This is the latest release of Guest Images.
New features and changes
This section describes new features in the Trellix Guest Images release 24.0101, including any new commands, resolved issues, and known issues.
Each Guest Images update release includes all the features and fixes from previous releases, ensuring a comprehensive and up-to-date product. Trellix quality assurance process includes continuous security testing and emphasizes the importance of updating products with the latest release. It is always a good idea to stay current with updates for the best user experience.
Changes implemented in this release:
support for various AMSI bypass techniques
Reporting of code injection
Logging low level API
Command line output capture support
Monitoring and reporting of PowerShell event
Secondary phase analysis for executables
Keylogger detection
Reporting of WMIC baseboard query check
Detection enhancement for DLL files
URL extraction from active memory regions
HTML based attack detection
Script file attacks detection
Default Windows 10 profile for 64-bit PEs
Detection of malicious Qakbot samples by utilizing curl application to download a second stage payload
Enhanced reporting of events related to Sandbox Evasion.
Evasion handling for Memory Check samples and OS resolution
Detection for python based executables
Sample submission through-put improvements
Improvement detection for ransomware samples
Detection enhancement for samples requiring elevated privileges
Enhanced support for memory dumps extraction
Added support and classification for ~23 different MITRE ATT&CK tactics
Improved browser support
Important
Make sure to verify that there is at least 200 GB of free space available on "/data partition" before proceeding with the installation of the Guest Images 24.0101 on your appliance. Use the
show file systemcommand to verify that the appliance has enough free space.You may need to create more disk space especially when you use offline updates or have a one-way license.
Guest Images is compatible with 9.1.x and 10.x versions of the appliance build.
Make sure that the latest version of Security Content must be installed on the appliance.
Enabling automatic downloading
Trellix strongly recommends enabling the automatic downloading feature of Guest Images in order to maintain the most recent version. Automatic downloading is enabled by default. If automatic downloading is not enabled, enable it with the command fenet guest-images auto enable. Running an outdated version of Guest Images will result in a loss of performance and detection capability.
Caution
Guest Images 24.0301 is only available for Virtual VX running on Nutanix platform. For all other products, Guest Images 24.0201 is the latest GI version.
If the automatic downloading feature of Guest Images is not enabled, Trellix recommends downloading the 24.0101 release and immediately installing it.
Trellix recommends to obtain the 24.0101 release of Guest Images during non-peak hours, as the download process can consume time and network resources.
If the download process is abruptly terminated, you can typically resume the downloading process. You can pick up from where you left off and continue downloading the file without starting from the beginning.
File associations
Modifying file associations will affect the performance and detection capability of Guest Images. Trellix strongly recommends that users do not modify file associations.
Offline portal users
If you are using the Offline Portal to upgrade your appliance, consult the following document for more information and instructions for installing Guest Images:
DTI Update Portal User Guide
Caution
You must have a DTI Update Portal user account to install Guest Images from the Offline Portal.
Guest Image profiles included in this release
Individual profiles in Guest Images bundles are updated frequently. To see the profiles available in this release, use the Web UI or the CLI.
In the Web UI: Go to Settings > Guest Images and click the Analysis Images tab.
In the CLI: Go to configuration mode. Enter
show guest-images available defaultsto see the profiles included in the default bundle.
For details, see the topics "Managing Guest Images Using the Web UI" and "Viewing Guest Images Using the CLI" in the "System Configuration" section of the User Guide for your appliance.
Guest Images versions and bundle versions
The GI Bundle refers to how Guest Images are deployed on the Trellix cloud, while GI Version refers to how Guest Images are shown on Trellix appliances.
GI Release 24.0101 contains two GI bundles:
GI Bundle version 24.0201 includes Windows, OSX and Linux profiles.
GI Bundle version 24.0301 includes only Windows profiles.
GI 24.0201 (GI Profiles - Linux/Windows/OSX) is supported for the following appliances:
Malware Analysis: 9.1.x, 10.0.x
Email Security -Server: 9.1.x, 10.0.x
File Protect: 9.1.x, 10.0.x
Network Security: 9.1.x, 10.0.x
Virtual Execution: 9.1.x, 10.0.x
Virtual VX on ESXi
ATD VX
GI 24.0301 (GI Profiles - Windows) is supported for the following appliance:
Virtual VX on Nutanix
Guest Images downloads
Signed Guest Images are released in full download format. The following table in the Guest Images download size section lists the image information for this release.
Guest Images download size
Plan Guest Images download based on the following information:
Download type | Download size |
|---|---|
Full download of windows profiles only + Overlay (Nutanix) | 55.7 GB |
Full download of Windows, Linux and OSX profiles + Overlay | 88 GB |
Software download support
You can download Guest Images from the DTI Update Portal (https://portal-dti.fireeye.com) to upgrade your offline appliances and appliances managed by a Central Management System appliance.
Note
Contact Trellix Support to see if the GI 24.0101 upgrade is available through the Offline Portal.
Upgrade using the Offline Portal
Upgrading a standalone appliance
To update your standalone appliance to GI 24.0201 (GI Profiles - Windows/Linux/OSX):
Log in to the Offline portal.
Select Filter Resources, the product type, your product software version and "guest-images" as Resource. Click Filter.
Select Details under Show Resource.
A list of Guest Images appears.
Click gi-bundle-GI 24.0201 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0201
2 OSX profiles
1 Linux profiles
After downloading the profiles on the local client desktop or on the web server, transfer the downloaded files to the appliance under "/data/fenet/updates" using SCP or SFTP protocol.
Note
To transfer the files on the appliance, you need to enable the SCP and SFTP protocols.
Use
guest-images download manifestto download a list of guest images manifest files.Use
show guest-images available profilesto see the list of profiles available for downloading.Use
guest-images download-and-installto download and install the required profiles.Use the show
guest-images downloadcommand to monitor the progress.
To update your standalone appliance to GI 24.0301 (GI Profiles - Windows):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears. Select the Details.
Click gi-bundle-GI 24.0301 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0301
After downloading the profiles, enter the
guest-images downloadcommand to download the Guest Images.Use the show
guest-images downloadcommand to monitor the progress.When Guest Images have been downloaded, enter the
guest-images installcommand to install the Guest Images on your offline, standalone appliance.
Upgrading appliances managed by a Central Management System appliance
Follow the steps below to upgrade an appliance managed by a Central Management System appliance.
To update your Central Management System-managed appliance to GI 24.0201 (GI Profiles - Windows/Linux/OSX):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears. Select the Details.
Select gi-bundle-24.0201 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0201
2 OSX profiles
1 Linux profiles
After the profiles are downloaded, log in to the Central Management appliance and enter the
guest-images downloadcommand to download the Guest Images.Use the show
guest-images downloadcommand to monitor the progress.After Guest Images are available to install, enter the
guest-images installcommand to install the Guest Images on your offline appliance.
To update your Central Management System-managed appliance to GI 24.0301 (GI Profiles - Windows):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears. Select the Details.
Select gi-bundle-24.0301 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0301
After the profiles are downloaded, log in to the Central Management appliance and enter the
guest-images downloadcommand to download the Guest Images.Use the show
guest-images downloadcommand to monitor the progress.After Guest Images are available to install, enter the
guest-images installcommand to install the Guest Images on your offline appliance.