Trellix Mobile Threat Defense (formerly Trellix Mobile Security) v5.10 is available now through the Apple Store or the Google Play Store.
This release includes new features, enhancements, and resolved issues.
New features
-
Enable or Disable MTD App Reset feature: Ability to enable or disable the display of the Trellix Mobile Threat Defense (MTD) app’s Reset button within the Advanced Troubleshooting section. This can be configured using the Enable App Reset feature via the MTD App Advanced Troubleshooting checkbox under Policies > App Settings in MTD console 5.37.5 or later.
-
Go To Site button: A new Go to Site button is added on the Web screen in the MTD app, allowing users to visit safe websites directly.
-
New categories for AI-based phishing detections: This release introduces new subcategories, namely Phishing Domains AI and Phishing Links AI, which help users to view AI-detected phishing domains or links and take the appropriate phishing actions as required. These subcategories are used for machine learning-based phishing detection.
Note: This feature requires MTD console Release 5.37.x or later.
-
Location permission prompt on the Threat Zones tile: This release introduces a location permission prompt on the Threat Zones tile to improve users' privacy. Now, when a user logs in to the MTD enabled device, the MTD app requests a location permission only when the user uses the Threat Zones feature, and when the following conditions are met:
- The location permissions are not required in the admin console.
- The Danger Zone checkbox is enabled from MTD console’s Policies > App Settings.
The user can manage location access from the iOS system option. If location permission is denied, a default location is displayed. This ensures that location data is accessed only when needed, reducing unnecessary data collection.
Enhancements
-
Enhanced iOS deep scan: The deep scan analysis on iOS devices is enhanced with clearer messaging and a streamlined process that has been optimized to significantly reduce processing time.
-
MTD dashboard functionality update: The MTD app dashboard has been enhanced to a dynamic, interactive interface, featuring improved scroll performance for smoother navigation; a tile organization selector that allows sorting by default, severity, or recently used; and an adaptive layout that dynamically adjusts tile placement based on user behavior.
-
Enhanced URL Threat Forensics: This release updates phishing and Web Content Filtering (WCF) threats generated by the Web scanning feature in the MTD app. The Source field in Threat Forensic in the Console is now more granular to precisely identify the method used to enter a malicious URL into the MTD app’s Web scanning feature.
The updated Threat Forensic > Source values are:- User Entry - URL: The user manually types or pastes the URL into the MTD app's Web tile.
-
QR Code: The user scans a QR code containing a URL using the MTD app's Web tile.
These updated values are displayed in both the Threat details of the MTD app and the Threat Forensic in the console. This update improves threat forensics and reporting.
-
App tile display enhancement: The App tile in the MTD app is displayed based on the MTD console configuration. The tile is shown when either of the following conditions is met:
- The Enable the App Risk Lookup feature in the MTD checkbox is enabled from the Policies > App Settings tab in the MTD console.
- The app threats are enabled from the Policies > Threat tab in the MTD console.
-
Enhanced SMS / MMS URL inspection (iOS): The MTD app enhances URL inspection for SMS or MMS messages from unknown senders through a secure remote server. In addition to the existing on-device checks, when suspicious content is detected, the complete message is securely transmitted to the remote server to extract and evaluate URLs. If identified as phishing, then the message is automatically marked as Junk and moved to the Junk or Spam folder, depending on the iOS version. The Add SMS / MMS URL inspection on the remote server (iOS only) checkbox should be selected from the MTD console’s Policies > Phishing and Content Filtering page to enable this feature in the MTD app.
Note: This feature requires MTD console Release 5.37.x or later.
-
Enhanced sideloaded iOS app detection: The MTD app includes enhanced detection for sideloaded iOS apps when EMM / MDM sync is enabled. When a sideloaded iOS app is detected, the Sideloaded iOS App threat is automatically generated with additional details.
- When both Suspected Sideloaded iOS App and Sideloaded iOS App threats are generated, it is recommended to disable the Suspected Sideloaded iOS App threat from the MTD console’s Policies > Threat page.
- EMM / MDM sideloaded iOS app detection is currently supported by Ivanti, Intune, and VMware Workspace ONE.
- This feature requires MTD console Release 5.37.x or later.
-
UI enhancements for RTL languages: The MTD app introduces an enhanced user-interface for Right-to-Left (RTL) languages such as Arabic and Hebrew. The user-interface alignment has been improved for arrows, buttons, icons, and text to fully support the RTL layout. These improvements streamline navigation and significantly enhance the overall user experience for users when the app is used with RTL languages.
-
Enhanced Full Event log: This release introduces an updated Full Event log along with an Activity Report, which provides detailed data across various tabs such as Apps, Web, Device, Network, and Shortcuts with All selected by default in the tabs. It provides a clear view of security incidents by categorizing events into Active Issues and Resolved Issues. The severity level of Active and Resolved Issues is categorized as Updates, Risks, and Threats for the effective prioritization, with All selected by default in the tabs. Also, you can enable Notifications from the Settings to receive a summary of device protection activity. You can also perform the actions below as required:
- Sort threats by severity levels: A new sorting menu is added that enables you to sort threats by their Severity levels, such as Critical, Elevated, Low, or Normal, in addition to the previous option of sorting by Date and Time.
- Custom date ranges: You can select your preferred date range, such as 1 day, 1 week, 1 month, or 3 months, to view statistics. The selected date range is displayed in the report, along with the number of scans performed.