- 16 Oct 2024
- 2 Minutes to read
- PDF
Integrate Trend Micro Vision One with Red Canary
- Updated on 16 Oct 2024
- 2 Minutes to read
- PDF
To integrate Trend Micro Vision One with Red Canary, follow the procedure from beginning to end.
Prerequisites
Your Trend Vision One user must have admin level access to complete the following steps successfully.
Your Trend Vision One tenant must have one of the following licenses:
Trend Vision One Endpoint Security - Essentials
Trend Vision One Endpoint Security - Pro
Sufficient Trend Micro Vision One credits to enable the AWS S3 bucket connector. Please contact your Trend Micro account team if you do not have access to the AWS S3 bucket connector detailed in Step 2.
Step 1: Configure a Trend Micro Vision One API key
Record your Trend Micro Vision One Business ID.
Navigate to the License Information section within your Trend Micro Vision One console.
Copy the Business ID.
Enter your Trend Micro Vision One Business ID into Red Canary.
Create a user role to be used with your new API key. Note: Red Canary is committed to accessing your environment using the fewest permissions required.
Navigate to the User Roles page in the Trend Micro Portal and click Add Role.
Enter the name red-canary-api for the role and click Permissions.
Configure the following permissions:
Platform Capabilities
XDR Threat Investigation
Workbench check the View, filter, and search and Modify alert details boxes.
Search check the View, filter, and search box.
Workflow and Automation
Response Management check the View, filter, and search (Task list tab), Isolate endpoint, and Terminate process boxes.
Third-party integrations check the View box.
Security Functions
Endpoint Security
Endpoint Inventory check the View box.
Settings
Administration
User Roles check the View box.
API Keys check the View box.
Role permissions should look like this when completed successfully.
Create a new API key for Red Canary to ingest telemetry and alerts.
Navigate to the API Keys section within your Trend Micro Vision One console and click Add API Key.
Name the API key red-canary and assign the user role created in step 1.2.
Expiration Time should be set to “No expiration date.”
Copy the newly created API key.
Enter the API key into Red Canary.
Step 2: Configure Trend Micro Vision One to export data to Red Canary’s AWS S3 bucket
Navigate to the AWS S3 Bucket Connector within your Trend Micro Vision One console.
Click Workflow and Automation in the main menu on the left.
Select Third-Party Integration.
Click AWS S3 Bucket Connector.
In the Bucket name field, copy the bucket name listed from the in-line instructions in Red Canary.
In the Role ARN field, copy the Role ARN listed in the in-line instructions in Red Canary.
In the Data Transfer section, check the following boxes:
Workbench alerts
Activity data -> Scope: Endpoint
Step 3: Trend Vision One–Provide Red Canary access to your Vision One environment
Click on the Business Name menu at the top right.
Select User Accounts.
Click Add User Account.
Select Local Account.
Enter the email listed in the in-line instructions in Red Canary into the Account field.
Select Auditor for the Role field.
Click Add.
Red Canary will accept the invite to finalize access.
Ingest Details
Red Canary collects telemetry and alert data from Trend Micro Vision One. Vision One “Activity” data is what Red Canary considers to be telemetry, and “Workbench Alerts” are what Red Canary ingests as alerts. Both types of telemetry are required for a effective detection and investigations. In order to enable the AWS S3 bucket connector, Trend Micro Vision One customers must have sufficient credits. It takes credits to export data to an S3 bucket, so please contact your Trend Micro account team if you don’t have access to the AWS S3 bucket connector listed in Step 2.