The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What's new

Prev Next

Rebranding Updates

This is solely for informational purpose, there is no action required. You can continue to secure your organization with   Trellix Intrusion Prevention System (formerly, McAfee Network Security Platform) as usual.  

You will notice the following changes:  

Product Name - Network Security Platform is renamed to   Trellix Intrusion Prevention System. The associated software, hardware, features, and options prefixed with product name are renamed with the new product name.  

FQDN - The fully qualified domain names (FQDNs) to access the resources related to Trellix and Skyhigh Security products have been updated. So, users are recommended to update the Destination URLs in their Firewall configuration to ensure uninterrupted communication. For information on the updated destination URLs, refer to the section   Set the desktop firewall in   Trellix Intrusion Prevention System 10.1.10 Product Guide.  

Note

The   Trellix IPS products are in the process of rebranding from McAfee. So, users might be viewing mixed branding elements at a few places across the products and documentation.  

Note

Rebranding changes are not applicable for products (both hardware and software) that have reached End of Sale and currently under support period threshold. For more information, see KB96058.  

New features

This release of   Trellix Intrusion Prevention System includes the following new features:  

Integration with Multi-Vector Virtual Execution (MVX) Engine

Multi-Vector Virtual Execution (MVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The MVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.  

Starting with this release of 10.1,   Trellix IPS offers integration capabilities with Trellix Virtual Execution (VX) appliances which utilize Multi-Vector Virtual Execution (MVX) engine's technology to perform malware analysis. MVX serves as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines.  

To enable integration with MVX:  

  • At Global level:   Devices → <Admin Domain Name> → Global → IPS Device Settings → MVX Integration.  

  • At Device level:   Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → MVX Integration.  

To select MVX malware engine in an Advanced Malware policy, go to   Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware. You can enable inspection by MVX for all supported file types that is, Executables, MS Office Files, PDF Files, Compressed Files, Android Application Package, Java Archive, and Flash Files.  

Use the Manager to view the following information with respect to files submitted for malware analysis to MVX Engine:  

Dashboard tab: Use the   Top Malware Files monitor to view the blocked and unblocked detections together or filter them out separately. Additionally, you can filter data based on the confidence level of the detection as well.  

Analysis tab: The following enhancements are supported in the   Malware Files page:  

  • The overall malware confidence for a file is derived based on the results from MVX and any other malware engines configured.  

  • If applicable, you can view the MVX‑specific details for a particular type. This is similar to how you view the details for other engines.  

  • In the   Malware Files page, click     next to the confidence level of MVX to view the results reported by MVX. You can also download a file that contains all the reports for the malware from MVX. This file contains detailed analysis result data and can be opened with any text editor.  

Devices tab: You can view the statistics of the malware detected for a given device under   Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics → Advanced Malware Analysis tab. The   By Malware Engine option displays the malware detected data based on the malware engines configured for the device. This includes the malware detected data associated with the   MVX engine.  

A list of Sensor CLI commands have been added to support the MVX engine integration.  

The following Sensor CLI commands are added:  

Normal Mode

Command  

Description  

show mvx config

This command displays the MVX configuration details.  

show mvx stats

This command displays statistics specifics to MVX engine analysis.  

show mvx status

This command displays the connection status of the MVX engine.  

A list of Sensor CLI commands have been updated to support the MVX engine integration.  

The following Sensor CLI commands are updated:  

Normal Mode

Command  

Description  

clearmalwarecache

This command now allows users to clear MVX related cache entries made in the Sensor.  

clrstat

This command now clears all the statistics counters in the Sensor including the MVX counters.  

show malwareenginestats

This command now displays the malware engine statistics related to MVX.  

show malwarefilestats

This command now displays the malware file statistics related to MVX.  

The following Sensor CLI commands are updated:  

Debug Mode

Command  

Description  

set malwareEngine

This command now allows users to enable or disable MVX engine.  

show malwareclientstats

The command now displays the malware client statistics in the scan engines including MVX engine for all supported file types.  

show malwareEngine status

This command now displays the status of the MVX engine.  

show malwareserverstats

This command now displays the malware server statistics in all scan engines including MVX engine for all supported file types.  

For more information on MVX integration and malware scanning using MVX, refer to   Trellix Intrusion Prevention System 10.1.10 Integration Guide and Trellix Intrusion Prevention System 10.1.10 Product Guide.  

Monitoring Sensor Health

Starting with this release of 10.1, the   Health Status page is designed to monitor the Sensor health and take necessary actions, if required. You can access the   Health Status page from   Devices → <Admin Domain Name> → Global → Sensor Health → Health Status. It provides a consolidated view of all health-related faults generated for the Sensor in Manager. You can view these faults in admin domain including those configured in the child admin domains. The   Health Status page provides a cumulative view of system health, processor health, resource usage, and traffic nature of all devices configured in the Manager.  

In the   Health Status grid view, you can view the fault details for   Overall Health,   Hardware,   Capacity, and   Inspection elements of all configured Sensors. You can explore the summary of these parameters by clicking the hyperlink in required column.  

When you double-click on a required device, the   Abnormal health details of <Sensor Name> panel is displayed at the right end of the page. You can view various faults, its causes, recommended actions, and total count of same fault. You can take necessary actions for these faults by selecting   Take action. For more information, see the   Monitoring Sensor Health section in   Trellix Intrusion Prevention System 10.1.10 Product Guide.  

Note

This feature is not applicable for NS3x00, NS9300, and Virtual-IPS Sensors.  

Device Manager support in   Trellix IPS Central Manager

Starting with this release of 10.1,   IPS Central Manager comes with the   Device Manager page which displays all devices that are connected to each Manager configured with it, such as NS-series Sensors, Virtual IPS Sensors, and NTBA Appliances. The   Device Manager grid view provides real-time visibility into the device details, that include general device information, faults status and system health, thus offering a consolidated view of all devices available on individual Managers.  

To view the   Device Manager page in Central Manager, navigate to   Devices → Manager Management → Device Manager. For more information, refer to   Device Manager in Trellix IPS Central Manager in   Trellix Intrusion Prevention System 10.1.10 Product Guide.  

Enhancements

This release of Trellix Intrusion Prevention System includes the following enhancements:  

Support for Extended Master Secret (EMS) Extension

Starting with this release, the Sensor supports Extended Master Secret (EMS) Extension for SSL decryption as per RFC 7627.  

Note

EMS Extension is currently supported for Known-key and Agent based decryption methods under Inbound SSL Decryption.  

IPS CLI enhancements

Along with MVX commands documented in the   What's new section, the following Sensor CLI commands are added:  

Normal Mode

Command  

Description  

clear afo dst-mac

This command clears the previously configured destination MAC address on the specified port-pairs.  

set afo port-pair and dst-mac

This command is used to configure the destination MAC address in the heartbeat packets sent by the Active Fail-Open (AFO) kit. These packets will be used by Sensor to determine the status of the AFO kit.  

show afo status

This command displays the MAC address detected in the Heartbeat packets sent by the Active Fail-Open (AFO) kit, followed by the current AFO kit state.  

For more information, see   CLI Commands in   Trellix Intrusion Prevention System 10.1.10 Product Guide.  

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:  

MariaDB upgrade

Starting with this release of 10.1, the IPS Manager uses MariaDB version 10.5.16 that includes additional security against new vulnerabilities and bug fixes.  

JDK upgrade

Starting with this release of 10.1, the IPS Manager uses JDK version 1.8u342 that includes additional security against new vulnerabilities.  

Apache Log4j library upgrade

Starting with this release of 10.1, the IPS manager uses Apache Log4j version 2.17.1 that includes additional security and bug fixes.