Skip to main content

Trend Micro Vision One

Endpoint Protection

The Vision One connector integrates with Trend Micro Vision One (the Trend Vision One XDR platform) through its public REST API v3.0. It syncs the correlated threat detections the platform raises — Workbench alerts — and the detection models behind them as alert definitions. Alongside the detections it syncs the asset inventory those detections are reported against: the endpoints managed by Endpoint Security, the Vision One user accounts, and the devices, domain names and internet-facing IP addresses discovered by Attack Surface Risk Management. This gives Brinqa the XDR detection surface (MITRE ATT&CK techniques, matched rules, indicators, impacted entities) correlated to the hosts, people and internet-facing assets they affect.

Data retrieved from Trend Micro Vision One

Connector ObjectRequiredMaps to Data Model
HostYesHost
PersonYesPerson
DeviceYesDevice
SiteYesSite
AlertYesAlert
Alert DefinitionYesAlert Definition

Model relationships

note

For detailed steps on how to view the data retrieved from Trend Micro Vision One in the Brinqa Platform, see How to view your data.