Trend Micro
Trend Micro is a comprehensive cybersecurity and threat defense platform that provides enterprise-level security solutions for protecting digital infrastructure, endpoints, cloud environments, networks, and data. The platform offers advanced threat detection, prevention, and response capabilities to safeguard organizations against malware, ransomware, phishing attacks, zero-day exploits, and other cyber threats.
| Category | EDR |
| Direction | Query source |
| Sign-in | API Token |
| Query languages | STIX |
| Website | trendmicro.com |
Before you start
Huntbase signs in to Trend Micro with API Token. Create the credential in Trend Micro first, then keep it to hand for the Connect step.
- In the Trend Vision One console, go to Administration › API Keys and click Add API key.
- Enter a Name, choose the Role assigned to the key, and set an Expiration time. The default is one year.
- Make sure Status is enabled, then click Add.
- Copy the authentication token before you click Close. You can't view it again.
- This connection searches endpoint and email activity data. Use a role that can view that data.
For the vendor's own instructions, see Trend Vision One API keys.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Trend Micro
- Go to Connections and click New connection, or click New connection on the Trend Micro product page.
- On Product, pick Trend Micro and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Trend Micro lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The Vision One API domain for your region. |
| Port | Yes | 443. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is API Token. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| API Token | Yes | Set the authentication token of Trend Micro Vision One search API. Secret — not shown again after you save it. |
Query it
Once connected, Trend Micro can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog