Trellix EDR Release Notes (Cloud) - July 27, 2026 release

Prev Next

This Trellix Endpoint Detection and Response - Cloud July 27, 2026 release includes new features, enhancements, and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release.

New or changed

View detection rules in the Monitoring page

The Monitoring page displays the top detection rule below each threat. Although multiple detection rules can contribute to a threat, the user interface displays only the top detection rule. This additional context helps analysts understand why a threat was triggered without reviewing additional details.

The Device Search dashboard displays a Detection Date column in the required artifacts. This column distinguishes when an event occurred on a device from when the system processed the data. The Detection Timeframe label replaces the Detection Window label. The date picker prevents an invalid past or future date from being selected.

Export data using a selected time zone

You can select a time zone when exporting data from the Historical Search, Device Search, and Real Time Search. This exports data using your preferred time zone instead of the default UTC format.

View Agent ID and GUID for affected devices in Threat Details

The Threat Details pane on the Monitoring page displays the Agent ID and GUID columns in the Device section. These columns identify devices associated with the selected threat. These identifiers help you distinguish between affected devices during threat investigations. You can also search for threats using the Agent ID or GUID.

Updated threat severity filter terminology

On the Monitoring page, the Threat By Ranking filter is renamed to Threat by Severity. This update aligns the user interface with product documentation.

Updated terminology in the Alerting dashboard

The Trellix EDR Alerting dashboard uses updated terminology. The user interface displays Alerts instead of Events for alert counts.

Catalog API support for custom reactions

The Catalog API supports create, read, update, and delete (CRUD) operations for custom reactions. Developers can manage custom reactions programmatically to automate workflows and integrate third-party systems.

Key capabilities:

  • Create: Programmatically generate custom reactions.

  • Read: Retrieve configuration details of existing custom reactions.

  • Update: Modify custom reaction properties.

  • Delete: Remove custom reactions.

Resolved issues

Reference

Resolution

SEC-213319

Resolves an issue on the Trellix EDR Monitoring dashboard, where the Threat Name search enforced a minimum three-character limit, preventing users from searching for legitimate short threat names, such as sh and /bin/sh.

SEC-213803

Resolves an issue where the Did You Know pop-up appeared after every sign-in to Trellix EDR. The pop-up now appears only when you sign in from a new browser, device or when the pop-up content version is updated. Standard user logouts does not reset the dismissed pop-up status.

SEC-214184

Resolves an issue where Trellix EDR documentation omitted explanations for API return fields. For details, see EDRF APIs.

Installation information

The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.

Known issues

For a list of known issues in this product release, see the Trellix Knowledge Base article KB91275.