This Trellix Endpoint Detection and Response 4.2.1 (On-premises and SaaS) release includes resolved issues.
Release details
Component | Version |
|---|---|
Trellix EDR Client for Windows | 4.2.1.4528 |
Trellix EDR Client for macOS | 4.2.0.3461 |
Trellix EDR Client for Linux | 4.2.0.3481 |
Trellix EDR Client Extension | 4.2.1.85 |
Trellix EDR Endpoint Snapshot Tool 1 | 6.6.0.10 |
Trellix EDR Windows Rules | 4.2.1.4528 |
Trellix EDR macOS Rules | 4.2.0.3461 |
Trellix EDR Linux Rules | 4.2.0.3481 |
Note
This release does not deliver the Trellix EDR 4.2.1 Linux and Mac versions at this time.
1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.
Important
(For use with ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.
(For use with ePO - SaaS only) After upgrading macOS endpoints to the latest versions of Trellix products, Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.
Updated platform, environment, or operating system support
For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.
Resolved issues
Reference | Resolution |
|---|---|
SEC-182936 | The COM MAPI hooking capability is now improved. Hence, Microsoft Office Applications no longer crashes on endpoints. |
SEC-180345 | Trellix EDR successfully now detects the .net COM API detections on endpoints. |
SEC-181482 | Addresses a high memory consumption issue on endpoints. |
SEC-183841 | The Trellix EDR Policy Catalog page now has separate input fields for the Linux rules for ignoring processes and disabling trace rules. |
SEC-184296 | The Trellix ePO Reports and Queries page now successfully shows the threat events when you query for EDR Threats Events in the Last 4 hours. |
Known issues
For a list of known issues in this product release, see KB91275.
Installation information
The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.