The Trellix EDR with Forensics (EDRF) 50.1.0 release includes new features, enhancements, and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
Component | Version |
|---|---|
Trellix EDR with Forensics for Windows | 50.1.0.933 |
Trellix EDR with Forensics for Linux | 50.1.0.936 |
Trellix EDR with Forensics for macOS | 50.1.0.934 |
For release details and supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
Introducing Endpoint Security (HX) modules in EDRF
This release adds Endpoint Security (HX) modules that include Logon Tracker, Process Tracker, and Host Remediation, extending endpoint visibility and enabling deeper investigations across Windows, Linux, and macOS endpoints. These modules provide analysts with richer context across detection, investigation, and response workflows. This enhancement helps reduce investigation time, enables more effective remediation, and improves overall security coverage.
The Logon Tracker module collects detailed logon event data across Windows, Linux, and macOS endpoints, providing more context than previously available in EDRF Cloud. Security teams can define custom detection rules to flag suspicious authentication activity. For Windows endpoints, events are enriched with information that supports lateral movement investigations. This capability enhances SOC workflows by identifying potentially unauthorized access attempts early in the attack chain.
The Process Tracker module records process execution events across Windows, Linux, and macOS and streams the associated metadata to the Endpoint Security Server. Events are also published to a message bus for integration with Helix or SIEM solutions, stored locally in a database, and made accessible through an API. These events can be viewed in the Forensic workspace on the Process Tracker home page, where analysts can identify unknown or suspicious processes and investigate abnormal execution patterns.
When the Enricher Module is installed and enabled, Process Tracker can detect malicious processes and generate alerts. These alerts can be configured to automatically trigger a triage, helping analysts respond to threats more efficiently. By providing detailed visibility into process activity across endpoints, this module supports both real-time monitoring and historical investigations, while improving SOC workflows through automated detection and response.
The Host Remediation module allows administrators and analysts to investigate and take action directly on affected endpoints. Analysts can isolate compromised devices, perform detailed investigations, and apply remediation actions remotely. This capability reduces response time, improves control during incidents, and provides a more complete investigation-to-remediation workflow within Helix.
Support for GCP storage buckets
EDRF Client now supports sending trace data and detection logs to Google Cloud Platform (GCP) storage buckets. This feature allows security teams to centralize EDRF data with telemetry from other security products in their own environment. Centralized storage improves data management, supports compliance with organizational policies, and enables more effective threat hunting and analytics. In this release, the capability is supported on Windows endpoints only. For details, see Streaming policy.
Enhanced detection with Event Tracing for Windows (ETW) integration
This release introduces Event Tracing for Windows (ETW) integration to enhance threat detection by monitoring low-level system API calls using two new ETW providers - Microsoft-Windows-Threat-Intelligence and Microsoft-Windows-Kernel-Process to address evasion techniques used by adversaries. This integration provides deeper visibility into endpoint activity, improving the detection of previously missed threats such as code injections. Administrators can control this feature, as the ETW data collection can be enabled or disabled in the Streaming policy in the ePO Policy Catalog.
Dark mode implementation in Trellix ePO - SaaS
A dark mode option is now available in Trellix ePO - SaaS, improving usability for users who prefer a low-light or high-contrast interface. This is a visual update and does not change functional behavior, but it provides flexibility in how users interact with the console.
Automatic uninstall of xAgent during deployment
As part of deployment, the EDRF Client now automatically removes legacy xAgent and xAgent Proxy components across Windows, Linux, and macOS. This ensures a clean installation by preventing conflicts with the current client and removes the need for manual uninstallation steps. Automating this process simplifies upgrades and reduces errors in large-scale deployments.
As part of deployment, the EDRF Client now automatically uninstalls legacy xAgent and xAgent Proxy components across Windows, Linux, and macOS. This ensures a clean installation by preventing conflicts with the current client and eliminating the need for manual uninstallation steps. In addition, when upgrading from xAgent to the EDRF Client, policies can be seamlessly migrated, reducing configuration effort. Together, these enhancements simplify upgrades, reduce errors in large-scale deployments, and ensure consistent policy application.
For more information, see:
Extended forensic data collection
This release extends forensic data acquisition is enhanced with four new collection actions, in addition to the three previously available. Collection action support has also been extended to the Alerting, Investigation, and Real-Time Search dashboards, alongside Monitoring, Historical, and Device Search. All collection actions, both existing and new, are now accessible from every EDR dashboard, with collected data managed centrally through the Collections dashboard.
The new collection actions include:
Standard Investigative Details — captures endpoint information, disk audits, volume details, and user accounts
Process Memory — acquires a full memory dump of a running process for detailed malware analysis
Driver Memory — collects memory from a specific system driver to investigate kernel-level threats
Raw Disk — provides a raw disk image for comprehensive forensic review
For details, see Collect and manage forensic data.
IPv6 support
EDRF now supports pure IPv6 and dual-stack (IPv4/IPv6) network configurations. This update provides EDRF functionality for environments operating within IPv6 infrastructures. Communication is enabled between the EDRF cloud, managed endpoints, and on-premises components such as Trellix ePO and DXL Brokers, for any IP stack configuration. Additionally, outbound communications from the EDRF cloud, which include integrations with Webhook, Amazon S3, and Syslog, are supported in IPv6 networks.
Improved performance and connectivity (Windows and macOS)
Windows and macOS
DXL connectivity — Increased the Data Exchange Layer (DXL) asynchronous timeout (
DXL_TIMEOUT_ASYNC) from 10,000 milliseconds to 20,000 milliseconds. This reduces disconnection events and improves stability in high-latency networks.Data integrity — Implemented a 60-second retry mechanism for failed trace transmissions to ensure reliable delivery of telemetry data during temporary network interruptions.
Library upgrades — Updated the internal
restclientcomponent to version 8.12.1 to improve general client performance and stability.Refined diagnostics — Optimized log messages to provide greater clarity for troubleshooting.
macOS specific improvements
Codebase synchronization — Synchronized the EDRF Client codebase with the Active Response Client to ensure feature parity and consistent functionality across Trellix endpoint security components on macOS.
Process genealogy optimization — Optimizes process genealogy by removing unnecessary parent process hierarchy and reducing the genealogy cleanup duration. These changes improve overall system performance.
File Hash calculation for traces — Reduces the default file size used for hash calculation. You can configure this file size limit in the EDRF Policy Catalog.
Tanium compatibility — Adds a default exclusion for the Tanium client. This prevents interoperability conflicts and performance overhead.
EDRF documentation updates
The EDRF documentation has been consolidated into a single landing page in the Trellix Product Documentation portal. This update provides one central location for the latest guidance, making it easier to find the information you need. See EDRF documentation for details.
Resolved issues
Reference | Resolution |
|---|---|
ES-21742 | Fixed an issue where collecting an endpoint snapshot from the investigation dashboard in the EDR workspace and the Phoenix tool failed for an EDRF Client managed by ePO - SaaS. |
ES-21740 | Fixed an issue where the default Fast Poll interval of 30 seconds in the EDRF General policy was not applied correctly. |
ES-22401 | Fixed an issue where the EDRF Client continuously restarted after a Forensics server was selected for management. |
Known issues
For a list of known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.