Security Playbooks Requirements

View the required entitlement needed to access each type of playbook.

The availability of certain playbook templates and the ability to execute playbooks depends on your license entitlement for the associated Trend Vision One features and the required data source configuration in Risk Insights.

To view the credits needed for each required entitlement, see Trend Micro Offerings Supporting Credits.

The following table details the requirements for each playbook type.

Category

Template

Required Data Source

Required Entitlement

Risk Insights

Account Configuration Risk

  • Azure AD

  • Active Directory (on-premises)

Risk Insights

CVEs with Global Exploit Activity - Internal Assets

  • XDR Endpoint Sensor

  • Third-party data sources (Nessus Pro, Qualys, Rapid7, or Tenable.io)

CVEs with Global Exploit Activity - Internet-Facing Assets

Root domain configuration in Attack Surface Discovery

XDR Threat Investigation

Automated Response Playbook

  • XDR Endpoint Sensor

  • XDR Email Sensor

XDR Threat Investigation

Run Custom Script

XDR Endpoint Sensor

Incident Response Evidence Collection

XDR Endpoint Sensor

Microsoft Exchange vulnerability assessment for CVE-2021-34470

XDR Endpoint Sensor

Samba vulnerability assessment for CVE-2021-44142

XDR Endpoint Sensor