We are excited to announce the General Availability of Trellix Network Detection and Response (NDR) Console 4.0.0 Update Release (formerly Network Investigator) on November 4, 2025.
The NDR Console 4.0.0 Update Release incorporates powerful new features, impactful enhancements, and significant detection and response capabilities from the previous NDR Console 4.0.0, in addition to the following:
- Trellix Wise and GTI Proxy Configuration Support
- Elasticsearch Field Mapping Optimization
- Select critical fixes on top of the earlier 4.0 GA release
Note: This NDR Console 4.0.0 Update release replaces the previous 4.0 GA release
Core features and enhancements available from the earlier 4.0.0 release:
- Rich analyst experience with enhanced workflows and new views, synchronized filtering across alerts data, analyst springboards, and risk-based severity scoring for alerts
- Improved asset visibility with risky assets and risky conversations
- Comprehensive integrations with SIEM (Splunk), Tenable, and on-premise ePO
- Selective packet capture for live on-demand full packet capture
- NDR console capabilities can be enabled through licensed NDR Product Editions, including Essentials, Core, and Enterprise. Existing Network Forensics customers who have Network Investigator (NI / IA) will default to NDR Essentials
- Expanded threat detection capabilities like identifying communication with newly registered domains and known malicious domains, DNS and ICMP tunneling, phishing attempts (exfil / credential steal), SSL anomalies, Tor activity, and lookups / detections of suspicious URLs
- Integration with Trellix Wise (GenAI) solution
- Integration with Global Threat Intelligence (GTI) to determine the reputation of files and URLs
- Revamped UI with addition of many new widgets and improved page layouts
Resolved issues:
- For details of the issues fixed in this release, see the Network Detection and Response Console 4.0.0 Release Notes.
The following product documentation is available for this release:
- Network Detection and Response Console Product Guide 4.x
- Network Detection and Response Console 4.0.0 Release Notes
For more information, see the NDR documentation on the Trellix Docs portal.
Note: To receive information about product updates, sign up for the Support Notification Service.
For instructions, see the Thrive Portal User Guide and navigate to Profile and Settings > My Settings > Manage Support Notification Services (SNS) subscription preferences.