The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes about upgrading from 9.1, 9.2, 10.1 to 10.1.7.50

Prev Next

Display of SHA1 and SHA256 file hashes in the Attack Log

Starting with this release of 10.1, SHA1 and SHA256 file hashes are displayed with MD5 file hashes in the Attack Log page and Malware Files pages.

To view the files hashes, go to Analysis → <Admin Domain Name> → Attack Log and Analysis → <Admin Domain Name> → Malware Files.

Network security posture score through MVISION Insights integration

Starting with this release of 10.1, MVISION Insights evaluates the network protection configuration, derives the network security posture score, and shares recommendations to improve the score and configuration.

Note

The security posture score will be available in the MVISION Insights web console with the next MVISION Insights update release.

A new report Default - Telemetry (Insights Security Posture) is added to view the data shared with MVISION Insights.

The following general setup and feature usage information is now shared with MVISION Insights and is available in the Default - Telemetry (Insights Security Posture) report:

  • General Setup
    • Manager GUID, MDR GUID (as applicable) and Telemetry GUID
    • Callback Detector & Gateway Anti-Malware version for each active device
    • Interface name, protection category and assigned IPS, Malware and Inspection Options policy IDs
  • Feature Usage
    • Block and alert only based CVE coverage for each of the IPS policies in use
    • Engine status and file types enabled for each of the Malware policies in use
    • Option status for each of the inspection options policies in use

To view the data shared with MVISION Insights, go to Analysis → <Admin Domain Name> → Event Reporting → Next Generation Reports and run the report.

Provision of 30 days grace period to expired System licenses

Starting with this release of 10.1, a grace period of 30 days is provided to subscription-based System licenses upon expiry. This allows users to continue deploying the latest signature set on the Sensors, and to renew license during the grace period.

Note

This feature is applicable only for subscription-based System licenses on NS7500, NS9500 standalone and NS9500 stack Sensors.

Manager GUI accessibility improvement

Starting with this release of 10.1, the Manager includes several accessibility enhancements that enable screen readers to accurately interpret the Manager GUI as listed below:

  • An alternative text and title attributes are provided for all the images.
  • All icons differ by both shape and color.
  • Combo boxes, radio buttons, checkboxes, and other form elements are provided with a visual/accessibility software readable label.
  • For all checkboxes and radio buttons, you can also enable/disable an option by clicking title/text area.

The accessibility improvement is not supported for JSP pages. It is supported only for the following ExtJS pages:

Navigation Path Options

Manager → <Admin Domain Name>

  • Summary
  • NSP Protection Status
  • Setup → E-mail Server
  • Setup → Licenses
  • Setup → Certificates
  • Setup → GUI Access → CAC Authenication
  • Integration → MVISION
  • Integration → GTI
  • Maintenance → Malware Archive
  • Troubleshooting → Health Check
  • Troubleshooting → Alert Relevance
  • Troubleshooting → Logs
Devices → <Admin Domain Name> Global tab:
  • Device Manager
  • Common Device Settings → GAM Updating
  • Common Device Settings → Remote Access → RADIUS
  • IPS Device Settings → ATD Integration
  • IPS Device Settings → DXL Integration
  • IPS Device Settings → SSL Decryption
  • IPS Device Settings → IPS Event Logging
  • IPS Device Settings → Passive Device Profiling
  • IPS Device Settings → Advanced Device Settings
  • IPS Device Settings → Virtualization Settings
  • IPS Device Settings → EIA Integration
Devices → <Device Name>:
  • Setup → Physical Ports
  • Setup → IP Bindings
  • Advanced → Anti-Spoofing
  • Troubleshooting → Traffic Statistics
  • Troubleshooting → Performance Charts
  • Troubleshooting → Layer 2 Bypass
Policy → <Admin Domain Name> → Intrusion Prevention
  • Policy Manager
  • Policy types → IPS
  • Policy types → Inspection Options
  • Policy types → Connection Limiting
  • Firewall Policies
  • Ignore Rules
  • Exceptions → File Hashes
  • Exceptions → Domain Names
  • Exceptions → SSL Decryption Exclusions
  • Exceptions → Auto-Acknowledgement
  • Objects → Policy Groups
  • Objects → Rule Objects
  • Objects → Attack Set Profiles
  • Objects → Quarantine Zones
  • Objects → Rate Limiting Profiles
  • NTBA Policies
  • Policy Import
  • Policy Export
Analysis → <Admin Domain Name>
  • Attack Log
  • Threat Explorer
  • Malware Files
  • Callback Activity
  • High-Risk Endpoints
  • Network Forensics
  • Endpoint Executables
  • Quarantine

Anti-virus scan updates

Update of avvdat signatures: Starting with this release of 10.1, you can update the avvdat signatures. To update execute the manager shell command avvdat -a. If proxy settings are configured in your network, execute shell command edit environment to enter the proxy details before executing the shell command avvdat -a.

Exclusion of directories from system anti-virus scan: Starting with this release of 10.1, you can exclude directories from system anti-virus scan. To exclude the directories, execute the manager shell command edit avexclusionlist and add the directory paths that you want to exclude.

Terminology updates in the UI

This release contains the following terminology updates in the Manager UI:

Navigation Path Prior to 10.1.7.50 10.1.7.50 and later
Manager → <Admin Domain Name> Updating

The following sub-menus are available under Updating menu:

  • Download Signature Sets
  • Download Callback Detectors
  • Download Device Software
  • Manual Import
  • Messages From McAfee
  • Automatic Updating
    • Signature Sets
    • Callback Detectors
NSP Protection Status

The following tabs are available under NSP Protection Status page:

  • Signature Sets
  • Callback Detectors
  • Device Software
  • Manual Import
  • Release Announcements
The manual download, automatic download, and deployment of signature sets and callback detectors are not integrated.

The manual download, automatic download, and deployment of signature sets and callback detectors are integrated under Signature Sets and Callback Detectors tabs respectively.

In Messages From McAfee, you can acknowledge the messages that you have already seen and they will not be listed again.

The option is provided to delete the read announcements in Release Announcements tab.

Manager → <Admin Domain Name> → Setup GUI Access → GUI Certificate. In the Certificates page, GUI Certificate tab is available.