The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix EDR 4.1.0 Release Notes (On-premises)

Prev Next

This   Trellix Endpoint Detection and Response 4.1.0 (On-premises) release includes new features, enhancements, resolved issues, and product rebranding changes.  

Release details

Component  

Version  

Trellix EDR Client for Windows  

4.1.0.2253  

Trellix EDR Client for Linux  

4.1.0.2243  

Trellix EDR Client for macOS  

4.1.0.2253  

Trellix EDR Client Extension  

4.1.0.1260  

Trellix EDR Endpoint Snapshot Tool   1  

6.6.0.10  

Trellix EDR Rules  

4.1.0.2253  

1Separate release cadence is followed for   Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see   Software Catalog or   Trellix Products Downloads site.  

Before installing or upgrading to the   Trellix EDR client 4.1.x or later:  

  • Make sure to update the   MsgBus Cert Updater package to the latest version available. This package is available on   Software Catalog under the   Trellix Agent product.  

  • Make sure to install the   Trellix Data Exchange Layer   Broker extension. This package is available on   Software Catalog under the   Trellix Data Exchange Layer   product.  

When you install or upgrade to   Trellix EDR 4.1.x:  

  • You might be required to reboot the endpoint. On some installs and upgrades,   Trellix EDR installation will not proceed until the endpoint is rebooted and the installation or upgrade is restarted. For details, see   KB96049.  

  • Endpoints unaffected by   KB96049 might be prompted to reboot the endpoint. It is a good practice to reboot the endpoint but not mandatory. The reboot message can be suppressed by disabling the   Prompt User When a Reboot is Required option on the   Trellix Agent properties page.  

New features and changes

This release includes the following features and changes.  

  • Rebranding changes — You can continue to secure your organization with   Trellix EDR as usual. You will notice the following changes in the software:  

    • Brand logo — McAfee logo is replaced with   Trellix logo.  

    • User interface — Color and typeface are updated to provide better user experience.  

    • Product name — MVISION EDR is renamed as   Trellix EDR.  

    • End User License Agreement and Copyright — The End User License Agreement and Copyright are updated according to legal requirements. For more details, read the agreement details.  

    As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update/installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.  

    For information on downloading and installing the certificates, see   KB91697.  

  • Separate   Trellix EDR client packages - In this release, the single   Trellix EDR client package is now split into three separate packages for each operate system — Windows, Linux, and macOS. When installing the   Trellix EDR client, select the appropriate package and install on endpoints.  

  • Linux traces — The   Trellix EDR trace feature now supports the Linux operating system. The traces are collected from the Linux endpoints to detect any suspicious activity on the endpoint and threats are shown on the   Monitoring dashboard with metadata to help you in investigation.  

    Before installing the   Trellix EDR client on Linux endpoints, make sure to enable kernel syscall auditing to discover security violations and track security-relevant information. For details about enabling syscall auditing on different Linux distributions, see:  

    For the Linux kernel version 3.15 or earlier, the Linux trace functionality can't co-exist with auditd:  

    • If auditd is running, enabling the Linux trace functionality stops the audit service.  

    • To start the auditd service, the trace functionality must be disabled before restarting the auditd service.  

    The audit system must not be in immutable mode to use trace functionality. Otherwise, trace process will not be able to add the audit rules.  

    Note

    The audit flag to set failure must not be set to "2" (2=panic). If set, it can cause the kernel panic once the backlog limit exceeds.  

    The supported event types on Linux endpoints are:  

    • Processes  

    • Files  

    • Network connections  

    • Service change events  

    • User logon events  

    • Kernel module load and unload events  

  • Content update methods — In this release on the   Trellix EDR client version 4.1.x, you have an option to select either   Dynamic content update or   ePO push content update method to update content on Windows endpoints.  

    • By default, the   Dynamic content update is selected and effective only for Windows endpoints.  

    • macOS endpoints will automatically default to the   ePO Push Content update method.  

      For more details about the content update methods, see   General policy configuration.  

      Note

      The   Trellix EDR content update is not supported on Linux endpoints.  

      The below table gives details about the supported content update methods according to the version and operating system.  

      Version  

      Endpoints with operating system  

      Supported methods  

      4.1.x or later  

      Windows  

      Dynamic content update and ePO push content update  

      Linux  

      Content update is not supported  

      macOS  

      ePO push content update  

      4.0.x  

      Windows  

      Dynamic content update  

      Linux  

      Content update is not supported  

      macOS  

      ePO push content update  

      3.5.2 or earlier  

      Windows  

      ePO push content update  

      Linux  

      Content update is not supported  

      macOS  

      ePO push content update  

Updated platform, environment, or operating system support

Trellix EDR client is now compatible with:  

  • Microsoft Windows 10 and 11, version 22H2  

  • Red Hat Enterprise Linux 7.9, 8.4, 8.5, 8.6, and 9.0  

  • SUSE 15.3  

  • Ubuntu 22.04  

  • macOS Big Sur 11.5.2, 11.6.0, 11.6.1, and 11.6.2  

  • macOS Monterey 12.0.1, 12.1, 12.2, 12.2.1, 12.3, and 12.3.1  

For the complete list of system requirements, see supported platforms for   Trellix EDR in   KB91345.  

Resolved issues

Reference  

Resolution  

SEC-104788  

The   Trellix EDR trace plugin now successfully uploads the   Trace.log and   Trace.db files to the cloud.  

SEC-106523  

From   Trellix EDR 4.1.0 onwards, the   Trellix EDR client version no longer displays incorrectly as 0.0.0 with   Trellix Agent 5.7.6 installed on endpoints.  

SEC-105852  

Trellix EDR now releases file events quickly for better performance.  

SEC-104788  

The   Trellix EDR trace plugin now successfully runs on SkyTap virtual machines.  

SEC-18283  

The   Trellix EDR client no longer blocks the installation of SAP BOBJ application.  

SEC-91945  

The   Real-time Search dashboard now shows the correct hash value of a file.  

SEC-50818  

The   Process collector collects the hash for the process instead of its parent process on Linux endpoints.  

SEC-86490  

The   Trellix ePO - SaaS subscription page now successfully shows the   Trellix EDR extension "Used" count.  

SEC-80433  

The password set in the policy to uninstall the   Trellix EDR client no longer changes unintentionally.  

SEC-73140  

The   Trellix EDR trace plugin now successfully downloads files in OneDrive.  

SEC-106409  

Boot time values in Sysinfo are now corrected.  

SEC-91822  

The content update feature now works successfully even if the cloud API URL in   Trellix DXL   policies has space at the end.  

SEC-41675  

The   Dump Process To File reaction now creates dump files in folders with characters Umlaut.  

SEC-40674  

The   Delete Registry Value reaction now deletes the registry value with characters Umlaut.  

SEC-40352  

The   Trellix EDR client can be now successfully uninstalled from endpoints that are protected with a password consists of characters Umlaut.  

Known issues

For a list of known issues in this product release, see   KB91275.  

Installation information

The   Trellix Endpoint Detection & Response Installation Guide has the information you need to install the product for the first time and to migrate from   McAfee® Active Response.