New features and changes
This section describes new features or enhancements in the Intelligent Virtual Execution - Server 10.0.3 release.
You can now integrate pGTI with Intelligent Virtual Execution - Server. New CLIs to integrate pGTI with Intelligent Virtual Execution - Server are listed here:
mvx analysis pgti base url— Stores the URL address of the pGTI server.mvx analysis pgti enable— Enables the IVX integration with the pGTI server.show mvx analysis pgti— Verify the configuration status of pGTI with Intelligent Virtual Execution - Server.no mvx analysis pgti enable— Disables the Intelligent Virtual Execution - Server integration with the pGTI server.no mvx analysis pgti base url— Deletes the URL address of the pGTI server.mvx analysis pgti apikey certificate <cert_name> ca-list <ca-chain-cert_name>— Generates API key for communicating with the PGTI server using the API.no mvx analysis pgti apikey— Deletes the pGTI API key.
You can integrate ICAP with Intelligent Virtual Execution - Server. New CLIs to integrate ICAP with Intelligent Virtual Execution - Server are listed here:
icap-service enable— This command enables the ICAP functionality on IVX. By default, the ICAP functionality will be disabled on the IVX. To disable the ICAP functionality, useno icap-service enable.icap-service respmod enable— This command enables the processing of response modification for ICAP data. IVX service sends 204 code to ICAP client if it is set as disabled. To disable, useno icap-service respmod enable.Note
Currently, ICAP supports only response modification (RESPMOD) and does not support request modification (REQMOD).
icap-service block-mode response-page enable— This command enables or disables the response page functionality for ICAP blocking on IVX. By default this is set to enabled on the IVX.icap-service tcp port <port-num>— This command allows the user to customize the TCP port over ICAP server.icap-service interface <intf>— This command allows the user to configure the interface used by ICAP server.icap-service secure certificate <cert>— This command allows the user to configure the certificate for secure ICAP.icap-service secure port <port>— This command allows the user to configure the port for secure ICAP.icap-service max-connections— This command allows the user to configure the number of ICAP connections.icap-service block-mode enable— This command enables the ICAP blocking functionality on IVX. By default, the ICAP blocking functionality is not be enabled on IVX. To disable, useno icap-service block-mode enable.icap-service max-file-size— This command configures the maximum file size supported (in MB) by ICAP.show icap-service config— This command displays the ICAP server configuration. This command does not display the Internal configuration.show icap-service stats— This command displays the ICAP module statistics.
CLIs for Riskware rules in Intelligent Virtual Execution - Server are listed here:
mvx analysis riskware policy fe-rules enable— Enables riskware detection based on the set of Trellix common rules on the Intelligent Virtual Execution - Server appliance.no mvx analysis riskware policy fe-rules enable— Disables riskware detection based on the set of Trellix common rules on the Intelligent Virtual Execution - Server appliance.mvx analysis riskware policy rule * enable— Enables a specific riskware detection custom policy rule on the Intelligent Virtual Execution - Server series appliance.no mvx analysis riskware policy rule * enable— Disables a specific riskware detection custom policy rule on the Intelligent Virtual Execution - Server series appliance.show analysis riskware policy rules— This is an existing CLI command which displays the current riskware detection custom policy rule configuration.
CLIs to configure alert retention period and the deletion cron execution time:
mvx analysis fedb data-retention alert duration-days <1 - 3650>mvx analysis fedb data-retention alert schedule-time <HH:MM>show mvx analysis fedb data-retention
Use the following CLIs to configure the submission results retention period. By default, the retention period for submissions is set to two days.
mvx analysis cdb data-retention all <2-15>show mvx analysis cdb data-retention
Use the following CLI to search for intel feeds like hash/url/md5:
show analysis intel url <url>— Display Intel information for URL.show analysis intel sha256 <sha265>— Display Intel information for sha256.show analysis intel md5 <mdsum>— Display Intel information for md5.
APIs for Intelligent Virtual Execution - Server 10.0.3 are listed:
Submission filtering by Verdict, Submitter name and Time range — This API for submission filtering provides users with the capability to filter submissions based on specific criteria, such as verdict type (malicious or riskware) and submitter name.
Fetching artifacts from any VX broker in a cluster — You can now fetch artifacts from any VX Broker in the cluster, irrespective of the original submission location. This enhancement allows data to be shared across all brokers, enabling users to call APIs on any VX Broker to retrieve artifacts seamlessly.
The triage bundle and log archive password is changed to Trellix Customer Support Archive.
Resolved issues
The following issues were resolved in the Intelligent Virtual Execution - Server 10.0.3 release.
Tracking number | Summary |
|---|---|
CMS-17212 | Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted. |
COM-30655 | Fixes the issue of prolonged processing of database backup when alert purge is in progress. |
COM-30659 | Fixes the issue of missing alert details in the report generated during alert purging. |
COM-31673 | Java libraries are upgraded to address CVEs. |
COM-62171 | Fixes an issue where ATD model-specific IVX DTI credentials were not applied to the factory default FENET configurations. |
COM-62263 | Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes. |
COM-62169 | Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx. |
VX-2718 | Fixes an issue where the geolocation service is now updated in the appliance. |
Known issues
The following issues are known in the Intelligent Virtual Execution - Server 10.0.3 release.
Tracking number | Summary |
|---|---|
VX-2615 | Enabling broker role on new or upgraded cluster appliances takes cluster to degraded state. Cluster stabilizes in 10 minutes with autorecovery. |
Upgrade support
The Trellix Intelligent Virtual Execution - Server 10.0.3 release requires a reboot for the update to take effect. You can upgrade your IVX appliance to 10.0.3 from release 9.0.0 or later.
Note
You can upgrade Intelligent Virtual Execution - Server appliances to 10.0.3 only if they are standalone nodes. For information on upgrading MVX clusters (MVX Smart Grid), see Upgrading MVX Clusters on the next page.
IPMI and BIOS firmware updates are required for the VX 5500 model. See the section "Upgrading IPMI 3.11 and BIOS 1.9 Firmware for Specific Platforms" below.
Note
After an upgrade to version 10.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Upgrading MVX clusters
Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.3 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.
Note
To upgrade 9.1.x MVX clusters, you must first upgrade the CMS to version 10.0.2.
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.3.
Downloading content from the DTI offline update portal
If you download Intelligent Virtual Execution - Server 10.0.3 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the
Trellix DTI Offline Update Portal User Guide
Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms
The VX 5500 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)
For detailed instructions about upgrading IPMI, see the
System Administration Guide
To upgrade IPMI to version 3.11:
Note
IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.
Do not shut down or remove power from the appliance during the upgrade.
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
ipmi firmware update latestConfirm the upgrade:
hostname (config) #
show ipmi
If the upgrade fails, try the steps again.
If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:
Stop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
To upgrade the BIOS to version 1.9:
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
system bios firmware update latestNote
Do not shut down or remove power from the appliance during the upgrade.
Confirm the upgrade:
hostname (config) #
show system biosStop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
YARA rules supported versions
Before you upgrade an Intelligent Virtual Execution - Server appliance to the 10.0.1 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.