Agent Key features

Prev Next

Trellix Agent architecture is single threaded and asynchronous based on services (messaging) architecture. In messaging-based architecture, the services communicate using a common language. This reduces the use of system resources, such as number of threads, number of handles, memory, and CPU.

Agent version 5.6.0 is the minimum required version for McAfee ePO Cloud.

(ePO - On-prem) McAfee Agent 5.6.x supports ePO - On-prem 5.10.x or later.

The Trellix Agent 5.x.x extension manages all previous versions of Trellix Agent (4.8.x and 5.0.x). But, previous versions of the Trellix Agent management extension cannot manage Trellix Agent 5.x.x clients.

Trellix Agent includes these features:

Manifest based policy

When using Trellix Agent 5.x.x with ePO - On-prem, the manifest based policy improves the scalability of ePO - On-prem. Trellix Agent fetches only the changed policy settings from ePO - On-prem, using fewer resources for comparing or merging settings. Also, ePO - On-prem doesn't have to compute the changed policies at each agent-server communication. This helps save network bandwidth every time a policy update is downloaded.

Persistent connection

When performing an agent-server communication, Trellix Agent keeps the communication channel with ePO - On-prem alive, so that multiple requests and responses such as property upload, policy download, and events upload are passed between the agent and the Agent Handler in the same TCP connection. Once the communication is complete, the connection is closed.

Previous versions of ePO - On-prem required multiple TCP connections from Trellix Agent during a single agent-server communication. This required more network bandwidth, whereas keeping the connection alive reduces the network bandwidth.

Sensor services

Trellix Agent uses sensor services to track system events and take actions on the client system. There are two types of sensor services:

  • User sensors — Detects the logged on users on the client system using operating system APIs and apply the user-based policies accordingly.

  • Network sensors — Detects the network connectivity status using operating system network APIs and determines if the agent functionality such as pulling updates from the repository or communicating to should be performed.

Peer-to-peer communication

To retrieve updates and install products, Trellix Agent communicates with ePO - On-prem. These updates might be available with the agents in the same subnet. With peer-to-peer communication, Trellix Agent downloads updates from the peer agents in the same subnet, reducing bandwidth consumption between ePO - On-prem and Trellix Agent.

Remote provisioning

You can use remote provisioning to:

Convert an unmanaged Trellix Agent to managed — Use the command-line switch to convert Trellix Agent mode from unmanaged to managed (that is, provision to ePO - On-prem).

Migrate from one ePO - On-prem to another — Use the command-line switch to migrate Trellix Agent from one ePO - On-prem to another.

See Changing agent management modes for more details.

Third-party software authentication

Trellix Agent supports third-party integration, such as integration with software developed by SIA partners. For these third-party software to communicate with Trellix Agent, the software should have Message Bus Certificates for mutual authentication. We have added MsgbuscertupdaterPackage.zip on SDM and other source locations which certify third-party software to communicate with Trellix Agent.

Note: The MsgbuscertupdaterPackage.zip package is downloaded automatically at the client nodes. This default download task is also scheduled to download the package at 12 a.m. (local time) every day.

Self-protection

Trellix Agent protects unauthorized access to all internal Agent assets such as the databases, files, folders, and registries using VSCore. The admin can choose to enable or disable the service protection with Trellix Agent self-protection policy.

Because Agent version 5.0.5 or later doesn't consume SysCore in its installer, it doesn't upgrade or install SysCore on the system. This makes Trellix Agent installer lightweight and reduces the size of the package and installation time. Once a supported version of SysCore (15.3.0.673 or later) is installed on the system, Trellix Agent starts using its protection capabilities, enables self-protection for files, folders, registry, services, and executables.

Installer improvements

In the event of shutdown or restart, Trellix Agent now provides additional information to the user when products are being deployed onto the system.

If the user initiates system shutdown or restart when the agent is deploying products, Trellix Agent notifies the user that the shutdown can't continue. If continued, this might cause stability issues to the operating system. The user can still continue with the shutdown operation. Once the product deployment is complete, the user can reinitiate shutdown later by clicking Cancel on the notification displayed. If not, the system automatically continues for shutdown.

Note: Trellix product updates such as DAT and content updates are not affected by this new feature.

(ePO - On-prem) Incompatibility check

McAfee Agent 5.6.0 checks for incompatibility with products before it is deployed on the client system using ePO - On-prem the deployment task. Trellix Agent has in-built content driven incompatibility specification list which controls the product installation using the ePO - On-prem deployment task.

McAfee Agent 5.6.0 has the capability to block the deployment of incompatible products on the client system, which is based on the incompatibility specification list.

Management platform support

Below table shows the management platform support for Trellix Agent features and functionality.

Feature

ePO - On-prem

McAfee ePO Cloud

ePO - SaaS

RelayServer

Yes

Yes

Yes

Peer-to-peer

Yes

Yes

Yes

Trellix Smart Installer

Yes

Yes

Yes

Property collection

Yes

Yes

Yes

Policy enforcement

Yes

Yes

Yes

Task enforcement

Yes

Yes

Yes

Trellix Agent Wake-up

Yes

Yes

Yes

Product Update

Yes

Yes

Yes

Product Deployment

Yes

Yes

Yes

Event Forwarding

Yes

Yes

Yes

Automatic Trellix Agent uninstall from Trellix ePO

Yes

Yes

Yes

Remote provisioning

Yes

Yes

Yes

Incompatibility check

Yes

No

Yes

SuperAgent

Yes

No

No

Run Client Task Now

Yes

No

No

Remote log access

Yes

No

No

User-based policy

Yes

Yes

Yes

Data channel support

Yes

No

No

Mirror Task

Yes

No

No

UNC repository updating

Yes

No

No