Trellix EDR with Forensics (EDRF) On-prem December 2025 release includes the new features and enhancements.
Release details
For release details and supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
Introduction of Trellix EDR Telemetry Store virtual appliance
The EDR Telemetry Store virtual appliance serves as the central data store for all on-premises endpoint telemetry. The appliance is delivered as an Open Virtual Appliance (OVA) package and is based on a security-enhanced AlmaLinux 9.6.
Key features include:
Centralized telemetry storage: All endpoint telemetry is securely forwarded by Trellix Data Exchange Layer (DXL) Brokers and indexed in the EDR Telemetry Store cluster, making it searchable for historical investigation.
Flexible deployment: The virtual appliance can be deployed as a single node for small environments or scaled into a multi-node cluster for high-capacity and high-availability deployments.
Dedicated node roles: Supports distributing workloads across different node roles, including Cluster-Manager, Data, and Ingest.
CLI setup wizard: A command-line interface (CLI) wizard guides administrators through the initial appliance configuration and cluster setup.
Secure management roles: Includes two user roles — admin for installation and configuration, and config (low-privilege) for retrieving diagnostic logs.
For more information, see Install the EDR Telemetry Store virtual appliance.
Historical Search module for HX Server
The Historical Search capability is deployed as a module on the on-prem HX Server. This interface allows analysts to investigate past endpoint activity by querying the centralized EDR Telemetry Store, where all endpoint telemetry is collected through the DXL Broker and indexed.
Key features include:
Centralized querying: Runs queries against the EDR Telemetry Store, eliminating performance impact on devices.
Offline device investigation: Search and investigate the collected data even if endpoints are offline, reimaged, or decommissioned.
Proactive threat hunting: Enables analysts to search for static Indicators of Compromise (IOCs) and behavioral Indicators of Attack (IOAs), and apply new threat intelligence to historical data.
Secure communication: Configures and enables a secure Mutual Transport Layer Security (mTLS) connection between the HX Server and the EDR Telemetry Store.
Historical Search UI features:
Provides a search syntax with a Syntax Help panel to assist in building complex queries.
Refines the search results through Add to Query or Exclude from Query options in the event row.
Displays detailed event information in a side panel, including parent/child process data, file hashes (MD5, SHA1, SHA256), command line, API activity, and other artifacts.
Export the entire results table or individual event rows as a CSV file.
Historical Search API: Provides an API for performing searches and retrieving results, enabling integrations with third-party tools.
For more information, see Historical Search module.
EDRF ePO extension for on-prem
The Trellix EDRF Client v2.1.1 extension integrates your Trellix ePO server with the EDR Telemetry Store virtual appliance.
Installing the extension allows you to add the EDR Telemetry Store virtual appliance as registered servers in ePO. This enables a secure mTLS connection, allowing the DXL Broker to securely transmit endpoint trace data to the EDR Telemetry Store virtual appliance for storage and indexing.
For more information, see Configure the EDR Telemetry Store server on ePO.
DXL Broker for telemetry routing
The DXL Broker is activated as the transport layer for telemetry from endpoints running EDRF. After the EDRF ePO extension is configured, the ePO server distributes the EDR Telemetry Store connection settings to all connected DXL Brokers.
This configuration automatically enables brokers to receive trace data from endpoints and securely forward it to the EDR Telemetry Store virtual appliance using mTLS for storage and indexing. This setup ensures consistent telemetry delivery from endpoints both inside the corporate network and from roaming endpoints.
For more information, see How EDRF On-prem works.
Known Issues
For a list of known issues in this product release, see the Trellix Knowledge Base article, Trellix EDR with Forensics Known Issues - KB000015039.