EDRF Cloud February 2026

Prev Next

This EDRF - Cloud February 2026 release includes new features and enhancements.

Every update release is cumulative and includes all features and fixes from the previous release.

Release details

For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

New or changed

View unique threat IDs on the Monitoring dashboard

EDRF now displays the threat ID, providing a unique identifier for every threat. This field allows you to cross-reference alerts from API and Monitoring dashboard to ensure accurate identification during investigations.

The unique threat ID is visible on the Monitoring dashboard. The search filter in the Threats by Ranking/ Threats by Time pane allows you to filter using the Threat Name or Threat ID.

Agent ID implementation in the EDR dashboards

EDRF now includes the Agent ID field to provide a unique identifier for every device. This field ensures accurate device identification during investigations and allows you to correlate data with Endpoint Security (HX).

The Agent ID field is now available in these dashboards:

  • Monitoring — View the Agent ID in the Device details table.

  • Device Search — View the Agent ID in the Device Details pane.

  • Alerting — View the Agent ID in the alert listing table and the Alert Details pane. You can also filter and sort by this field.

  • Historical Search — View the Agent ID in the Device Details pane.

Custom reaction API support

EDRF now supports triggering custom reactions using Remediation APIs. This feature allows you to programmatically execute response actions for specific security use cases.

Invoke custom reactions via the API using these methods:

  • Search-based — Execute a Real-Time Search. Trigger the reaction using the search ID parameter based on the search results.

  • Host-based — Target a specific endpoint. Trigger the reaction using the MAGUID parameter.

Note

This release supports the invocation of custom reactions via APIs only. You must use the Trellix EDR interface to create, update, read, or delete custom reactions.

For more information, see POST - Host Remediation and POST - Search Remediation.

Known issues

For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.