Trend Micro
Telemetry Evidence
These values show how indexed rules identify Trend Micro telemetry.Kusto
TMApexOneEvent TrendMicro_XDR_WORKBENCH_CL TrendMicroCAS
Detection Rules
Kusto #
- ApexOne - Attack Discovery Detection source high: 'Detects Attack Discovery Detection events.'
T1190 - ApexOne - C&C callback events source high: 'Detects C&C callback events.'
T1071 - ApexOne - Commands in Url source high: 'Detects commands in Url.'
T1133,T1190 - ApexOne - Device access permissions was changed source medium: 'Query shows device access permissions was changed.'
T1078 - ApexOne - Inbound remote access connection source high: 'Detects inbound remote access connection.'
T1021 - ApexOne - Multiple deny or terminate actions on single IP source high: 'Detects multiple deny or terminate actions on single IP.'
T1190 - ApexOne - Possible exploit or execute operation source high: 'Detects possible exploit or execute operation.'
T1546 - ApexOne - Spyware with failed response source high: 'Detects spyware with failed response.'
T1190 - ApexOne - Suspicious commandline arguments source high: 'Detects suspicious commandline arguments.'
T1059 - ApexOne - Suspicious connections source high: 'Detects suspicious connections.'
T1102
Show 10 more
- Trend Micro CAS - DLP violation source high: 'Detects when DLP policy violation occurs.'
T1048 - Trend Micro CAS - Infected user source high: 'Detects when malware was detected for user account.'
T1566 - Trend Micro CAS - Multiple infected users source high: 'Detects when same malware was detected for multiple user account.'
T1566 - Trend Micro CAS - Possible phishing mail source medium: 'Detects possible phishing mail.'
T1566 - Trend Micro CAS - Ransomware infection source high: 'Triggeres when ransomware was detected.'
T1486 - Trend Micro CAS - Ransomware outbreak source high: 'Triggeres when ransomware was detected on several accounts.'
T1486 - Trend Micro CAS - Suspicious filename source medium: 'Detects unexpected filename.'
T1566 - Trend Micro CAS - Threat detected and not blocked source high: 'Detects when threat was not blocked by CAS solution.'
T1685 - Trend Micro CAS - Unexpected file on file share source medium: 'Detects unexpected files on file share.'
T1566 - Trend Micro CAS - Unexpected file via mail source medium: 'Detects when unexpected file received via mail.'
T1566
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #
Compatible Rules
These rules declare Trend Micro connector or schema compatibility without a product-specific query filter.Kusto #
T1490T1547T1112, T1547T1685T1685T1204T1027, T1059