October 29, 2024 release

Prev Next

This Trellix Endpoint Detection and Response 4.2.1 (On-premises and SaaS) release includes new features and resolved issues.

Release details

Component

Version

Trellix EDR Client for Windows

4.2.1.4528

Trellix EDR Client for macOS

4.2.0.3461

Trellix EDR Client for Linux

4.2.1.4637

Trellix EDR Client Extension

4.2.1.155

Trellix EDR Endpoint Snapshot Tool 1

6.6.0.10

Trellix EDR Windows Rules

4.2.1.4528

Trellix EDR macOS Rules

4.2.0.3461

Trellix EDR Linux Rules

4.2.1.4637

Note

This release does not deliver the Trellix EDR 4.2.1 Mac versions at this time.

1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.

Important

(For use with ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.

(For use with ePO - SaaS only) After upgrading macOS endpoints to the latest versions of products, recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.

Updated platform, environment, or operating system support

Trellix EDR client is now compatible with:

  • Amazon Linux 2

  • Amazon Linux 2023 on X64

For the complete list of system requirements, see KB91345.

New features and changes

Trellix EDR supports FIPS enabled endpoints: You can now install Trellix EDR client on Linux operating systems running in FIPS mode to perform the cryptographic operations in a way that is validated with FIPS 140-2. For more details, see Trellix EDR in FIPS mode.

Optimized Linux trace buffering feature — This release reduces the CPU consumption by optimizing Linux trace buffering feature.

ISecGRT dependencies removed on Linux endpoints — This release removes the ISecGRT dependencies on Linux endpoints to reduce complexity and support new compiler features.

Resolved issues

Reference

Resolution

SEC-183841

The EDR policies are updated to exclude process(es) and disable trace rules on Linux endpoints.

SEC-184421

This release resolves the issue of empty field occurence in a few traces under parentTraceIds fields.

SEC-184753

Resolves hard disk write rate issue when EDR trace is enabled to ensure optimal write rate.

Known issues

For a list of known issues in this product release, see KB91275.

Installation information

The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.