Trellix EDR 4.1.0 Release Notes (On-premises)

Prev Next

This Trellix Endpoint Detection and Response 4.1.0 (On-premises) release includes new features, enhancements, resolved issues, and product rebranding changes.

Release details

Component Version
Trellix EDR Client for Windows 4.1.0.2253
Trellix EDR Client for Linux 4.1.0.2243
Trellix EDR Client for macOS 4.1.0.2253
Trellix EDR Client Extension 4.1.0.1260
Trellix EDR Endpoint Snapshot Tool 1 6.6.0.10
Trellix EDR Rules 4.1.0.2253

1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.

Before installing or upgrading to the Trellix EDR client 4.1.x or later:

  • Make sure to update the MsgBus Cert Updater package to the latest version available. This package is available on Software Catalog under the Trellix Agent product.
  • Make sure to install the Trellix Data Exchange Layer Broker extension. This package is available on Software Catalog under the Trellix Data Exchange Layer product.

When you install or upgrade to Trellix EDR 4.1.x:

  • You might be required to reboot the endpoint. On some installs and upgrades, Trellix EDR installation will not proceed until the endpoint is rebooted and the installation or upgrade is restarted. For details, see KB96049.
  • Endpoints unaffected by KB96049 might be prompted to reboot the endpoint. It is a good practice to reboot the endpoint but not mandatory. The reboot message can be suppressed by disabling the Prompt User When a Reboot is Required option on the Trellix Agent properties page. For details, see Trellix Agent properties page.

New features and changes

This release includes the following features and changes.

  • Rebranding changes — You can continue to secure your organization with Trellix EDR as usual. You will notice the following changes in the software:
    • Brand logo — McAfee logo is replaced with Trellix logo.
    • User interface — Color and typeface are updated to provide better user experience.
    • Product name — MVISION EDR is renamed as Trellix EDR.
    • End User License Agreement and Copyright — The End User License Agreement and Copyright are updated according to legal requirements. For more details, read the agreement details.

    As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update/installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.

    For information on downloading and installing the certificates, see KB91697.

  • Separate Trellix EDR client packages - In this release, the single Trellix EDR client package is now split into three separate packages for each operate system — Windows, Linux, and macOS. When installing the Trellix EDR client, select the appropriate package and install on endpoints.
  • Linux traces — The Trellix EDR trace feature now supports the Linux operating system. The traces are collected from the Linux endpoints to detect any suspicious activity on the endpoint and threats are shown on the Monitoring dashboard with metadata to help you in investigation.

    Before installing the Trellix EDR client on Linux endpoints, make sure to enable kernel syscall auditing to discover security violations and track security-relevant information. For details about enabling syscall auditing on different Linux distributions, see:

    For the Linux kernel version 3.15 or earlier, the Linux trace functionality can't co-exist with auditd:

    • If auditd is running, enabling the Linux trace functionality stops the audit service.
    • To start the auditd service, the trace functionality must be disabled before restarting the auditd service.

    The audit system must not be in immutable mode to use trace functionality. Otherwise, trace process will not be able to add the audit rules.

    Note

    The audit flag to set failure must not be set to "2" (2=panic). If set, it can cause the kernel panic once the backlog limit exceeds.

    The supported event types on Linux endpoints are:

    • Processes
    • Files
    • Network connections
    • Service change events
    • User logon events
    • Kernel module load and unload events
  • Content update methods — In this release on the Trellix EDR client version 4.1.x, you have an option to select either Dynamic content update or ePO push content update method to update content on Windows endpoints.
    • By default, the Dynamic content update is selected and effective only for Windows endpoints.
    • macOS endpoints will automatically default to the ePO Push Content update method.

      For more details about the content update methods, see General policy configuration.

      Note

      The Trellix EDR content update is not supported on Linux endpoints.

      The below table gives details about the supported content update methods according to the version and operating system.

      Version Endpoints with operating system Supported methods
      4.1.x or later Windows Dynamic content update and ePO push content update
      Linux Content update is not supported
      macOS ePO push content update
      4.0.x Windows Dynamic content update
      Linux Content update is not supported
      macOS ePO push content update
      3.5.2 or earlier Windows ePO push content update
      Linux Content update is not supported
      macOS ePO push content update

Updated platform, environment, or operating system support

Trellix EDR client is now compatible with:

  • Microsoft Windows 10 and 11, version 22H2
  • Red Hat Enterprise Linux 7.9, 8.4, 8.5, 8.6, and 9.0
  • SUSE 15.3
  • Ubuntu 22.04
  • macOS Big Sur 11.5.2, 11.6.0, 11.6.1, and 11.6.2
  • macOS Monterey 12.0.1, 12.1, 12.2, 12.2.1, 12.3, and 12.3.1

For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.

Resolved issues

Reference Resolution
SEC-104788 The Trellix EDR trace plugin now successfully uploads the Trace.log and Trace.db files to the cloud.
SEC-106523 From Trellix EDR 4.1.0 onwards, the Trellix EDR client version no longer displays incorrectly as 0.0.0 with Trellix Agent 5.7.6 installed on endpoints.
SEC-105852 Trellix EDR now releases file events quickly for better performance.
SEC-104788 The Trellix EDR trace plugin now successfully runs on SkyTap virtual machines.
SEC-18283 The Trellix EDR client no longer blocks the installation of SAP BOBJ application.
SEC-91945 The Real-time Search dashboard now shows the correct hash value of a file.
SEC-50818 The Process collector collects the hash for the process instead of its parent process on Linux endpoints.
SEC-86490 The Trellix ePO - SaaS subscription page now successfully shows the Trellix EDR extension "Used" count.
SEC-80433 The password set in the policy to uninstall the Trellix EDR client no longer changes unintentionally.
SEC-73140 The Trellix EDR trace plugin now successfully downloads files in OneDrive.
SEC-106409 Boot time values in Sysinfo are now corrected.
SEC-91822 The content update feature now works successfully even if the cloud API URL in Trellix DXL policies has space at the end.
SEC-41675 The Dump Process To File reaction now creates dump files in folders with characters Umlaut.
SEC-40674 The Delete Registry Value reaction now deletes the registry value with characters Umlaut.
SEC-40352 The Trellix EDR client can be now successfully uninstalled from endpoints that are protected with a password consists of characters Umlaut.

Known issues

For a list of known issues in this product release, see KB91275.

Installation information

The Trellix Endpoint Detection & Response Installation Guide has the information you need to install the product for the first time and to migrate from McAfee® Active Response.