The Trellix EDR with Forensics (EDRF) 50.0.2 release includes new features and enhancements.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
Component | Version |
|---|---|
Trellix EDR with Forensics for Windows | 50.0.2.772 |
Trellix EDR with Forensics for Linux | 50.0.2.787 |
Trellix EDR with Forensics for macOS | 50.0.2.773 |
For release details and supported platforms, see the Trellix Knowledge Base article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
What's new
Introducing the Collections dashboard in the EDR workspace — The Collections dashboard in the EDR workspace provides a centralized view to track, manage, and analyze acquisitions from endpoints. It supports filtering, sorting, and grouping via an interactive AG Grid and offers quick access to triage summaries and audit data.
You can now collect data using Single File, Multiple Files, and Triage acquisition methods.
Acquisitions can be initiated from:
Monitoring dashboard
Sequential View (within the Monitoring dashboard)
Device Search
Historical Search
For more information about the Collections dashboard, see the EDRF Product Guide.
Manage IOC Detection Rules in the EDR workspace — You can now define and manage Indicators of Compromise (IOCs) directly from the EDR workspace. This enhancement improves detection precision and enables you to respond to threats specific to your environment.
New capabilities include:
Unified IOC management: View, edit, clone, delete, and export both system-generated and custom rules from a centralized dashboard.
Create custom rules: Define tailored IOC rules using presence or execution-based conditions and criteria.
Import/Export rules: Import IOC rules from external environments and export them in CSV or XLSX formats.
Streamlined filtering: Use global search, column filters, and quick filters to manage rule visibility.
Logical matching: Leverage OR logic across conditions and AND logic within criteria to fine-tune detection accuracy.
Flexible scope: Apply rules to selected servers and operating systems, with support for up to 30 conditions per rule.
For more information about IOC Detection Rules, see the EDRF Product Guide.
Automated upgrade from EDR to EDRF — You can now upgrade from EDR to EDRF seamlessly, with support for ePO - On-prem and ePO - SaaS environments.
Key enhancements include:
Automated upgrade workflow: Upgrade custom EDR policies and assignments to the EDRF Policy Catalog without losing configurations or data.
Client upgrade support: Upgrade from EDR Client to EDRF Client to use the features of EDRF.
Note
EDRF provides equivalent EDR policy frameworks to assist in manual policy and assignment upgrades.
This feature simplifies migration to the advanced EDRF platform, ensuring continuity and improved functionality with minimal effort. For more information, see the EDRF Installation Guide.
Integration of eBPF Linux sensors in EDRF — A new eBPF (Extended Berkeley Packet Filter) sensor is now part of the Linux sensor architecture. This sensor leverages eBPF technology to run custom commands in the Linux kernel and capture endpoint events with minimal overhead.
The eBPF sensor loads and unloads programs based on requested events. It uses tracepoints or kprobes to hook into the kernel and collect data through perf or ring buffers.
Key advantages over the traditional Linux sensor include:
Lower performance overhead
Enhanced visibility into system-level activity
Increased efficiency
Reduced resource utilization
No conflicts with third-party tools
Known issues
For a list of current known issues, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.