Integrate Trend Vision One with Zscaler MDR - RC DRAFT

Prev Next

Zscaler MDR integrates with Trend Vision One to enhance threat detection and response capabilities by sharing security telemetry and threat intelligence between the two platforms. The integration ingests the following types of security data:

  • Threat Detections - Confirmed threats identified by Zscaler MDR’s detection engine

  • Security Alerts - Suspicious activities and potential security incidents

  • Endpoint Telemetry - Activity data from monitored endpoints

  • Investigation Data - Contextual information about security events

  • Indicators of Compromise (IOCs) - Threat intelligence artifacts

The integration leverages an AWS S3 bucket as the data transfer mechanism:

  • Zscaler MDR exports detection and telemetry data to a designated S3 bucket

  • Trend Vision One connects to this S3 bucket using the S3 connector

  • Data is pulled periodically from the bucket into Vision One for correlation and analysis

Zscaler MDR collects telemetry and alert data from Trend Vision One. Vision One “Activity” data is what Zscaler MDR considers to be telemetry, and “Workbench Alerts” are what Zscaler MDR ingests as alerts. Both types of telemetry are required for a effective detection and investigations. In order to enable the AWS S3 bucket connector, Trend Vision One customers must have sufficient credits. It takes credits to export data to an S3 bucket, so please contact your Trend Micro account team if you don’t have access to the AWS S3 bucket connector listed in Step 2.

To integrate Trend Vision One with Zscaler MDR, follow the procedure from beginning to end.

Prerequisites

Before you start the Trend Vision One integration, please make sure the following requirements are met:

  • Your Trend Vision One user account has admin level access.

  • Your Trend Vision One tenant has one of the following licenses:

    • Trend Vision One Endpoint Security - Essentials

    • Trend Vision One Endpoint Security - Pro

  • You have sufficient Trend Vision One credits to enable the AWS S3 bucket connector.

Note

The 30-day trial version of TrendMicro is NOT sufficient for testing because of the Trend Vision One credits requirement.

1 Zscaler MDR | Add the Integration

The first step is to add the new integration in Zscaler MDR.

  1. In the Zscaler MDR portal, go to the Integrations page then click Add Integration.
    Add a new Red Canary integration

  2. On the Add integration dialog, search for the Trend Vision One integration then click Configure.

  3. On the Add Integration page, enter a name for the integration.

2 Zscaler MDR/Trend Micro | Configure a Trend Vision One API key

  1. Record your Trend Vision One Business ID.

    1. Navigate to the License Information section within your Trend Vision One console.

    2. Copy the Business ID.

    3. Enter your Trend Vision One Business ID into Zscaler MDR.  

  2. Create a user role to be used with your new API key.  Note: Zscaler MDR is committed to accessing your environment using the fewest permissions required.

    1. Navigate to the User Roles page in the Trend Vision One console and click Add Role.

    2. Enter the name red-canary-api for the role and click Permissions.

    3. Configure the following permissions:

      1. Platform Capabilities

        1. XDR Threat Investigation

          1. Workbench check the View, filter, and search and Modify alert details boxes.

          2. Search check the View, filter, and search box.

        2. Workflow and Automation

          1. Response Management check the View, filter, and search (Task list tab), Isolate endpoint, and Terminate process boxes.

          2. Third-party integrations check the View box.

      2. Security Functions

        1. Endpoint Security

          1. Endpoint Inventory check the View box.

      3. Settings

        1. Administration

          1. User Roles check the View box.

          2. API Keys check the View box.

    4. Role permissions should look like this when completed successfully.

  3. Create a new API key for Zscaler MDR to ingest telemetry and alerts.

    1. Navigate to the API Keys section within your Trend Vision One console and click Add API Key.

    2. Name the API key red-canary and assign the user role created in step 1.2.

    3. Expiration Time should be set to “No expiration date.”

    4. Copy the newly created API key.

    5. Enter the API key into Zscaler MDR.

3 Zscaler MDR/Trend Micro | Configure Trend Vision One to Export Data to the Zscaler MDR AWS S3 Bucket

Note

Please contact your Trend Micro account team if you do not have access to the AWS S3 bucket connector

  1. Navigate to the AWS S3 Bucket Connector within your Trend Vision One console.

    1. Click Workflow and Automation in the main menu on the left.

    2. Select Third-Party Integration.

    3. Click AWS S3 Bucket Connector.

  2. In the Bucket name field, copy the bucket name listed from the in-line instructions in Zscaler MDR.

  3. In the Role ARN field, copy the Role ARN listed in the in-line instructions in Zscaler MDR.

  4. In the Data Transfer section, check the following boxes:

    1. Workbench alerts

    2. Activity data -> Scope: Endpoint

4 Zscaler MDR/Trend Micro | Create a User for Zscaler MDR to Access Your Environment

  1. Click on the Business Name menu at the top right.

  2. Select User Accounts.

  3. Click Add User Account.

  4. Select Local Account.

  5. Enter the email listed in the in-line instructions in Zscaler MDR into the Account field.

  6. Select Auditor for the Role field.

  7. Click Add.

  8. Zscaler MDR will accept the invite to finalize access.

5 Zscaler MDR | Activate the Integration

After you’ve completed the configuration, click Save to activate the integration.

The Trend Vision One integration is now live!

You should see Trend Vision One alerts start appearing in Zscaler MDR within one hour.

6 Zscaler MDR | Modify the Integration

After the Trend Vision One integration is active, you can make the following modifications to the configuration:

  • TBD

  • TBD

  • Decommission the integration

To modify the configuration:

  1. In the Zscaler MDR portal, go to the Integrations page then click on the name of the integration you want to modify.

  2. After you’ve finished the editing the configuration, click Save to apply your changes.

Decommissioning the Integration

To remove the integration from Zscaler MDR, click the button then click OK to confirm.

Important

If you decommission the integration, no new alerts will be sent to Zscaler MDR. Although threats will be retained, all processed alerts will be deleted. This action cannot be undone.

Ingest Details

Zscaler MDR collects telemetry and alert data from Trend Vision One. Vision One “Activity” data is what Zscaler MDR considers to be telemetry, and “Workbench Alerts” are what Zscaler MDR ingests as alerts. Both types of telemetry are required for a effective detection and investigations. In order to enable the AWS S3 bucket connector, Trend Vision One customers must have sufficient credits. It takes credits to export data to an S3 bucket, so please contact your Trend Micro account team if you don’t have access to the AWS S3 bucket connector listed in Step 2.

Troubleshooting

Error: Missing Required Permissions

Error Message: Trend Micro API Key : User role associated with the API key is missing one or more required permissions - please ensure that the provided key is correctly configured

If you receive this error message in Zscaler MDR, it means the API key's associated user role in Trend Vision One does not have sufficient access. To resolve this, sign in to your Trend Vision One console and ensure the custom user role created for Zscaler MDR has the following permissions enabled:

  • Platform Capabilities > XDR Threat Investigation

    • Under Workbench, check the boxes for View, filter, and search and Modify alert details.

    • Under Search, check the box for View, filter, and search.

  • Platform Capabilities > Workflow and Automation

    • Under Response Management, check the boxes for View, filter, and search (Task list tab), Isolate endpoint, and Terminate process.

    • Under Third-party integration, check the View box.

  • Security Functions > Endpoint Security

    • Under Endpoint Inventory, check the View box.

  • Settings > Administration

    • Under User Roles, check the View box.

    • Under API Keys, check the View box.

Error: Missing Pipeline Configurations

Error Message: Trend Micro API Key: Missing valid export pipeline configurations for telemetry configurations - please ensure that the required pipelines are configured correctly in your Trend Micro account

If you receive this error message in Zscaler MDR, it means that the integration is not configured to send the correct telemetry and alert data to Zscaler MDR. To fix this, you must configure the data export settings in Trend Vision One:

  1. In your Trend Vision One console, go to the Data Transfer section.

  2. Ensure the following boxes are checked:

    • Workbench alerts

    • Activity data (with the Scope set to Endpoint)