This Trellix Endpoint Detection and Response - Cloud July 7, 2025 release includes new features, enhancements, and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
New or changed
Introducing Forensics capabilities in Trellix EDR— The Forensics capabilities, which include Collections dashboard and IOC Detection Rules, are now integrated with Trellix EDR. Additionally, you can now upgrade from Trellix EDR policies to EDRF policies. To access these capabilities, ensure you are subscribed to the EDRF SKU via the Trellix EDR support page. See the EDRF Product Guide for more information.
Collections dashboard now integrated with Trellix EDR — The Collections dashboard in the Trellix EDR provides a centralized view to track, manage, and analyze acquisitions from endpoints. It supports filtering, sorting, and grouping via an interactive AG Grid and offers quick access to triage summaries and audit data.
You can now collect data using Single File, Multiple Files, and Triage acquisition methods.
Acquisitions can be initiated from:
Monitoring dashboard
Sequential View (within the Monitoring dashboard)
Device Search
Historical Search
For more information about the Collections dashboard, see the EDRF Product Guide.
Manage IOC Detection Rules in Trellix EDR — You can now define and manage Indicators of Compromise (IOCs) directly from the EDR workspace. This enhancement improves detection precision and enables you to respond to threats specific to your environment.
New capabilities include:
Unified IOC management: View, edit, clone, delete, and export both system-generated and custom rules from a centralized dashboard.
Create custom rules: Define tailored IOC rules using presence or execution-based conditions and criteria.
Import/Export rules: Import IOC rules from external environments and export them in CSV or XLSX formats.
Streamlined filtering: Use global search, column filters, and quick filters to manage rule visibility.
Logical matching: Leverage OR logic across conditions and AND logic within criteria to fine-tune detection accuracy.
Flexible scope: Apply rules to selected servers and operating systems, with support for up to 30 conditions per rule.
For more information about IOC Detection Rules, see the EDRF Product Guide.
Automated upgrade from Trellix EDR to EDRF — You can now upgrade from EDR to EDRF seamlessly, with support for ePO - On-prem and ePO - SaaS environments.
Key enhancements include:
Automated upgrade workflow: Upgrade custom Trellix EDR policies and assignments to the EDRF Policy Catalog without losing configurations or data.
Client upgrade support: Upgrade from Trellix EDR Client to EDRF Client to use the features of EDRF.
Note
EDRF provides equivalent Trellix EDR policy frameworks to assist in manual policy and assignment upgrades.
This feature simplifies migration to the advanced EDRF platform, ensuring continuity and improved functionality with minimal effort. For more information, see the EDRF Installation Guide.
Integration of eBPF Linux sensors in EDRF — A new eBPF (Extended Berkeley Packet Filter) sensor is now part of the Linux sensor architecture. This sensor leverages eBPF technology to run custom commands in the Linux kernel and capture endpoint events with minimal overhead.
The eBPF sensor loads and unloads programs based on requested events. It uses tracepoints or kprobes to hook into the kernel and collect data through perf or ring buffers.
Key advantages over the traditional Linux sensor include:
Lower performance overhead
Enhanced visibility into system-level activity
Increased efficiency
Reduced resource utilization
No conflicts with third-party tools
Resolved issues
Reference | Resolution |
|---|---|
SEC-202031 | Resolves an issue in the Investigation dashboard that prevented users from uploading endpoint snapshot files. |
Installation information
The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.
Known issues
For a list of known issues in this product release, see KB91275.