This is the latest release of Trellix File Protect.
New features and changes
This section describes new features in the Trellix File Protect release 10.0.1.
Support for OpenStack KVM
Support for virtual FX deployments on KVM servers.
New, modified and deprecated CLI commands
The CLI command in this section was added in this release.
New command
New CLI to reset all DTI services credentials
fenet dti credentials reset factory-defaultResets credentials of all the existing DTI services to factory settings.
Resolved issues
The following issues were resolved in the Trellix File Protect 10.0.1 release.
Tracking Number | Summary |
|---|---|
COM-30687 | The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server. |
COM-31382 | Fixes an issue by adding mechanism to clean up outdated triage packages. |
COM-31481 | Fixes an issue that, by default, upgraded all the File Protect appliance applications to the high-security factory default cipher-lists. |
COM-31650 | Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details. |
Known Issues
The following issues are known in the Trellix File Protect 10.0.1 release.
Tracking Number | Summary |
|---|---|
COM-30655 | The database backup process takes a long time when the alert purge is in progress. Workaround: Schedule the database backup and purge processes at different times. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
COM-30659 | Alert details might be missing from the report generated during alert purging. |
FMPS-2582 | Comfort files are not created for files quarantined on Sharepoint On-prem storage scans. |
WEBUI-14922 | You cannot delete the scans paused by the system from the Web UI. Workaround: Abort the paused scan using the CLI command |
WEBUI-15000 | For smartvision alerts generated earlier to 9.1.3 releases, base events details and events summary information will not be displayed in the Central Management System. |
Upgrade support
The Trellix File Protect 10.0.1 release requires a reboot for the update to take effect. You can upgrade your FX appliance to 10.0.1 from release 9.0.0 or later.
After an upgrade to version 10.0.1, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
After an upgrade to version 10.0.1, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.
Note
After an upgrade to version 10.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.1.
Downloading content from the DTI offline update portal
If you download Trellix File Protect 10.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
YARA rules supported versions
YARA rules support version 4.3.2.
Important
Before you upgrade a File Protect appliance to the 10.0.1 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.