January 09, 2024 release

Prev Next

This Trellix Endpoint Detection and Response 4.2.0 (On-premises and SaaS) release includes new feature, enhancement, and resolved issues.

Release details

Component

Version

Trellix EDR Client for Windows

4.2.0.3455

Trellix EDR Client for macOS

4.2.0.3461

Trellix EDR Client for Linux

4.2.0.3481

Trellix EDR Client Extension

4.2.0.555

Trellix EDR Endpoint Snapshot Tool 1

6.6.0.10

Trellix EDR Windows Rules

4.2.0.3455

Trellix EDR macOS Rules

4.2.0.3461

Trellix EDR Linux Rules

4.2.0.3481

1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.

Important

(For use with ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.

(For use with ePO - SaaS only) After upgrading macOS endpoints to the latest versions of Trellix products, Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.

New or changed

  • Traces from macOS endpoints — The Trellix EDR trace feature now supports the mac operating system. The traces are collected from the mac endpoints to detect any suspicious activity on the endpoint and threats are shown on the Monitoring dashboard with metadata to help you in investigation.

    The supported trace event types are:

    • File

      • File created

      • File modified

      • File moved

      • File attribute modified

      • File hardlinked

      • File deleted

    • Process

      • Process create (Fork & Exec)

  • Improved COM API hooking capability — This release fixes several edge cases that could cause instability or crashes in a monitored application. Improved scope of visibility into attack tactics and techniques used by adversaries.

  • Optimized the Linux trace performance — This release improves the memory and CPU usage of Linux trace.

Updated platform, environment, or operating system support

Trellix EDR client is now compatible with:

  • Windows version 23H2

  • macOS 14 Sonoma

Note

Trellix EDR 4.2.0 no longer supports macOS 11.x BigSur.

For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.

Resolved issues

Reference

Resolution

UCFL-2878

Fixed Trace Scanner consuming high CPU on some Linux distribution versions.

UCFL-2888

Fixed Trace Scanner causing high memory on the Linux endpoints (RHEL 8.7).

SEC-106568

Updated the OpenSSL version being used by Trellix EDR.

SEC-109027

Fixed an issue where network mounted shares on Linux endpoints were not being excluded by default.

SEC-157417

Fixed a performance issue in Trace when browsing a network share with executable files.

SEC-174880

Fixed compatibility issues when injected into Microsoft processes like Word and Excel(COM hooking).

SEC-175779

Fixed a performance issue when using AWS S3 buckets with Trace.

SEC-175109

Updated the Trellix EDR client logging with details in the log files highlighting the name of the collector which is disabled along with error code.

SEC-177806

Fixed an edge case where injection could cause a deadlock.

SEC-175469 & SEC-180628

Added detection of attack vector related to LSASS.

SEC-180704

Fixed an issue where the Trellix EDR policy tab does not appear with Internet Explorer.

Known issues

For a list of known issues in this product release, see KB91275.

Installation information

The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.