Trellix Agent architecture is single threaded and asynchronous based on services (messaging) architecture. In messaging-based architecture, the services communicate using a common language. This reduces the use of system resources, such as number of threads, number of handles, memory, and CPU.
Agent version 5.6.0 is the minimum required version for McAfee ePO Cloud.
(ePO - On-prem) McAfee Agent 5.6.x supports ePO - On-prem 5.10.x or later.
The Trellix Agent 5.x.x extension manages all previous versions of Trellix Agent (4.8.x and 5.0.x). But, previous versions of the Trellix Agent management extension cannot manage Trellix Agent 5.x.x clients.
Trellix Agent includes these features:
Manifest based policy
When using Trellix Agent 5.x.x with ePO - On-prem, the manifest based policy improves the scalability of ePO - On-prem. Trellix Agent fetches only the changed policy settings from ePO - On-prem, using fewer resources for comparing or merging settings. Also, ePO - On-prem doesn't have to compute the changed policies at each agent-server communication. This helps save network bandwidth every time a policy update is downloaded.
Persistent connection
When performing an agent-server communication, Trellix Agent keeps the communication channel with ePO - On-prem alive, so that multiple requests and responses such as property upload, policy download, and events upload are passed between the agent and the Agent Handler in the same TCP connection. Once the communication is complete, the connection is closed.
Previous versions of ePO - On-prem required multiple TCP connections from Trellix Agent during a single agent-server communication. This required more network bandwidth, whereas keeping the connection alive reduces the network bandwidth.
Sensor services
Trellix Agent uses sensor services to track system events and take actions on the client system. There are two types of sensor services:
User sensors — Detects the logged on users on the client system using operating system APIs and apply the user-based policies accordingly.
Network sensors — Detects the network connectivity status using operating system network APIs and determines if the agent functionality such as pulling updates from the repository or communicating to should be performed.
Peer-to-peer communication
To retrieve updates and install products, Trellix Agent communicates with ePO - On-prem. These updates might be available with the agents in the same subnet. With peer-to-peer communication, Trellix Agent downloads updates from the peer agents in the same subnet, reducing bandwidth consumption between ePO - On-prem and Trellix Agent.
Remote provisioning
You can use remote provisioning to:
Convert an unmanaged Trellix Agent to managed — Use the command-line switch to convert Trellix Agent mode from unmanaged to managed (that is, provision to ePO - On-prem).
Migrate from one ePO - On-prem to another — Use the command-line switch to migrate Trellix Agent from one ePO - On-prem to another.
See Changing agent management modes for more details.
Third-party software authentication
Trellix Agent supports third-party integration, such as integration with software developed by SIA partners. For these third-party software to communicate with Trellix Agent, the software should have Message Bus Certificates for mutual authentication. We have added MsgbuscertupdaterPackage.zip on SDM and other source locations which certify third-party software to communicate with Trellix Agent.
Note: The MsgbuscertupdaterPackage.zip package is downloaded automatically at the client nodes. This default download task is also scheduled to download the package at 12 a.m. (local time) every day.
Self-protection
Trellix Agent protects unauthorized access to all internal Agent assets such as the databases, files, folders, and registries using VSCore. The admin can choose to enable or disable the service protection with Trellix Agent self-protection policy.
Because Agent version 5.0.5 or later doesn't consume SysCore in its installer, it doesn't upgrade or install SysCore on the system. This makes Trellix Agent installer lightweight and reduces the size of the package and installation time. Once a supported version of SysCore (15.3.0.673 or later) is installed on the system, Trellix Agent starts using its protection capabilities, enables self-protection for files, folders, registry, services, and executables.
Installer improvements
In the event of shutdown or restart, Trellix Agent now provides additional information to the user when products are being deployed onto the system.
If the user initiates system shutdown or restart when the agent is deploying products, Trellix Agent notifies the user that the shutdown can't continue. If continued, this might cause stability issues to the operating system. The user can still continue with the shutdown operation. Once the product deployment is complete, the user can reinitiate shutdown later by clicking Cancel on the notification displayed. If not, the system automatically continues for shutdown.
Note: Trellix product updates such as DAT and content updates are not affected by this new feature.
(ePO - On-prem) Incompatibility check
McAfee Agent 5.6.0 checks for incompatibility with products before it is deployed on the client system using ePO - On-prem the deployment task. Trellix Agent has in-built content driven incompatibility specification list which controls the product installation using the ePO - On-prem deployment task.
McAfee Agent 5.6.0 has the capability to block the deployment of incompatible products on the client system, which is based on the incompatibility specification list.
Management platform support
Below table shows the management platform support for Trellix Agent features and functionality.
Feature | ePO - On-prem | McAfee ePO Cloud | ePO - SaaS |
|---|---|---|---|
RelayServer | Yes | Yes | Yes |
Peer-to-peer | Yes | Yes | Yes |
Trellix Smart Installer | Yes | Yes | Yes |
Property collection | Yes | Yes | Yes |
Policy enforcement | Yes | Yes | Yes |
Task enforcement | Yes | Yes | Yes |
Trellix Agent Wake-up | Yes | Yes | Yes |
Product Update | Yes | Yes | Yes |
Product Deployment | Yes | Yes | Yes |
Event Forwarding | Yes | Yes | Yes |
Automatic Trellix Agent uninstall from Trellix ePO | Yes | Yes | Yes |
Remote provisioning | Yes | Yes | Yes |
Incompatibility check | Yes | No | Yes |
SuperAgent | Yes | No | No |
Run Client Task Now | Yes | No | No |
Remote log access | Yes | No | No |
User-based policy | Yes | Yes | Yes |
Data channel support | Yes | No | No |
Mirror Task | Yes | No | No |
UNC repository updating | Yes | No | No |