EDRF Cloud July 2026

Prev Next

This EDRF - Cloud July 2026 release includes new features, enhancements and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release.

Release details

For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.

New or changed

View detection rules in the Monitoring page

The Monitoring page displays the top detection rule below each threat. Although multiple detection rules can contribute to a threat, the user interface displays only the top detection rule. This additional context helps analysts understand why a threat was triggered without reviewing additional details.

The Device Search dashboard displays a Detection Date column in the required artifacts. This column distinguishes when an event occurred on a device from when the system processed the data. The Detection Timeframe label replaces the Detection Window label. The date picker prevents an invalid past or future date from being selected.

Export data using a selected time zone

You can select a time zone when exporting data from the Historical Search, Device Search, Real Time Search, and IOC Detection Rules dashboards. This exports data using your preferred time zone instead of the default UTC format.

View additional information about Mandiant Intel rules

An information icon appears on the Endpoint Security (HX) (Forensics workspace) Rules page and on the Trellix EDR IOC Detection Rules listing page. The tooltip explains that the page displays custom rules and selected Mandiant Unrestricted Intel Rules. Mandiant Restricted Intel Rules appear only when an indicator of compromise (IOC) matches a configured condition.

View Agent ID and GUID for affected devices in Threat Details

The Threat Details pane on the Monitoring page displays the Agent ID and GUID columns in the Device section. These columns identify devices associated with the selected threat. These identifiers help you distinguish between affected devices during threat investigations. You can also search for threats using the Agent ID or GUID.

Updated threat severity filter terminology

On the Monitoring page, the Threat By Ranking filter is renamed to Threat by Severity. This update aligns the user interface with product documentation.

Updated terminology in the Alerting dashboard

The Trellix EDR Alerting dashboard uses updated terminology. The user interface displays Alerts instead of Events for alert counts.

Catalog API support for custom reactions

The Catalog API supports create, read, update, and delete (CRUD) operations for custom reactions. Developers can manage custom reactions programmatically to automate workflows and integrate third-party systems.

Key capabilities:

  • Create: Programmatically generate custom reactions.

  • Read: Retrieve configuration details of existing custom reactions.

  • Update: Modify custom reaction properties.

  • Delete: Remove custom reactions.

Resolved issues

Reference

Resolution

SEC-213319

Resolves an issue on the Trellix EDR Monitoring dashboard, where the Threat Name search enforced a minimum three-character limit, preventing users from searching for legitimate short threat names, such as sh and /bin/sh.

SEC-213803

Resolves an issue where the Did You Know pop-up appeared after every sign-in to Trellix EDR. The pop-up now appears only when you sign in from a new browser, device or when the pop-up content version is updated. Standard user logouts does not reset the dismissed pop-up status.

SEC-214184

Resolves an issue where EDRF documentation omitted explanations for API return fields. For details, see EDRF APIs.

Known issues

For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.