Endpoint Forensics Bridge Release Notes

Prev Next

This Trellix Endpoint Forensics Bridge - January 2024 release includes an enhanced capability for Trellix EDR and Trellix ePO.

Advance the Trellix EDR and Trellix ePO capabilities using Trellix Endpoint Forensics Bridge

Trellix Endpoint Forensics Bridge connects the Trellix Endpoint Detection and Response and Trellix ePO ecosystem with Trellix Endpoint Security (HX) to provide a more unified solution for endpoint security. You can choose to view alerts or threats from multiple Trellix sources on Trellix EDR and Trellix ePO.

Trellix Endpoint Forensics Bridge consists of the following components:

  • Trellix Endpoint Forensics Bridge ePO extension — the supported version is 36.0.0.95

  • Trellix Endpoint Security Agent (HX) package for Windows, Linux, and macOS endpoints. The supported versions are:

    • Windows — 35.31.25

    • Linux — 36.21.0

    • Mac — 36.20.0

  • Corresponding Trellix Endpoint Security (HX) module named Forensics Bridge — the supported version is 1.0.6

    The Forensic Bridge module utilizes the Trellix Endpoint Security (HX) Agent, also known as xAgent, to provide additional alerting.

    For more information about the Forensics Bridge module, including supported platforms, resolved issues, and known issues, see the Forensics Bridge module Release Notes.

Trellix Endpoint Forensics Bridge enables the following capabilities:

  • Single phase deployment—You can deploy Agent (HX), along with Trellix ENS and Trellix EDR clients, either individually or as combined deployment tasks using ePO - On-prem or ePO - SaaS. Previously, Agent (HX) deployment was done only through HX. However, you can now choose either of the methods. With Trellix ePO, you will continue to have the capability to manage both Trellix ENS and Trellix EDR, while HX remains the platform for configuring Agent (HX) settings. Use the Product Deployment page from the Trellix ePO console to deploy Client or Agent packages on your endpoints.

    Important

    Trellix Endpoint Forensics Bridge requires you to install and configure HX and several modules such as AMSI, Logon Tracker, and Forensics Bridge.

  • Unified view to alerts—You can get a consolidated perspective on alerts from various Trellix agent sources, enhancing the alerting experience on both Trellix EDR and Trellix ePO platforms. Once the products are deployed, the solution thoroughly assesses both new and past events on your endpoints, incorporating Trellix Endpoint Security (HX) data like Logon Tracker, AMSI, and IOC alerts. These additional alerts or potential threats are presented on Trellix ePO and Trellix EDR consoles, providing you with relevant information.

    This covers three alert types:

    • IOC Alerts—Enriches Trellix EDR and Trellix ePO with the deep detections uncovered by Trellix Endpoint Forensics Bridge.

    • AMSI Alerts—Provides insight into malicious activity being performed through PowerShell and other scripts.

    • Logon Tracker—Provides detections on suspicious logon activities, further enabling the detection of lateral movement.

    Note

    The alerts displayed on HX are shown as Trellix Forensics (AMSI, IOC, or LT) Alert on the TEDR console. In APIs, alerts are displayed as LT (Logon Tracker), AMSI, and IOC.

  • Integrated detection and response— Use the native capabilities of Trellix EDR to investigate Agent (HX)-originated threats on your endpoints .

    • Trellix EDRTrellix EDR enables you to visualize the additional context for threats and endpoints associated with them. You can drill into the additional data and telemetry such as threat behavior, process activity, sequence of events leading to the compromise, and so on. Also, If you want to do in-depth investigation of a Logon Tracker, AMSI, or IOC related alert, you can do so in the Trellix Endpoint Security (HX) UI by navigating to the Hosts page to view the triage acquisition for the host.

      The observed threat behaviors are aligned with the MITRE ATT&CK™ framework. TEDR identifies adversary Tactics, Techniques, and Procedures (TTPs) as defined by MITRE.

    • Trellix ePO—You can optionally direct the Endpoint Forensics Bridge to send the xAgent alerts to Trellix ePO. Within Trellix ePO, you can view alerts as well as create dashboards and actions based on the new alerts.

This release represents an initial step in the journey to normalize converge our Trellix EDR products under XConsole and Trellix XDR with expanded feature sets and updated cross-product workflows.

New certificates to sign Trellix software

As part of Trellix rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update or installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.

For information on downloading and installing the certificates, see KB91697.

Installation information

For details about installation, configuration, and usage of Trellix Forensics, see Trellix Endpoint Forensics Bridge Product Guide.