File Protect 10.0.2 Release Notes

Prev Next

This is the latest release of Trellix File Protect.

New features and changes

This section describes new features in the Trellix File Protect release 10.0.2.

On-premise S3 integration with the File Protect appliance

You can now use the on-premise Simple Storage Service on the File Protect appliance to store and secure files. The File Protect appliance scans the files in the on-premise S3 storage for malware and moves the malicious files to a secured quarantine location.

The S3 on-premise feature can only be configured via the CLI.

General Enhancements

This section describes the enhancements which are a part of the Trellix File Protect release 10.0.2.

  • The triage bundle and log archive password is changed to Trellix Customer Support Archive.

  • The HTM file type is now enabled by default, for pre-filtering.

  • A new CLI is introduced to search for intel feed information. The CLI displays the signature , source and other details of an SHA-256 hash file, URL, or MD5 checksum.

New CLI commands

The CLI commands in this section were added in this release.

On-premise S3 configuration CLIs

Use the following CLIs to configure the on-premise S3 storage on the File Protect appliance.

  • fmps s3-onprem config access-id: Sets the value for access-id node.

  • fmps s3-onprem config secret: Sets the value for secret key nodes.

  • fmps s3-onprem config hostname: Sets the IP where the S3 on-prem storage is hosted.

  • fmps s3-onprem config port: Sets the HTTPs port on which the S3 on-prem APIs are enabled.

  • show fmps s3-onprem config: Shows the existing values of the configuration nodes.

On-premise S3 storage creation CLIs

Use the following CLIs to create on-premise S3 storage on the File Protect appliance.

  • fmps storage create s3-onprem name * app s3 bucket * region *: Creates the S3 on-prem storage.

  • fmps storage configure s3-onprem * quarantine * good *: Configures good and quarantine locations for the S3 on-prem storage created (mandatory for starting a scan).

  • show fmps storage type s3-onprem: Displays all configured S3 on-prem storages.

CLIs to search details of intel feeds

Use the following CLIs to search the details of the corresponding intel feeds.

  • show analysis intel url <URL> : Displays intel information for the mentioned URL.

  • show analysis intel sha256 <sha256> : Displays intel information for the mentioned sha256.

  • show analysis intel md5 <md5> : Displays intel information for the mentioned md5.

CLI to enable HTM file type

Use the following CLI to enable HTM file type. Use the 'no' form of the command to disable it.

  • filter-analysis filetype htm enable

Resolved issues

The following issues were resolved in the Trellix File Protect 10.0.2 release.

Tracking Number

Summary

CMS-17212

Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted.

COM-31551

Fixes an issue with log archives creation.

COM-31673

Java libraries are upgraded to address CVEs.

COM-62169

Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx.

COM-62263

Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes.

COM-62368

Fixes an issue where adding a root CA was failing in rare cases.

FMPS-2915

Fixes issues related to configured scan which required rebooting the appliance to restore settings.

Known Issues

The following issues are known in the Trellix File Protect 10.0.2 release.

Tracking Number

Summary

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

FMPS-2582

Comfort files are not created for files quarantined on Sharepoint On-prem storage scans.

WEBUI-14922

You cannot delete the scans paused by the system from the Web UI.

Workaround: Abort the paused scan using the CLI command fmps scan abort <scan-id> and then delete the scan using the command fmps scan delete <scan-id>.

Upgrade support

The Trellix File Protect 10.0.2 release requires a reboot for the update to take effect. You can upgrade your FX appliance to 10.0.2 from release 9.0.0 or later.

After an upgrade to version 10.0.2, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

After an upgrade to version 10.0.2, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Created Log archive files will not be preserved on upgrade to 10.0.2. Please have a backup of logs before upgrade.

Note

After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.2.

Downloading content from the DTI offline update portal

If you download File Protect 10.0.2 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an File Protect appliance to the 10.0.2 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel context