This is the latest release of Guest Images.
New features and changes
This section describes new features in the Trellix Guest Images release 24.0102, including any new commands, resolved issues, and known issues.
Each Guest Images update release includes all the features and fixes from previous releases, ensuring a comprehensive and up-to-date product. Trellix quality assurance process includes continuous security testing and emphasizes the importance of updating products with the latest release. It is always a good idea to stay current with updates for the best user experience.
This release includes significant enhancements to threat detection and evasion handling capabilities, along with expanded file type support and improved reporting.
Important
Make sure to verify that there is at least 200 GB of free space available on "/data partition" before proceeding with the installation of the Guest Images 24.0102 on your appliance. Use the
show file systemcommand to verify that the appliance has enough free space.You may need to create more disk space especially when you use offline updates or have a one-way license.
Guest Images is compatible with 9.1.x, 10.x, and 11.x versions of the appliance build.
Make sure that the latest version of Security Content must be installed on the appliance.
Key Enhancements:
Detection and Evasion
Detection support for various AMSI bypass techniques.
Improved handling of wmi query.
Enhanced evasion handling for:
systembiosversion check samples
GetTickCount64
SetTimer API based samples
Improved macro evasion handling in Office documents.
Enhanced Webshell detection.
Enhanced office detection on Windows 10 : Improved evasion handling, embedded objects activation, macro code execution, and macro evasion handling, URL extraction from office files.
Enhanced support for different MITRE ATT&CK tactics.
Detection enhancement for process count, memory, and disk size-based evasive files.
File Type Support:
Added support for Microsoft Management Console MMC files.
Added support for Python Pickle PKL file.
Expanded the default file type support on Windows 10 profiles.
Improved Reporting:
Enhanced command-line output capture.
Enhanced reporting of URLs in document summaries for FAUDE/DUA analysis.
Improved monitoring and reporting of PowerShell events.
Other Enhancements:
Detection for Python-based executables.
Improved detection for button click-based malicious HTA samples.
Detection enhancement for ransomware executables.
Detection enhancement for info stealers.
Enabling automatic downloading
Trellix strongly recommends enabling the automatic downloading feature of Guest Images in order to maintain the most recent version. Automatic downloading is enabled by default. If automatic downloading is not enabled, enable it with the command fenet guest-images auto enable. Running an outdated version of Guest Images will result in a loss of performance and detection capability.
Caution
Guest Images 24.0602 is only available for Virtual VX running on the Nutanix platform. For all other products on 9.1.x and 10.x versions of the appliance build, Guest Images 24.0502 is the latest available version. For all other products on 11.x versions of the appliance build, Guest Images 24.0702 is the latest available version.
If the automatic downloading feature of Guest Images is not enabled, Trellix recommends downloading the 24.0102 release and immediately installing it.
Trellix recommends to obtain the 24.0102 release of Guest Images during non-peak hours, as the download process can consume time and network resources.
If the download process is abruptly terminated, you can typically resume the downloading process. You can pick up from where you left off and continue downloading the file without starting from the beginning.
File associations
Modifying file associations will affect the performance and detection capability of Guest Images. Trellix strongly recommends that users do not modify file associations.
Offline portal users
If you are using the Offline Portal to upgrade your appliance, consult the following document for more information and instructions for installing Guest Images:
DTI Update Portal User Guide
Caution
You must have a DTI Update Portal user account to install Guest Images from the Offline Portal.
Guest Image profiles included in this release
Individual profiles in Guest Images bundles are updated frequently. To see the profiles available in this release, use the Web UI or the CLI.
In the Web UI: Go to Settings > Guest Images and click the Analysis Images tab.
In the CLI: Go to configuration mode. Enter
show guest-images available defaultsto see the profiles included in the default bundle.
For details, see the topics "Managing Guest Images Using the Web UI" and "Viewing Guest Images Using the CLI" in the "System Configuration" section of the User Guide for your appliance.
Guest Images versions and bundle versions
The GI Bundle refers to how Guest Images are deployed on the Trellix cloud, while GI Version refers to how Guest Images are shown on Trellix appliances.
GI Release 24.0102 contains two GI bundles:
GI Bundle version 24.0502 includes Windows, OSX, and Linux profiles.
GI Bundle version 24.0602 includes only Windows profiles.
GI Bundle version 24.0702 includes Windows, OSX, and Linux profiles.
GI 24.0502 (GI Profiles - Linux/Windows/OSX) is supported for the following appliances:
Malware Analysis: 9.1.x, 10.0.x
Email Security -Server: 9.1.x, 10.0.x
File Protect: 9.1.x, 10.0.x
Network Security: 9.1.x, 10.0.x
Virtual Execution: 9.1.x, 10.0.x
Virtual VX on ESXi: 9.1.x, 10.0.x
ATD VX: 9.1.x, 10.0.x
GI 24.0602 (GI Profiles - Windows) is supported for the following appliance:
Virtual VX on Nutanix
GI 24.0702 (GI Profiles - Linux/Windows/OSX) is supported for the following appliances:
Malware Analysis: 11.0.x
Email Security -Server: 11.0.x
File Protect: 11.0.x
Network Security: 11.0.x
Virtual Execution: 11.0.x
Virtual VX on ESXi: 11.0.x
ATD VX: 11.0.x
Guest Images downloads
Signed Guest Images are released in full download format. The following table in the Guest Images download size section lists the image information for this release.
Guest Images download size
Plan Guest Images download based on the following information:
Download type | Download size |
|---|---|
Full download of windows profiles (Nutanix) | 55.7 GB |
Overlay for 24R1.2 | 24 MB |
Full download of Windows, Linux and OSX profiles | 88 GB |
GI Bundle version 24.0502
4 Windows profiles
1 gi-overlay-24.0502
2 OSX profiles
1 Linux profiles
GI Bundle version 24.0602
4 Windows profiles
1 gi-overlay-24.0602
GI Bundle version 24.0702
4 Windows profiles
1 gi-overlay-24.0702
1 OSX profiles
1 Linux profiles
Note
Reverting Guest Images to previous release 24R1.1 (24.0101) is not supported as 24R1.2 (24.0102) is a minor release with only configuation changes.
Software download support
You can download Guest Images from the DTI Update Portal (https://portal-dti.fireeye.com) to upgrade your offline appliances and appliances managed by a Central Management System appliance.
Note
Contact Trellix Support to see if the GI 24.0102 upgrade is available through the Offline Portal.
Upgrade using the Offline Portal
Upgrading a standalone appliance
To update your standalone appliance to GI 24.0502 (GI Profiles - Windows/Linux/OSX):
Log in to the Offline portal.
Select Filter Resources, the product type, your product software version and "guest-images" as Resource. Click Filter.
Select Details under Show Resource.
A list of Guest Images appears.
Click gi-bundle-GI 24.0502 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0502
2 OSX profiles
1 Linux profiles
After downloading the profiles on the local client desktop or on the web server, transfer the downloaded files to the appliance under "/data/fenet/updates" using SCP or SFTP protocol.
Note
To transfer the files on the appliance, you need to enable the SCP and SFTP protocols.
Use
guest-images download manifestto download a list of guest images manifest files.Use
show guest-images available profilesto see the list of profiles available for downloading.Use
guest-images download-and-installto download and install the required profiles.Use the show
guest-images downloadcommand to monitor the progress.
To update your standalone appliance to GI 24.0602 (GI Profiles - Windows):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears. Select the Details.
Click gi-bundle-GI 24.0602 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0602
After downloading the profiles, enter the
guest-images downloadcommand to download the Guest Images.Use the show
guest-images downloadcommand to monitor the progress.When Guest Images have been downloaded, enter the
guest-images installcommand to install the Guest Images on your offline, standalone appliance.
To update your standalone appliance to GI 24.0702 (GI Profiles - Windows/Linux/OSX):
Note
To transfer the files on the appliance, enable the SCP and SFTP protocols.
Log in to the Offline portal.
Select Filter Resources, the product type, your product software version and guest-images as resource. Click Filter.
Select Details under Show Resource.
A list of guest Images appears.
Click gi-bundle-GI 24.0702 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0702
1 OSX profiles
1 Linux profiles
After downloading the profiles on the local client desktop or on the web server, transfer the downloaded files to the appliance under "/data/fenet/updates" using SCP or SFTP protocol.
Use guest-images download manifest to download a list of guest images manifest files.
Use
show guest-imagesavailable profiles to see the list of profiles available for downloading.Use
guest-images download-and-installto download and install the required profiles.Use the
show guest-imagesdownload command to monitor the progress.
Upgrading appliances managed by a Central Management System appliance
Follow the steps below to upgrade an appliance managed by a Central Management System appliance.
To update your Central Management System-managed appliance to GI 24.0502 (GI Profiles - Windows/Linux/OSX):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears. Select the Details.
Select gi-bundle-24.0502 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0502
2 OSX profiles
1 Linux profiles
After the profiles are downloaded, log in to the Central Management appliance and enter the
guest-images downloadcommand to download the Guest Images.Use the show
guest-images downloadcommand to monitor the progress.After Guest Images are available to install, enter the
guest-images installcommand to install the Guest Images on your offline appliance.
To update your Central Management System-managed appliance to GI 24.0602 (GI Profiles - Windows):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears. Select the Details.
Select gi-bundle-24.0602 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0602
After the profiles are downloaded, log in to the Central Management appliance and enter the
guest-images downloadcommand to download the Guest Images.Use the show
guest-images downloadcommand to monitor the progress.After Guest Images are available to install, enter the
guest-images installcommand to install the Guest Images on your offline appliance.
To update your Central Management System managed appliance to GI 24.0702 (GI Profiles - Windows/Linux/OSX):
Log in to the Offline Portal.
Select Filter Resources, the product type, and your product software version. Click Filter.
A list of Guest Images appears.
Select Details.
Select gi-bundle-24.0702 and expand the profile.
Download the following under Intel GI Profiles:
4 Windows profiles
1 gi-overlay-24.0702
1 OSX profiles
1 Linux profiles
After the profiles are downloaded, log in to the Central Management System appliance and enter the
guest-images downloadcommand to download the Guest Images.Use the
show guest-imagesdownload command to monitor the progress.After Guest Images are available to install, enter the guest-images install command to install the Guest Images on your offline appliance.