Trellix EDR Release Notes (Cloud) - December 12, 2023 release

Prev Next

This Trellix Endpoint Detection and Response - Cloud December 12, 2023 release includes supporting Trellix EDR capabilities on macOS endpoints.

Every update release is cumulative and includes all features and fixes from the previous release.

Trellix EDR detection and investigation capabilities support macOS endpoints

Trellix EDR now extends its detection and investigation capability to support macOS endpoints in your environment.

Note

You need to install or upgrade to Trellix EDR client 4.2.x or later for using detection and investigation capabilities on macOS endpoints. For details, see Trellix Endpoint Detection and Response 4.2.x Release Notes (On-premises).

The below Trellix EDR capabilities are now extended to macOS endpoints so that you can be effective in analysis:

  1. Collects enough data from macOS endpoints to have visibility into historic events irrespective of the state of endpoints.

  2. Detects suspicious behavior in your organization's macOS endpoints so that you can quickly respond to threats.

  3. Provides support to search for macOS endpoints data or events in real-time so that you can have visibility of the threat across your organization.

The following dashboards and respective features now show the macOS endpoint details to help you in the investigation:

  1. Monitoring

    1. Exclude from threats — This feature now supports macOS File path and Command line details to exclude a threat from the threat list.

      Note

      Trellix EDR for macOS does not support the MD5 and SHA1 hashes.

      For details about supported wildcards during threat exclusions on macOS endpoints, see KB94998.

    2. Process Activity — The new Type field is added to differentiate the type of process started on macOS endpoints. The different types of processes are:

      • Fork — Creates a new process that is a copy of itself. The forked process gets a new process id.

      • Exec — An existing process that replaces the current process image with another one. The process id remains the same.

      • Fork+Exec — When the parent forks a child and subsequently performs an exec to refresh the process image. The exec is performed immediately after fork.

  2. Investigations

    The following features display the respective file path based on the endpoint Operating System (Windows, Linux, or Mac):

    • In Device Details, File Details, and Finding Details — file path is now displayed for macOS endpoints.

    • In the Artifacts table view, the file path is now displayed for macOS endpoints.

    Note

    The Device and Snapshot based investigations are not supported on Linux and macOS endpoints.

  3. Alerting

    The file path is now displayed for macOS endpoints.

  4. Real-time Search

    The file path is now displayed in the File path and Command Line columns for macOS endpoints.

  5. Historical Search

    The file path is now displayed in the Event Details and File Path columns for macOS endpoints.

    Note

    Trellix EDR for macOS does not support the MD5 and SHA1 hashes.

    In this release, the new columns are added to the results grid on the Historical Search dashboard.

    • Generic — The new columns such as OS, Process Start Time, Family, Connected, User Id, User Gid etc. are now added.

    • macOS specific — The new columns such as File Last modification Date, Network Family, Network Connected, Service Start Commands, Kernel Module Action etc. are now added.

  6. Device Search

    The file path is now displayed in the Command Line column for macOS endpoints.

    Note

    Trellix EDR for macOS does not support the MD5 and SHA1 hashes.

  7. ConfigurationManage Threat Exclusions

    The File Path and Command Line fields now support macOS details to exclude a threat from the threat list.

    For details about supported wildcards during threat exclusions on macOS endpoints, see KB94998.

  8. Contain and remediation actions

    Trellix EDR supports containment and remediation actions on macOS endpoints. For details, see Contain threats and Remediate threats.

  9. Trellix EDR APIs

    Trellix EDR APIs are supported on macOS endpoints. For details, see Trellix EDR APIs.

Installation information

The Trellix Endpoint Detection and Response Installation Guide has all the information you need to install the product for the first time and to migrate from Trellix® Active Response.

Known issues

For a list of known issues in this product release, see KB91275.