This Trellix Endpoint Detection and Response 4.2.0 (On-premises and SaaS) release includes new feature, enhancement, and resolved issues.
Release details
Component | Version |
|---|---|
Trellix EDR Client for Windows | 4.2.0.3455 |
Trellix EDR Client for macOS | 4.2.0.3461 |
Trellix EDR Client for Linux | 4.2.0.3481 |
Trellix EDR Client Extension | 4.2.0.555 |
Trellix EDR Endpoint Snapshot Tool 1 | 6.6.0.10 |
Trellix EDR Windows Rules | 4.2.0.3455 |
Trellix EDR macOS Rules | 4.2.0.3461 |
Trellix EDR Linux Rules | 4.2.0.3481 |
1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.
Important
(For use with ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.
(For use with ePO - SaaS only) After upgrading macOS endpoints to the latest versions of Trellix products, Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.
New or changed
Traces from macOS endpoints — The Trellix EDR trace feature now supports the mac operating system. The traces are collected from the mac endpoints to detect any suspicious activity on the endpoint and threats are shown on the Monitoring dashboard with metadata to help you in investigation.
The supported trace event types are:
File
File created
File modified
File moved
File attribute modified
File hardlinked
File deleted
Process
Process create (Fork & Exec)
Improved COM API hooking capability — This release fixes several edge cases that could cause instability or crashes in a monitored application. Improved scope of visibility into attack tactics and techniques used by adversaries.
Optimized the Linux trace performance — This release improves the memory and CPU usage of Linux trace.
Updated platform, environment, or operating system support
Trellix EDR client is now compatible with:
Windows version 23H2
macOS 14 Sonoma
Note
Trellix EDR 4.2.0 no longer supports macOS 11.x BigSur.
For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.
Resolved issues
Reference | Resolution |
|---|---|
UCFL-2878 | Fixed Trace Scanner consuming high CPU on some Linux distribution versions. |
UCFL-2888 | Fixed Trace Scanner causing high memory on the Linux endpoints (RHEL 8.7). |
SEC-106568 | Updated the OpenSSL version being used by Trellix EDR. |
SEC-109027 | Fixed an issue where network mounted shares on Linux endpoints were not being excluded by default. |
SEC-157417 | Fixed a performance issue in Trace when browsing a network share with executable files. |
SEC-174880 | Fixed compatibility issues when injected into Microsoft processes like Word and Excel(COM hooking). |
SEC-175779 | Fixed a performance issue when using AWS S3 buckets with Trace. |
SEC-175109 | Updated the Trellix EDR client logging with details in the log files highlighting the name of the collector which is disabled along with error code. |
SEC-177806 | Fixed an edge case where injection could cause a deadlock. |
SEC-175469 & SEC-180628 | Added detection of attack vector related to LSASS. |
SEC-180704 | Fixed an issue where the Trellix EDR policy tab does not appear with Internet Explorer. |
Known issues
For a list of known issues in this product release, see KB91275.
Installation information
The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.