Intelligent Virtual Execution - Cloud 24R4 Release Notes

Prev Next

IVX Cloud 24R4 introduces new features, enhancements to existing features and resolved issues.

New features and changes

This section describes new features or enhancements in the Intelligent Virtual Execution - Cloud 24R4 release.

  • Regular health checks for IVX Cloud integrationsIVX Cloud now performs regular health checks for all product integrations to ensure seamless functionality. If any integration fail, an alert notification will be displayed in the web UI, and the affected integration will be temporarily disabled. For example, if your Slack account is integrated with IVX Cloud and an issue arises, the integration will be disabled until the problem is resolved. This enhancement enables proactive monitoring of services for products integrated with IVX Cloud.

  • Enhancements for Azure Integration with IVX Cloud — The following changes are done for Azure integration:

    • The Shared access signature and Resource providers options are moved to a new location for improved accessibility.

    • A Configure Action screen has been added at the bottom of the interface to guide users through actions, similar to the setup provided for Slack.

  • IVX Cloud is now updated with the latest version of its dynamic analysis engine, improving detection capabilities for enhanced performance.

  • Zoom Team Chat integration with IVX Cloud — This release introduces the integration of Zoom Team Chat with IVX Cloud, enabling the tracking of message creation and updates. The integration supports various policy filters, allowing users to customize the scanning process based on criteria such as Sender, Channel ID, Content Type (links and attachments), Link or Link Prefix, Attachment Name or Prefix, and Attachment Type.

    Users can also set actions (Scan/Do Not Scan) for specific criteria to enhance flexibility in scanning.

  • The submission report in the UI is now updated to display the details related to the sample file instead of the operating system (OS). This enhancement provides accurate and relevant representation of the data in the sample file. The following components in the submission report are updated:

    • Detection

    • Files

    • Processes

    • Registry

    • APIs

    • Network

    • Search

  • IVX Cloud can now scan the shared Google Drive folders to detect malicious attachments.

  • Trellix DLP Network Prevent integration with IVX Cloud — The Trellix Data Loss Prevention (DLP) Network Prevent appliance is now integrated with IVX Cloud. This integration enables IVX Cloud to access rule match information through the Trellix DLP Prevent API allowing automated actions to be executed based on predefined DLP settings. The enhanced DLP rules enable users to scan across various integrations, ensuring improved protection for sensitive information.

    Note

    Users must have an active product subscription for Trellix ePO, Data Loss Prevention (DLP) Network and IVX Cloud to ensure seamless functionality.

  • Track user activities in audit logs — With IVX Cloud, you can now track all user activity in the portal as part of the audit log. Audit Logs is available under Resources in the UI.

    Events tracked as Audit Logs are:

    • Login events.

    • Submissions made through the portal.

    • Reports accessed by the user.

    • Updates to user settings.

    • User configurations such as creating or deleting API keys, updating guest image settings, and modifying or deleting policies.

  • Trellix WISE (AI Assistant) integration with IVX Cloud — When integrated with IVX Cloud, Trellix WISE offers the following key features as part of the submission analysis results:

    • Provides a summary of the submission report (analysis results).

    • Delivers a submission verdict.

    • Identifies and displays files detected as malicious.

    • Lists scanned URLs from the submission along with their verdicts.

    • Highlights the types of MITRE ATT&CK techniques involved.

    • Offers linguistic support.

    • Enables users to ask questions related to the submission.

    Note

    • Under a single contract, AI usage is limited as follows:

      • For reports, 100 queries per day and 1000 queries per month.

      • For chats, 10000 queries per month.

    • A single submission report allows up to 20 queries per day.

Resolved issues

The following issues were resolved in the Intelligent Virtual Execution - Cloud 24R4 release.

Tracking number

Summary

DOD-3245

Fixes the issue where the MITRE matrix only displays the first BALE rule across all OS profiles instead of showing all applicable rules.

DOD-3311

Fixes the issue where enabling 'Live' in the API submission settings did not apply to the submission, while all other settings worked as expected.

DOD-3312

Fixes the issue where a Slack integration appears deleted but is still visible in the UI without an option to remove it completely.

DOD-3319

(Security vulnerability issue)

DOD-3346

Fixes the issue where certain filenames and MD5 hashes were not displayed in the Analysis reports and Process Graph section when different profiles were selected. Additionally, the report did not show OS changes and screen activities for some filenames.

DOD-3348

Fixes the following issues on the Submission Settings page:

  • The Delete button was not visible preventing users from removing a specific API Key.

  • The 'Plugin' variable, though enabled in settings and enforced strictly, did not appear as enabled on the Submission Settings page.

  • UI controls were not aligned correctly.