Trend Vision One Integration

Note: This integration requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

Trend Vision One is an Extended Detection and Response (XDR) and Endpoint Detection and Response (EDR) offering. In Cisco XDR, we enable Trend Vision One users to leverage it for threat hunting and investigation features, as well as rapid response actions to understand and defend against threats on the endpoint. It also provides important device inventory context to help triage detected threats.

Use the Trend Vision One integration to search for security detections involving specific hostnames, host GUIDs, domains, IP addresses, file hashes, email senders and subjects, usernames, process names, and process arguments. Trend Vision One can also be used through Cisco XDR to isolate hosts from the network and block many kinds of observables, including file hashes, email senders, and network resources such as IP addresses, domains, and URLs.