25.0202 Release Notes

Prev Next

This is the latest release of Guest Images.

New features and enhancements

This section describes new features in the Trellix Guest Images release , including any new commands, resolved issues, and known issues.

Each Guest Images update release includes all the features and fixes from previous releases, ensuring a comprehensive and up-to-date product. Trellix quality assurance process includes continuous security testing and emphasizes the importance of updating products with the latest release. It is recommended to check the latest updates for the best user experience.

This release introduces several critical detection improvements, expanded file type support, and a new macOS profile to strengthen your environment's security posture.

Important

  • Make sure to verify that there is at least 200 GB of free space available on "/data partition" before proceeding with the installation of the Guest Images on your appliance. Use the show file system command to verify that the appliance has enough free space.

  • You may need to create more disk space especially when you use offline updates or have a one-way license.

  • Guest Images is compatible with 11.0.1 versions of the appliance build.

  • Make sure that the latest version of Security Content must be installed on the appliance.

  • Guest Images release is not supported on the NX2500 appliance.

  • Browser automation and framework updates

    • Chromium support: Enhanced the browser automation framework for Chromium-based browsers with the following new features:

      • Native support for Clickfix captchas.

      • Clipboard data extraction and execution capabilities for script-based text.

      • Improved detection for SVG file formats.

  • Expanded file type and reporting support

    • MSBuild support: Added support for MSBuild Inline Task (.csproj) file types.

    • API reporting: Upgraded API reporting functionality for more comprehensive data output.

  • Detection and security enhancements

    • Strengthened threat identification: Improved detection capabilities for MSI installer files, ransomware executables, and information stealers.

    • Evasion defense: Refined detection of evasive files by analyzing process counts, memory allocation, and disk identifiers.

    • Web-based attack prevention: Optimized detection for HTML smuggling techniques.

    • Office sample analysis: Increased detection accuracy for Microsoft Office samples specifically on Windows 10 profiles.

  • New guest image profiles

    • macOS Intel Sonoma (osx14): Introduced a new macOS Intel Sonoma image featuring advanced detection support for various script files.

      Important

      For virtual VX/EX appliances, the macOS Intel Sonoma (osx14) profile is only supported on hardware with CPUs that support the AVX-2 instruction set.

Additional information

Enabling automatic downloading

Trellix strongly recommends enabling the automatic downloading feature of Guest Images in order to maintain the most recent version. Automatic downloading is enabled by default. If automatic downloading is not enabled, enable it with the command fenet guest-images auto enable. Running an outdated version of Guest Images will result in a loss of performance and detection capability.

Caution

  • If the automatic downloading feature of Guest Images is not enabled, Trellix recommends downloading the release and immediately installing it.

  • Trellix recommends to obtain the release of Guest Images during non-peak hours, as the download process can consume time and network resources.

  • If the download process is abruptly terminated, you can typically resume the downloading process. You can pick up from where you left off and continue downloading the file without starting from the beginning.

File associations

Modifying file associations will affect the performance and detection capability of Guest Images. Trellix strongly recommends that users do not modify file associations.

Offline portal users

If you are using the Offline Portal to upgrade your appliance, consult the following document for more information and instructions for installing Guest Images:

  • DTI Update Portal User Guide

Caution

You must have a DTI Update Portal user account to install Guest Images from the Offline Portal.

Guest Image profiles included in this release

Individual profiles in Guest Images bundles are updated frequently. To see the profiles available in this release, use the Web UI or the CLI.

  • In the Web UI: Go to Settings > Guest Images and click the Analysis Images tab.

  • In the CLI: Go to configuration mode. Enter show guest-images available defaults to see the profiles included in the default bundle.

For details, see the topics "Managing Guest Images Using the Web UI" and "Viewing Guest Images Using the CLI" in the "System Configuration" section of the User Guide for your appliance.

Guest Images versions and bundle versions

The GI Bundle refers to how Guest Images are deployed on the Trellix cloud, while GI Version refers to how Guest Images are shown on Trellix appliances.

The Guest Images Release contains two distinct Guest Image bundles:

  • Guest Image Bundle version 25.0302 includes Windows (Intel and AMD), macOS, and Linux profiles.

  • Guest Image Bundle version 25.0402 includes Windows (Intel) profiles only.

Guest Image Bundle version 25.0402 is supported for the following appliance:

  • Virtual EX on Nutanix: 11.0.1

  • Virtual VX on Nutanix: 11.0.1

Guest Image Bundle version 25.0302 is supported for the following appliances:

  • Malware Analysis: 11.0.1

  • Email Security -Server: 11.0.1

  • File Protect: 11.0.1

  • Network Security: 11.0.1

  • Virtual Execution: 11.0.1

  • Virtual EX on ESXi: 11.0.1

  • Virtual VX on ESXi: 11.0.1

  • ATD VX: 11.0.1

Note

Guest Images 25.0402 is only available for Virtual VX and EX 11.0.1 running on the Nutanix platform. For all other products on 11.0.1 versions of the appliance build, Guest Images 25.0302 is the latest available version.

For all products on 9.1.x, 10.x and 11.0.0 versions of the appliance build, Guest Images 24.0103 is the latest available version.

Guest Images downloads

Signed Guest Images are released in full download format. The following table in the Guest Images download size section lists the image information for this release.

Guest Images download size

The following table provides the download sizes for the respective Guest Image package types:

Download type

Download size

Full download of Windows profiles (AMD)

77.1 GB

Full download of Windows profiles (Nutanix)

76.6 GB

Overlay for 25R1.2

37 MB

Full download of Windows (Intel), Linux, and macOS profiles

119 GB

GI Bundle version 25.0302

  • Five Windows Intel profiles ()

  • Five Windows AMD profiles ()

  • One gi-overlay- file

  • Two macOS profiles

  • One Linux profile

GI Bundle version 25.0402 

  • Five Windows Intel profiles ()

  • One gi-overlay- file

Note

Reverting the Guest Images to previous release 25R1.1 (25.0101) is not supported as 25R1.2 (25.0202) is a minor release with only configuration changes.

Software download support

You can download Guest Images from the DTI Update Portal (https://portal-dti.fireeye.com) to upgrade your offline appliances and appliances managed by a Central Management System appliance.

Note

Contact Trellix Support to see if the Guest Images  upgrade is available through the Offline Portal.

Upgrade using the Offline Portal

Upgrading a standalone appliance

To update your standalone appliance to GI 25.0402 (GI Profiles - Windows):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, the product type, and your product software version. Click Filter.

  3. A list of Guest Images appears. Select the Details.

  4. Click gi-bundle-GI 25.0402 and expand the profile.

  5. Download the following under GI Profiles:

    GI Bundle version 25.0402

    • Five Windows Intel profiles ()

    • One gi-overlay- file

  6. After downloading the profiles, enter the guest-images download command to download the Guest Images.

    Use the show guest-images download command to monitor the progress.

  7. When Guest Images have been downloaded, enter the guest-images install command to install the Guest Images on your offline, standalone appliance.

To update your standalone appliance to GI 25.0302 (GI Profiles -  Windows/Linux/OSX):

Note

To transfer the files on the appliance, enable the SCP and SFTP protocols.

  1. Log in to the Offline portal.

  2. Select Filter Resources, the product type, your product software version and guest-images as resource. Click Filter.

  3. Select Details under Show Resource.

    A list of guest Images appears.

  4. Click gi-bundle-GI 25.0302 and expand the profile.

  5. Download the following under GI Profiles:

    GI Bundle version 25.0302

    • Five Windows Intel profiles ()

    • Five Windows AMD profiles ()

    • One gi-overlay- file

    • Two macOS profiles

    • One Linux profile

  6. After downloading the profiles on the local client desktop or on the web server, transfer the downloaded files to the appliance under "/data/fenet/updates" using SCP or SFTP protocol.

  7. Use guest-images download manifest to download a list of guest images manifest files.

  8. Use show guest-images available profiles to see the list of profiles available for downloading.

  9. Use guest-images download-and-install to download and install the required profiles.

  10. Use the show guest-images download command to monitor the progress.

Upgrading appliances managed by a Central Management System appliance

Follow the steps below to upgrade an appliance managed by a Central Management System appliance.

To update your Central Management System-managed appliance to GI 25.0402 (GI Profiles - Windows):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, the product type, and your product software version. Click Filter.

  3. A list of Guest Images appears. Select the Details.

  4. Select gi-bundle-25.0402 and expand the profile.

  5. Download the following under GI Profiles:

    GI Bundle version 25.0402

    • Five Windows Intel profiles ()

    • One gi-overlay- file

  6. After the profiles are downloaded, log in to the Central Management appliance and enter the guest-images download command to download the Guest Images.

  7. Use the show guest-images download command to monitor the progress.

  8. After Guest Images are available to install, enter the guest-images install command to install the Guest Images on your offline appliance.

To update your Central Management System managed appliance to GI 25.0302 (GI Profiles - Windows/Linux/OSX):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, the product type, and your product software version. Click Filter.

    A list of Guest Images appears.

  3. Select Details.

  4. Select gi-bundle-25.0302 and expand the profile.

  5. Download the following under GI Profiles:

    GI Bundle version 25.0302

    • Five Windows Intel profiles ()

    • Five Windows AMD profiles ()

    • One gi-overlay- file

    • Two macOS profile

    • One Linux profile

  6. After the profiles are downloaded, log in to the Central Management System  appliance and enter the guest-images download command to download the Guest Images.

  7. Use the show guest-images download command to monitor the progress.

  8. After Guest Images are available to install, enter the guest-images install command to install the Guest Images on your offline appliance.