Trend Micro Vision One
TrendAI Vision One™ is a purpose-built threat defense platform that provides added value and new benefits beyond XDR solutions, allowing you to see more and respond faster. Providing deep and broad extended detection and response (XDR) capabilities that collect and automatically correlate data across multiple security layers—email, endpoints, servers, cloud workloads, and networks—TrendAI Vision One™ prevents the majority of attacks with automated protection.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- TrendMicroVisionOne
Configuration parameters
- url — API URL (e.g. https://api.xdr.trendmicro.com) (required)
- apikey — (required)
- isFetch — Fetch incidents
- incidentFetchInterval — Incidents Fetch Interval
- incidentType — Incident type
- first_fetch — Sync On First Run (days)
- max_fetch — Max Incidents
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- integrationReliability — Source Reliability
Commands (22)
- trendmicro-visionone-add-note — Attaches a note to a workbench alert.
- trendmicro-visionone-add-objects-to-exception-list — Adds domains, file SHA-1 values, IP addresses, or URLs to the Exception List and prevents these objects from being added to the Suspicious Object List.
- trendmicro-visionone-add-objects-to-suspicious-list — Adds domains, file SHA-1 values, IP addresses, or URLs to the Suspicious Object List.
- trendmicro-visionone-add-to-block-list — Adds a file SHA-1, IP address, domain, or URL object to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections.
- trendmicro-visionone-check-task-status — Command gives the status of the running task based on the action id.
- trendmicro-visionone-collect-forensic-file — Compresses a file on an endpoint in a password-protected archive and then sends the archive to the XDR service platform.
- trendmicro-visionone-delete-email-message — Deletes a message from a mailbox.
- trendmicro-visionone-delete-objects-from-exception-list — Deletes domains, file SHA-1 values, IP addresses, or URLs from the Exception List.
- trendmicro-visionone-delete-objects-from-suspicious-list — Deletes domains, file SHA-1 values, IP addresses, or URLs from the Suspicious Object List.
- trendmicro-visionone-download-information-for-collected-forensic-file — Retrieves a URL and other information required to download a collected file via the trendmicro-visionone-collect-forensic-file command.
- trendmicro-visionone-get-endpoint-info — Retrieves information about a specific endpoint.
- trendmicro-visionone-get-file-analysis-report — Retrieves the analysis report, investigation package, or Suspicious Object List of a submitted file.
- trendmicro-visionone-get-file-analysis-status — Retrieves the status of a sandbox analysis submission.
- trendmicro-visionone-isolate-endpoint — Disconnects an endpoint from the network (but allows communication with the managing TrendAI™ product).
- trendmicro-visionone-quarantine-email-message — Moves a message from a mailbox to the quarantine folder.
- trendmicro-visionone-remove-from-block-list — Removes a file SHA-1, IP address, domain, or URL from the User-Defined Suspicious Objects List.
- trendmicro-visionone-restore-endpoint-connection — Restores network connectivity to an endpoint that applied the "isolate endpoint" action.
- trendmicro-visionone-run-sandbox-submission-polling — Runs a polling command to retrieve the status of a sandbox analysis submission.
- trendmicro-visionone-submit-file-entry-to-sandbox — Submits the file corresponding to EntryID to the sandbox for analysis (Note. For more information about the supported file types, see the TrendAI Vision One™ Online Help. Submissions require credits. Does not require credits in regions where Sandbox Analysis has not been officially released.)
- trendmicro-visionone-submit-file-to-sandbox — Submits a file to the sandbox for analysis (Note. For more information about the supported file types, see the TrendAI Vision One™ Online Help. Submissions require credits. Does not require credits in regions where Sandbox Analysis has not been officially released.)
- trendmicro-visionone-terminate-process — Terminates a process that is running on an endpoint.
- trendmicro-visionone-update-status — Updates the status of a workbench alert.