New features and changes

Prev Next

This section describes new features in the Trellix Central Management System release 10.0.0.

Trellix rebranding updates

As Trellix continues our exciting evolution, our customers will begin to see our solutions reflect our new name and brand. In this release, we have updated the Central Management System Web UI with the Trellix logo and name. This rebranding change requires no effort from you.

Automated generation of artifacts

All the supported artifacts are now generated for malware-object and riskware-object alerts if the display of static information for malicious and non-malicious files and URLs on the Central Management System appliance Web UI is enabled. From this release, the display of static information is enabled by default.

Datastreaming submission data to third-party SIEM

You can now configure datastreaming to Splunk servers.

Metadata streaming through an HTTP proxy

Metadata streaming through an HTTP proxy is now supported.

MUSE Web UI improvements

The Central Management System appliance Web UI has adopted the MUSE design for UX improvements.

Network Anomalies Visualization on Web UI

The Network Anomalies widget displays suspicious activities inside the network. The Alerts > Network Anomalies page displays a complete view of attackers-victims relations inside the network, using a force-directed chart.

The Health Services tab

The Health Services tab allows you to configure health monitoring parameters for all the available health services on the appliance.

New data retention and purging policy

You can now set the number of days to retain data in the database. Data will be purged after the retention period. You can change the frequency and time of the data purge.

Restoring the database from a backup file

You can now restore a backup database belonging to a different appliance model of the same release version. This feature is useful when upgrading from one appliance model to another.

IPv6 support on the IPMI for x600 appliances

IPMI on the Central Management System 6th generation appliances is now compatible with IPv6 management network.

Termination of support for x400 appliances

Upgrades to release version 10.0.0 will not be supported on Central Management System 4th generation appliances.

List of ciphers modified

The existing FIPS and CC high-security cipher lists have been updated. For more details, refer to Central Management System User Guide.

New format for alert URLs

All notification and API alert traceback URLs now use the new common format. The new URL format is https://%s/detection/objects?uuid=%s.

Sensor management changes

Retain sensor data within CMS even when a sensor is removed through the CMS UI. During re-addition of the sensor to the CMS, only the additional data will be synchronized. To completely remove all sensor-related information from the CMS, you must explicitly delete the sensor data using the CLI.

General enhancements

  • You can now select all the managed appliances for a bulk upgrade by specifying All in the Sensor Group dropdown on the Update Sensors page.

  • The HTTP events generated on the appliance can now be sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.

  • Log-management functionality has been improved.

  • The malware artifacts data downloaded as a zip file for any specified alert includes OS Change Graph data.

  • The Service Health Statistics Trend widget on the Central Management System appliance Web UI dashboard highlights the health level of the most critical service in each category tile.

  • All the supported formats for Rsyslog notifications are now displayed in the Central Management System Web UI.

  • Factory default certificate generation key size is changed to 3072 bits.

  • You can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.

  • You can now add a YARA rule to specific appliances or groups managed by a Central Management System appliance using the API.

  • Alert type 'Riskware-Object' has been added for the report type 'Riskware Details' for both Static and Scheduled Reports in the Reports option on the Central Management System Web UI.

  • The Monitored Traffic widget on the Central Management System appliance Web UI dashboard now has the option to view the network traffic rate for a specific interface.