Trellix Mobile Console 5.38.x Release Notes
Trellix® Mobile Console 5.38.x release includes enhancements and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
Release details
Release Date: June 2026
For additional information about documentation and release details, visit the Customer Support Portal (login required).
End-of-Life details:
For information about the End-of-Life (EOL) dates for Trellix Mobile Console versions, see Trellix Product End-of-Life Information.
New dynamically added threats
Refer to the Trellix Threat Reference Guide for the details on new and updated threats.
System requirements
The recommended browser is Google Chrome. The current version of Chrome is supported.
The minimum releases for device OS support are:
The minimum OS version for the Trellix Mobile Threat Defense application on Android is Android 6.
The minimum OS version for the Trellix Mobile Threat Defense application on iOS is iOS 12.
New or changed
Mobile Console enhancements
IBM MaaS360 Synchronization Enhancement
This release includes an enhancement of the IBM MaaS360 Enterprise Mobility Management (EMM) connector synchronization process. This change reduces the number of interactions, increases efficiency, and improves performance. The new processing model is event-driven rather than pull-based. This enhancement reduces the processing time for both the Console and the IBM MaaS360 EMM.
Display MITRE ATT&CK Tactics for Threats
This release introduces a display of related MITRE ATT&CK tactics for each threat listed on the Threat page of the Console. In threat details, link to the MITRE website for more information. MITRE is an independent organization that provides a knowledge base of adversary tactics and techniques. The Console exports MITRE ATT&CK tactics with a threat to a Security Information and Event Management (SIEM) or XDR solution.
Dynamic Characteristics-Based Templates for App Policies
This release provides characteristic templates in App Policies. These templates reside in a central location and new templates are added dynamically. Templates give you a starting point for policy refinement instead of creating policies from scratch. When viewing the list of affected applications for a rule, Trellix Mobile Console displays whether the application targets iOS or Android. Open the Technical report directly from the affected applications window. Filter by characteristics on the App Inventory page to simplify application searches.
Enhanced iOS Certificate Analysis
This release provides an enhancement of iOS certificate analysis to support faster threat assessments of certificates installed on iOS or iPadOS devices. Trellix Mobile Console displays detailed certificate attributes, including full certificate details, key identifiers, key usage, extended key usage, and certificate authority information. This feature requires synchronization with Microsoft Intune certificate inventory.
Enhanced Threat Action for Intune EMM
This release provides an enhancement to threat response actions for Microsoft Intune. You can optionally use a custom application ID in Microsoft Entra ID for Microsoft Intune threat response actions. This custom application enables group-based response actions in Microsoft Intune using minimum required permissions without full read and write access to devices and groups in Microsoft Entra ID.
When configured, Trellix Mobile Console uses this custom application to move devices into and out of Microsoft Intune response groups. Trellix Mobile Console accesses only the groups associated with that application, reducing the need for tenant-wide device and group write permissions.
Note
Access is provided to selected Microsoft Intune groups using a custom application ID.
Security Hub Integration for IBM Verify Secure Identity
This release introduces the Security Hub feature for IBM Verify integration to enhance authentication security. Security Hub continuously monitors device security status and evaluates if devices meet required standards. When a device enters a high-risk state, Trellix Mobile Security automatically blocks critical Secure Sign On (SSO) actions, including enrollment, login, and authentication approvals such as One-Time Password (OTP) and push notifications.
Configure Security Hub settings in Policies > App Settings after completing setup in Account Management on Trellix Mobile Console. Trellix Mobile Console pushes these configurations to Trellix Mobile Security for device-level enforcement to ensure compliant authentication factors. You can also configure threat access restrictions in Policies > Threat > Device Actions for all devices in a group to block push notifications, OTP enrollment, and authentication.
Enable the Security Sign-On Enrollment Request threat on the Policies > Threat tab to request on-device enrollment.
Important
This feature requires a license from IBM for the IBM Verify product.
Note
Contact your administrator to request access to this feature. This feature requires Trellix Mobile Security Release 5.10 or later.
Dynamic Android Deep Scan Forensic Analysis and Bug Report Log Collection
This release introduces two checkboxes on the Policies > App Settings page to enhance device analysis and troubleshooting:
Enable Android Deep Scan Forensic Analysis Feature: Select this option to activate the forensic analysis feature in Trellix Mobile Security for all Android devices. This feature runs a deep scan analysis on the device to determine if a threat compromised the device and displays a summary of the results.
Enable Android Bug Report Log Collection: Select this option to allow a user to request an Android bug report by selecting Request Logs in the Action column on the Devices page. This functionality requests an on-demand, system-generated bug report to support advanced troubleshooting and analysis.
To enable these features, select Enable Premium Device Log Collection in Account Settings. Additionally, to enable Android bug report log collection, select Enable Android Deep Scan Forensic Analysis Feature in App Settings. Contact your administrator to request access to these features in your account. Android bug report collection is unavailable in Device Owner (DO) mode and on devices with a policy that restricts enabling developer options.
App Protection enhancements
Re-protect Protected App: Using the Re-protect feature on the Protected Apps page, you can reapply protection to an existing protected app without uploading it again.
App Scanning enhancements
Security Improvements: When you upload a binary directly—not through a URL link to a store—and the platform analyzes the application, the app analysis backend automatically removes data collected from the analysis, including metadata and the binary.
This process prevents the storage of binaries and their data in a centralized location. The Console stores the metadata and binary information only on the customer side.
Note
Once an application is purged, an issue might require you to provide the binary again.
General Console enhancements
Incident Management and SOC Analyst Agent
This release introduces an AI-supported Incidents page. Administrators can view and resolve incidents in this dedicated space. An incident is a group of threats that require analysis based on criteria defined by Console AI analysis. An AI-powered incident report provides the following information:
Overview
Attack narrative
Key compiled MITRE tactics
Threat forensics
Recommended resolution steps
To see the list of applicable threats, refer to the Incidents documentation topic.
Note
This feature requires a premium subscription.
AI-Powered Chatbot
The AI-Powered Chatbot is now fully released in the Console user interface. The chatbot helps users find product information from existing documentation and knowledge base articles. Users do not need to search through documentation manually or contact support. This feature improves self-service capabilities.
Note
The AI-Powered Chatbot is optional for an account and is not enabled by default.
Email template message customization
This release introduces the Email Template feature. Administrators can edit and manage automated email responses directly from Account Management in the Console. You can modify predefined email templates for automated communications, including:
Profile change emails
Security threat emails
Account activation emails
Support ticket creation via chatbot
The Trellix Mobile Console AI chatbot now supports direct creation of support tickets. If automated responses do not solve an issue, users can create a support ticket directly in the chat interface. The chatbot automatically populates key details, including account ID, product version, Console version, and Console module. The system prompts users to provide any remaining required information before submission. Upon confirmation, the platform creates the ticket, and the chatbot displays the ticket number.
Note
Contact the Customer Success team to request access to this feature for your account.
Devices page time range preference update
This release updates the persistent user-level time range preference on the Devices page. The system saves the last time range that you select.
For example, if you select Last 30 days, the system automatically displays that selection the next time that you view the Devices page.
Indonesian and Malay language support for threat alerts
Trellix Mobile Security SDK version 5.9.51 and later supports Indonesian and Malay languages for threat alert text messages. Users receive localized threat notifications that improve message clarity.
Over-the-air detection configuration
This release introduces an Over-the-Air (OTA) detection configuration. Administrators can select a detection set for each policy group. You can select from the following options:
PROD (Production): This default setting applies to all new and existing accounts. It uses the latest production detection content and rule updates. This option prioritizes security coverage and fast access to new detections.
LTS (Long Term Support): This option uses a stable subset of production rules. It prioritizes system stability and reduces the risk of application errors. The system promotes rules to LTS only after successful use in production for a defined period.
BETA (For Testing): This option provides pre-release testing models and rules to preview upcoming detections. It is available when you configure devices to use BETA for joint testing and validation.
Note
Contact the Customer Success team to request access to this feature for your account. This feature requires a future version of Trellix Mobile Security SDK.
REST APIs
New API for Retrieving MITRE Tactic Information: This release introduces an API to retrieve the full set of MITRE ATT&CK tactics and their corresponding URLs on the MITRE website.
New API for Retrieving Failed EMM Connections: This release introduces an API to retrieve the set of Enterprise Mobility Management (EMM) connections that have errors.
New API for Resetting the State of a Failed EMM Connection: This release introduces an API to reset the state of an EMM connection that had an error.
Create a Connection API Update: In this release, the Create a Connection API accepts a syncMode parameter for IBM MaaS360.
Search for Threats and Get Threat Details API Update: In this release, the threat search API and Get Threat Details API return MITRE tactic information.
Search for Threats and Devices Point-in-Time API Updates: In this release, the threat and devices search Point-in-Time (PIT) APIs accept a before timestamp parameter.
Create and Update Account API Key Updates: In this release, these two APIs have a boolean parameter, selectAllScopes, that allows account API keys to automatically acquire new scopes added in a release. If the value is false, specify the scopes array.
Note
Some REST API documentation is provided in a separate document. For more information, contact Trellix Support.
Resolved issues
This release resolves the general stability issues.