Skip to main content

Trend Micro

Trend Micro is a comprehensive cybersecurity and threat defense platform that provides enterprise-level security solutions for protecting digital infrastructure, endpoints, cloud environments, networks, and data. The platform offers advanced threat detection, prevention, and response capabilities to safeguard organizations against malware, ransomware, phishing attacks, zero-day exploits, and other cyber threats.

CategoryEDR
DirectionQuery source
Sign-inAPI Token
Query languagesSTIX
Websitetrendmicro.com

Before you start​

Huntbase signs in to Trend Micro with API Token. Create the credential in Trend Micro first, then keep it to hand for the Connect step.

  1. In the Trend Vision One console, go to Administration › API Keys and click Add API key.
  2. Enter a Name, choose the Role assigned to the key, and set an Expiration time. The default is one year.
  3. Make sure Status is enabled, then click Add.
  4. Copy the authentication token before you click Close. You can't view it again.
Watch out for
  • This connection searches endpoint and email activity data. Use a role that can view that data.

For the vendor's own instructions, see Trend Vision One API keys.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Trend Micro​

  1. Go to Connections and click New connection, or click New connection on the Trend Micro product page.
  2. On Product, pick Trend Micro and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Trend Micro lives:

FieldRequiredNotes
Server AddressYesThe Vision One API domain for your region.
PortYes443. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is API Token. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API TokenYesSet the authentication token of Trend Micro Vision One search API. Secret — not shown again after you save it.

Query it​

Once connected, Trend Micro can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​