Trellix EDR 4.1.1 Release Notes (On-premises)

Prev Next

This Trellix Endpoint Detection and Response 4.1.1 (On-premises) release includes a new feature and resolved issues.

Release details

Component Version
Trellix EDR Client for Windows 4.1.1.2850
Trellix EDR Client for Linux 4.1.1.2850
Trellix EDR Client for macOS 4.1.1.2821
Trellix EDR Client Extension 4.1.1.582
Trellix EDR Endpoint Snapshot Tool 1 6.6.0.10
Trellix EDR Rules for Windows 4.1.1.2850
Trellix EDR Rules for Linux 4.1.1.2884

1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.

Important

(For use with Trellix ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.

(For use with Trellix ePO - SaaS only) After upgrading macOS endpoints to the latest versions of Trellix products, Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.

Before installing or upgrading to the Trellix EDR client 4.1.x or later:

  • Make sure to update the MsgBus Cert Updater package to the latest version available. This package is available on Software Catalog under the Trellix Agent product.
  • Make sure to install the Trellix Data Exchange Layer Broker extension.
  • Make sure to install the Trellix EDR client extension 4.1.1.

Note

These package are available on Software Catalog under Trellix Data Exchange Layer and Trellix EDR products respectively.

When you install or upgrade to Trellix EDR 4.1.x:

  • You might be required to reboot the endpoint. On some installs and upgrades, Trellix EDR installation will not proceed until the endpoint is rebooted and the installation or upgrade is restarted. For details, see KB96049.
  • Endpoints unaffected by KB96049 might be prompted to reboot the endpoint. It is a good practice to reboot the endpoint but not mandatory. The reboot message can be suppressed by disabling the Prompt User When a Reboot is Required option on the Trellix Agent properties page. For details, see Trellix Agent properties page.

New features

This release includes the following features and changes.

  • End the quarantine of an endpoint using a tool — you can now enable an option Enforce password to unquarantine the Trellix EDR client at endpoint (Windows only) in the network flow policy, set a password, and then enforce a policy on endpoints to end the quarantine using a tool. For details, see End quarantine devices using a tool or Network flow policy configuration.
  • Expanded coverage of the MTIRE ATT&CK Framework — provides greater visibility into attack tactics and technique used by adversaries and also helps in strengthening your overall security strategy.

Updated platform, environment, or operating system support

Trellix EDR client is now compatible with:

  • RHEL 8.7 and 8.8
  • RHEL 9.1 and 9.2
  • SUSE 15.4
  • Oracle Linux 7.9 and later
  • Apple Silicon M1 and M2
  • Big Sur up to version 11.7.3
  • Monterey up to version 12.6.3
  • Ventura 13.0 and 13.1
  • Sonoma 14.0

    Note

    Trellix EDR 4.1.1 supports Sonoma 14.0 only when the operating system is upgraded from earlier versions.

For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.

Resolved issues

Reference Resolution
SEC-111461 The option "Triggers Enable" is no longer displayed in the General Settings of the policy comparison page. This option was an inherited rule and never applicable to Trellix EDR client.
SEC-107063 Resolves the issue where Microsoft applications stop responding (crash) when heavily embedded macro files are loaded and processed.
SEC-109132 Resolves crash in Microsoft Office applications when connecting or rendering web content within the application.
SEC-171723 Resolves crash in SearchProtocolHost.exe during setup of Microsoft Outlook.
SEC-110968 and SEC-174861 Resolves issue where Microsoft Office applications were not integrating correctly with 3rd party tools.
SEC-146315 Resolves issues related to uninstalling Trellix EDR with password protection.
SEC-147216 The hardlinks folder is now removed from the endpoint successfully when Trellix EDR is uninstalled.
SEC-108297 The Files and NetworkFlow collector result limit check has been fixed not to exceed the maximum results allowed.
SEC-172999 The file hashing policy page is now updated to fix a typo error.
SEC-140172 Generating Trellix EDR queries and reports no longer fails on Trellix ePO - SaaS.
SEC-168702 The Trellix rebranding changes are successfully done on a few missing user interface for macOS.
SEC-119582 Trellix EDR now detects ransomware-related tactic ' Volume Shadow Copy Deletion'.
SEC-110602 Trellix EDR successfully prevents trace.db from reaching the maximum size set in policy.
SEC-107912 Resolves issues where sharing violations could occur during certain file operations

Known issues

For a list of known issues in this product release, see KB91275.

Installation information

The Trellix Endpoint Detection and Response Installation Guide has the information you need to install the product for the first time and to migrate from McAfee® Active Response.