Guest Images 21.0101 Release Notes

Prev Next

2021 / Software Release 21.0101 / Revision 1

Announcements

This document provides an overview of the new features, resolved issues, and known issues in the FireEye Guest Images 21.0101 release.

IMPORTANT!

  • FireEye recommends that a minimum of 200 GB of free space is available in the /data partition before you upgrade the appliance to this Guest Images (21.0101). Use the show file system command to verify that the appliance has enough free space.

  • If you use offline Guest Images updates or have a one-way license, you may need to create more disk space before updating GI 21.0101.

  • Guest Images 21.0101 is backward-compatible with the same appliance versions as GI 17.0115.

  • The latest version of Security Content must be installed on the appliance.

Enabling Automatic Downloading

FireEye strongly recommends enabling the automatic downloading feature of Guest Images in order to maintain the most recent version. Automatic downloading is enabled by default. If automatic downloading is not enabled, enable it with the command fenet guest-images. Running an outdated version of Guest Images will result in a loss of performance and detection capability.

Note: If the automatic downloading feature of Guest Images is not enabled, FireEye recommends downloading the 21.0101 release and immediately installing it.

File Associations

Modifying file associations will affect the performance and detection capability of Guest Images. FireEye strongly recommends that users do not modify file associations.

FireEye Customer Security Best Practices

Because our quality assurance process includes continuous security testing, FireEye recommends updating all FireEye products with the latest releases as soon as possible. As an overall strategy to reduce risk exposure, customers are also encouraged to follow best practices, which include:

  • Always keep the product version up-to-date

  • Limit network access to the management interfaces of the appliance using firewalls or similar measures

  • Only issue accounts to trusted administrators

  • Use strong passwords

  • Monitor logs

  • Restrict physical access to the appliance to trusted administrators

Offline Portal Users

If you are using the Offline Portal to upgrade your appliance, consult the following documents for more information and instructions for installing Guest Images:

  • Offline Portal User Guide

You must have a DTI Update Portal user account to install Guest Images from the Offline Portal.

Guest Image Profiles Included in This Release

Individual profiles in Guest Images bundles are updated frequently. To see the profiles available in this release, use the Web UI or the CLI.

  • In the Web UI: Go to Settings > Guest Images and click the Analysis Images tab.

  • In the CLI: Go to configuration mode. Enter show guest-images available defaults to see the profiles included in the default bundle.

For details, see the topics "Managing Guest Images Using the Web UI" and "Viewing Guest Images Using the CLI" in the "System Configuration" section of the User Guide for your appliance.

Guest Images Versions and Bundle Versions

The Installed Version and Latest Version numbers shown on the About > Upgrade screen are for the GI bundle version, not the GI version. GI Bundle refers to how Guest Images are deployed on the FireEye cloud, while GI Version refers to how Guest Images are shown on FireEye appliances.

GI Release 21.0101 contains two GI bundles: GI Bundle version 21.0201 does not include a Linux profile. GI Bundle version 21.0301 includes a Linux profile.

GI 21.0201 (GI Profiles - Windows/OSX) is downloaded under the following circumstances:

Intel Platform x5xx (GI Profiles Downloaded)

AMD Platform x4xx (GI Profiles Downloaded)

Malware Analysis 8.1, 8.0 (Windows/OSX)

Malware Analysis 8.1, 8.0 (Windows Only)

Network Security* 8.2, 8.1, 8.0 (Windows/OSX)

Network Security 8.2, 8.1, 8.0 (Windows Only)

File Protect 8.2 (Windows/OSX), 8.0 (Windows Only)

File Protect 8.2, 8.0 (Windows Only)

VX Series 8.2, 8.1, 8.0 (Windows/OSX)

n/a

Email Security — Server Edition 8.4, 8.3, 8.2, 8.1, 8.0 (Windows/OSX)

Email Security — Server Edition 8.4, 8.3, 8.2, 8.1, 8.0 (Windows Only)

GI 21.0301 (GI Profiles - Linux/Windows/OSX) is downloaded under the following circumstances:

Intel Platform x5xx (GI Profiles Downloaded)

AMD Platform x4xx (GI Profiles Downloaded)

Malware Analysis 9.1.x, 9.0.x, 8.4, 8.3, 8.2 (Linux/Windows/OSX)

Malware Analysis 9.1.x, 9.0.x, 8.4, 8.3, 8.2 (Windows Only)

Network Security* 9.1.x, 9.0.x, 8.3 (Linux/Windows/OSX)

Network Security 9.1.x, 9.0.x, 8.3 (Windows Only)

File Protect 9.1.x, 9.0.x, 8.3 (Linux/Windows/OSX)

File Protect 9.1.x, 9.0.x, 8.3 (Windows Only)

VX Series 9.1.x, 9.0.x, 8.3 (Linux/Windows/OSX)

n/a

Email Security — Server Edition 9.1.x, 9.0.x (Linux/Windows/OSX)

Email Security — Cloud Edition 9.1.x, 9.0.x (Windows Only)

*NX2500 appliances have 4 profiles: 3 Windows and 1 OSX.

What's New

This section describes new features in the FireEye Guest Images release 21.0101.

General Enhancements

  • Updated base image for Windows 10

  • Enhanced performance for Windows 10

  • Enhanced phishing detection in Google Chrome

  • Enhanced macro detection on Windows 7 64-bit

  • Enhanced Microsoft Office templates to report macro activities

  • Evasion handling for Operating System resolution

  • Support for Media Multimedia Redirection (MMR) on Windows 64-bit

  • Enhanced honey credentials

  • Enhanced observation of attacks using Microsoft Equation Editor

  • Latest certificates on all the profiles

  • Application updates on all the profiles

  • Enhanced macro reporting on Windows 7 64-bit

Known Guest Images Issues

The following issues are known in Guest Images release 21.0101.

Blue circular clipboard icon with a document inside, representing notes

The relevant issue tracking numbers for each item are included in parentheses.

  • If you are running a Central Management appliance version 9.1.0, you cannot upgrade the Guest Images using the Central Management Web UI. You can use the Central Management CLI, or the Web UI of each individual sensor connected to the Central Management appliance. (CMS-16348)


Guest Images Downloads

Signed Guest Images are released in full download format. The following tables list the image information for this release.

AMD Guest Image Size

Choose your AMD Guest Images download based on the following information.

Upgrade Type

Upgrade From

Patch Size

Full + Overlay

All

53.6 GB

Intel Guest Image Size

Choose your Intel Guest Images download based on the following information.

Upgrade Type

Upgrade From

Patch Size

Full download of windows profiles only + Overlay

All

52.3 GB

Additional Linux profile for Malware Analysis 9.1, 9.0, 8.4, 8.3, and 8.2 will be downloaded

17.0106 or below

3.2 GB

Additional Linux profile for Email Security — Server Edition 9.1 and 9.0 will be downloaded

17.0113 or below

3.2 GB

Additional Linux profile for File Protect 9.1, 9.0, and 8.3 will be downloaded

17.0111 or below

3.2 GB

Additional Linux profile for Network Security and VX Series 9.1, 9.0, and 8.3 will be downloaded 17.0109 or below 3.2 GB            

Additional Linux profile for Network Security and VX Series 9.1, 9.0, and 8.3 will be downloaded 17.0109 or below 3.2 GB            

Additional Linux profile for Network Security and VX Series 9.1, 9.0, and 8.3 will be downloaded 17.0109 or below 3.2 GB            

Software Download Support  

You can download Guest Images from the DTI Update Portal (https://portal-dti.fireeye.com) to upgrade your offline appliances and appliances managed by a Central Management appliance.

Upgrade Using the Offline Portal

Contact Support to see if the GI 21.0101 upgrade is available through the Offline Portal.

Upgrading a Standalone Appliance

Follow the steps below to upgrade standalone appliances.

Refer to Guest Images Versions and Bundle Versions and use the bundle appropriate for your appliance model and version.

To update your standalone appliance to GI 21.0301 (GI Profiles - Linux/Windows/OSX):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, the product type, and your product software version. Click Filter.

  3. A list of Guest Images appears. Select the Details.

  4. Click gi-bundle-21.0301 and expand the profile.

  5. Download the following:

  • 4 Windows profiles

  • 1 gi-overlay-21.0301

  • 2 OSX profiles

  • 1 Linux profile

  1. After downloading the profiles, enter the guest-images download command to download the Guest Images.

  2. Use the show guest-images download command to monitor the progress.

  3. When Guest Images have been downloaded, enter the guest-images install command to install the Guest Images on your offline, standalone appliance.

To update your standalone appliance to GI 21.0201 (GI Profiles - Windows/OSX):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, the product type, and your product software version. Click Filter.

  3. A list of Guest Images appears. Select the Details.

  4. Click gi-bundle-21.0201 and expand the profile.

  5. Download 4 Windows profiles and the gi-overlay-21.0201 file.

  6. After downloading the profiles, enter the guest-images download command to download the Guest Images.

    Use the show guest-images download command to monitor the progress.

  7. When Guest Images have been downloaded, enter the guest-images install command to install the Guest Images on your offline, standalone appliance.

Upgrading Appliances Managed by a Central Management Appliance

Follow the steps below to upgrade an appliance managed by a Central Management appliance.

To update your Central Management-managed appliance to GI 21.0301 (GI Profiles - Linux/Windows/OSX):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, the product type, and your product software version.. Click Filter.

  3. A list of Guest Images appears. Select the Details.

  4. Select gi-bundle-21.0301 and expand the profile.

  5. Download the profiles under IntelGIProfiles:

    • 4 Windows profiles

    • 2 OSX profiles

    • 1 Linux profile

    • 1 gi-overlay

  6. After the profiles are downloaded, log in to the Central Management appliance and enter the guest-images download command to download the Guest Images.

  7. Use the show guest-images download command to monitor the progress.

  8. After Guest Images are available to install, enter the guest-images install command to install the Guest Images on your offline appliance.

To update your Central Management-managed appliance to GI 21.0201 (GI Profiles - Windows/OSX):

  1. Log in to the Offline Portal.

  2. Select Filter Resources, product type, and version number. Click Filter.

  3. A list of Guest Images appears. Select the Details.

  4. Select gi-bundle-21.0201 and expand the profile.

  5. Download the profiles under AMDGIProfiles:

    • 4 Windows profiles and one gi-overlay

  6. After the profiles are downloaded, log in to the Central Management appliance and enter the guest-images download command to download the Guest Images.

  7. Use the show guest-images download command to monitor the progress.

  8. After Guest Images are available to install, enter the guest-images install command to install the Guest Images on your offline appliance.