Response Actions

Object-specific actions allow you to directly respond to threats without leaving the Trend Vision One console.

You can take specific actions on events or objects found on the Trend Vision One console. After triggering a response, the Response Management app creates a task and sends the command to the target.

The following tables describe the actions you can take on users, networks, endpoints, and email messages.

Table 1. User

Action

Description

Supported Services

Disable User Account

Signs the user out of all active application and browser sessions of the user account. It may take a few minutes for the process to complete. Users are prevented from signing in any new session.

Note:

Not applicable on accounts assigned the Azure AD Administrator role.

For more information, see Disable User Account Task.

  • Azure AD

  • Active Directory (on-premises)

  • Okta

  • OpenLDAP

Enable User Account

Allows the user to sign in to new application and browser sessions. It may take a few minutes for the process to complete.

For more information, see Enable User Account Task.

  • Azure AD

  • Active Directory (on-premises)

  • Okta

  • OpenLDAP

Force Password Reset

Signs the user out of all active application and browser sessions, and forces the user to create a new password during the next sign-in attempt. It may take a few minutes for the process to complete.

For more information, see Force Password Reset Task.

  • Azure AD

  • Active Directory (on-premises)

  • Okta

  • OpenLDAP

Force Sign Out

Signs the user out of all active application and browser sessions of the user account. It may take a few minutes for the process to complete. Users are not prevented from immediately signing back in the closed sessions or signing in new sessions.

For more information, see Force Sign Out Task.

  • Azure AD

  • Okta

Table 2. Network

Action

Description

Supported Services

Add to Block List

Adds supported objects such as File SHA-1, URL, IP address, or domain objects to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections

Important:

Adding an object to the User-Defined Suspicious Objects List does not terminate any active processes or connections to the object. To terminate active processes, ensure that you also trigger the Terminate response.

For more information, see Add to Block List Task.

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

  • Cloud App Security

  • Deep Discovery Inspector

  • Deep Security Software

Collect File

Compresses the selected file detected by the network appliance in a password-protected archive and then sends the archive to the Response Management app

  • Deep Discovery Inspector

Collect Investigation Package

Compresses the selected investigation package that includes OpenIOC files describing Indicators of Compromise identified on the affected host or network in a password-protected archive and then sends the archive to the Response Management app

Important:

To execute the Collect Investigation Package action, you must first enable the Virtual Analyzer in Deep Discovery Inspector.

  • Deep Discovery Inspector

Collect Network Analysis Package

Compresses the selected network analysis package (including an investigation package, a PCAP file, and a selected file detected by the network appliance) in a password-protected archive and then sends the archive to the Response Management app

For more information, see Collect Network Analysis Package Task.

Important:

To execute the Collect Network Analysis Package task, you must first enable the Virtual Analyzer and packet capture function in Deep Discovery Inspector.

Note:

The Collect PCAP File action only supports Deep Discovery Inspector 6.5 or above.

  • Deep Discovery Inspector

Collect PCAP File

Compresses the selected Packet Capture file in a password-protected archive and then sends the archive to the Response Management app

Note:

The Collect PCAP File action only supports Deep Discovery Inspector 6.5 or above.

Important:

To execute the Collect PCAP File action, you must first enable the packet capture function in Deep Discovery Inspector.

  • Deep Discovery Inspector

Remove from Block List

Removes the File SHA-1, URL, IP address, or Domain object added to the User-Defined Suspicious Objects List through the Add to Block List response

For more information, see Remove from Block List Task.

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

  • Cloud App Security

  • Deep Discovery Inspector

  • Deep Security Software

Submit for Sandbox Analysis

Submits the selected file objects for automated analysis in a sandbox, a secure virtual environment

For more information, see Submit for Sandbox Analysis Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

  • Apex One as a Service

    • Windows agent

    • Linux agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

    • Mac agent

  • Deep Discovery Inspector

Table 3. Endpoint

Action

Description

Supported Services

Add to Block List

Adds supported objects such as File SHA-1, URL, IP address, or domain objects to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections

Important:

Adding an object to the User-Defined Suspicious Objects List does not terminate any active processes or connections to the object. To terminate active processes, ensure that you also trigger the Terminate response.

For more information, see Add to Block List Task.

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

  • Cloud App Security

  • Deep Security Software

Collect File

Compresses the selected file on the endpoint in a password-protected archive and then sends the archive to the Response Management app

For more information, see Collect File Sample Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

    • Linux agent

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

    • Mac agent

Dump Process Memory

Directly accesses an endpoint and executes remote shell commands to identify currently running processes that may be causing suspicious activity during an investigation

Important:

The Dump Process Memory action is only triggered by the memdump command through remote shell on endpoints running Windows or macOS, and is disabled by default. Contact your support provider to enable the command.

Note:

Use an external decompression program (such as 7-zip) to extract the file contents.

  • Trend Vision One

    • Windows agent

    • Mac agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Mac agent

Isolate Endpoint

Disconnects the target endpoint from the network, except for communication with the managing Trend Micro server product

For more information, see Isolate Endpoint Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

    • Mac agent

Remove from Block List

Removes the File SHA-1, URL, IP address, or Domain object added to the User-Defined Suspicious Objects List through the Add to Block List response

For more information, see Remove from Block List Task.

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

  • Cloud App Security

  • Deep Security Software

Restore Connection

Restores network connectivity to an endpoint that already applied the Isolate Endpoint action

For more information, see Restore Connection Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

    • Mac agent

Run Remote Custom Script

Connects to a monitored endpoint and executes a previously uploaded PowerShell or Bash script file

For more information, see Run Remote Custom Script Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

    • Linux agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Mac agent

    • Linux agent

Start Remote Shell Session

Connects to a monitored endpoint and allows you to execute remote commands or a custom script file for investigation

For more information, see Start Remote Shell Session Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

    • Linux agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Mac agent

    • Linux agent

Submit for Sandbox Analysis

Submits the selected file objects for automated analysis in a sandbox, a secure virtual environment

For more information, see Submit for Sandbox Analysis Task.

  • Trend Vision One

    • Windows agent

    • Mac agent

  • Apex One as a Service

    • Windows agent

    • Linux agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

    • Mac agent

Terminate Process

Terminates the active process and allows you to terminate the process on all affected endpoints

For more information, see Terminate Process Task.

  • Apex One as a Service

    • Windows agent

Table 4. Email

Action

Description

Supported Services

Add to Block List

Adds supported objects such as File SHA-1, URL, IP address, or domain objects to the User-Defined Suspicious Objects List, which blocks the objects on subsequent detections

Important:

Adding an object to the User-Defined Suspicious Objects List does not terminate any active processes or connections to the object. To terminate active processes, ensure that you also trigger the Terminate response.

For more information, see Add to Block List Task.

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

  • Cloud App Security

  • Deep Security Software

Delete Message

Deletes the selected email message from the selected mailboxes

For more information, see Delete Email Message Task.

  • Cloud App Security

Quarantine Message

Moves the selected email message to the quarantine folder and allows you to quarantine the message from all affected mailboxes

For more information, see Quarantine Email Message Task.

  • Cloud App Security

Remove from Block List

Removes the File SHA-1, URL, IP address, or Domain object added to the User-Defined Suspicious Objects List through the Add to Block List response

For more information, see Remove from Block List Task.

  • Apex One as a Service

    • Windows agent

  • Trend Cloud One - Endpoint & Workload Security

    • Windows agent

    • Linux agent

  • Cloud App Security

  • Deep Security Software