This Trellix Endpoint Detection and Response 4.2.1 (On-premises and SaaS) release includes new features and resolved issues.
Release details
Component | Version |
|---|---|
Trellix EDR Client for Windows | 4.2.1.4528 |
Trellix EDR Client for macOS | 4.2.0.3461 |
Trellix EDR Client for Linux | 4.2.1.4637 |
Trellix EDR Client Extension | 4.2.1.155 |
Trellix EDR Endpoint Snapshot Tool 1 | 6.6.0.10 |
Trellix EDR Windows Rules | 4.2.1.4528 |
Trellix EDR macOS Rules | 4.2.0.3461 |
Trellix EDR Linux Rules | 4.2.1.4637 |
Note
This release does not deliver the Trellix EDR 4.2.1 Mac versions at this time.
1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.
Important
(For use with ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.
(For use with ePO - SaaS only) After upgrading macOS endpoints to the latest versions of products, recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.
Updated platform, environment, or operating system support
Trellix EDR client is now compatible with:
Amazon Linux 2
Amazon Linux 2023 on X64
For the complete list of system requirements, see KB91345.
New features and changes
Trellix EDR supports FIPS enabled endpoints: You can now install Trellix EDR client on Linux operating systems running in FIPS mode to perform the cryptographic operations in a way that is validated with FIPS 140-2. For more details, see Trellix EDR in FIPS mode.
Optimized Linux trace buffering feature — This release reduces the CPU consumption by optimizing Linux trace buffering feature.
ISecGRT dependencies removed on Linux endpoints — This release removes the ISecGRT dependencies on Linux endpoints to reduce complexity and support new compiler features.
Resolved issues
Reference | Resolution |
|---|---|
SEC-183841 | The EDR policies are updated to exclude process(es) and disable trace rules on Linux endpoints. |
SEC-184421 | This release resolves the issue of empty field occurence in a few traces under parentTraceIds fields. |
SEC-184753 | Resolves hard disk write rate issue when EDR trace is enabled to ensure optimal write rate. |
Known issues
For a list of known issues in this product release, see KB91275.
Installation information
The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.