Network Detection and Response 4.0.0 Update Release Notes

Prev Next

Note

For essential security configurations and best practices for deploying NDR, see article 000015495.

The NDR Console 4.0.0 Update Release incorporates the powerful new features, impactful enhancements, and significant detection and response capabilities from previous NDR Console 4.0, in addition to the following critical additions.

Enhancements

  • TrellixWise and GTI Proxy Configuration Support

    New configuration options are available to route TrellixWise and GTI communication through a proxy server. This enables secure external connectivity and threat intelligence updates for appliances deployed in restricted or air-gapped network environments.

  • Elasticsearch Field Mapping Optimization

    Trellix NDR now uses optimized static field mapping for Elasticsearch. This enhancement prevents data indexing failures by ensuring data types are correctly defined and by blocking fields that are not critical for search or analysis. This significantly reduces the risk of mapping errors, prevents the total field count limit from being exceeded, and ensures stable, long-term data ingestion.

New Features

This section describes new features and changes in the Trellix NDR Console release 4.0.0.

  • Enhanced alert analysis

    This feature significantly improves the analyst experience by providing enhanced visibility, organization, and efficiency in threat detection and response. This is achieved through:

    • Enhanced workflows and the introduction of new views such as the Alert details view, Alerts List view, and Users List view.

    • Synchronized filtering across the alert timeline, alert table, conversation map, and event table. Additionally, users can now filter and view suppressed alerts directly within the Alerts page.

    • Enhanced analyst springboards that provide focused views and enable analyst to quickly prioritize and investigate threats based on specific criteria. Analyst Springboards now offer insights by geography, MITRE tactic, asset OS vs. severity, protocol usage over time, risky assets, and risky conversations.

    • Risk-based severity scoring for alerts incorporating:

      • MITRE information - Enhances alerts with MITRE ATT&CK tactics, offering analysts a clear view of attacker techniques. This enables prioritization based on the severity and prevalence of specific tactics, improving threat correlation.

      • Tenable integration - Enriches alerts and asset details with vulnerability data from Tenable Security Center for a holistic risk assessment. This combines network threat data with vulnerability insights, enabling risk mitigation and prioritized investigation.

      • ePO integration - Utilizes the managed state for an endpoint in ePO to perform holistic risk assessment for all risky assets.

      • Customizable severity badges - Allows customizable severity badges, enabling analysts to visually prioritize alerts based on organizational risk tolerance. Security teams can define severity levels and indicators for quicker identification and response to the most urgent threats.

  • Improved asset visibility

    • A new and enhanced Assets List view with features like persistent filters, CSV download (including priority asset tagging), pagination, static asset type filtering, integration with ePO and Tenable to provide enriched asset data.

    • The Asset Details view includes dedicated panels for events, alerts, and conversation graphs. It also provides priority tagging, acknowledgements, and packet capture of an asset capability.

  • Comprehensive Integrations

    • A dedicated Integration Hub has been added for streamlined management of integrations.

    • New integrations include enhanced SIEM integration (Splunk), Tenable Security Center, and on-premises ePO.

      • SIEM integration (Splunk) - Provide security teams with centralized monitoring and log analysis capabilities from numerous assets across the network. By receiving notifications, a SIEM can extract metadata from logs to provide additional context for forensic investigations, thereby reducing the time needed to investigate an attack.

      • Tenable Security Center - Enhances asset details by incorporating scan reports from Tenable Security, improves risk scoring by increasing alert severity when a CVE matches both the alert and a Tenable-reported asset vulnerability, and improves risk scoring by increasing alert severity when a CVE matches both the alert and a Tenable-reported asset vulnerability

      • ePO - On-premises - Enhances endpoint visibility and control within the NDR Console. It correlates network-based detections with ePO's endpoint data and offers a unified view of assets and their security posture.

  • Selective Packet Capture

    Enables the analyst to capture network traffic for a defined duration of interest around suspicious assets, from the connected NDR Console-sensor, enabling closer investigations and quicker threat analysis on suspicious assets.

  • NDR Console Product Editions

    • The product name has been consistently updated to Network Detection & Response Console (NDR Console).

    • NDR Console has different product editions: Essentials, Core, and Enterprise. Each edition offers varying features and capabilities, which are detailed within the documentation.

      The following capabilities are available based on the product editions:

    • Minimum system requirements for NDR Console-CORE and NDR Console-ENTERPRISE Licenses

      • Minimum RAM: 64 GB

      • Minimum CPU: 16 cores

      Note

      These requirements apply to all Virtual NDR Console variants when using an NDR Console-CORE or NDR Console-ENTERPRISE license.

  • Expanded threat detection

    • New detection capabilities include identifying communication with newly registered and known malicious domains, DNS and ICMP tunneling, phishing attempts (exfil/credential steal), SSL anomalies, Tor activity, and lookups/detections of suspicious URLs.

  • NDR Console Alert Integration with Trellix WISE (GenAI) Solution

    Trellix Wise assists with alert investigations, reducing false positives and facilitating remediation through conversational AI. It offers various investigation tips that suggests remediation actions, enables effective alert handling, and enhances learning about alert hunting.

  • Integrate NDR Console with Global Threat Intelligence (GTI) to determine the reputation of URLs

    Integration between NDR Console can now query GTI for the reputation of a URL, specifically for use within the NDR Console module. This integration aims to enhance the detection capabilities of the NDR system by using URL information from PX, NX, and IPS metadata.

  • Support to detect DNS tunneling exploits

    You can effectively configure DNS tunneling detection using the CLI. The NDR Console appliance shall monitor DNS queries for signs of malicious activity, alerting you when suspicious patterns are detected, and allowing for timely response to potential threats.

  • General UI/UX Improvements

    • Improved page layouts.

    • Improved widgets on dashboards.

Resolved issues

The following issues were resolved in the NDR Console4.0.0 release.

Tracking number

Summary

NETFIM-7773

Prevents nginx logs (specifically ext_dga.DEBUG entries) from filling the /var partition, which previously led to system disk space exhaustion and performance degradation.

NDR-2324

NDR Console now accurately displays data associated with specific protocols in the Bytes Over Time widget.

NETFIM-7764

Eliminates a validation_exception that occurred during database indexing.

NETFIM-7725

Ensures the NDR Console appliance can successfully save LDAP configurations.

NETFIM-7711

Corrects the issue causing the dashboard to fail loading field mappings, restoring auto-completion features and removing the error message.

NETFIM-7499

Restores the login banner customization feature's availability when the appliance is configured in Director mode.

NETFIM-7437

Implements a Save and Cancel option in the GTI Klish menu.

NETFIM-7414

Suppresses the incorrect "GTI Services Not Running" message when the service is intentionally disabled.

NETFIM-7138

Security and Stability Enhancements:

  • Sensitive front-end build and package files are removed from the NDR Console appliance.

  • Vulnerable packages are upgraded to stable versions.

  • The security vulnerability related to the dependencies.js file is corrected through underlying code sanitization.

  • Web server information is obfuscated to improve overall stability.

NDR-2530

Ensures the last packet is correctly displayed in the Reconstruction view.

NDR-2595

Confirms packet availability after session reconstruction on the primary appliance.

NDR-2216

Removes deleted patches from the visible list on the Image Management page.

NDR-2468

Restores data reception for the Tenable integration.

NDR-2478

Increases the maximum character length for database field data to prevent overflow errors.

NDR-2509

Corrects asset listing to exclude APIPA (169.254.x.x) and IPv6 link-local (fe80) entries.

NDR-2582

Optimizes Elasticsearch configuration to prevent data indexing failures caused by exceeding the maximum open shard limit.

NDR-2224

Improves NDR Console data indexing reliability by optimizing Elasticsearch index shard configuration and reducing the overall open shard count.

NDR-2265

Enables the successful removal of old devices from the Health Status page.

NDR-2501

Eliminates the delay experienced when initiating Reconstruction from the icon in the Events table.

NDR-2523

Prevents the error message that appeared when a Reconstruction request could not be created for specific alerts.

NETFIM-7846

Ensures the iaconfig and postgres services remain running after security hardening is enabled on the data node.

NDR-2090

Displays hash values correctly during Reconstruction.

NETFIM-7856

Reduces disk space consumption by preventing Postgres errors from generating excessive logs.

NDR-2034

Stops the error.log file from being filled with excessive ext_dga debug messages.

NETFIM-7853

Introduces support for creating usernames that include hyphens.

NDR-2018

Displays the top 5 CVEs under Tenable data in the WebUI, rather than only one.

NETFIM-7826

Manages the growth of pxvlaninfo tables to prevent the /data/ia/db partition from filling up.

NDR-1884

Optimizes logging to prevent failed Postgres queries from creating excessive error logs and consuming disk space.

NDR-1855

Ensures the Asset Details timeline correctly displays the customer's local time instead of UTC.

NDR-1848

Accelerates the NDR Console Console login process by optimizing Google API calls.

NDR-1834

Corrects the Conversation Map to accurately reflect asset severity, preventing a misleading low severity status when no alerts are associated.

NDR-1833

Enhances stability to prevent the Users page from crashing.

NDR-1832

Enables Trellix Wise to function correctly for riskware alerts.

NDR-1743

Ensures alerts are visible for assets managed from Trellix ePO (ePO).

NDR-1742

Enhances security by ensuring the epo-configure command does not return passwords in plain text.

NDR-1702

Corrects the user name hyperlink on the User List to redirect to the correct user information instead of Asset Details.

NDR-1699

Restores the correct display of source and destination information in the Alert Details view.

NDR-1631

Corrects the siem-export status reporting to accurately reflect the license state, preventing a false critical status when the NDR Console license is not installed.

NETFIM-7825

Prevents the nxingress service from shutting down after receiving a SIGHUP signal, ensuring continuous alert synchronization to NDR Console.

NDR-1986

Ensures the Director successfully loads data even if one of the connected master nodes is experiencing problems.

NDR-2094

Displays the top 5 CVEs under Tenable data in the WebUI, rather than only one.

NETFIM-7850

Prevents Elasticsearch indexing failures by managing the open shards count to prevent it from reaching its limit.

NDR-1934

Stops the logging of excessive ElasticsearchException errors that were flooding the npulse logs.

NDR-2181

Restores data visibility to the Protocol Overview chart.

NDR-2177

Enhances PostgreSQL stability by resolving the “invalid byte sequence for encoding ‘UTF8’” error on insert statements, preventing log file growth.

NDR-2185

Ensures reliable log rotation for PostgreSQL, eliminating log file growth and storage concerns.

NDR-2155

Confirms NSM no longer appears in the Health Status after its association with NDR Console is disabled, ensuring accurate health reporting.

NDR-2229

Optimizes PostgreSQL checkpoint frequency, reducing the generation of excessive log entries.

NDR-2231

Stabilizes Kafka operation to ensure continuous event delivery to topics.

NDR-2212

Improves disk space management to prevent the PostgreSQL partition from running out of disk space.

NDR-2034

Prevents ext_dga DEBUG level messages from being logged when the system log level is set to INFO.

NDR-2198

Ensures reliable alert session reconstruction from the Alerts page for alerts raised by NDR Console.

NDR-2293

Enables successful PCAP reconstruction tasks from the Alerts page for alerts with source NX.

NDR-2292

Ensures reliable alert session reconstruction from the Alerts page for alerts raised by the NDR Console plugin.

NDR-2248

Corrects PCAP reconstruction failure by resolving the "Requested events were not found in PX" error.

NDR-2383

Secures the Trellix Wise URL configuration to prevent it from being overwritten.

NDR-2397

Ensures all essential processes start successfully after an upgrade by preventing certificate corruption.

NDR-2337

Automatically removes stale files in the /data/ia/images directory to free up disk space and prevent new upgrade failures.

NDR-2326

Stabilizes the /var folder disk usage to prevent it from intermittently reaching 100% capacity and impacting system operations.

Known Issues

The following issues are known in the NDR Console 4.0.0 release.

Tracking number

Summary

NETFIM-7039

The Network Anomalies chart does not display the hostname. The Hosts page displays both the IP address and hostname for the same host.

NETFIM-6808

Session reconstruction of NX events does not work in a certain scenario.

Workaround: When PX release 6.1.x connected to NDR Console release 2.2.0 is upgraded, remove PX from metadata menu and add it back for session reconstruction of NX events to work (when using the client group workflow).

NETFIM-6420

Adding a standalone NDR Console appliance as a data node to a cluster fails if the cluster name has changed. The message “unable to join cluster exception/cluster UUID not matching” is displayed. Workaround is to clean up the older data residing in the /data/ia/elasticsearch directory.

NETFIM-5968

Lists, saved queries, and scheduled searches are not shown in the UI after the cluster name is changed.

NETFIM-5488

DTI proxy authorization types "ntlm" and "none" are not supported.

NETFIM-5427

On virtual NDR Console appliances, the show nxstatus command only outputs metadata received from a paired Network Security Series appliance within the last 60 minutes.

NETFIM-5181

In a virtual NDR Console primary-secondary set up in ESXi, the cluster health may fail if the gateway recovery count is not set correctly. The Gateway Recovery Count must be set to the total number of non-director instances in the cluster. For example, if there are 2 instances in a cluster, the gateway recovery count must be set to 2. Use the show cluster command in KLISH to determine the number of instances in a cluster, and ignore any director node included in the show cluster output.

NETFIM-4932

Restarting a virtual NDR Console environment set up in AWS may cause the instance's IP address to change, which may cause the NDR Console-PX or NDR Console-Director connection to fail.

NETFIM-4712

If a virtual NDR Console OVA is deployed with only one hard disk as data storage, Elasticsearch may fail at startup.

NDR-2170

The automatic resizing functionality for the conversation map within the Asset Details view does not operate as designed.

NDR-2257

The NDR console reports an inflated asset count compared to the actual deployed asset inventory.

NDR-2091

The Follow Stream option on the Reconstruct page within the WebUI is non-functional.

Additional Information

Upgrade support

Note

Configure DNS server before you upgrade the NDR Console appliance.

You can upgrade your NDR Console appliance to release 4.0.0 from release 3.1. For upgrade instructions, see NDR Product Guide.

Product compatibility

This release supports Packet Capture Series versions 6.2 and later.