This Trellix Endpoint Detection and Response - Cloud February 28, 2026 release includes new features and enhancements.
Every update release is cumulative and includes all features and fixes from the previous release.
New or changed
View unique threat IDs on the Monitoring dashboard
Trellix EDR now displays the threat ID, providing a unique identifier for every threat. This field allows you to cross-reference alerts from API and Monitoring dashboard to ensure accurate identification during investigations.
The unique threat ID is visible on the Monitoring dashboard. The search filter in the Threats by Ranking/ Threats by Time pane allows you to filter using the Threat Name or Threat ID.
Agent ID implementation in the EDR dashboards
Trellix EDR now includes the Agent ID field to provide a unique identifier for every device. This field ensures accurate device identification during investigations and allows you to correlate data with Endpoint Security (HX).
The Agent ID field is now available in these dashboards:
Monitoring — View the Agent ID in the Device details table.
Device Search — View the Agent ID in the Device Details pane.
Alerting — View the Agent ID in the alert listing table and the Alert Details pane. You can also filter and sort by this field.
Historical Search — View the Agent ID in the Device Details pane.
Custom reaction API support
Trellix EDR now supports triggering custom reactions using Remediation APIs. This feature allows you to programmatically execute response actions for specific security use cases.
Invoke custom reactions via the API using these methods:
Search-based — Execute a Real-Time Search. Trigger the reaction using the search ID parameter based on the search results.
Host-based — Target a specific endpoint. Trigger the reaction using the MAGUID parameter.
Note
This release supports the invocation of custom reactions via APIs only. You must use the Trellix EDR interface to create, update, read, or delete custom reactions.
For more information, see API sample for Remediation.
Installation information
The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.
Known issues
For a list of known issues in this product release, see the Trellix Knowledge Base article KB91275.