The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.6.1 Release Notes

Prev Next

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Release details of Trellix ESM 11.6.1

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade Considerations

Distributed ESM – Trellix ESM 11.6.x and higher does not support environments with Distributed ESM configurations.

When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered. Follow the below upgrade process:

  1. Refer to the HA Receiver upgrade process in, Trellix Enterprise Security Manager 11.6.x Installation Guide.

  2. Skip step 6.

  3. On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.

Note

The above steps are only needed when upgrading to 11.6.x for the first time.

New features and changes

This release includes these new features and changes.

Rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Enterprise Security Manager as usual.

You will notice the following changes in the software:

  • Product Name - McAfee Enterprise Security Manager is renamed to Trellix Enterprise Security Manager. All features and options prefixed with product name are renamed with the new product name.

  • Brand logo - McAfee logo is replaced with Trellix logo.

  • User interface - Color and typeface are updated and provide better user experience.

  • End User License Agreement and Copyright - The End User License Agreement and Copyright are updated as per legal requirements. Please read the agreement for details.

  • Updated internally used certificates.

  • McAfee Event Format is changed to Trellix ESM Event Format.

New features

This release provides support for these features.

  • UI Migration from Flash to Royale.

  • Added support for Trellix Email Security.

  • Added support for Trellix Endpoint Security (HX).

  • Added support for Trellix Network Security.

  • Kafka Data Source – Added support to use Kafka as a retrieval method for data sources.

Removed features

This release removes support for these features.

  • Distributed ESM – Trellix ESM 11.6.x and higher does not support environments with Distributed ESM configurations.

  • Removed sound support for Alarms.

  • Removed the DEM, MVM, ELMERC and Distributed ESM from the Add Device wizard options list from the UI.

  • All McAfee Vulnerability Manager dependent device references are removed from the UI.

  • All DEM references are removed from the UI.

  • The ESM Admin application is no longer available for download.

  • Removed the Alarms and Cases Pane feature for all users.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

Data Source Management

SIEM-35231

Fixed an issue where a hostname was removed from a data source after migrating to a new receiver.

ELM Device

SIEM-33961

Added validation to check that the ELM MGTDB storage location can handle files over 2GB in size.

Policy, ASP Rule Editor

SIEM-37328

An incorrect error message would be displayed when the policy editor was locked by another user.

Policy Rollout

SIEM-27383

Ending the value of an ASP variable with a '$' would cause policy rollout to fail.

NGC Collector

SIEM-38149

The NGC configuration parser will ignore unreadable data source configurations and log an appropriate message in the NGC logs.

Receiver

SIEM-38125

A red flag is no longer raised for a missing McAfeeP2P directory.

AWS Platform

SIEM-38224

Updated the AWS install scripts to allow for the latest kernels on EC2.

Correlation, Historical Correlation

SIEM-38235

Fixed a failure to trigger some correlation rules after receiving events with timestamps in the future.

Collectors

SIEM-32160

Resolved an NGC collection issue when no IP address was added to a data source.

This release provides resolution for the following content issues through a rule update since Trellix ESM 11.5.11.

Category

Reference

Resolution

3rd party, Windows Rules

SIEM-37248

Updated parsing rule 1011177 for the InterSect Alliance Snare for Windows data source to map additional data.

3rd party, Dependent Device

SIEM-33762

Updated the Trellix ePO – On prem query for ATP data to be more performant.

Known issues

For a list of known issues in this product release, see KB90422.