category: Authentication & Identity Management provider: TrendAI™ sectionorder: - Connect - Collect commonfields: id: TrendMicro Cloud App Security version: -1 configuration: - additionalinfo: The place where your Cloud App Security service is hosted defaultvalue: U.S.A display: Service URL name: serviceURL options: - U.S.A - EU - Japan - Australia and New Zealand - UK - Canada - India - Singapore - Middle East (UAE) required: true type: 15 section: Connect - display: Token name: token required: false type: 4 section: Connect hidden: true - displaypassword: Token name: credentials_token required: false hiddenusername: true type: 9 section: Connect - display: Service event to fetch name: service options: - exchange - sharepoint - onedrive - dropbox - box - googledrive - gmail - teams - exchangeserver type: 16 section: Collect required: false - display: Event type to fetch name: event_type options: - securityrisk - virtualanalyzer - ransomware - dlp type: 16 section: Collect required: false - defaultvalue: '50' display: Maximum number of incidents per fetch name: max_fetch type: 0 section: Collect required: false - defaultvalue: 3 days display: First fetch time name: first_fetch type: 0 section: Collect required: false - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - display: Incident type name: incidentType section: Collect required: false type: 13 - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - display: Fetch incidents name: isFetch required: false section: Collect type: 8 description: 'Use TrendAI™ Cloud App Security integration to protect against ransomware, phishing, malware, and unauthorized transmission of sensitive data for cloud applications, such as Microsoft 365, Box, Dropbox, Google G Suite and Salesforce.' display: TrendAI™ Cloud App Security name: TrendMicro Cloud App Security script: commands: - arguments: - auto: PREDEFINED description: 'Name of the protected service whose logs you want to retrieve. Can be: "exchange", "sharepoint", "onedrive", "dropbox", "box", "googledrive", "gmail", "teams", or "exchangeserver".' name: service predefined: - exchange - sharepoint - onedrive - dropbox - box - googledrive - gmail - teams - exchangeserver required: true - auto: PREDEFINED description: 'Type of the security event whose logs you want to retrieve. Can be: "securityrisk", "virtualanalyzer", "ransomware", or "dlp".' name: event_type predefined: - securityrisk - virtualanalyzer - ransomware - dlp required: true - description: |- The start time to retrieve logs, using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". The request retrieves logs within a maximum of 72 hours before the request is sent. If a start time is added, the request retrieves all from the start time. If a start and end time are added, the request retrieves logs within the configured duration. If start and end times are not added, the request retrieves logs within 5 minutes before the request is sent. name: start - description: |- The end time to retrieve logs, using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". The request retrieves logs within a maximum of 72 hours before request is sent. If an end time is added, the request retrieves logs within five minutes before the end time. If start and end are added, the request retrieves logs within the configured duration. Ensure the end time is no earlier than the start time. If the start and end times are not added, the request retrieves logs within 5 minutes before the request is sent. name: end - description: The maximum number of log items to display. Default is 50 and Maximum is 500. name: limit - description: The URL for the results page if the total number of log items in a previous request exceeds the specified limit. When the maximum log items exceeds the limit, a URL is specified in the response. To retrieve the remaining log items, use the URL from the response. name: next_link description: Retrieves security event logs of services. name: trendmicro-cas-security-events-list outputs: - contextPath: TrendMicroCAS.Events.last_log_item_generation_time description: The time and date when the last log item in the current request was generated. type: Date - contextPath: TrendMicroCAS.Events.next_link description: URL for the follow-up request if the requested logs exceed the specified limit to display at a time. Use this URL to form a second request. type: String - contextPath: TrendMicroCAS.Events.security_events.event description: The type of the requested security event. type: String - contextPath: TrendMicroCAS.Events.security_events.log_item_id description: The ID of a log item. type: String - contextPath: TrendMicroCAS.Events.security_events.message.action description: The action that Cloud App Security took after detecting the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.action_result description: The result of the action. type: String - contextPath: TrendMicroCAS.Events.security_events.message.affected_user description: The Mailbox that received an email message triggering the security event, or the user account that uploaded or modified a file triggering the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.detected_by description: The technology or method through which the email message or file triggering the security event was detected. type: String - contextPath: TrendMicroCAS.Events.security_events.message.detection_time description: The time and date when the security event was detected. type: Date - contextPath: TrendMicroCAS.Events.security_events.message.location description: The location where the security event was detected. type: String - contextPath: TrendMicroCAS.Events.security_events.message.log_item_id description: The ID of the log item. type: String - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_delivery_time description: The time and date when the email message triggering the security event was sent. type: Date - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_file_name description: The name of the email attachment that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_id description: The ID of the email message that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_recipient description: The Email address of the recipient. type: String - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_sender description: The Email address of the sender. type: String - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_subject description: The subject of the email message that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.mail_message_submit_time description: The time and date when the email message triggering the security event was received. type: Date - contextPath: TrendMicroCAS.Events.security_events.message.file_name description: The name of the file that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.file_upload_time description: The time and date when the file triggering the security event was uploaded. type: Date - contextPath: TrendMicroCAS.Events.security_events.message.risk_level description: The web reputation risk level assigned to the analyzed URL that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.scan_type description: A real-time scan or manual scan that detected the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.security_risk_name description: The name of the security risk detected. type: String - contextPath: TrendMicroCAS.Events.security_events.message.triggered_policy_name description: The name of a configured policy that was violated. type: String - contextPath: TrendMicroCAS.Events.security_events.message.triggered_security_filter description: The name of the security filter that detected the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.virus_name description: The name of the detected virus. type: String - contextPath: TrendMicroCAS.Events.security_events.message.file_sha1 description: The SHA-1 hash value of the file that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.detection_type description: The type of the suspicious object that triggered the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.message.ransomware_name description: The name of the detected ransomware. type: String - contextPath: TrendMicroCAS.Events.security_events.message.triggered_dlp_template description: The details of the compliance template that was violated to trigger the security event. type: String - contextPath: TrendMicroCAS.Events.security_events.service description: The name of the requested service. type: String - contextPath: TrendMicroCAS.Events.traceId description: The randomly generated ID to trace the request. type: String - arguments: - description: |- The Email address of the mailbox for which to search. A non-prefix wildcard is supported. For example, u*ser@gmail.com or user@gm*ail.com. name: mailbox - description: |- The number of days (n × 24 hours) before the request is sent to search. Do not configure lastndays and start/end at the same time. name: lastndays - description: |- The start time to search for email messages using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". The request searches email messages according to the following settings: If both start and end are not added, the request searches email messages within seven days (7 × 24 hours) before the request was sent. If both start and end are added, the request searches email messages within this configured duration. Ensure the end time is no earlier than the start time. If only start is added, the request searches email messages within seven days (7 × 24 hours) after the start time. If only end is added, the request searches email messages within seven days (7 × 24 hours) before the end time. Do not configure lastndays and start/end at the same time. name: start - description: |- The end time to search for email messages using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". Cloud App Security saves the meta information of email messages for 90 days. The request searches email messages according to the following settings: If both start and end are not added, the request searches email messages within seven days (7 × 24 hours) before the request was sent. If both start and end are added, the request searches email messages within this duration. Ensure the end time is no earlier than the start time. If only start is added, the request searches email messages within seven days (7 × 24 hours) after the start time. If only end is added, the request searches email messages within seven days (7 × 24 hours) before the end time. Do not configure lastndays and start/end at the same time. name: end - description: |- The subject of email messages for which to search. Use double quotes to search for an exact phrase, for example, "messageA messageB" otherwise a partial match based on the phrase is performed. For example, a search is performed on a subject containing messageA, or messageB, or messageA message B. name: subject - description: The SHA-1 hash value of the attachment file for which to search. name: file_sha1 - description: 'The name of the attachment file for which to search, with or without a filename extension. A non-prefix wildcard is supported. For example, me*ssage.' name: file_name - description: 'The filename extension of attachment files for which to search without a period ".". A non-prefix wildcard is supported. For example, do*.' name: file_extension - description: |- The URL contained in an email body or in an attachment for which to search. Type the full URL. name: url - description: 'The email address of the sender for which to search. Type the full email address. A non-prefix wildcard is supported. For example, u*ser@gmail.com.' name: sender - description: 'The email address of the recipient for which to search. Type the full email address. A non-prefix wildcard is supported. For example, u*ser@gmail.com.' name: recipient - description: The Internet message ID of the email message for which to search. Can be obtained from Microsoft Graph API or EWS API. name: message_id - description: 'The Source IP address, with or without a subnet mask, of the email message to search. For example, xx.yy.zz.ww or xx.yy.zz.ww/16.' name: source_ip - description: The Source domain of email messages for which to search. Type a complete domain name. A non-prefix wildcard is supported. For example, gm*ail.com. name: source_domain - description: The maximum number of email messages to display. Maximum is 1,000 email messages. If not specified, default is 20. name: limit - description: The URL for the results page if the total number of email messages in a previous request exceeds the specified limit. When the maximum limit has been exceeded, a URL is specified in the response. To retrieve the remaining email messages, use the URL from the response. name: next_link description: Searches for email messages in mailboxes, matching search criteria. name: trendmicro-cas-email-sweep outputs: - contextPath: TrendMicroCAS.EmailSweep.next_link description: URL for the follow-up request if the requested email messages exceed the specified limit to display at a time. Use this URL to form a second request. type: String - contextPath: TrendMicroCAS.EmailSweep.traceId description: The randomly generated ID to trace the request. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_attachments.file_sha1 description: The SHA-1 hash value of the attachment file. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_attachments.file_name description: The name of the attachment file. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_internet_headers.HeaderName description: The Internet header name of the email address. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_internet_headers.Value description: The email address of the sender. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_message_delivery_time description: The time and date when the email message was sent. type: Date - contextPath: TrendMicroCAS.EmailSweep.value.mail_message_id description: The Internet message ID of the email message. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_message_recipient description: A list of recipient email addresses of the email message. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_message_sender description: The email address of the sender. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_message_subject description: The subject of the email message. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_unique_id description: The ID of the email message. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mail_urls description: The URL contained in the email body or attachment. type: String - contextPath: TrendMicroCAS.EmailSweep.value.mailbox description: The mailbox which contains the email message. type: String - contextPath: TrendMicroCAS.EmailSweep.value.source_domain description: The source domain of the email message. type: String - contextPath: TrendMicroCAS.EmailSweep.value.source_ip description: The source IP address of the email message. type: String - arguments: - auto: PREDEFINED description: |- Action to take on a user's account. Can be: "ACCOUNT_DISABLE": Disables a user's account. "ACCOUNT_ENABLE_MFA": Enforces a user to perform a multi-factor authentication before being forced to change their password. "ACCOUNT_RESET_PASSWORD": Requests to reset the password for a user's account. NOTE: Before using ACCOUNT_ENABLE_MFA and ACCOUNT_RESET_PASSWORD, you need to assign the Administrator role to Cloud App Security. For more information, see https://docs.trendmicro.com/en-us/enterprise/cloud-app-security-integration-api-online-help/supported-cloud-app-_001/threat-mitigation-ap/take-actions-on-user/assigning-the-user-a.aspx. name: action_type predefined: - ACCOUNT_DISABLE - ACCOUNT_ENABLE_MFA - ACCOUNT_RESET_PASSWORD required: true - description: Comma separated email addresses to take action. isArray: true name: account_user_email required: true description: |- Takes action on a batch of specified user accounts, such as disabling users accounts, requesting multi-factor authentication, and requesting to reset a password for users accounts. Relevant for office365 exchange only. name: trendmicro-cas-user-take-action outputs: - contextPath: TrendMicroCAS.UserTakeAction.action_type description: The type of the action. type: String - contextPath: TrendMicroCAS.UserTakeAction.account_user_email description: The list of user accounts for the action. type: String - contextPath: TrendMicroCAS.UserTakeAction.batch_id description: The unique ID of the API request, including all actions to take on user accounts specified within this request. type: String - contextPath: TrendMicroCAS.UserTakeAction.traceId description: Randomly generated ID to uniquely trace the request. type: String - arguments: - auto: PREDEFINED description: |- The action to take on an email message, such as delete or quarantine. Can be: "MAIL_DELETE", or "MAIL_QUARANTINE". name: action_type predefined: - MAIL_DELETE - MAIL_QUARANTINE required: true - description: The email address of an email message for which to take action. name: mailbox required: true - description: |- The Internet message ID of an email message for which to take action. To retrieve the ID, use the "trendmicro-cas-email-sweep" command. name: mail_message_id required: true - description: |- The unique ID of an email message for which to take action. To retrieve the ID, use the "trendmicro-cas-email-sweep" command. name: mail_unique_id required: true - description: |- The time and date when an email message sent To retrieve the information, use the "trendmicro-cas-email-sweep" command. name: mail_message_delivery_time required: true description: |- Takes action on a batch of specified email messages, such as deleting and quarantining email messages. Relevant for office365 exchange only. name: trendmicro-cas-email-take-action outputs: - contextPath: TrendMicroCAS.EmailTakeAction.action_type description: The type of action taken on an email message. type: String - contextPath: TrendMicroCAS.EmailTakeAction.batch_id description: The unique ID of the API request. type: String - contextPath: TrendMicroCAS.EmailTakeAction.mailbox description: The email address to take action. type: String - contextPath: TrendMicroCAS.EmailTakeAction.traceId description: Randomly generated ID to trace the request. type: String - arguments: - description: The unique ID of the action taken. Retrieve the ID from the "trendmicro-cas-email-take-action" command. name: batch_id - description: |- The start time to retrieve action results within a time period, using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". If using start, end is required. name: start - description: |- The end time to retrieve action results within a time period, using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". If using end, start is required. Ensure the end time is not earlier than the start time. name: end - description: The Maximum number of action results to display. Default (and maximum) is 500. name: limit description: Queries the results of actions taken on a user's account. name: trendmicro-cas-user-action-result-query outputs: - contextPath: TrendMicroCAS.UserActionResult.account_provider description: The supplier of the protected service. type: String - contextPath: TrendMicroCAS.UserActionResult.account_user_email description: The email address on which the action was taken. type: String - contextPath: TrendMicroCAS.UserActionResult.action_executed_at description: The time and date when the action was processed. type: Date - contextPath: TrendMicroCAS.UserActionResult.action_id description: The unique ID of a threat mitigation task. type: String - contextPath: TrendMicroCAS.UserActionResult.action_requested_at description: The time and date when the API request was received. type: Date - contextPath: TrendMicroCAS.UserActionResult.action_type description: The action taken on a user's account. type: String - contextPath: TrendMicroCAS.UserActionResult.batch_id description: The unique ID of a Threat Mitigation API request. type: String - contextPath: TrendMicroCAS.UserActionResult.error_code description: The result code of the action. type: Number - contextPath: TrendMicroCAS.UserActionResult.error_message description: 'The string of the result code. For example, 0: success.' type: String - contextPath: TrendMicroCAS.UserActionResult.service description: The name of the protected service. type: String - contextPath: TrendMicroCAS.UserActionResult.status description: 'The status of the action. Can be: "Created": The API request was received. "Executing": The action is executing. "Success": The action was successful. "Skipped": The action was skipped. "Failed": The action failed.' type: String - arguments: - description: The unique ID of the action taken. Retrieve the ID from the "trendmicro-cas-email-take-action" command. name: batch_id - description: |- The start time to retrieve action results within a time period, using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". If using start, end is required. name: start - description: |- The end time to retrieve action results within a time period, using the date and time format ISO 8601. For example, 2020-08-01T02:31:20Z or in human-readable format. For example, "in 1 day" or "3 weeks ago". If using end, start is required. Ensure the end time is not earlier than the start time. name: end - description: The maximum number of action results to display. Default (and maximum) is 500. name: limit description: Queries the results of actions taken for email messages. name: trendmicro-cas-email-action-result-query outputs: - contextPath: TrendMicroCAS.EmailActionResult.account_provider description: The supplier of the protected service. type: String - contextPath: TrendMicroCAS.EmailActionResult.account_user_email description: The email address on which the action was taken. type: String - contextPath: TrendMicroCAS.EmailActionResult.action_executed_at description: The time and date when the action was processed. type: Date - contextPath: TrendMicroCAS.EmailActionResult.action_id description: The unique ID of a threat mitigation task. type: String - contextPath: TrendMicroCAS.EmailActionResult.action_requested_at description: The time and date when the API request was received. type: Date - contextPath: TrendMicroCAS.EmailActionResult.action_type description: The action taken on an email message. type: String - contextPath: TrendMicroCAS.EmailActionResult.batch_id description: The unique ID of a Threat Mitigation API request. type: String - contextPath: TrendMicroCAS.EmailActionResult.error_code description: The result code of the action. type: Number - contextPath: TrendMicroCAS.EmailActionResult.error_message description: 'The string of the result code. For example, 0: success.' type: String - contextPath: TrendMicroCAS.EmailActionResult.service description: The name of the protected service. type: String - contextPath: TrendMicroCAS.EmailActionResult.status description: 'The status of the action. Can be: "Created": The API request was received. "Executing": The action is executing. "Success": The action was successful. "Skipped": The action was skipped. "Failed": The action failed.' type: String - contextPath: TrendMicroCAS.EmailActionResult.mail_unique_id description: The unique ID of an email message on which an action was taken. type: String - contextPath: TrendMicroCAS.EmailActionResult.mail_message_id description: The Internet message ID of an email message on which an action was taken. type: String - contextPath: TrendMicroCAS.EmailActionResult.mailbox description: The email address of an email message on which an action was taken. type: String - description: Retrieves all blocked senders, URLs, and SHA-1 hash values that have been configured to quarantine Exchange Online email messages. name: trendmicro-cas-blocked-lists-get outputs: - contextPath: TrendMicroCAS.BlockedList.filehashes description: A list of blocked configured SHA-1 hash values. type: String - contextPath: TrendMicroCAS.BlockedList.senders description: A list of configured blocked senders. type: String - contextPath: TrendMicroCAS.BlockedList.urls description: A list of blocked configured URLs. type: String - arguments: - auto: PREDEFINED description: |- The type of the action to take. Can be: "create", to add to the blocked lists, or "delete", to remove from the blocked lists. name: action_type predefined: - create - delete required: true - description: |- Comma separated email addresses from which the email message is sent to update. isArray: true name: senders - description: |- Comma separated URLs included in an email message to update. isArray: true name: urls - description: |- Comma separated SHA-1 hash values of an email attachment to update. isArray: true name: filehashes description: Adds or removes senders, URLs, SHA-1 hash values to or from blocked lists. You must specify one of senders, urls, or filehashes. name: trendmicro-cas-blocked-lists-update outputs: - contextPath: TrendMicroCAS.BlockedList.filehashes description: A list of blocked SHA-1 hash values. type: String - contextPath: TrendMicroCAS.BlockedList.senders description: A list of blocked senders. type: String - contextPath: TrendMicroCAS.BlockedList.urls description: A list of blocked URLs. type: String dockerimage: demisto/python3:3.12.13.10116658 isfetch: true runonce: false script: '-' subtype: python3 type: python tests: - No tests (auto formatted) fromversion: 5.0.0