File Protect 10.0.1 Release Notes

Prev Next

This is the latest release of Trellix File Protect.

New features and changes

This section describes new features in the Trellix File Protect release 10.0.1.

  • Support for OpenStack KVM

    Support for virtual FX deployments on KVM servers.

New, modified and deprecated CLI commands

The CLI command in this section was added in this release.

New command

  • New CLI to reset all DTI services credentials

    • fenet dti credentials reset factory-default

      Resets credentials of all the existing DTI services to factory settings.

Resolved issues

The following issues were resolved in the Trellix File Protect 10.0.1 release.

Tracking Number

Summary

COM-30687

The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server.

COM-31382

Fixes an issue by adding mechanism to clean up outdated triage packages.

COM-31481

Fixes an issue that, by default, upgraded all the File Protect appliance applications to the high-security factory default cipher-lists.

COM-31650

Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details.

Known Issues

The following issues are known in the Trellix File Protect 10.0.1 release.

Tracking Number

Summary

COM-30655

The database backup process takes a long time when the alert purge is in progress.

Workaround: Schedule the database backup and purge processes at different times.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-30659

Alert details might be missing from the report generated during alert purging.

FMPS-2582

Comfort files are not created for files quarantined on Sharepoint On-prem storage scans.

WEBUI-14922

You cannot delete the scans paused by the system from the Web UI.

Workaround: Abort the paused scan using the CLI command fmps scan abort <scan-id> and then delete the scan using the command fmps scan delete <scan-id>.

WEBUI-15000

For smartvision alerts generated earlier to 9.1.3 releases, base events details and events summary information will not be displayed in the Central Management System.

Upgrade support

The Trellix File Protect 10.0.1 release requires a reboot for the update to take effect. You can upgrade your FX appliance to 10.0.1 from release 9.0.0 or later.

After an upgrade to version 10.0.1, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

After an upgrade to version 10.0.1, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Note

After an upgrade to version 10.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.1.

Downloading content from the DTI offline update portal

If you download Trellix File Protect 10.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade a File Protect appliance to the 10.0.1 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel content