This is now GA and is being rolled out to
Workload Security customers. If it is not available in your account yet, it will be
soon.
Trend Micro Managed Detection and Response (MDR) detects and responds to threats across
email, servers, cloud workloads and networks. Workload Security can send server activity
metadata and Integrity Monitoring data to the MDR server for correlation and visibility
across physical, virtual, and cloud workloads. For more information about MDR, see
XDR - Managed Detection and Response Service.
To enable Managed Detection and Response:
Procedure
- Obtain the following information from your Threat Investigation Center administrator:
- Threat Investigation Center Server URL
- Company GUID
- Data Source GUID
- Proxy server address (optional)
- In the Workload Security console, go to .
- Click Enable the MDR service and fill in the following information:
- Server URL (for example: "https://[server]/"): The Threat Investigation Center Server URL
- Company GUID
- Data Source GUID
- If required, you can choose to use a proxy to access MDR. Select When accessing MDR server, use proxy and click Edit to specify the proxy server address provided by your Threat Investigation Center administrator.
- Before saving, click Test Connection to make sure Workload Security is connected to TIC. If the connection fails, double-check that all the information entered is correct. If the connection passes, click Save.