.0.1.133

For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

Advanced Trellix EDR and Endpoint Security (HX) capabilities with Trellix EDR with Forensics

Trellix EDR with Forensics integrates Trellix EDR and Trellix Endpoint Security (HX) workspaces with the ePO platform, providing a unified and enhanced endpoint security solution. This unified solution combines the capabilities of Trellix EDR with core Endpoint Security (HX) features, including IOC detections, Custom IOCs, Acquisitions, Enterprise Search, and Enrichment. It can be deployed and managed through either ePO - On-prem or ePO - SaaS platforms.

Trellix EDR with Forensics enables the following capabilities:

  • Single-phase deployment — You can deploy Trellix Agent, Trellix EDR with Forensics, and other components individually or through combined deployment tasks using ePO - On-prem or ePO - SaaS platforms. You can also deploy them using the Smart Installer. Use the Product Deployment page in the ePO console to deploy the Trellix EDR with Forensics Client and Agent packages.

  • Unified Policy Catalog Trellix EDR with Forensics provides a unified Policy Catalog in the ePO environment, where various configurations pertaining to Trellix EDR and Endpoint Security (HX) can be configured. You can utilize ePO as the centralized platform to configure policies for Trellix EDR and Endpoint Security (HX). For more information on Trellix EDR with Forensics policy catalog, see Trellix EDR with Forensics Product Guide.

  • Integrated detection, response, and containment — You can utilize the integrated capabilities of Trellix EDR with Forensics to detect, investigate, respond, and contain potential threats on your endpoints.

    • Trellix EDR enables you to visualize additional context for threats and their associated endpoints. You can drill into detailed data and telemetry, such as threat behavior, process activity, and the sequence of events leading to the compromise.

      With Trellix EDR, you can detect and analyze threats in real time, investigate security incidents using in-depth forensic tools, and automate responses to contain and mitigate risks quickly. It allows users to visualize attack paths, uncover hidden threats, and gain actionable insights through advanced analytics and reporting.

    • Endpoint Security (HX) enhances endpoint security through capabilities such as scanning endpoints for potential threats and vulnerabilities. It enables efficient IOC management, allowing you to detect and respond to malicious activity. With Acquisitions, you can collect and analyze forensic data from endpoints, while Enterprise Search provides search capabilities across the environment for threat identification. Additionally,Endpoint Security (HX) supports data enrichment.

    • ePO allows you to manage the functionalities of Trellix EDR and Endpoint Security (HX) through the ePO platform. Additionally, you can configure alerts from Endpoint Security (HX) to be displayed in ePO. You can also utilize the built-in reports, dashboards, and monitors to track various product features.

Product compatibility

For more information about supported platforms, environments, and operating systems, see the Trellix Knowledge Base article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

Component versions

Trellix EDR with Forensics requires the installation of the following components:

ePO components

Component

Version

ePO - On-prem

5.10 Service Pack 1 Update 3 or later

Trellix Agent Extension

5.8.2.929 or later

DXL Data Exchange Layer (DXL)

6.0.3 RTW or later

Trellix EDR with Forensics Extension

2.0.0.1310 or later

Trellix EDR with Forensics

2.2.0.89 or later

Trellix EDR Client Extension

4.2.1.85 or later

Trellix EDR Endpoint Snapshot Tool

6.6.0.10 or later

Trellix EDR Cloud Endpoint

23.10.410.1 or later

Trellix EDR with Forensics Client

Windows: 50.0.1.135

macOS: 50.0.1.133

Linux: 50.0.1.166

Endpoint Security (HX) Server

10.0.2 1



1 - Version 10.0.1 is also supported. However, the containment feature is not supported for XClient on this version. Upgrade to version 10.0.2 to use the containment feature.

For ePO - SaaS, the components are preconfigured. However, you must deploy the Trellix Agent and the Trellix EDR with Forensics packages. For details, see Trellix EDR with Forensics Installation Guide.

Installation information

For details about installation, configuration, and usage of Trellix EDR with Forensics, see Trellix EDR with Forensics Installation Guide.

Known issues

For a list of known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.