TrendAI Vision One™ enables transfer of suspicious object data and retrieval of threat intelligence data directly with the MISP threat sharing platform.
Important
|
Procedure
- On the TrendAI Vision One™ console, go to .
- Locate and click the MISP card.
- On the Direct Connection tab, click Add Connection.
- Turn on the toggle to enable the MISP connection.
- Select Send data to MISP.
- Configure settings to allow TrendAI Vision One™ to send suspicious object data to MISP.
- Select Retrieve data from MISP.
- Configure settings to allow TrendAI Vision One™ to
retrieve threat intelligence data from MISP.
-
You can only add indicator type STIX objects that are not revoked and do not have the anomalous activity, anonymization, benign, compromised, or unknown labels to the Suspicious Object List.
-
Auto sweeping is only supported for report type STIX objects.
-
The pattern field supports only single-condition patterns. Compound patterns that combine multiple conditions with the
ANDorORoperator are not supported. For example,[ipv4-addr:value = '1.2.3.4']is supported, but[domain-name:value = 'example.com' AND domain-name:resolves_to_refs[*].value = '1.2.3.4']is not.
TrendAI Vision One™ extracts the following observable types from the pattern field of retrieved MISP indicators. Any other type is ignored.Supported pattern types
Supported type Extracted as file:hashes.SHA-1/file:hashes.SHA1/file:hashes.sha1sha1 file:hashes.SHA-256/file:hashes.SHA256/file:hashes.sha256sha256 url:valueurl ipv4-addr:valueipv4 ipv6-addr:valueipv6 domain-name:valuedomain email-message:from_ref.value/email-message:sender_ref.valueemail_sender -
- Click Save.
