11.0.1 Release Notes

Prev Next

New features

This section describes new features in release 11.0.1.

  • Trellix IVX Private Cloud

    Important

    Technical Preview: This feature is provided strictly for Technical Preview purposes. It is not GA (Generally Available) and is not ready for production use.

    SUPPORT: Trellix welcomes any and all customer feedback regarding this new capability during the Technical Preview. Critical issues may be addressed at Trellix’s discretion; however, Technical Preview features are provided without formal support, maintenance, patches, or bug fixes. Standard support commitments apply only when the feature becomes General Availability.

    RISKS: As a Technical Preview, this feature may include defects, security vulnerabilities, or performance issues. It is provided “as-is” during the evaluation period, and Trellix does not provide warranties, guarantees, or commitments regarding its performance or suitability. Customers should evaluate it in non-production environments and are encouraged to share feedback to help guide future improvements.

    COMPLIANCE: Trellix IVX Private Cloud is undergoing preparation for formal industry and regulatory compliance certification. These certifications are targeted for the General Availability (GA) release and do not apply to the current Technical Preview version.

    The Trellix IVX Private Cloud solution is deployed within your own AWS cloud infrastructure to align with your specific operational and security requirements. Deployment and management are handled using an AWS CDK (Cloud Development Kit) and CodePipeline process. This method allows you to deploy, configure, update, and upgrade the Trellix Cloud IVX solution within your environment, ensuring seamless integration with your existing infrastructure. This gives you control and customization for seamless infrastructure integration.

    This solution provides multiple dedicated integration interfaces such as APIs, Amazon S3, and ICAP—to ensure seamless connectivity with your existing systems. These integrations allow automated data exchange and streamline security operations. By automating data exchange with Trellix Cloud IVX, it allows to:

    • Automate threat analysis

    • Enhance detection and response workflows

    • Gain actionable insights to strengthen your overall security posture.

    For more information on how to configure and use IVX Private Cloud, see our Deployment Guide.

  • Virtual IP support for IVX cluster — IVX Server now introduces a Virtual IP to create a High Availability (HA) environment for your cluster. This feature enables automatic failover, which significantly reduces downtime and ensures file analysis continues with no or minimal file loss. If the active broker node fails, another broker automatically takes its place using the same VIP address to continue operations without manual intervention.

  • Syslog integration for IVX notifications — You can now integrate the IVX appliance with a remote syslog server to automatically forward malicious and riskware notifications when a file analysis is complete. This feature helps SOC teams centralize alerts and streamline threat monitoring within their existing security tools.

  • Interactive malware analysis with VNC — You can now enable a Virtual Network Computing (VNC) session when submitting a sample through the Web UI to view and interact with it in real-time during analysis in the virtual environment.

  • The show mvx submission CLI is now updated to show the data for entire cluster.

Enhancements

  • ICAP enhancements:

    • REQMOD now supports uploading up to 5 files in a single submission request, and the entire request is blocked if any one of the files is found to be malicious.

    • icap-service block-mode verdict-timeout <seconds> — This command sets the maximum time (in seconds) that the ICAP service will hold a connection while waiting for analysis verdict. The value ranges from 0-300 seconds and the default value is 300.

      Setting the value to 0 means the ICAP service immediately releases the connection without waiting for the analysis verdict. It still submits the file for analysis, but the user's connection is not blocked.

  • IVX Server now allows users to download PDF report for all the completed analysis from Web UI.

  • In integrated virtual systems, the show version command now displays the maximum number of licensed and configured virtual machines currently running.

  • Warning message in show version output for Virtual VX — After upgrading a Virtual VX appliance, a new warning message will appear in the output of the show version command. This message is expected and can be safely ignored. The warning displays as follows:

    NOTICE: Wrong License: Your FIREEYE_APPLIANCE license is missing the Max Running VMs attribute! Please contact customer support. 
    Maximum running VMs:
        VMs licensed: n/a (please install an MVX-integrated appliance license) 
        VMs configured: 16
  • The show mvx submission tenant-id <id> CLI command is now deprecated.

Resolved Issues

The following issues were resolved in the  11.0.1 release.

Tracking number

Summary

COM-63130

Removed the diffie-hellman-group14-sha1 Key Exchange (KEX) cipher from our supported CC and FIPS cipher lists.

COM-63634

Fixes the issue where the /data partition fills up, triggering disk space warnings and potential system failures.

COM-63528

Resolved an issue where the AX appliance's management interface (ether1) was incorrectly attempting to establish connections for sandbox analysis.

COM-63527

Fixes the issue where the sandbox analysis traffic was incorrectly originating from the management interface (ether1) instead of the designated live interface (ether2).

VX-3201

Fixes the issue where live mode submissions were incorrectly labeled as 'sandbox' on the Running page of the UI.

VX-3251

Fixes the issue where the IVX UI took an excessive amount of time to load during login, and certain tabs were missing upon logging in.

VX-3254

Fixes the issue where the IVX UI was not displaying all generated alerts.

VX-3256

Fixes the issue where the IVX UI attempted to reach out to external CDNs and load JavaScript libraries over the network during the login process.

VX-3258

Fixes the issue were the file submission was not working for an Analyst user.

VX-3260

Fixes the issue where the number of alerts displayed in the UI differs in count when switching between themes.

VX-3283

Fixes the issue where the SWG to IVX connection incorrectly displayed an Error 500 for some Secure Web Gateway (SWG) submissions.

VX-3295

Fixes the issue where the show mvx submission CLI command, along with other MVX CLI and JSON outputs, incorrectly used the label Sensor ID. This label has been corrected to the more accurate submitter/submitter_name.

VX-3359

Fixes the issue where IVX could not process files submitted with non-UTF-8 characters in their name on the ICAP interface.

VX-3368

Fixes the issue where the VX appliance incorrectly stopped extracting inner sample files from an archive after 245 files, ignoring the configured 'maximum number of attachments per archive' limit. The appliance now correctly extracts all files up to the set limit, for example, 500.

VX-3509

Fixes the issue where users were unable to connect to VNC when using a Fully Qualified Domain Name (FQDN) or hostname.

Known issues

The following issues are known in the  11.0.1 release.

Tracking number

Summary

COM-63635

Compliance mode appliances are logging too much noise with SSL_ERROR_WANT_READ informational status.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

VX-3324

The number of records displayed in the UI appears to shift or not properly counted at the boundary of a user's local time zone.

VX-3370

The IVX appliance does not support certificate-based authentication, as the sign-in certificate option is not available.

VX-3502

When submitting a sample, the default application option sometimes fails to appear in the selection menu.

VX-3579

If the VNC icon is clicked immediately after a file is submitted for analysis, the resulting VNC window may intermittently display a blank white screen.

Additional information

Upgrade support

The   11.0.1 release requires a reboot for the update to take effect. You can upgrade your  appliance to 11.0.1 from release 9.1.x or later.

Note

You can upgrade  appliances to 11.0.1 only if they are standalone nodes. For information on upgrading MVX clusters (MVX Smart Grid), see Upgrading MVX Clusters.

Note

After an upgrade to version 11.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the Download the security content bundle section.

Important

When upgrading an X500  running in FIPS/CC compliance mode to version 11.0.1, you must reapply the compliance mode immediately after the upgrade. Use the CLI command compliance apply standard <standard name> and save the configuration using the CLI write memory.

After reapplying compliance mode, ensure that any necessary compliance options overrides are reasserted as needed. In rare instances, the appliance may become unresponsive before compliance can be applied. If this occurs, the appliance may need to be power cycled.

Upgrading MVX clusters

IVX clusters running 11.0.0 can be directly upgraded to 11.0.1 using the CMS cluster UI page.

Direct upgrade of MVX clusters (MVX Smart Grid) from 9.1.x or 10.0.x release to 11.0.x is not supported. See the Upgrading IVX Clusters to Version 11.0.x section for more information. For instructions on upgrading the appliance through IVX command line, refer to Upgrading the appliance using the CLI.

Note

You cannot upgrade clusters directly from versions 9.1.x or 10.0.x to 11.0.x. To upgrade, you must first dismantle the cluster and then upgrade each IVX standalone node individually to version 11.0.x.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.1.

If you download  11.0.1 security content from the DTI Offline Update Portal, use the SCNET-9.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the

Trellix DTI Offline Update Portal User Guide

.

YARA rules supported versions

Before you upgrade an  appliance to the 11.0.1 release, modify any custom YARA rules to YARA 4.5.0. For details about YARA 4.5.0, see YARA's Documentation, Release 4.5.0 by Victor Alvarez.