New features and changes
Trellix Malware Analysis release 10.0.1 does not contain new features and changes.
New, modified, or deprecated CLI commands
Trellix Malware Analysis release 10.0.1 new modified or deprecated CLI commands.
New command
New CLI to reset all DTI services credentials
fenet dti credentials reset factory-defaultResets credentials of all the existing DTI services to factory settings.
Resolved issues
The following issues were resolved in the Malware Analysis 10.0.1 release.
Tracking number | Summary |
|---|---|
COM-30687 | The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server. |
COM-31382 | Fixes an issue by adding mechanism to clean up outdated triage packages. |
COM-31481 | Fixes an issue that, by default, upgraded all the Malware Analysis appliance applications to the high-security factory default cipher-lists. |
COM-31615 | The AX appliances are not vulnerable to CVE-2023-5072. |
COM-31650 | Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details. |
MAS-3999 | On submitting any URL containing languages other than English, the appliance analyses them as as invalid. This issue is resolved. |
MAS-4017 | Fixes an issue with new files not getting included for analysis when they were uploaded to the shares. |
Known issues
The following issues are known in the Malware Analysis 10.0.1 release.
Tracking number | Summary |
|---|---|
COM-30405 | SAML Response decoding sometimes fails with IDP. The appliance displays a "bad encoding" error when the system's IDP response contains carriage return and newline characters. |
COM-30655 | The database backup process takes a long time when the alert purge is in progress. Workaround: Schedule the database backup and purge processes at different times. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
COM-30659 | Alert details might be missing from the report generated during alert purging. |
COM-30902 | Streamed data is appearing only in json format even when all the formats are enabled for rsyslog consumer. |
MAS-3749 | The CLI command system cleanup profile <profile name> older-than cannot clean up the mentioned artifacts. |
MAS-3947 | Files cannot be extracted if they have passwords containing characters other than English. |
Upgrade support
The Trellix Malware Analysis 10.0.2 release requires a reboot for the update to take effect. You can upgrade your AX appliance to 10.0.2 from release 9.0.0 or later.
After an upgrade to version 10.0.2, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
Created Log archive files will not be preserved on upgrade to 10.0.2. Please have a backup of logs before upgrade.
Important
When you upgrade an Malware Analysis appliance to 10.0.2, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" in the
Malware Analysis User Guide
.
Note
After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.2.
Downloading content from the DTI offline update portal
If you download Malware Analysis 10.0.2 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms
The AX 5550 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-25469)
For detailed instructions about upgrading IPMI, see the System Administration Guide.
To upgrade IPMI to version 3.11:
Note
IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.
Do not shut down or remove power from the appliance during the upgrade.
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
ipmi firmware update latestConfirm the upgrade:
hostname (config) #
show ipmi
If the upgrade fails, try the steps again.
If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:
Stop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
To upgrade the BIOS to version 1.9:
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
system bios firmware update latestNote
Do not shut down or remove power from the appliance during the upgrade.
Confirm the upgrade:
hostname (config) #
show system biosStop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
YARA rules supported versions
YARA rules support version 4.3.2.
Important
Before you upgrade an Malware Analysis appliance to the 10.0.2 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.
Enabling access to intel context
Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.
Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.