New features and changes

Prev Next

This section describes new features in the Trellix Malware Analysis release 10.0.0.

Trellix rebranding updates

As Trellix continues our exciting evolution, our customers will begin to see our solutions reflect our new name and brand. In this release, we have updated the Malware Analysis Web UI with the Trellix logo and name. This rebranding change requires no effort from you.

Automated generation of artifacts

All the supported artifacts are now generated for all submissions if the display of static information for malicious and non-malicious files and URLs on the Malware Analysis appliance Web UI is enabled. From this release, the display of static information is enabled by default.

Show submission CLI enhancement

md5sum and sha256 values are now populated in the show submission command output.

Datastreaming submission data to third-party SIEM

You can now configure datastreaming to Splunk servers.

Metadata streaming through an HTTP proxy

Metadata streaming through an HTTP proxy is now supported.

MUSE Web UI improvements

The Malware Analysis appliance Web UI has adopted the MUSE design for UX improvements.

New data retention and purging policy

You can now set the number of days to retain data in the database. Data will be purged after the retention period. You can change the frequency and time of the data purge.

IPv6 support on the IPMI for x600 appliances

IPMI on the Malware Analysis 6th generation appliances is now compatible with IPv6 management network.

Termination of support for x400 appliances

Upgrades to release version 10.0.0 will not be supported on Malware Analysis 4th generation appliances.

Restoring the database from a backup file

You can now restore a backup database belonging to a different appliance model of the same release version. This feature is useful when upgrading from one appliance model to another.

List of ciphers modified

The existing FIPS and CC high-security cipher lists have been updated. For more details, refer to Malware Analysis User Guide.

The Health Services tab

The Health Services tab allows you to configure health monitoring parameters for all the available health services on the appliance.

Reusing Malware Analysis settings

You can now use previously used Malware Analysis settings for preferences and profiles when submitting a malware. You can set default preferences and save it for future use.

Enhancements

  • Malware, non-malicious and riskware artifacts data downloaded as a zip file for any specified alert includes OS Change Graph data.

  • All the supported formats for Rsyslog notifications are now displayed in the Malware Analysis Web UI.

  • The Service Health Statistics Trend widget on the Malware Analysis appliance Web UI dashboard highlights the health status level in each category tile.

  • Factory default certificate generation key size is changed to 3072 bits.

  • You can now use previously applied Malware Analysis settings for preferences and profiles when submitting a malware. You can set default preferences and save it for future use.

  • Localsig enhancements:

    • sh localsig url and sh localsig file-hash now lists all the active localsig entries.

    • Black listed URLs/Hashes will not be added to localsig.

    • Localsig also supports file hashes.

  • The FAUDE URL screenshot is now generated along with other artifacts after successful submission.

  • If you download security content from the DTI Offline Update Portal, you now use the SCNET-8.0 channel of the portal.

  • Log-management functionality has been improved.

  • You can now download artifacts data corresponding to the specified artifact types (if available for the specified UUID) as a zip file using the API.

  • Alert type 'Riskware-Object' has been added for the report type 'Riskware Details' for both Static and Scheduled Reports in the Reports option on the Malware Analysis Web UI.