Trellix EDR with Forensics provides a Federal Information Processing Standard (FIPS) mode for environments requiring high-level security. This mode follows the security guidelines detailed in FIPS 140-2 for Trellix EDR and Endpoint Security (HX).
In FIPS mode, Trellix EDR with Forensics:
Enforces constraints on allowed security methods.
Performs integrity tests on startup.
Restricts connections to FIPS-validated devices only.
The cryptographic boundary
FIPS validation requires an explicitly defined continuous perimeter that establishes the physical bounds of a cryptographic module.
The cryptographic boundary defines this perimeter and contains the set of hardware, software, and firmware that implements valid security functions. Only the approved set of interfaces can access the cryptographic modules inside the cryptographic boundary. No other mechanism is allowed or provided when in FIPS mode.
Modules in the boundary perform these processes:
FIPS-validated security methods performing cryptography, hashing, and related services running in Trellix EDR
Startup and verification testing needed by FIPS
Extension and executable signature verification
TLS connection management
Cryptographic API wrapping
Trellix EDR with Forensics feature status in FIPS mode
Feature status | Description |
|---|---|
Features not available in FIPS mode | When FIPS mode is enabled on the Windows endpoints, Trellix EDR with Forensics disables or ignores the MD5 hash usage. The following dashboards show the behavior of the MD5 hash value:
|
For more information, see Deploy EDRF in FIPS mode.