Views:

TrendAI Vision One™ enables transfer of suspicious object data and retrieval of threat intelligence data directly with the MISP threat sharing platform.

Important
Important
  • The MISP API does not return unpublished events for version 2.4.717 or later. Publish events on the MISP server to ensure that threat intelligence data can be sent to TrendAI Vision One™.
  • To send MISP attributes as suspicious objects to TrendAI Vision One™, add the Intrusion Detection System flag. This determines if the attribute can be automated.
  • For more information about MISP instance sizing, see Sizing your MISP instance.

Procedure

  1. On the TrendAI Vision One™ console, go to Workflow and AutomationThird-Party Integration.
  2. Locate and click the MISP card.
  3. On the Direct Connection tab, click Add Connection.
  4. Turn on the toggle to enable the MISP connection.
  5. Select Send data to MISP.
  6. Configure settings to allow TrendAI Vision One™ to send suspicious object data to MISP.
  7. Select Retrieve data from MISP.
  8. Configure settings to allow TrendAI Vision One™ to retrieve threat intelligence data from MISP.
    • You can only add indicator type STIX objects that are not revoked and do not have the anomalous activity, anonymization, benign, compromised, or unknown labels to the Suspicious Object List.
    • Auto sweeping is only supported for report type STIX objects.
    • The pattern field supports only single-condition patterns. Compound patterns that combine multiple conditions with the AND or OR operator are not supported. For example, [ipv4-addr:value = '1.2.3.4'] is supported, but [domain-name:value = 'example.com' AND domain-name:resolves_to_refs[*].value = '1.2.3.4'] is not.
    TrendAI Vision One™ extracts the following observable types from the pattern field of retrieved MISP indicators. Any other type is ignored.

    Supported pattern types

    Supported type Extracted as
    file:hashes.SHA-1 / file:hashes.SHA1 / file:hashes.sha1 sha1
    file:hashes.SHA-256 / file:hashes.SHA256 / file:hashes.sha256 sha256
    url:value url
    ipv4-addr:value ipv4
    ipv6-addr:value ipv6
    domain-name:value domain
    email-message:from_ref.value / email-message:sender_ref.value email_sender
  9. Click Save.