This Trellix Endpoint Detection and Response 4.1.1 (On-premises) release includes a new feature and resolved issues.
Release details
| Component | Version |
|---|---|
| Trellix EDR Client for Windows | 4.1.1.2850 |
| Trellix EDR Client for Linux | 4.1.1.2850 |
| Trellix EDR Client for macOS | 4.1.1.2821 |
| Trellix EDR Client Extension | 4.1.1.582 |
| Trellix EDR Endpoint Snapshot Tool 1 | 6.6.0.10 |
| Trellix EDR Rules for Windows | 4.1.1.2850 |
| Trellix EDR Rules for Linux | 4.1.1.2884 |
1Separate release cadence is followed for Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see Software Catalog or Trellix Products Downloads site.
Important
(For use with Trellix ePO - On-prem only) If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.
(For use with Trellix ePO - SaaS only) After upgrading macOS endpoints to the latest versions of Trellix products, Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see KB96552.
Before installing or upgrading to the Trellix EDR client 4.1.x or later:
- Make sure to update the MsgBus Cert Updater package to the latest version available. This package is available on Software Catalog under the Trellix Agent product.
- Make sure to install the Trellix Data Exchange Layer Broker extension.
- Make sure to install the Trellix EDR client extension 4.1.1.
Note
These package are available on Software Catalog under Trellix Data Exchange Layer and Trellix EDR products respectively.
When you install or upgrade to Trellix EDR 4.1.x:
- You might be required to reboot the endpoint. On some installs and upgrades, Trellix EDR installation will not proceed until the endpoint is rebooted and the installation or upgrade is restarted. For details, see KB96049.
- Endpoints unaffected by KB96049 might be prompted to reboot the endpoint. It is a good practice to reboot the endpoint but not mandatory. The reboot message can be suppressed by disabling the Prompt User When a Reboot is Required option on the Trellix Agent properties page. For details, see Trellix Agent properties page.
New features
This release includes the following features and changes.
- End the quarantine of an endpoint using a tool — you can now enable an option Enforce password to unquarantine the Trellix EDR client at endpoint (Windows only) in the network flow policy, set a password, and then enforce a policy on endpoints to end the quarantine using a tool. For details, see End quarantine devices using a tool or Network flow policy configuration.
- Expanded coverage of the MTIRE ATT&CK Framework — provides greater visibility into attack tactics and technique used by adversaries and also helps in strengthening your overall security strategy.
Updated platform, environment, or operating system support
Trellix EDR client is now compatible with:
- RHEL 8.7 and 8.8
- RHEL 9.1 and 9.2
- SUSE 15.4
- Oracle Linux 7.9 and later
- Apple Silicon M1 and M2
- Big Sur up to version 11.7.3
- Monterey up to version 12.6.3
- Ventura 13.0 and 13.1
- Sonoma 14.0
Note
Trellix EDR 4.1.1 supports Sonoma 14.0 only when the operating system is upgraded from earlier versions.
For the complete list of system requirements, see supported platforms for Trellix EDR in KB91345.
Resolved issues
| Reference | Resolution |
|---|---|
| SEC-111461 | The option "Triggers Enable" is no longer displayed in the General Settings of the policy comparison page. This option was an inherited rule and never applicable to Trellix EDR client. |
| SEC-107063 | Resolves the issue where Microsoft applications stop responding (crash) when heavily embedded macro files are loaded and processed. |
| SEC-109132 | Resolves crash in Microsoft Office applications when connecting or rendering web content within the application. |
| SEC-171723 | Resolves crash in SearchProtocolHost.exe during setup of Microsoft Outlook. |
| SEC-110968 and SEC-174861 | Resolves issue where Microsoft Office applications were not integrating correctly with 3rd party tools. |
| SEC-146315 | Resolves issues related to uninstalling Trellix EDR with password protection. |
| SEC-147216 | The hardlinks folder is now removed from the endpoint successfully when Trellix EDR is uninstalled. |
| SEC-108297 | The Files and NetworkFlow collector result limit check has been fixed not to exceed the maximum results allowed. |
| SEC-172999 | The file hashing policy page is now updated to fix a typo error. |
| SEC-140172 | Generating Trellix EDR queries and reports no longer fails on Trellix ePO - SaaS. |
| SEC-168702 | The Trellix rebranding changes are successfully done on a few missing user interface for macOS. |
| SEC-119582 | Trellix EDR now detects ransomware-related tactic ' Volume Shadow Copy Deletion'. |
| SEC-110602 | Trellix EDR successfully prevents trace.db from reaching the maximum size set in policy. |
| SEC-107912 | Resolves issues where sharing violations could occur during certain file operations |
Known issues
For a list of known issues in this product release, see KB91275.
Installation information
The Trellix Endpoint Detection and Response Installation Guide has the information you need to install the product for the first time and to migrate from McAfee® Active Response.