This Trellix Endpoint Detection and Response 4.1.0 (On-premises) release includes new features, enhancements, resolved issues, and product rebranding changes.
Release details
| Component | Version |
|---|---|
| Trellix EDR Client for Windows | 4.1.0.2253 |
| Trellix EDR Client for Linux | 4.1.0.2243 |
| Trellix EDR Client for macOS | 4.1.0.2253 |
| Trellix EDR Client Extension | 4.1.0.1260 |
| Trellix EDR Endpoint Snapshot Tool 1 | 6.6.0.10 |
| Trellix EDR Rules | 4.1.0.2253 |
1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.
Before installing or upgrading to the Trellix EDR client 4.1.x or later:
- Make sure to update the MsgBus Cert Updater package to the latest version available. This package is available on Software Catalog under the Trellix Agent product.
- Make sure to install the Trellix Data Exchange Layer Broker extension. This package is available on Software Catalog under the Trellix Data Exchange Layer product.
When you install or upgrade to Trellix EDR 4.1.x:
- You might be required to reboot the endpoint. On some installs and upgrades, Trellix EDR installation will not proceed until the endpoint is rebooted and the installation or upgrade is restarted. For details, see KB96049.
- Endpoints unaffected by KB96049 might be prompted to reboot the endpoint. It is a good practice to reboot the endpoint but not mandatory. The reboot message can be suppressed by disabling the Prompt User When a Reboot is Required option on the Trellix Agent properties page. For details, see Trellix Agent properties page.
New features and changes
This release includes the following features and changes.
- Rebranding changes — You can continue to secure your organization with
Trellix EDR as usual. You will notice the following changes in the software:
- Brand logo — McAfee logo is replaced with Trellix logo.
- User interface — Color and typeface are updated to provide better user experience.
- Product name — MVISION EDR is renamed as Trellix EDR.
- End User License Agreement and Copyright — The End User License Agreement and Copyright are updated according to legal requirements. For more details, read the agreement details.
As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update/installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.
For information on downloading and installing the certificates, see KB91697.
- Separate Trellix EDR client packages - In this release, the single Trellix EDR client package is now split into three separate packages for each operate system — Windows, Linux, and macOS. When installing the Trellix EDR client, select the appropriate package and install on endpoints.
- Linux traces — The
Trellix EDR trace feature now supports the Linux operating system. The traces are collected from the Linux endpoints to detect any suspicious activity on the endpoint and threats are shown on the
Monitoring dashboard with metadata to help you in investigation.
Before installing the Trellix EDR client on Linux endpoints, make sure to enable kernel syscall auditing to discover security violations and track security-relevant information. For details about enabling syscall auditing on different Linux distributions, see:
- Red Hat — Enable audit in grub configuration
- Ubuntu — Enable audit in grub configuration
- SUSE — Enable audit in grub configuration
For the Linux kernel version 3.15 or earlier, the Linux trace functionality can't co-exist with auditd:
- If auditd is running, enabling the Linux trace functionality stops the audit service.
- To start the auditd service, the trace functionality must be disabled before restarting the auditd service.
The audit system must not be in immutable mode to use trace functionality. Otherwise, trace process will not be able to add the audit rules.
Note
The audit flag to set failure must not be set to "2" (2=panic). If set, it can cause the kernel panic once the backlog limit exceeds.
The supported event types on Linux endpoints are:
- Processes
- Files
- Network connections
- Service change events
- User logon events
- Kernel module load and unload events
- Content update methods — In this release on the
Trellix EDR client version 4.1.x, you have an option to select either
Dynamic content update or
ePO push content update method to update content on Windows endpoints.
- By default, the Dynamic content update is selected and effective only for Windows endpoints.
- macOS endpoints will automatically default to the
ePO Push Content update method.
For more details about the content update methods, see General policy configuration.
Note
The Trellix EDR content update is not supported on Linux endpoints.
The below table gives details about the supported content update methods according to the version and operating system.
Version Endpoints with operating system Supported methods 4.1.x or later Windows Dynamic content update and ePO push content update Linux Content update is not supported macOS ePO push content update 4.0.x Windows Dynamic content update Linux Content update is not supported macOS ePO push content update 3.5.2 or earlier Windows ePO push content update Linux Content update is not supported macOS ePO push content update
Updated platform, environment, or operating system support
Trellix EDR client is now compatible with:
- Microsoft Windows 10 and 11, version 22H2
- Red Hat Enterprise Linux 7.9, 8.4, 8.5, 8.6, and 9.0
- SUSE 15.3
- Ubuntu 22.04
- macOS Big Sur 11.5.2, 11.6.0, 11.6.1, and 11.6.2
- macOS Monterey 12.0.1, 12.1, 12.2, 12.2.1, 12.3, and 12.3.1
For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.
Resolved issues
| Reference | Resolution |
|---|---|
| SEC-104788 | The Trellix EDR trace plugin now successfully uploads the Trace.log and Trace.db files to the cloud. |
| SEC-106523 | From Trellix EDR 4.1.0 onwards, the Trellix EDR client version no longer displays incorrectly as 0.0.0 with Trellix Agent 5.7.6 installed on endpoints. |
| SEC-105852 | Trellix EDR now releases file events quickly for better performance. |
| SEC-104788 | The Trellix EDR trace plugin now successfully runs on SkyTap virtual machines. |
| SEC-18283 | The Trellix EDR client no longer blocks the installation of SAP BOBJ application. |
| SEC-91945 | The Real-time Search dashboard now shows the correct hash value of a file. |
| SEC-50818 | The Process collector collects the hash for the process instead of its parent process on Linux endpoints. |
| SEC-86490 | The Trellix ePO - SaaS subscription page now successfully shows the Trellix EDR extension "Used" count. |
| SEC-80433 | The password set in the policy to uninstall the Trellix EDR client no longer changes unintentionally. |
| SEC-73140 | The Trellix EDR trace plugin now successfully downloads files in OneDrive. |
| SEC-106409 | Boot time values in Sysinfo are now corrected. |
| SEC-91822 | The content update feature now works successfully even if the cloud API URL in Trellix DXL policies has space at the end. |
| SEC-41675 | The Dump Process To File reaction now creates dump files in folders with characters Umlaut. |
| SEC-40674 | The Delete Registry Value reaction now deletes the registry value with characters Umlaut. |
| SEC-40352 | The Trellix EDR client can be now successfully uninstalled from endpoints that are protected with a password consists of characters Umlaut. |
Known issues
For a list of known issues in this product release, see KB91275.
Installation information
The Trellix Endpoint Detection & Response Installation Guide has the information you need to install the product for the first time and to migrate from McAfee® Active Response.