This section describes new features in the Trellix File Protect release 10.0.
Automated generation of artifacts
All the supported artifacts are now generated for malware-object and riskware-object alerts if the display of static information for malicious and non-malicious files and URLs on the File Protect appliance Web UI is enabled. From this release, the display of static information is enabled by default.
Datastreaming submission data to third-party SIEM
You can now configure datastreaming to Splunk servers.
Metadata streaming through an HTTP proxy
Metadata streaming through an HTTP proxy is now supported.
Show submission CLI enhancement
md5sum and sha256 values are now populated in the show submission command output.
MUSE Web UI improvements
The File Protect appliance Web UI has adopted the MUSE design for UX improvements.
New data retention and purging policy
You can now set the number of days to retain data in the database settings using the File Protect appliance Web UI.
Data will be purged after the retention period. You can change the frequency and time of the data purge.
IPv6 support on the IPMI for x600 appliances
IPMI on the File Protect 6th generation appliances is now compatible with IPv6 management network.
Termination of support for x400 appliances
Upgrades to release version 10.0.0 will not be supported on File Protect 4th generation appliances.
The Health Services tab
The Health Services tab allows you to configure health monitoring parameters for all the available health services on the appliance.
Restoring the database from a backup file
You can now restore a backup database belonging to a different appliance model of the same release version. This feature is useful when upgrading from one appliance model to another.
FX 2500V specifications upgrade
The FX 2500V appliance can now have a maximum of 8 CPU cores and 32 GB RAM.
FX 2500V Availability on Azure Virtual machines
The FX 2500V is now available to be deployed on Azure VM and has a maximum of 16 cores and 32GB RAM. Disk size can range between 2TB to 4TB.
New additions to the Configuring a Scan Wizard
The Configure Dynamic Analysis option is now added to the Filter this Scan section of the Configure a Scan Wizard.
You can select the file types for dynamic analysis at the appliance level. All the extensions supported for analysis on the File Protect appliance are, by default, enabled for dynamic analysis.
You can now edit scheduled and running scans to adjust filters and parameters.
When you edit a running scan, the changes are applied to the remaining files. Files already analyzed by the scan remain unaffected by the changes.
Microsoft Azure Blob storage integration with the File Protect appliance
Microsoft Azure Blob is now available to be configured on the File Protect appliance to analyze and scan for malware and manage results.
Azure Blob storage is Microsoft's object storage solution for the cloud. Blob storage is optimized for storing massive amounts of unstructured data, such as text or binary data. To know more about Azure Blob Storage, visit https://learn.microsoft.com/en-us/azure/storage/blobs.
List of ciphers modified
The existing FIPS and CC high-security cipher lists have been updated. For more details, refer to File Protect User Guide.
Azure NetApp Files (ANF) storage integration with the File Protect appliance
ANF is now available to be configured on the File Protect appliance to analyze and scan for malware and manage results. Azure NetApp Files is an Azure native, first-party, enterprise-class, high-performance file storage service. It provides NAS volumes as a service for which you can create NetApp accounts, capacity pools, select service and performance levels, create volumes, and manage data protection. Thus, extending File Protect Netapp On-prem support to Azure.
Enable dirty network on File Protect appliance
Live mode analysis is now available for File Protect appliance This enables the use of controlled live mode and URL dynamic analysis.
General Enhancements
All the supported formats for Rsyslog notifications are now displayed in the File Protect Web UI.
The HTTP events generated on the appliance can now be sent to the HTTP Event Collector (HEC) on a Splunk Enterprise instance.
The malware artifacts data downloaded as a zip file for any specified alert includes OS Change Graph data.
The Service Health Statistics Trend widget on the File Protect appliance Web UI dashboard highlights the health level of the most critical service in each category tile.
The Factory Default Certificate Generation Key size is changed to 3072 bits.
The FAUDE URL screenshot is now generated along with other artifacts after successful submission.
If you download security content from the DTI Offline Update Portal, you now use the SCNET-8.0 channel of the portal.
Log-management functionality has been improved.
You can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.
Alert type 'Riskware-Object' has been added for the report type 'Riskware Details' for both Static and Scheduled Reports in the Reports option on the File Protect Web UI.
Sharepoint On-Prem plugin has been updated. This can be used for Microsoft Sharepoint 2016 and above versions only.