TrendAI Vision One™ for Microsoft Sentinel (CCF)

Solution: TrendAI Vision One(CCF)

TrendAI Vision One(CCF) Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher TrendAI
Support Tier Partner
Support Link https://success.trendmicro.com/dcx/s/
Categories Security - Threat Protection
Version 3.0.0
Author TrendAI
First Published 2026-07-08
Last Updated 2026-08-24
Solution Folder TrendAI Vision One(CCF)
Marketplace Azure Marketplace · Popularity: 🟢 High (87%)

The TrendAI Vision One solution for Microsoft Sentinel provides two data connectors that ingest security data from the TrendAI Vision One platform using the Codeless Connector Framework (CCF):

This solution also includes KQL parser functions, an analytic rule, and a workbook dashboard for Workbench Alerts.

Contents

Data Connectors

This solution provides 2 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 2 table(s):

Table Used By Connectors Used By Content
TrendAI_XDR_OAT_V2_CL 🔶 TrendAI Vision One™ - OAT Detections (via Codeless Connector Framework) -
TrendAI_XDR_WORKBENCH_V2_CL 🔶 TrendAI Vision One™ - Workbench Alerts (via Codeless Connector Framework) Analytics, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 4 content item(s):

Content Type Count
Parsers 2
Analytic Rules 1
Workbooks 1

Analytic Rules

Name Severity Tactics Tables Used
TrendAI Vision One - Create Incident for Workbench Alerts High InitialAccess, Execution, Persistence, PrivilegeEscalation, DefenseEvasion, CredentialAccess, Discovery, LateralMovement, Collection, Exfiltration, CommandAndControl, Impact TrendAI_XDR_WORKBENCH_V2_CL

Workbooks

Name Tables Used
TrendAIVisionOneWorkbenchOverview TrendAI_XDR_WORKBENCH_V2_CL

Parsers

Name Description Tables Used
TrendAIOAT_Complete - TrendAI_XDR_OAT_V2_CL (read)
TrendMicro_XDR_OAT_CL (read)
TrendAIWorkbench_Complete - TrendAI_XDR_WORKBENCH_V2_CL (read)
TrendMicro_XDR_WORKBENCH_CL (read)

Additional Documentation

📄 Source: TrendAI Vision One(CCF)/README.md

Overview

The TrendAI Vision One solution for Microsoft Sentinel provides data connectors that ingest security data from the TrendAI Vision One platform into Microsoft Sentinel using the Codeless Connector Framework (CCF).

This solution includes two data connectors:

Connector Description
Workbench Alerts Ingests security alerts, incidents, and investigations from TrendAI Vision One Workbench
OAT Detections Ingests Observed Attack Techniques (OAT) detections with MITRE ATT&CK mappings

Both connectors poll the TrendAI Vision One API every 5 minutes, retrieving data from the last 5-minute window.


Solution Contents

Component Description
Data Connectors 2 connectors (Workbench Alerts, OAT Detections)
Custom Tables TrendAI_XDR_WORKBENCH_V2_CL, TrendAI_XDR_OAT_V2_CL
Parser Functions TrendAIWorkbench_Complete, TrendAIOAT_Complete
Data Collection Rules DCR-based ingestion-time transformations
Data Collection Endpoint Shared DCE for both connectors

Prerequisites

1. Microsoft Sentinel Workspace

2. TrendAI Vision One API Token

You need an API token from your TrendAI Vision One console with appropriate permissions.

Steps to Generate API Token:

  1. Log in to the TrendAI Vision One Console
  2. Navigate to Administration → API Keys
  3. Click Add API Key
  4. Configure the API key:
    • Name: Microsoft Sentinel Integration (or your preferred name)
    • Role: Select a role with the following permissions:
      • Workbench (View)
      • Observed Attack Techniques (View)
    • Expiration: Set according to your security policy
  5. Click Add
  6. Important: Copy and securely store the API token immediately. It will not be shown again.

3. Identify Your API Region

Determine the API domain based on your TrendAI Vision One tenant region:

Region API Domain
US api.xdr.trendmicro.com
EU api.eu.xdr.trendmicro.com
SG api.sg.xdr.trendmicro.com
JP api.xdr.trendmicro.co.jp
AU api.au.xdr.trendmicro.com
IN api.in.xdr.trendmicro.com
MEA api.mea.xdr.trendmicro.com
UK api.uk.xdr.trendmicro.com
CA api.ca.xdr.trendmicro.com
ZA (South Africa) api.za.xdr.trendmicro.com

Installation from Content Hub

Step 1: Navigate to Content Hub

  1. Sign in to the Azure Portal
  2. Navigate to Microsoft Sentinel
  3. Select your Sentinel workspace
  4. In the left menu, click Content hub

Step 2: Find and Install the Solution

  1. In the Content Hub, search for "TrendAI Vision One"

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 05-08-2026 Initial release of TrendAI Vision One solution via Codeless Connector Framework (CCF). Includes Workbench Alerts and OAT Detections connectors with DCR-based ingestion-time transformations, dropdown selectors for API domain and third-party exclusion, TMV1-Filter pass-through support, KQL parsers, an analytic rule with MITRE ATT&CK mappings, and a workbook dashboard. Fixed ARM template bracket escaping, added token rotation warning, optimized workbook queries, and removed the null alertRuleTemplateName field.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index