Malware Analysis 10.0.5 Release Notes

Prev Next

New features and changes

Trellix Malware Analysis release 10.0.5 does not contain new features and changes.

New, modified, or deprecated CLI commands

Trellix Malware Analysis release 10.0.5 does not contain new, modified, or deprecated CLI commands.

Resolved issues

The following issues were resolved in the Malware Analysis 10.0.5 release.

Tracking number

Summary

COM-62837

Fixes an issue in the certified 10.0.4 release where Malware Analysis and File Protect appliances configured in compliance mode (either FIPS, CC-NDCPP, or both) failed to boot into kernel FIPS cryptography enforcement mode.

There was a theoretical risk that appliances using kernel cryptography could access a non-FIPS-approved cryptographic algorithm. Kernel mode FIPS provides an additional safety assurance against such potential violations, although our products have not been found to use any non-compliant kernel algorithms. Furthermore, when the Trellix management plane is in FIPS crypto mode, it uses only FIPS-certified OpenSSL-based cryptography. Kernel cryptography is not used by management plane software.

COM-62861

Fixes an issue with X.509 CA certificate chains in configurations where individual chain members were also used in the default-ca list. In all releases earlier to 10.0.5, deleting chains from the configuration resulted in an inconsistent configuration database. This caused subsequent certificate and default-ca configurations to fail due to inconsistency. The fix repairs any damaged certificate databases and resolves the underlying issue.

Note

This issue only affects users of certificate chains (for example, SharePoint, Web Server, MTA), and only if they have any chain member certificates listed in the default-ca list.

Known issues

The Trellix Malware Analysis 10.0.5 release does not contain Known issues.

Upgrade support

The Trellix Malware Analysis 10.0.5 release requires a reboot for the update to take effect. You can upgrade your AX appliance to 10.0.5 from release 9.0.0 or later.

After an upgrade to version 10.0.5, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

After an upgrade to version 10.0.5, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Created Log archive files will not be preserved on upgrade to 10.0.5. Please have a backup of logs before upgrade.

Important

When you upgrade an Malware Analysis appliance to 10.0.5, FireEye Advanced URL Defense Engine (FAUDE) is enabled even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" in the

Malware Analysis User Guide

.

Note

After an upgrade to version 10.0.5, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.5.

Downloading content from the DTI offline update portal

If you download Malware Analysis 10.0.5 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Malware Analysis appliance to the 10.0.5 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel context

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.