Endpoint Security AMSI Module Release Notes Release 2.1.0
Last Updated: September 17, 2023


Contents
Announcements 3
FireEye Customer Security Best Practices 3
Product Compatibility 3
What's New 4
Known Issues 5
Documentation 6
1 | Announcements
Announcements
This document provides an overview of what's new, the resolved issues and known issues in the Trellix Endpoint Security AMSI Module 2.1.0 release.
FireEye Customer Security Best Practices
Because our quality assurance process includes continuous security testing, FireEye recommends updating all FireEye products with the latest releases as soon as possible. As an overall strategy to reduce risk exposure, customers are also encouraged to follow best practices, which include:
- Always keep the product version up-to-date.
- Limit network access to the management interfaces of the appliance using firewalls or similar measures.
- Only issue accounts to trusted administrators.
- Use strong passwords.
- Monitor logs.
- Restrict physical access to the appliance to trusted administrators.
Product Compatibility
- Endpoint Security Server 5.0.4 and later
- Endpoint Agent 32.0 and later
- Operating Systems
- Windows 10 and later
- Windows Server 2016 and later
macOS and Linux are not supported.
Endpoint Security AMSI Module Release Notes Release 2.1.0
3
2 | Announcements
What's New
This section describes the main features in the Endpoint Security AMSI Module release 2.1.0.
- Obtain the latest YARA rules for the AMSI Module via the Trellix DTI content package. Use AMSI to control how often to poll for and download the latest updates.
- Configure policy exclusions to bypass the AMSI scan for known scripts.
- AMSI generates alerts when malicious scripts are found and provides alert details in JSON format.
- Acquire AMSI scan artifacts on alerts.
- Control the number of alerts generated by using the confidence threshold for alerting and blocking.
- Advanced settings optimize disk space use and performance, including managing the database size on the endpoint to suit your environment.
For more information, see the AMSI Module User Guide.
3 | Announcements
Known Issues
The following issues are known issues in the AMSI Module release 2.1.0.
- Detection of AMSI bypass techniques is not supported in this release.
Endpoint Security AMSI Module Release Notes Release 2.1.05
4 | Announcements
Documentation
Documentation for all FireEye products is available on the FireEye Documentation Portal, and the FireEye Market, login is required for both sites:
COPYRIGHT
Copyright © 2026 Musarubra US LLC.
Trellix and FireEye are the trademarks or registered trademarks of Musarubra US LLC, FireEye Security Holdings US LLC, and their affiliates in the US and /or other countries. Other names and brands are the property of these companies or may be claimed as the property of others.

