The Trellix Application and Change Control 8.4.0 release includes enhancements to features and resolved issues.
Release details
For release dates and build numbers, see KB87944.
Upgrade support
This release supports upgrading from:
TACC extension 8.2.x and 8.3.0–8.3.8
When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.
TACC client 8.2.x and 8.3.0–8.3.7
For information about the TACC extension and client upgrade supported path, see KB87944.
New or changed
Customize client configuration—TACC client configurations are now integrated with the extension, making it easy to modify these configurations by pushing them through policy changes. For details, see KB96798.
Note
Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values.
Windows major updates in Enable mode—TACC 8.4.0 supports Windows major updates directly in Enable mode. You no longer need to switch the endpoint to Update mode before updating. After the Windows update is complete, proceed with resolidification. For details, see KB86551.
Rebranding changes in TACC Extension UI—Default policy names are now updated to replace McAfee Default with Trellix Default.
Rebranding changes in TACC Client UI—Event descriptions in Event Viewer are now updated to replace McAfee with Trellix.
Enhanced registry key security—TACC 8.4.0 supports enhanced integrity protection for the TACC registry key in update mode. Previously, registry entries of TACC were editable in update mode. Now, with version 8.4.0, these entries are secured against unauthorized changes in update mode. To disable integrity protection, run sadmin config set CustomerConfig=0x1229a (value is for example). By disabling this protection, users can proceed with updates as usual. For details, see KB97058.
Removed feature
In this release, we have removed some deprecated TACC UI features from Server Tasks, Queries & Reports, Policy Catalog, Dashboard, Solidcore rules, and Other tabs. For more information, see KB96942.
Known issues
For a list of current known issues, see Application Control 8.x Known Issues (KB87839) and Change Control 8.x Known Issues (KB87838).
Resolved issues
This release resolves known issues.
TACC extension
Category | Reference | Resolution |
|---|---|---|
User interface | MACC-11381 | Automatic Response configured to send threat events to the syslog server now runs successfully in ePO - On-prem 5.10 CU12 and above. |
User interface | MACC-11394 | Solidcore Inv/PD/CCT/ClientTasks event IDs now get registered on Event Filtering UI. Hence, these events can be restricted from going to the syslog server using the Event Filtering option. |
TACC client
Category | Reference | Resolution |
|---|---|---|
Fixes to features | MACC-11372 | The files are now successfully submitted to Trellix Intelligent Sandbox for analysis using port 443. |
Fixes to features | MACC-11302 | TACC events now get prioritized based on the Trellix Agent forwarding time interval. |
User interface | MACC-11467 | Solidcore events (in XML file) now show the correct operating system information. |
Fixes to features | MACC-11465 | Parsed event no longer changes the original encoded values to lowercase. |
Fixes to features | MACC-11865 | The default list for updaters now remains the same for all versions of TACC 8.3.x. |
Interoperability | MACC-12292 | The Vagrant application now works as expected with TACC in enabled mode with the added configuration entries. |
Performance | MACC-12397 | Memory leak due to QSGa Paged & Pool Nonpaged is no longer seen. |
Fixes to features | MACC-11920 | TACC End User Notifications policy option now generates the correct URL to show event details. |
Fixes to features | MACC-11642 | Solidcore Execution Control no longer fails when the rule triggers the event. |
Performance | MACC-11492 | TACC application latency is not seen during login and switching between modes. |