The Trellix EDR with Forensics (EDRF) 50.2.0 release includes new features, enhancements, and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
Component | Version |
|---|---|
Trellix EDR with Forensics for Windows | 50.2.0.644 |
Trellix EDR with Forensics for Linux | 50.2.0.612 |
Trellix EDR with Forensics for macOS | 50.2.0.614 |
For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
Mitigate evasion techniques with Windows Filtering Platform
This release adds a Windows Filtering Platform (WFP) protection feature to identify and remove unauthorized WFP blocking filters targeting EDRF processes. This prevents adversaries from using evasion techniques, ensuring alerts and events are forwarded to Trellix ePO. To enable this feature, upgrade to the EDRF Client 50.2 package and extension.
Note
The extension update automatically applies changes to the Trellix Default and My Default policies. It does not update pre-existing custom policies.
Performance enhancement with Exclusion Advisor
EDRF Client now includes the Exclusion Advisor, a built-in audit module that identifies high-frequency, repetitive system activities to optimize performance. By analyzing local event data such as file writes, DNS lookups, and process starts, this module generates structured JSON reports based on user-defined thresholds. Administrators can use this information to create targeted exclusion policies that suppress benign, high-volume activity. This reduces EDRF Client CPU usage and improves endpoint performance without affecting detection of genuine threats.
For more information about Exclusion Advisor Audit, see the Trellix Knowledge Base (KB) article, How to use Exclusion Advisor Audit to troubleshoot EDRF performance issues - 000015181.
FIPS mode support in EDRF
You can now install EDRF Client on Windows, Linux, and macOS operating systems running in FIPS mode to perform the cryptographic operations. For details, see Deploy EDRF in FIPS mode.
Self Protection support for Linux
The Self Protection feature is now enabled for Linux endpoints. You can enable this feature in the Trellix EDRF General policy to prevent unauthorized access to Trellix EDRF processes, files, and configurations.
For details, see EDRF General policy.
Resolved issues
Reference | Resolution |
|---|---|
ES-22678 | Resolves an issue where EDRF Client version 50.1.0.909 and earlier could not connect to newly provisioned Endpoint Security (HX) 10.0.4 servers. |
ES-23492 | Resolves an issue where the deployment of EDRF Client 50.1.x caused high CPU utilization. To address this, EDRF Client now uses the latest |
ES-24512 | Resolves an issue where EDRF Client endpoints lost connectivity while in quarantine. This caused quarantined devices to appear offline in the Trellix EDR workspace and prevented administrators from using the Release from quarantine action. |
Known issues
For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.