This Trellix Endpoint Detection and Response - Cloud December 05, 2024 release includes new features and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
View Trace Graph feature is implemented in Trellix EDR Alerting dashboard
The View Trace Graph feature is now available in the Trellix EDR Alerting dashboard to enhance alert analysis. The Trace Graph offers a detailed view, including the alert's origin, the various processes involved, API calls made, files accessed, registry keys involved, DLL files accessed, and any threats detected during the alert's progression. You can also view event details related to any of the processes involved in the Trace Graph. For more information, see the Check Individual Alerts section in the Trellix EDR Product Guide.
AG grid is implemented in the Trellix EDR Alerting dashboard
The Alerting dashboard features AG Grid, which provides a wide array of features for creating customizable interactive data tables and grids. Its capabilities include sorting, filtering, editing, grouping, column pinning, multi-level headers, and support for tree data structures.
MITRE ATT&CK Techniques and Tactics fields is now available in the Alert Details pane in the Alerting dashboard
The Alert Details pane, accessed upon clicking any alert on the Trellix EDR Alerting dashboard, now includes the MITRE ATT&CK Techniques and Tactics fields among other fields. The information available under these fields provides a link to the alert specific information by navigating you to the MITRE ATT&CK knowledge page, where you can view further details related to the alert's objectives and take necessary actions.
Technique Id columnar metric is added to the Trellix EDR Alerting dashboard
The Technique Id column is now introduced in the Trellix EDR Alerting dashboard. These IDs correspond to the MITRE ATT&CK Technique IDs available in the MITRE ATT&CK knowledge base. The techniques listed under the MITRE ATT&CK Techniques field in the Alert Details pane match the Technique ID shown in the alerting dashboard. You can also use these IDs to search for the corresponding MITRE ATT&CK knowledge base article on the MITRE ATT&CK web page.
Context Sensitive Help (CSH) is now implemented in Trellix EDR UI
The Context-Sensitive Help (CSH) feature has been integrated into the Trellix EDR UI. By clicking the interactive Help button on any UI page, users can access an overview of the page's functionalities. For more comprehensive information, users can navigate through the topic list in the Help pane or consult the detailed documentation available in the Trellix documentation portal.
Resolved issues
Reference | Resolution |
|---|---|
SEC-190862 | This release resolves the Trellix EDR user interface (UI) terminology issue. The UI term ' EDR-Support' is changed to EDR Support. |
SEC-189028 | Resolves the Alerts API call filtering issue, allowing users to obtain host-specific information. |
SEC-188060 | Resolves the issue where API queries consistently returned 1000 events, regardless of the actual number of events available. Queries now return the correct event count. |
SEC-185125 | Trellix EDR Real Time Search functionality is now working as expected without the CC-10005 error in support dashboard. |
SEC-188800 | Users can initiate remediation actions for affected endpoints, which are processed in batches of 1500 without requiring user intervention. The status of these actions can be viewed in the Action History UI dashboard. |
SEC-123132 | The SIEM collector now includes First Detection, Last Detection, and Host Information details. |
SEC-187844 | Resolves the issue with MVAPI returning 'error code 500' when data is fetched, by rectifying the API parameter. |
Installation information
The Trellix Endpoint Detection and Response Installation Guide has all the information you need to install the product for the first time and to migrate from Trellix® Active Response.
Known issues
For a list of known issues in this product release, see KB91275.