Object-specific actions allow you to directly respond to threats without leaving the Trend Vision One console.
You can take specific actions on events or objects found on the Trend Vision One console. After triggering a response, the Response Management app creates a task and sends the command to the target.
The following tables describe the actions you can take on users, networks, endpoints, and email messages.
Action |
Description |
Supported Services |
---|---|---|
Disable User Account |
Signs the user out of all active application and browser sessions of the user account. It may take a few minutes for the process to complete. Users are prevented from signing in any new session. Note:
Not applicable on accounts assigned the Azure AD Administrator role. For more information, see Disable User Account Task. |
|
Enable User Account |
Allows the user to sign in to new application and browser sessions. It may take a few minutes for the process to complete. For more information, see Enable User Account Task. |
|
Force Password Reset |
Signs the user out of all active application and browser sessions, and forces the user to create a new password during the next sign-in attempt. It may take a few minutes for the process to complete. For more information, see Force Password Reset Task. |
|
Force Sign Out |
Signs the user out of all active application and browser sessions of the user account. It may take a few minutes for the process to complete. Users are not prevented from immediately signing back in the closed sessions or signing in new sessions. For more information, see Force Sign Out Task. |
|
Action |
Description |
Supported Services |
---|---|---|
Add to Block List |
Adds supported objects such as File SHA-1, URL, IP address, or domain objects to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections Important:
Adding an object to the User-Defined Suspicious Objects List does not terminate any active processes or connections to the object. To terminate active processes, ensure that you also trigger the Terminate response. For more information, see Add to Block List Task. |
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
Cloud App Security Deep Security Software |
Collect File |
Compresses the selected file detected by the network appliance in a password-protected archive and then sends the archive to the Response Management app |
|
Collect Investigation Package |
Compresses the selected investigation package that includes OpenIOC files describing Indicators of Compromise identified on the affected host or network in a password-protected archive and then sends the archive to the Response Management app Important:
To execute the Collect Investigation Package action, you must first enable the Virtual Analyzer in Deep Discovery Inspector. |
|
Collect Network Analysis Package |
Compresses the selected network analysis package (including an investigation package, a PCAP file, and a selected file detected by the network appliance) in a password-protected archive and then sends the archive to the Response Management app For more information, see Collect Network Analysis Package Task. Important:
To execute the Collect Network Analysis Package task, you must first enable the Virtual Analyzer and packet capture function in Deep Discovery Inspector. Note:
The Collect PCAP File action only supports Deep Discovery Inspector 6.5 or above. |
|
Collect PCAP File |
Compresses the selected Packet Capture file in a password-protected archive and then sends the archive to the Response Management app Note:
The Collect PCAP File action only supports Deep Discovery Inspector 6.5 or above. Important:
To execute the Collect PCAP File action, you must first enable the packet capture function in Deep Discovery Inspector. |
|
Remove from Block List |
Removes the File SHA-1, URL, IP address, or Domain object added to the User-Defined Suspicious Objects List through the Add to Block List response For more information, see Remove from Block List Task. |
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
Cloud App Security Deep Security Software |
Submit for Sandbox Analysis |
Submits the selected file objects for automated analysis in a sandbox, a secure virtual environment For more information, see Submit for Sandbox Analysis Task. |
Trend Vision One
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
|
Action |
Description |
Supported Services |
---|---|---|
Add to Block List |
Adds supported objects such as File SHA-1, URL, IP address, or domain objects to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections Important:
Adding an object to the User-Defined Suspicious Objects List does not terminate any active processes or connections to the object. To terminate active processes, ensure that you also trigger the Terminate response. For more information, see Add to Block List Task. |
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
Cloud App Security Deep Security Software |
Collect File |
Compresses the selected file on the endpoint in a password-protected archive and then sends the archive to the Response Management app For more information, see Collect File Sample Task. |
Trend Vision One
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
|
Dump Process Memory |
Directly accesses an endpoint and executes remote shell commands to identify currently running processes that may be causing suspicious activity during an investigation Important:
The Dump Process Memory action is only triggered by the memdump command through remote shell on endpoints running Windows or macOS, and is disabled by default. Contact your support provider to enable the command. Note:
Use an external decompression program (such as 7-zip) to extract the file contents. |
Trend Vision One
Trend Cloud One - Endpoint & Workload Security
|
Isolate Endpoint |
Disconnects the target endpoint from the network, except for communication with the managing Trend Micro server product For more information, see Isolate Endpoint Task. |
Trend Vision One
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
|
Remove from Block List |
Removes the File SHA-1, URL, IP address, or Domain object added to the User-Defined Suspicious Objects List through the Add to Block List response For more information, see Remove from Block List Task. |
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
Cloud App Security Deep Security Software |
Restore Connection |
Restores network connectivity to an endpoint that already applied the Isolate Endpoint action For more information, see Restore Connection Task. |
Trend Vision One
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
|
Run Remote Custom Script |
Connects to a monitored endpoint and executes a previously uploaded PowerShell or Bash script file For more information, see Run Remote Custom Script Task. |
Trend Vision One
Trend Cloud One - Endpoint & Workload Security
|
Start Remote Shell Session |
Connects to a monitored endpoint and allows you to execute remote commands or a custom script file for investigation For more information, see Start Remote Shell Session Task. |
Trend Vision One
Trend Cloud One - Endpoint & Workload Security
|
Submit for Sandbox Analysis |
Submits the selected file objects for automated analysis in a sandbox, a secure virtual environment For more information, see Submit for Sandbox Analysis Task. |
Trend Vision One
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
|
Terminate Process |
Terminates the active process and allows you to terminate the process on all affected endpoints For more information, see Terminate Process Task. |
Apex One as a Service
|
Action |
Description |
Supported Services |
---|---|---|
Add to Block List |
Adds supported objects such as File SHA-1, URL, IP address, or domain objects to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections Important:
Adding an object to the User-Defined Suspicious Objects List does not terminate any active processes or connections to the object. To terminate active processes, ensure that you also trigger the Terminate response. For more information, see Add to Block List Task. |
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
Cloud App Security Deep Security Software |
Delete Message |
Deletes the selected email message from the selected mailboxes For more information, see Delete Email Message Task. |
Cloud App Security |
Quarantine Message |
Moves the selected email message to the quarantine folder and allows you to quarantine the message from all affected mailboxes For more information, see Quarantine Email Message Task. |
Cloud App Security |
Remove from Block List |
Removes the File SHA-1, URL, IP address, or Domain object added to the User-Defined Suspicious Objects List through the Add to Block List response For more information, see Remove from Block List Task. |
Apex One as a Service
Trend Cloud One - Endpoint & Workload Security
Cloud App Security Deep Security Software |