This EDRF - Cloud March 2026 release includes new features, enhancements and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
View WMI operation details in Monitoring and Alerting dashboards
This release adds operation details for Windows Management Instrument (WMI) event types. To view these details, select Sequential View in the Monitoring or Alerting dashboards. Select a WMI event. View the specific operation in the Event details pane.
Search threats by Device Name in Monitoring dashboard
You can now search for threats on the Monitoring dashboard using a full or partial device name. You can search using an Device Name, Threat Name, or Threat ID. The filter retains your selected category and value after the results load. Partial searches return results for multiple devices based on threat occurrence. The Monitoring dashboard displays an error message if the search term matches no threats.
Note
Device Name is now the default search field.
Search for endpoints by Agent ID in Device Search
The Device Search dashboard now includes Agent ID as a search criteria. You can now search for endpoints using an Device Name or Agent ID. The filter retains your selected category and value after the results load. The Monitoring dashboard also displays the Agent ID in the Threat Details pane.
The Agent ID field is displayed when the endpoint is connected to the Endpoint Security (HX) server. The field remains blank when the endpoint is disconnected.
Note
You must enter the complete Agent ID. The search does not support partial entries.
Synchronize email notifications with Threat Display Options
The system synchronizes the threat summary in email notifications with the threat displayed in the Monitoring dashboard based on the configured Threat display options. This update applies by default to all users who have enabled email notifications.
You can find informational labels confirming this synchronization on the Threat Display and Notification Settings pages. This adds a Threat display options filter to the existing category filter in your Notification settings. For details, see EDRF documentation
Additional Threat Alerts API support
EDRF now includes the edr/v3/alerts API. This API provides an expanded response that includes HostInfo data. For details, see API sample for Threats and Alerts.
Resolved issues
Reference | Resolution |
|---|---|
SEC-210401 | Resolves an issue where MD5 hash searches on endpoints failed to return results in Device Search. This interface previously used a merged hash column for MD5 and SHA-256 values. These values now appear in separate columns to ensure search accuracy. |
SEC-210943 | Resolved an issue where Trellix Wise generated inconsistent investigation reports across different languages. The Italian version now matches the English and German versions. Reports now include specific MITRE ATTACK techniques, accurate breach examples, and required log review steps. |
SEC-211441 | Resolves an issue where historical searches failed when using the |
SEC-211821 | Resolves an issue where the Monitoring dashboard displayed an infinite loading spinner during a backend timeout or 500 error. The interface now removes the spinner and displays a message if the system receives an error or no response within 250 seconds. |
SEC-206618 | Resolves an issue where Trellix EDR interface elements were visible to unauthorized users. Restricted users previously accessed unauthorized areas and data. This release corrects the enforcement of permissions. Users now view only the interface components and data that align with their assigned roles. For details, see Trellix EDR roles. |
Known issues
For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.