EDRF 50.2.0

Prev Next

The Trellix EDR with Forensics (EDRF) 50.2.0 release includes new features, enhancements, and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release.

Release details

Component

Version

Trellix EDR with Forensics for Windows

50.2.0.644

Trellix EDR with Forensics for Linux

50.2.0.612

Trellix EDR with Forensics for macOS

50.2.0.614

For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

New or changed

Mitigate evasion techniques with Windows Filtering Platform

This release adds a Windows Filtering Platform (WFP) protection feature to identify and remove unauthorized WFP blocking filters targeting EDRF processes. This prevents adversaries from using evasion techniques, ensuring alerts and events are forwarded to Trellix ePO. To enable this feature, upgrade to the EDRF Client 50.2 package and extension.

Note

The extension update automatically applies changes to the Trellix Default and My Default policies. It does not update pre-existing custom policies.

Performance enhancement with Exclusion Advisor

EDRF Client now includes the Exclusion Advisor, a built-in audit module that identifies high-frequency, repetitive system activities to optimize performance. By analyzing local event data such as file writes, DNS lookups, and process starts, this module generates structured JSON reports based on user-defined thresholds. Administrators can use this information to create targeted exclusion policies that suppress benign, high-volume activity. This reduces EDRF Client CPU usage and improves endpoint performance without affecting detection of genuine threats.

For more information about Exclusion Advisor Audit, see the Trellix Knowledge Base (KB) article, How to use Exclusion Advisor Audit to troubleshoot EDRF performance issues - 000015181.

FIPS mode support in EDRF

You can now install EDRF Client on Windows, Linux, and macOS operating systems running in FIPS mode to perform the cryptographic operations. For details, see Deploy EDRF in FIPS mode.

Self Protection support for Linux

The Self Protection feature is now enabled for Linux endpoints. You can enable this feature in the Trellix EDRF General policy to prevent unauthorized access to Trellix EDRF processes, files, and configurations.

For details, see EDRF General policy.

Resolved issues

Reference

Resolution

ES-22678

Resolves an issue where EDRF Client version 50.1.0.909 and earlier could not connect to newly provisioned Endpoint Security (HX) 10.0.4 servers.

ES-23492

Resolves an issue where the deployment of EDRF Client 50.1.x caused high CPU utilization. To address this, EDRF Client now uses the latest Syscore version.

ES-24512

Resolves an issue where EDRF Client endpoints lost connectivity while in quarantine. This caused quarantined devices to appear offline in the Trellix EDR workspace and prevented administrators from using the Release from quarantine action.

Known issues

For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.