This section describes new features in the Trellix Endpoint Security Agent (HX) release 35.31.22.
Endpoint Security (HX) Agent version 35.31.22 adds memory audit support for the following additional operating systems:
Windows 11 22H2
Windows 10 22H2
Windows Server 2022
Endpoint Security (HX) Agent version 35.31.22 adds support for the Linux Capsule8 sensor version 4.10.1. Eventor exclusions now support symbolic links for agents running on Linux. The following operating systems are no longer supported by Endpoint Security Agent 35.31.22:
RHEL 6
CentOS 6
Ubuntu 14.04 with kernel 3.16
Oracle 6 with kernel 2.6.32
Endpoint Security (HX) Agent version 35.31.22 supports the following new browser-related audits:
Cookie History, File Download History, Form History, and URL History audits on Brave browser for endpoints running macOS and Windows.
Cookie History, File Download History, Form History, and URL History audits on Firefox ESR browser for endpoints running macOS and Windows.
Cookie History and Form History browser audits on Chrome browser for endpoints running Windows.
Browser-related audits for macOS when no browser is selected. The audit is performed on all supported browsers.
Persistence browser audits for endpoints running macOS 13.
Quarantine Events audits for endpoints running macOS 12 and 13.
Improved filtering in audits allows you to acquire multiple files from one host. You can now specify which files to extract based upon their contents, hash value, or file type.
Users with the Administrator or Investigator role can now restart the FireEye agent running on the hosts via the Endpoint Server UI.
Improved security for the agent configuration file prevents the local export and import of designated sensitive fields. User credentials and authenticated proxy information are excluded from the configuration results. Administration users can now view which policy configuration is applied to the host by exporting the agent policy configuration via the Endpoint Security (HX) Server UI.
Endpoint Security (HX) Agent version 35.31.22 comes with improved agent logging features.
You can specify the number of days logged to be retained by the agent.
Exported agent log files now include the agent version information.
You can specify registry keys for exclusion during monitoring instead of capturing the full activity. This feature offers you more flexibility and increased performance for the monitoring system.
Microsoft's Azure Code Signing service is now required for agent antivirus drivers running on Windows 10 and Windows 11.
Endpoint Security (HX) Agent version 35.31.22 now includes the McAfee GTI Cloud lookup feature for Malware Guard detections. The new GTI Cloud lookup feature reduces false positives by comparing Malware Guard detections to the GTI Cloud data before alerts are generated. GTI Cloud lookup is disabled by default.
In this release, many features, services, add/remove program entries, and process descriptions have been updated to the new Trellix company name and logo.
Endpoint Security (HX) Agent version 35.31.22 now allows you to disable the SYSTEM account on the "process/deny_local_admin_stop" config key for Tamper protection. Disabling the account prevents both local administrators and the SYSTEM account from accessing agent services or bypassing the protection to uninstall the agent.