Note
For essential security configurations and best practices for deploying NDR, see article 000015495.
The NDR Console 4.0.0 Update Release incorporates the powerful new features, impactful enhancements, and significant detection and response capabilities from previous NDR Console 4.0, in addition to the following critical additions.
Enhancements
TrellixWise and GTI Proxy Configuration Support
New configuration options are available to route TrellixWise and GTI communication through a proxy server. This enables secure external connectivity and threat intelligence updates for appliances deployed in restricted or air-gapped network environments.
Elasticsearch Field Mapping Optimization
Trellix NDR now uses optimized static field mapping for Elasticsearch. This enhancement prevents data indexing failures by ensuring data types are correctly defined and by blocking fields that are not critical for search or analysis. This significantly reduces the risk of mapping errors, prevents the total field count limit from being exceeded, and ensures stable, long-term data ingestion.
New Features
This section describes new features and changes in the Trellix NDR Console release 4.0.0.
Enhanced alert analysis
This feature significantly improves the analyst experience by providing enhanced visibility, organization, and efficiency in threat detection and response. This is achieved through:
Enhanced workflows and the introduction of new views such as the Alert details view, Alerts List view, and Users List view.
Synchronized filtering across the alert timeline, alert table, conversation map, and event table. Additionally, users can now filter and view suppressed alerts directly within the Alerts page.
Enhanced analyst springboards that provide focused views and enable analyst to quickly prioritize and investigate threats based on specific criteria. Analyst Springboards now offer insights by geography, MITRE tactic, asset OS vs. severity, protocol usage over time, risky assets, and risky conversations.
Risk-based severity scoring for alerts incorporating:
MITRE information - Enhances alerts with MITRE ATT&CK tactics, offering analysts a clear view of attacker techniques. This enables prioritization based on the severity and prevalence of specific tactics, improving threat correlation.
Tenable integration - Enriches alerts and asset details with vulnerability data from Tenable Security Center for a holistic risk assessment. This combines network threat data with vulnerability insights, enabling risk mitigation and prioritized investigation.
ePO integration - Utilizes the managed state for an endpoint in ePO to perform holistic risk assessment for all risky assets.
Customizable severity badges - Allows customizable severity badges, enabling analysts to visually prioritize alerts based on organizational risk tolerance. Security teams can define severity levels and indicators for quicker identification and response to the most urgent threats.
Improved asset visibility
A new and enhanced Assets List view with features like persistent filters, CSV download (including priority asset tagging), pagination, static asset type filtering, integration with ePO and Tenable to provide enriched asset data.
The Asset Details view includes dedicated panels for events, alerts, and conversation graphs. It also provides priority tagging, acknowledgements, and packet capture of an asset capability.
Comprehensive Integrations
A dedicated Integration Hub has been added for streamlined management of integrations.
New integrations include enhanced SIEM integration (Splunk), Tenable Security Center, and on-premises ePO.
SIEM integration (Splunk) - Provide security teams with centralized monitoring and log analysis capabilities from numerous assets across the network. By receiving notifications, a SIEM can extract metadata from logs to provide additional context for forensic investigations, thereby reducing the time needed to investigate an attack.
Tenable Security Center - Enhances asset details by incorporating scan reports from Tenable Security, improves risk scoring by increasing alert severity when a CVE matches both the alert and a Tenable-reported asset vulnerability, and improves risk scoring by increasing alert severity when a CVE matches both the alert and a Tenable-reported asset vulnerability
ePO - On-premises - Enhances endpoint visibility and control within the NDR Console. It correlates network-based detections with ePO's endpoint data and offers a unified view of assets and their security posture.
Selective Packet Capture
Enables the analyst to capture network traffic for a defined duration of interest around suspicious assets, from the connected NDR Console-sensor, enabling closer investigations and quicker threat analysis on suspicious assets.
NDR Console Product Editions
The product name has been consistently updated to Network Detection & Response Console (NDR Console).
NDR Console has different product editions: Essentials, Core, and Enterprise. Each edition offers varying features and capabilities, which are detailed within the documentation.
The following capabilities are available based on the product editions:
Minimum system requirements for NDR Console-CORE and NDR Console-ENTERPRISE Licenses
Minimum RAM: 64 GB
Minimum CPU: 16 cores
Note
These requirements apply to all Virtual NDR Console variants when using an NDR Console-CORE or NDR Console-ENTERPRISE license.
Expanded threat detection
New detection capabilities include identifying communication with newly registered and known malicious domains, DNS and ICMP tunneling, phishing attempts (exfil/credential steal), SSL anomalies, Tor activity, and lookups/detections of suspicious URLs.
NDR Console Alert Integration with Trellix WISE (GenAI) Solution
Trellix Wise assists with alert investigations, reducing false positives and facilitating remediation through conversational AI. It offers various investigation tips that suggests remediation actions, enables effective alert handling, and enhances learning about alert hunting.
Integrate NDR Console with Global Threat Intelligence (GTI) to determine the reputation of URLs
Integration between NDR Console can now query GTI for the reputation of a URL, specifically for use within the NDR Console module. This integration aims to enhance the detection capabilities of the NDR system by using URL information from PX, NX, and IPS metadata.
Support to detect DNS tunneling exploits
You can effectively configure DNS tunneling detection using the CLI. The NDR Console appliance shall monitor DNS queries for signs of malicious activity, alerting you when suspicious patterns are detected, and allowing for timely response to potential threats.
General UI/UX Improvements
Improved page layouts.
Improved widgets on dashboards.
Resolved issues
The following issues were resolved in the NDR Console4.0.0 release.
Tracking number | Summary |
|---|---|
NETFIM-7773 | Prevents nginx logs (specifically ext_dga.DEBUG entries) from filling the /var partition, which previously led to system disk space exhaustion and performance degradation. |
NDR-2324 | NDR Console now accurately displays data associated with specific protocols in the Bytes Over Time widget. |
NETFIM-7764 | Eliminates a validation_exception that occurred during database indexing. |
NETFIM-7725 | Ensures the NDR Console appliance can successfully save LDAP configurations. |
NETFIM-7711 | Corrects the issue causing the dashboard to fail loading field mappings, restoring auto-completion features and removing the error message. |
NETFIM-7499 | Restores the login banner customization feature's availability when the appliance is configured in Director mode. |
NETFIM-7437 | Implements a Save and Cancel option in the GTI Klish menu. |
NETFIM-7414 | Suppresses the incorrect "GTI Services Not Running" message when the service is intentionally disabled. |
NETFIM-7138 | Security and Stability Enhancements:
|
NDR-2530 | Ensures the last packet is correctly displayed in the Reconstruction view. |
NDR-2595 | Confirms packet availability after session reconstruction on the primary appliance. |
NDR-2216 | Removes deleted patches from the visible list on the Image Management page. |
NDR-2468 | Restores data reception for the Tenable integration. |
NDR-2478 | Increases the maximum character length for database field data to prevent overflow errors. |
NDR-2509 | Corrects asset listing to exclude APIPA (169.254.x.x) and IPv6 link-local (fe80) entries. |
NDR-2582 | Optimizes Elasticsearch configuration to prevent data indexing failures caused by exceeding the maximum open shard limit. |
NDR-2224 | Improves NDR Console data indexing reliability by optimizing Elasticsearch index shard configuration and reducing the overall open shard count. |
NDR-2265 | Enables the successful removal of old devices from the Health Status page. |
NDR-2501 | Eliminates the delay experienced when initiating Reconstruction from the icon in the Events table. |
NDR-2523 | Prevents the error message that appeared when a Reconstruction request could not be created for specific alerts. |
NETFIM-7846 | Ensures the iaconfig and postgres services remain running after security hardening is enabled on the data node. |
NDR-2090 | Displays hash values correctly during Reconstruction. |
NETFIM-7856 | Reduces disk space consumption by preventing Postgres errors from generating excessive logs. |
NDR-2034 | Stops the error.log file from being filled with excessive ext_dga debug messages. |
NETFIM-7853 | Introduces support for creating usernames that include hyphens. |
NDR-2018 | Displays the top 5 CVEs under Tenable data in the WebUI, rather than only one. |
NETFIM-7826 | Manages the growth of pxvlaninfo tables to prevent the /data/ia/db partition from filling up. |
NDR-1884 | Optimizes logging to prevent failed Postgres queries from creating excessive error logs and consuming disk space. |
NDR-1855 | Ensures the Asset Details timeline correctly displays the customer's local time instead of UTC. |
NDR-1848 | Accelerates the NDR Console Console login process by optimizing Google API calls. |
NDR-1834 | Corrects the Conversation Map to accurately reflect asset severity, preventing a misleading low severity status when no alerts are associated. |
NDR-1833 | Enhances stability to prevent the Users page from crashing. |
NDR-1832 | Enables Trellix Wise to function correctly for riskware alerts. |
NDR-1743 | Ensures alerts are visible for assets managed from Trellix ePO (ePO). |
NDR-1742 | Enhances security by ensuring the epo-configure command does not return passwords in plain text. |
NDR-1702 | Corrects the user name hyperlink on the User List to redirect to the correct user information instead of Asset Details. |
NDR-1699 | Restores the correct display of source and destination information in the Alert Details view. |
NDR-1631 | Corrects the siem-export status reporting to accurately reflect the license state, preventing a false critical status when the NDR Console license is not installed. |
NETFIM-7825 | Prevents the nxingress service from shutting down after receiving a SIGHUP signal, ensuring continuous alert synchronization to NDR Console. |
NDR-1986 | Ensures the Director successfully loads data even if one of the connected master nodes is experiencing problems. |
NDR-2094 | Displays the top 5 CVEs under Tenable data in the WebUI, rather than only one. |
NETFIM-7850 | Prevents Elasticsearch indexing failures by managing the open shards count to prevent it from reaching its limit. |
NDR-1934 | Stops the logging of excessive ElasticsearchException errors that were flooding the npulse logs. |
NDR-2181 | Restores data visibility to the Protocol Overview chart. |
NDR-2177 | Enhances PostgreSQL stability by resolving the “invalid byte sequence for encoding ‘UTF8’” error on insert statements, preventing log file growth. |
NDR-2185 | Ensures reliable log rotation for PostgreSQL, eliminating log file growth and storage concerns. |
NDR-2155 | Confirms NSM no longer appears in the Health Status after its association with NDR Console is disabled, ensuring accurate health reporting. |
NDR-2229 | Optimizes PostgreSQL checkpoint frequency, reducing the generation of excessive log entries. |
NDR-2231 | Stabilizes Kafka operation to ensure continuous event delivery to topics. |
NDR-2212 | Improves disk space management to prevent the PostgreSQL partition from running out of disk space. |
NDR-2034 | Prevents ext_dga DEBUG level messages from being logged when the system log level is set to INFO. |
NDR-2198 | Ensures reliable alert session reconstruction from the Alerts page for alerts raised by NDR Console. |
NDR-2293 | Enables successful PCAP reconstruction tasks from the Alerts page for alerts with source NX. |
NDR-2292 | Ensures reliable alert session reconstruction from the Alerts page for alerts raised by the NDR Console plugin. |
NDR-2248 | Corrects PCAP reconstruction failure by resolving the "Requested events were not found in PX" error. |
NDR-2383 | Secures the Trellix Wise URL configuration to prevent it from being overwritten. |
NDR-2397 | Ensures all essential processes start successfully after an upgrade by preventing certificate corruption. |
NDR-2337 | Automatically removes stale files in the /data/ia/images directory to free up disk space and prevent new upgrade failures. |
NDR-2326 | Stabilizes the /var folder disk usage to prevent it from intermittently reaching 100% capacity and impacting system operations. |
Known Issues
The following issues are known in the NDR Console 4.0.0 release.
Tracking number | Summary |
|---|---|
NETFIM-7039 | The Network Anomalies chart does not display the hostname. The Hosts page displays both the IP address and hostname for the same host. |
NETFIM-6808 | Session reconstruction of NX events does not work in a certain scenario. Workaround: When PX release 6.1.x connected to NDR Console release 2.2.0 is upgraded, remove PX from metadata menu and add it back for session reconstruction of NX events to work (when using the client group workflow). |
NETFIM-6420 | Adding a standalone NDR Console appliance as a data node to a cluster fails if the cluster name has changed. The message “unable to join cluster exception/cluster UUID not matching” is displayed. Workaround is to clean up the older data residing in the /data/ia/elasticsearch directory. |
NETFIM-5968 | Lists, saved queries, and scheduled searches are not shown in the UI after the cluster name is changed. |
NETFIM-5488 | DTI proxy authorization types "ntlm" and "none" are not supported. |
NETFIM-5427 | On virtual NDR Console appliances, the |
NETFIM-5181 | In a virtual NDR Console primary-secondary set up in ESXi, the cluster health may fail if the gateway recovery count is not set correctly. The Gateway Recovery Count must be set to the total number of non-director instances in the cluster. For example, if there are 2 instances in a cluster, the gateway recovery count must be set to 2. Use the |
NETFIM-4932 | Restarting a virtual NDR Console environment set up in AWS may cause the instance's IP address to change, which may cause the NDR Console-PX or NDR Console-Director connection to fail. |
NETFIM-4712 | If a virtual NDR Console OVA is deployed with only one hard disk as data storage, Elasticsearch may fail at startup. |
NDR-2170 | The automatic resizing functionality for the conversation map within the Asset Details view does not operate as designed. |
NDR-2257 | The NDR console reports an inflated asset count compared to the actual deployed asset inventory. |
NDR-2091 | The Follow Stream option on the Reconstruct page within the WebUI is non-functional. |
Additional Information
Upgrade support
Note
Configure DNS server before you upgrade the NDR Console appliance.
You can upgrade your NDR Console appliance to release 4.0.0 from release 3.1. For upgrade instructions, see NDR Product Guide.
Product compatibility
This release supports Packet Capture Series versions 6.2 and later.