This EDRF - Cloud April 2026 release includes new features, enhancements and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
Search threats by Agent ID and GUID in the Monitoring dashboard
You can now search for threats on the Monitoring dashboard using a full Agent ID and GUID. With this update, you can search for threats on the Monitoring dashboard using Device Name, Threat Name, Threat ID, Agent ID, or GUID. The filter retains your selected category and value after the results load. The Monitoring dashboard displays an error message if the search term matches no threats.
Search for endpoints by GUID in Device Search
The Device Search dashboard now includes GUID as a search criteria. You can search for endpoints using Device Name, Agent ID, or GUID. The filter retains your selected category and value after the results load. For details, see Search for historical data on a single endpoint.
Agent ID support in the Historical Search
The Historical Search dashboard includes the Agent ID field. Use this field to identify endpoints associated with process created and sysinfo activities. You can also filter data from the Agent ID column in the results table. For details, see Search historical data of endpoints for investigation.
Note
The Historical Search dashboard displays the Agent ID information if you have deployed EDRF Client on your endpoints.
Export Threat Details in multiple time zones
You can now export threat details from the Monitoring dashboard in multiple time zones. Previously, the export only supported UTC.
View Detection Date in Alerting dashboard
The Alerting dashboard now includes the Detection Date field. This field shows the time the Trellix EDR cloud server processed the trace event. For details, see Check individual alert details.
Note
The Detection Date can differ from the Trace Date when an endpoint is offline. The Detection Date shows the time the endpoint reconnects to the cloud server.
Validate conditions for IOC Detection Rules
This release adds validation for IOC Detection Rules to ensure that the Match Value data type matches the selected Event Type. The dashboard creates the condition only when the Match Value contains a valid data type. If the data type is invalid, the condition is not created. For details, see Custom IOC detection rules.
Copy Ask Wise analysis results
You can now copy Ask Wise analysis results from the Monitoring and Device Searchdashboards. Select Draft Mail to view the analysis. Click the Copy Content button in the Draft Mail pane to copy the text to your clipboard.
Reactions API support
Use the Reactions API to create, manage, and trigger remediation actions for endpoints. You can trigger these actions programmatically from external platforms. Custom reactions completely automate the containment of threats. This automation significantly reduces the Mean Time To Respond. For details, see API sample for Reactions.
Resolved issues
Reference | Resolution |
|---|---|
SEC-212445 | Resolves an issue where the Search field remained empty when navigating from Insights to Real Time Search. The Real Time Search page now correctly displays the query string to accurately filter endpoint results. |
SEC-210614 | Resolves an issue in Real Time Search where a scheduled reboot failed to execute when users triggered the Contain action. The system failed to convert the scheduled time to the localized time. |
Known issues
For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.