Trellix Agent installation package ( ePO - On-prem )

Prev Next

You install the agent on client systems using the installation package generated when you install ePO - On-prem or check in the agent package.

This file is a customized installation package for Trellix Agent that reports to your ePO - On-prem. The package contains information needed for Trellix Agent to communicate with the server. Specifically, this package includes:

  • Trellix Agent installer

  • Sitelist.xml file

  • srpubkey.bin (the server public key)

  • reqseckey.bin (the initial request key)

  • req2048seckey.bin

  • sr2048pubkey.bin

  • agentfipsmode file

The default location of the installation package file:

  • For ePO - On-prem 5.10.0 Service Pack 1 or later: <System Drive>\Program Files (x86)\Trellix\ePolicy Orchestrator\DB\Software\Current\<Product Id>\Install\0409.

  • For ePO - On-prem 5.10.0 or earlier: <System Drive>\Program Files (x86)\McAfee\ePolicy Orchestrator\DB\Software\Current\<Product Id>\Install\0409.

Product IDs for supported operating systems are listed in the following table.

Operating System

Product ID

Linux

EPOAGENT3700LYNX

Windows

EPOAGENT3000

Macintosh

EPOAGENT3700MACX

The Windows installation package is FramePkg.exe and the non-Windows package is install.sh.

This is the installation package that ePO - On-prem uses to distribute and install Trellix Agent. FramePkg.exe files are created when:

  • You specifically create one in ePO - On-prem

  • Trellix Agent packages are checked in to any branch of the repository (Previous, Current, or Evaluation)

  • Encryption key changes

The default Trellix Agent installation package doesn't contain user credentials. When executed on the targeted system, the installation uses the account of the currently logged-on user.

You can create custom installation packages with embedded credentials if needed by your environment.

Important

Because an installer package has embedded credentials, access to it must be severely restricted. Installer packages with embedded credentials must only be used in specific situations where another deployment method is not available. For additional, important information about the use of embedded credentials, see KB65538.