This EDRF - Cloud August 2026 release includes new features, enhancements, and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
New or changed
Investigation dashboard retired
The Investigation Dashboard and its corresponding menu entries are retired from the EDRF UI.
To continue investigating threats, use the following workflows:
Live Threat Analysis using Trellix Wise: Use Ask Wise to trace threat behaviors, summarize incidents, and view attack paths in the Knowledge Graph.
For more information, see Investigate threats using Generative AI.
Investigate historical data using Case Graph Visualizer: Download the investigation historical case data from the EDRF UI and view it offline using the Case Graph Visualizer.
For more information, see the Trellix Knowledge Base article - How to use Case Graph Visualizer to view Trellix EDR investigation historical data - KB000015761.
View EDRF Client version in Device Search and Monitoring dashboards
The EDRF UI now displays the Client version installed on the endpoints. You can view the Client version in the following locations:
Device section of the Threat Details pane on the Monitoring dashboard.
Device Search details side panel.
Quarantine Linux endpoints in the Monitoring dashboard
The Monitoring dashboard now supports the Quarantine Device and End Quarantine Device actions for Linux endpoints.
For more information, see Quarantine devices using the Monitoring dashboard and End quarantine devices using the Monitoring dashboard.
Agent ID information icon tooltip with HX integration links
An information icon appears near the Agent ID field and column headers across the Alerting, Monitoring, Device Search, and Historical Search dashboards. Hover over this icon to display an interactive tooltip. The tooltip explains that an Agent ID displays only for endpoints connected to the Endpoint Security (HX) server.
The EDRF Client generates a unique Agent ID for each endpoint. The EDRF UI displays the Agent ID only when the endpoint runs the EDRF Client and is connected to the Endpoint Security (HX) server.
Context-sensitive Help redirect in EDRF UI
In the EDRF UI, selecting the Help button now opens the Trellix Documentation Portal home page in a new browser window.
Resolved issues
Reference | Resolution |
|---|---|
SEC-213380 | Resolves an issue where ePO tags appeared blank for cloud-hosted tenants on the Device Search page. An automated backend service now retrieves and caches ePO - SaaS tags every 24 hours. |
SEC-213157 | Resolves an issue in ePO - On‑prem deployments where the onboarded Trellix EDR tenants ingested data into the US–WEST data center by default because the DXL Cloud Databus URL was set incorrectly. The Correct DXL Cloud Databus URL scheduled server task now automatically updates and maintains the URL to point to the appropriate regional data center. |
SEC-216064 | Resolves an issue where the Internal error occurred banner continuously displayed on the Trellix EDR Configuration page when tenant registration errors occurred. |
Known issues
For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.