Endpoint Detection and Response - Getting Started Guide - FedRAMP

Prev Next

Updated: December 10, 2025

Getting started with Trellix EDR

Overview

Trellix Endpoint Detection and Response (Trellix EDR) is a cloud-delivered service that enables you to detect, investigate, and respond to threats.

Trellix EDR provides continuous data collection and advanced analytics that helps you detect suspicious behavior on your network. Using alert ranking and data visualization, you can quickly understand the threat and take immediate action.

Guided investigation automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves. With in-depth understanding of the threat and single-click response capabilities, Trellix EDR enables you to quickly and confidently respond to threats.

Trellix EDR reduces the expertise and effort needed to perform investigations and increases the speed with which analysts can determine the risk of incidents and their root cause. Trellix EDR can be managed using Trellix ePolicy Orchestrator - On-prem or Trellix ePolicy Orchestrator - SaaS in the FedRAMP environment.

The Getting Started Guide (FedRAMP) covers specific information such as activating the Trellix ePO - SaaS administrator account, network ports and URLs, configuration of Trellix EDR and Trellix ePO - On-prem interconnection, etc. in the FedRAMP environment.

Webhook

When creating webhooks using parameters for the Trellix EDR GovCloud environments such as FedRAMP, CRA, etc. use the appropriate API URLs. For URL details, see Server and client requirements.

Activate and configure SSO to log on to Trellix

To activate your Trellix account and configure Single Sign-On, follow these steps:

Server and client requirements

  • Before you install Trellix EDR,  make sure that your server and client systems meet all requirements (KB91345).

  • For information about Trellix EDR software and hardware requirements, and supported environments, see (KB91345).

Important: The supported Trellix EDR client version for FedRAMP is 4.1.x or later. Below are the minimum supported product versions for Trellix EDR(FedRAMP) managed using Trellix ePO - On-prem.

Table 1  Supported product versions 

Product

Minimum supported version or later

Trellix ePO - On-prem

5.10.0.4098 SP1 = CU16

CU Tool (CU 15)

2.0.0.1291

Trellix DXL Broker

6.0.3.990

Trellix Agent

5.7.7

TIE

4.0.0.369

Trellix ePO - SaaS Cloud Bridge

2.1.0.460

Trellix ENS

10.7.0.5162

Trellix EDR Client

4.1.0

Trellix EDR Cloud Endpoint Extension

23.02.410.2

For the Trellix ePO - On-prem connection to Trellix EDR solution to work within the FedRAMP boundary, you must upgrade the Trellix DXL Broker Extension to version 6.0.3.990 or later. This extension can be obtained from your Trellix Product Download Site and checked in to Trellix ePO - On-prem. It can also be obtained from Trellix ePO - On-prem Master Repository and checked in to Trellix ePO - On-prem.

Note: The Trellix Product Download Site requires entry of a valid Grant Number and associated email address to gain access to products available for download.

Network ports

Trellix EDR uses specific network ports to connect to DXL client and Trellix EDR client.

Note: Make sure your network settings are configured correctly and SSL traffic inspection is disabled on URL or IP address. For details about the default ports required for each component on Trellix ePO - On-prem, see {KB66797}.

URL allow list

You must allow access to Trellix EDR URLs.

Connections are always initiated from the client to the cloud services. You must allow access to Trellix EDR URLs. The Agent wakeup is done by using a DXL Agent wakeup, through an existing DXL connection.

DXL needs to be allowed from the On-premises administrator web browser and Trellix ePO - On-prem server to the following cloud service URLs.

Service

FQDN

Description

Trellix EDR UI

https://ui.soc.us.trellix-gov.com

Trellix EDR browser UI

UAM UI

https://ui.uam.us.trellix-gov.com

User Access Management. Browser UI

Authorization

https://iam.us.trellix-gov.com

Identity server. Identity authorization flows

UAM Rest API

https://api.uam.us.trellix-gov.com

User Access Management. Browser UI

IAM Rest API

https://iam-rs.us.trellix-gov.com

Identify registration flows

Okta

https://login.iam.us.trellix-gov.com

Okta authentication flows

Sign on

https://ui.iam.us.trellix-gov.com

User logon. Browser UI

DXL needs to be allowed on endpoints (clients) to Trellix EDR cloud services.

Service

FQDN

Description

Trellix EDR API

https://api.soc.us.trellix-gov.com

Trellix EDR interface and investigation flows

Authorization

https://iam.us.trellix-gov.com

Identity server. Identity authorization flows

RS

https://iam-rs.us.trellix-gov.com

Identify registration flows

The following IAM URLs can be used to register a tenant in the Cloud Bridge extension.

Service

FQDN

Trellix ePO - SaaS authentication server URI

https://iam.us.trellix-gov.com/iam/v1.0

Trellix ePO - SaaS registration service URI

https://iam-rs.us.trellix-gov.com/iam-registration-service/v1.1

Trellix ePO - SaaS user and access management URI

https://api.uam.us.trellix-gov.com/govprod/api/v1

Trellix ePO - SaaS SSO logon URL

https://ui.iam.us.trellix-gov.com

Trellix ePO - SaaS SSO issuer

https://iam.us.trellix-gov.com/iam/v1.0

Trellix ePO - TPSURL

https://tps.epo.us.trellix-gov.com/

Table 2  Common paths for Trellix ePO - On-prem and Trellix ePO - SaaS implementations 

Source

Destination

Port

Description

URL


Browsers

Trellix EDR workspace

TCP 443

Access Trellix EDR interface

• https:// ui.soc.us.trellix-gov.com

• https://auth.ui.trellix.com

Endpoint —Trellix Agent

Enterprise DNS server

TCP 443

Resolution of Trellix GTI URLs.

  • tie.gti.trellix.com

  • tieserver.rest.gti.trellix.com

Endpoint — Trellix EDR Agent

Trellix EDR workspace

TCP 443

Snapshots (default route, and recommended one)

https://ui.soc.us.trellix-gov.com


All components

Enterprise NTP server

TCP 123

Network time synchronization


Administrator workstation

Trellix ePolicy

Orchestrator On-prem

TCP 8443

Required only during the Trellix EDR service installation to configure Trellix Agent.


Administrator workstation

Trellix ePO - SaaS

TCP 443



Endpoint — Phoenix Agent

Trellix EDR workspace

TCP 443

Snapshot Agent, it detects proxy settings automatically.

https://ui.soc.us.trellix-gov.com

Table 3  Specific paths - Implementation with Trellix ePO - On-prem 

Source

Destination

Port

Description

URL

Endpoint — Trellix Agent

Trellix ePO -

On-prem

TCP 80

TCP 443

Policies download, Trellix system logs upload.


Trellix ePO - On-prem /

Endpoint

(Trellix Agent)

Endpoint (Trellix Agent)

TCP 8081

Trellix Agent wake-up call / SADR/Peer-to-Peer/Relay. See Trellix Agent KB66797.


Trellix ePO - On-prem /

Endpoint

(Trellix Agent)

Endpoint (Trellix Agent)

UDP 8082

Super agent/agent update broadcast, Peer-to-Peer server discovery, RelayServer discovery.


Endpoint

(Trellix Agent)

Endpoint (Trellix Agent)

UDP 8083

RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open.


Endpoint

(Trellix Agent)

Trellix ePO On-prem /AH/ Repos /Endpoint

(Trellix Agent )

SADR

ICMP

Ping or Subnet distance calculation


Endpoint

(Trellix Agent

5.6 or Trellix

DXL client)

Trellix DXL broker

TCP 8883

Trellix DXL messaging


Trellix EDR

Databus

Trellix EDR workspace

TCP 443

Send information to Trellix EDR workspace:

  • Trace data from Endpoints / Trellix EDR client.

  • Real-time search responses from Endpoints /Trellix EDR client.

https://api.soc.us.trellix-gov.com/cloudproxy/databus/produce

Trellix DXL broker

IAM

TCP 443

Authentication

  • https://iam.us.trellix-gov.com

  • https://iam-rs.us.trellix-gov.com

Trellix Endpoint

IAM

TCP 443

Authentication

  • https://iam.us.trellix-gov.com

  • https://iam-rs.us.trellix-gov.com

Trellix ePO -

On-prem

IAM

TCP 443

Authentication

  • https://iam.us.trellix-gov.com

  • https://iam-rs.us.trellix-gov.com

Trellix ePO -

On-prem

Trellix EDR workspace

TCP 443

Queries and responses used in investigations (examples, queries to Trellix ePO - On-prem events and queries to SIEM).

As of today, bridge for Trellix

DXL cloud to on-premises (real-time queries and remediations). This will change in future versions of Trellix DXL .

Alternate route for Snapshots.

https://api.soc.us.trellix-gov.com/

Trellix ePO -

On-prem

Endpoint (Trellix EDR client)

Configurable by default 8088 and 8089

Alternate route for snapshots

(not by default, not recommended).


Trellix DXL broker

Trellix ePO -

On-prem

TCP 443

Policies download, Trellix system logs upload.


Trellix ePO - On-prem

Trellix DXL broker

TCP 8081

Trellix Agent wake-up call. See Trellix Agent KB66797.


Table 4  Specific paths — Implementation with Trellix ePO - SaaS 

Source

Destination

Port

Description

URL

Endpoint — Trellix Agent

Trellix ePO - SaaS

TCP 80

Policies download, Trellix

Agent system logs upload.

POD specific Implementation —

ah-<pod>.manage.trellix.com. Only one URL



Trellix Agent handlers

TCP 443


per POD.

Currently:

• https://ah.gov001.epo.us.trellix-gov.com/

Trellix ePO - SaaS

Endpoint (Trellix Agent)

TCP 8081

Trellix Agent wakeup call/

SADR (not supported) /

Peer-to-Peer/ Relay. See Trellix Agent KB66797.


TCP 8082

Peer-to-peer server discovery, RelayServer discovery.


TCP 8083

RelayServer discovery for previous versions of Trellix Agent, if Enable RelayServer is selected on the Trellix Agent policy. If deselected, this port is not open.


Endpoint — (Trellix Agent 5.6 or Trellix DXL client)

Trellix ePO - SaaS

TCP 443

Trellix DXL messaging (ICMP is not supported) and real-time search queries.

POD specific implementation — dxl-<pod>.manage.trellix.com. Only one URL per POD. Currently:

• dxl.gov001.epo.us.trellix-gov.com

Endpoint — (Trellix Agent 5.6 workspace

or Trellix DXL client)

Trellix EDR workspace

TCP 443

Send information to Trellix EDR workspace:

  • Trace data from Endpoints /Trellix EDR client.

  • Real-time search responses from Endpoints /Trellix EDR client.


Configure Trellix ePO - On-prem and Trellix EDR interconnection

You can set up and configure the existing Trellix ePO - On-prem connections to the Trellix EDR within the FedRAMP boundary. This connection allows the Trellix EDR user interface to monitor or view threat events normally viewed by the Trellix ePO On-prem server.

Task

  1. On the Trellix ePO – On-prem ePO Server, run the following remote command from a web browser, using your values for the variables. Caution with cut & paste regarding spacing.

    Template Command:

    https://<epo fqdn>:<port>/remote/cloudbridge.updateIAMConfig? newIAMCID=efb532b4d8e914c2619d&newIAMURL=https://iam.us.trellix-gov.com/iam/ v1.0&newIRSURL=https://iam-rs.us.trellix-gov.com/iam-registration-service/ v1.1&newUAMURL=https://api.uam.us.trellix-gov.com/govprod/api/v1&newMVISIONSSOIssuer=https:// iam.us.trellix-gov.com/iam/v1.0&newMVISIONSSOSignInURL=https://ui.iam.us.trellix-gov.com/ &newTPSURL=https://tps.epo.us.trellix-gov.com/govprod/api/v1/tenant/

    This sets the IAM connection status as OK.

  2. On Trellix ePO - On-prem, select Menu | Server Settings | Trellix CB to configure the Trellix ePO - SaaS Cloud Bridge.

    This step must be performed using the Trellix EDR Tenant administrator user credentials.

    Note: The Tenant administrator user must not have been onboarded in Trellix ePO - SaaS.

  3. Select Menu | Users to add details and configure the Trellix Tenant administrator user in the Trellix ePO - On-prem server.

    Note: This is not a mandatory step.

  4. Select Menu | Server Settings to configure DXL Cloud Databus with the Trellix EDR Monitoring URL.

    FedRAMP UAM URL — https://api.soc.us.trellix-gov.com/cloudproxy/databus/produce

  5. Select Menu | Server Settings | Trellix EDR Settings to make sure that Monitoring Activated indicates True and Connection Status indicates Connection Successful for the Trellix EDR Cloud services.

    Note: Once the connection is successful, Monitoring Activated might take one or two minutes to reflect as True.

  6. Log on to the FedRAMP Trellix EDR user interface. Make sure the configuration of Trellix EDR managed using Trellix ePO On-prem is complete by verifying the below items.

    1. Check the Monitoring dashboard for the traces.

    2. Search endpoint data using the Real-time Search "and" or "or" Historical Search dashboards.

    3. Validate Trellix EDR workflows by performing actions as needed.

Unsupported Trellix EDR features in the FedRAMP environment

The following features in the Trellix EDR commercial environment are not yet available in the FedRAMP environment.

  • Trellix EDR integration with Trellix Intelligent Sandbox and Trellix SIEM products.

  • Trellix EDR sending traces to external Amazon S3 bucket