Deploy and manage Trellix Agent for OT

Prev Next

Starting with Trellix Agent 5.8.4, a new package called Trellix Agent for Operational Technology (OT) is available. This package is supported only on Windows systems and can be deployed through ePO - On-prem. It is designed for environments that need to limit the use of third-party tools. This package includes System Information Reporter (SIR) module that installs automatically after the Agent and DXL components are installed. The primary benefit of this package is the seamless, automatic installation of the System Information Reporter (SIR), which streamlines the process of gathering detailed system information from endpoints in Operational Technology (OT) environments.

System Information Reporter (SIR) features:

  • Centralized management — Allows you to enforce System Information Reporter policies on managed nodes using Trellix ePO management software.

  • Query system properties — Allows you to query the managed nodes to collect:

    • System properties such as versions, patches, and hotfixes.

    • Custom environment variable value.

    • Registry key values.

  • File search support — Allows you to query the managed nodes to search for files and file details.

  • Registry key modification support — Allows you to query the managed nodes to create, edit, or delete registry keys.

  • Backup and restore registry keys — Creates a backup of registry keys before modifying and restores registry backup file using Set Registry policy.

Understanding the difference between Trellix Agent for OT and standard Trellix Agent packages

  • Standard Trellix Agent — In the standard Windows package, SIR is not installed by default. You can install SIR with the standard Agent package by adding a command-line parameter (/installsir) during the deployment task. However, if SIR was previously installed, it will still be upgraded automatically when a newer version of Trellix Agent is deployed.

  • Trellix Agent for OT — This package is configured for automatic SIR installation. This package is available only for Windows systems.