The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix EDR 4.1.1 Release Notes (On-premises)

Prev Next

This   Trellix Endpoint Detection and Response 4.1.1 (On-premises) release includes a new feature and resolved issues.  

Release details

Component  

Version  

Trellix EDR Client for Windows  

4.1.1.2850  

Trellix EDR Client for Linux  

4.1.1.2850  

Trellix EDR Client for macOS  

4.1.1.2821  

Trellix EDR Client Extension  

4.1.1.582  

Trellix EDR Endpoint Snapshot Tool   1  

6.6.0.10  

Trellix EDR Rules for Windows  

4.1.1.2850  

Trellix EDR Rules for Linux  

4.1.1.2884  

1Separate release cadence is followed for   Trellix EDR Endpoint Snapshot Tool. The latest available version is considered for this release. For installing or upgrading to the latest available version, see   Software Catalog or   Trellix Products Downloads site.  

Important

(For use with   Trellix ePO - On-prem only) If you are using older versions of   Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except   Trellix Agent and   Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading   Trellix products on macOS, see   KB96485.  

(For use with   Trellix ePO - SaaS only) After upgrading macOS endpoints to the latest versions of   Trellix products,   Trellix recommends checking the installed product versions. If any products are missing or have not been upgraded to the latest version, it is necessary to manually upgrade them. For details, see   KB96552.  

Before installing or upgrading to the   Trellix EDR client 4.1.x or later:  

  • Make sure to update the   MsgBus Cert Updater package to the latest version available. This package is available on   Software Catalog under the   Trellix Agent product.  

  • Make sure to install the   Trellix Data Exchange Layer   Broker extension.  

  • Make sure to install the   Trellix EDR client extension 4.1.1.  

Note

These package are available on   Software Catalog under   Trellix Data Exchange Layer   and   Trellix EDR products respectively.  

When you install or upgrade to   Trellix EDR 4.1.x:  

  • You might be required to reboot the endpoint. On some installs and upgrades,   Trellix EDR installation will not proceed until the endpoint is rebooted and the installation or upgrade is restarted. For details, see   KB96049.  

  • Endpoints unaffected by   KB96049 might be prompted to reboot the endpoint. It is a good practice to reboot the endpoint but not mandatory. The reboot message can be suppressed by disabling the   Prompt User When a Reboot is Required option on the   Trellix Agent properties page.  

New features

This release includes the following features and changes.  

  • End the quarantine of an endpoint using a tool — you can now enable an option   Enforce password to unquarantine the Trellix EDR client at endpoint (Windows only) in the network flow policy, set a password, and then enforce a policy on endpoints to end the quarantine using a tool. For details, see   End quarantine devices using a tool or   Network flow policy configuration.  

  • Expanded coverage of the MTIRE ATT&CK Framework — provides greater visibility into attack tactics and technique used by adversaries and also helps in strengthening your overall security strategy.  

Updated platform, environment, or operating system support

Trellix EDR client is now compatible with:  

  • RHEL 8.7 and 8.8  

  • RHEL 9.1 and 9.2  

  • SUSE 15.4  

  • Oracle Linux 7.9 and later  

  • Apple Silicon M1 and M2  

  • Big Sur up to version 11.7.3  

  • Monterey up to version 12.6.3  

  • Ventura 13.0 and 13.1  

  • Sonoma 14.0  

    Note

    Trellix EDR 4.1.1 supports Sonoma 14.0 only when the operating system is upgraded from earlier versions.  

For the complete list of system requirements, see supported platforms for   Trellix EDR in   KB91345.  

Resolved issues

Reference  

Resolution  

SEC-111461  

The option "Triggers Enable" is no longer displayed in the General Settings of the policy comparison page. This option was an inherited rule and never applicable to   Trellix EDR client.  

SEC-107063  

Resolves the issue where Microsoft applications stop responding (crash) when heavily embedded macro files are loaded and processed.  

SEC-109132  

Resolves crash in Microsoft Office applications when connecting or rendering web content within the application.  

SEC-171723  

Resolves crash in SearchProtocolHost.exe during setup of Microsoft Outlook.  

SEC-110968 and SEC-174861  

Resolves issue where Microsoft Office applications were not integrating correctly with 3rd party tools.  

SEC-146315  

Resolves issues related to uninstalling   Trellix EDR with password protection.  

SEC-147216  

The hardlinks folder is now removed from the endpoint successfully when   Trellix EDR is uninstalled.  

SEC-108297  

The   Files and   NetworkFlow collector result limit check has been fixed not to exceed the maximum results allowed.  

SEC-172999  

The file hashing policy page is now updated to fix a typo error.  

SEC-140172  

Generating   Trellix EDR queries and reports no longer fails on   Trellix ePO - SaaS.  

SEC-168702  

The   Trellix rebranding changes are successfully done on a few missing user interface for macOS.  

SEC-119582  

Trellix EDR now detects ransomware-related tactic ' Volume Shadow Copy Deletion'.  

SEC-110602  

Trellix EDR successfully prevents   trace.db from reaching the maximum size set in policy.  

SEC-107912  

Resolves issues where sharing violations could occur during certain file operations  

Known issues

For a list of known issues in this product release, see   KB91275.  

Installation information

The   Trellix Endpoint Detection and Response Installation Guide has the information you need to install the product for the first time and to migrate from   McAfee® Active Response.