Trellix Application and Change Control 8.4.5 Windows Release Notes

Prev Next

The Trellix Application and Change Control 8.4.5 release includes new features, enhancements, and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating

The rating defines the urgency for installing this update.

This release is recommended for all environments. Apply this update at the earliest convenience.

Release details

For release dates and build numbers, see KB87944.

Upgrade support

This release supports upgrading from:

  • TACC extension 8.3.6–8.3.8, 8.4.0, 8.4.1, 8.4.2, 8.4.3, and 8.4.4

    Note

    TACC 8.4.5 requires Trellix ePO - On-prem 5.10.0 Service Pack 1 Update 3 or later.

    When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.

    Note

    Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values. For details, see KB96798.

  • TACC client 8.3.6, 8.3.7, 8.4.0, 8.4.1, 8.4.2, 8.4.3, and 8.4.4

For information about the TACC extension and client upgrade supported path, see KB87944.

New or changed

[TACC Client] Request approval for users without administrative rights — Users without administrative rights can now request approval for restricted actions.

[TACC Extension] Registry bypass for Windows rule groupsTrellix Application Control now includes a registry bypass option for Windows rule groups. In the Exclusions tab, select Advanced OptionsExclude file from registry operations to apply the registry bypass (attr -g) to a specific process. This policy bypasses registry operations for the specified process on the client.

[TACC Extension] Skiplist for Linux rule groups — The skiplist (-s) option is now available in the user interface for Linux rule groups. In Application Control (Unix) rule groups, select the Exclusions tab, then select Exclude local path and all its files and sub-directories from the allow list. Use this option to exclude a local path and its contents from the allow list.

[TACC Client and Extension] Exclusive TIE Enterprise reputation source — This release introduces an enhancement to the Trellix Threat Intelligence Exchange (TIE) integration. A new TIE Enterprise Trust Level option is now available in the Application Control Options (Windows) policy. When you enable this option, Application Control uses TIE Enterprise as the exclusive source for file reputations, disabling the use of Trellix GTI and Intelligent Sandbox reputations.

Note the following behavior for this feature:

  • The TIE Enterprise Trust Level option can only be configured in the policy through ePO; it cannot be modified on the endpoint.

  • When this option is enabled in the policy, the Trellix GTI reputation feature cannot be enabled by a user on the endpoint.

  • If a user disables the TIE reputation feature on the endpoint, both the TIE reputation feature and the TIE Enterprise Trust Level setting are disabled locally, with the trust level resetting to zero.

To improve visibility, a new TieEnterpriseLevelTrustEnable property has been added to the System Tree. This property displays the status of the TIE Enterprise Trust Level for each endpoint, allowing you to quickly verify whether the setting is enabled or disabled across your environment.

[TACC Extension] Enhanced reputation display for TIE overrides — To provide a clear context for user-defined reputations, the display format in the Solidcore Events page has been updated. An (Enterprise) suffix is now added for events generated for files whose reputation was specifically overridden as Malicious by a user through the TIE Reputations page.

This applies to events originating from endpoints where the deny reasons are either TIE - Malicious process SHA-1 or TIE - Malicious Certificate.

The Reputation column in the Solidcore Events page now displays these overridden reputations as:

  • Known Malicious (Enterprise)

  • Most Likely Malicious (Enterprise)

  • Might Be Malicious (Enterprise)

Known issues

For a list of current known issues, see Application and Change Control 8.x Known Issues (KB87839).

Resolved issues

This release resolves known issues.

TACC extension

Category

Reference

Resolution

Fixes to features

MACC-15736

Resolved an issue where a regular expression (regex) validation error prevented the use of the wildcard character (*) in the Trusted Local Group configuration.

User Interface

MACC-15093

Resolved an issue where the Inventory Update Time displayed incorrectly in the By Systems UI because of an incorrect Coordinated Universal Time (UTC) mapping.

Performance

MACC-15338

Optimized the Inventory Clean-up workflow to delete binary paths in batches of 2000 to prevent ePO - On-prem unresponsiveness.

Fixes to features

MACC-13508

Resolved an issue where default rule groups for some Linux distributions were missing from the Integrity Monitor rules page.

Fixes to features

MACC-15837

Resolved an issue where the Orion.log file recorded excessive SCORDashboard warnings when users without administrator permissions logged on.

Performance

MACC-15777

Improved Policy Discovery page load performance by reverting to the stable query structure.



TACC client

Category

Reference

Resolution

Performance

MACC-15838

Resolved a memory leak issue identified in TACC 8.4.4.

Security

MACC-15709

Resolved an issue where TACC incorrectly allowed files to execute from Distributed File System (DFS) shares.

Security

MACC-15577

Resolved an issue where an internal error caused execution control to fail and block the SYSTEM process.

Interoperability

MACC-13530

Resolved an issue where the software incorrectly identified solidified .psm1 files as unsolidified and denied execution on Windows 11. For information about case sensitivity configuration, see Configuring Case Sensitivity on ePO-Managed Solidcore Client.

Fixes to features

MACC-15543

Resolved an issue where the s3diag.log file did not record FILE_CREATED events for .ps1 and .cpl files copied from a remote system.

Security

MACC-15339

Resolved an issue where privileged users could not write or delete files on specific endpoints due to null user SID values.

Fixes to features

MACC-16133

Resolved an issue where a BugCheck 50 occurred after restarting a Windows 11 system with Driver Verifier enabled.

Fixes to features

MACC-16088

Resolved an issue where a BugCheck C4 occurred after restarting a Windows 11 system with Driver Verifier enabled.

Security

MACC-16030

Resolved an issue where TACC blocked the execution of the MER tool and SSSO Launcher due to missing certificates.

Fixes to features

MACC-15102

Resolved an issue where TACC stopped responding when the system parsed specific drive paths.

Performance

MACC-14669

Optimized boot and application launch performance and eliminated reputation checks for known trusted system files.