EDRF Cloud January 2026

Prev Next

This EDRF - Cloud January 2026 release includes new features and enhancements, and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release.

Release details

For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

New or changed

Trellix Wise enhancements
  • Integrated remediation actions links: The Suggested Actions pane in the Interactive mode now includes direct links to remediation actions. This allows you to perform device remediation actions such as Quarantine Device, Dismiss Threat, and Kill Process directly, removing the need for manual navigation. For details, see Analyze threats with Generative AI.

  • Response streaming: Trellix Wise now supports real-time streaming for AI-driven insights in EDR Monitoring and Device Search. Findings appear in the Interactive and Dossier modes as they are generated.

  • Action and feedback notifications: The EDR Monitoring dashboard now displays pop-up confirmations for system actions and user feedback.

    • Remediation tracking: The Suggested Actions now displays pop-up notifications when actions such as Quarantine Host, Terminate Process, and Block IP are initiated.

    • Feedback acknowledgement: Confirmation pop-up notifications appear after clicking the Feedback (thumbs up or down) button.

  • Markdown format support: Trellix Wise now generates output in Markdown instead of JSON to provide structured, readable insights.

IOC Detection Rule enhancements

In the Trellix EDR workspace, the IOC Detection Rules dashboard now filters event types based on the selected operating system. When you create custom rules, the Event Type drop-down menu displays only the events applicable to the target operating system.

Access Endpoint Security (HX) modules in Trellix EDR workspace

This release adds Process Tracker and Logon Tracker deep links to the Trellix EDR Monitoring dashboard. These links provide direct access to the Forensics workspace, enabling you to investigate devices and processes in detail.

Enhanced forensic data collection

This release adds additional forensic data collection actions across the Trellix EDR dashboards. Use the Collections dashboard to centrally manage the collected data.

The new forensic data collection actions include:

  • Command Shell History: Captures command shell activity from Windows endpoints.

  • PowerShell History: Collects Windows event logs to track PowerShell activity for security auditing.

  • Full Memory: Uses memory-acquisition audits to acquire physical memory from Windows endpoints.

  • Comprehensive Investigative Details: Collects forensic data from Windows, macOS, and Linux endpoints.

  • Quick File Listing: Retrieves file and directory records from Windows, macOS, and Linux endpoints.

For details, see Collect and manage forensic data.

Resolved issues

Reference

Resolution

ES-24586

Resolves an issue in Trellix EDR dashboards where the Custom Time Range option failed to include the to date timestamp and sent the from date as a calculated time difference instead of a specific Epoch start time.

Known issues

For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.