Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | Security - Threat Protection |
| Version | 3.1.2 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2021-09-28 |
| Solution Folder | Trend Micro Cloud App Security |
| Marketplace | Azure Marketplace · Rating: ★★★★★ 4.5/5 (44 ratings) · Popularity: 🟡 Low (18%) |
The Trend Micro Cloud App Security data connector provides the capability to retrieve security event logs of the services that Cloud App Security protects and more events into Microsoft Sentinel through the Log Retrieval API. Refer to API documentation for more information. The connector provides the ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies might result in additional ingestion or operational costs:
a. Codeless Connector Framework (CCF)
c. Data Collection Rules (DCR)
d. Azure Monitor HTTP Data Collector API
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 2 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
TrendMicroCASV2_CL |
Trend Micro Cloud App Security, Trend Micro Cloud App Security (via Codeless Connector Framework) | Analytics, Hunting, Workbooks |
TrendMicroCAS_CL 🔶 |
Trend Micro Cloud App Security | Analytics, Hunting, Workbooks |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 22 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 10 |
| Hunting Queries | 10 |
| Workbooks | 1 |
| Parsers | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Trend Micro CAS - DLP violation | High | Exfiltration | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Infected user | High | InitialAccess | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Multiple infected users | High | InitialAccess | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Possible phishing mail | Medium | InitialAccess | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Ransomware infection | High | Impact | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Ransomware outbreak | High | Impact | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Suspicious filename | Medium | InitialAccess | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Threat detected and not blocked | High | DefenseEvasion | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Unexpected file on file share | Medium | InitialAccess | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Trend Micro CAS - Unexpected file via mail | Medium | InitialAccess | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Name | Tables Used |
|---|---|
| TrendMicroCAS | TrendMicroCASV2_CLTrendMicroCAS_CL |
| Name | Description | Tables Used |
|---|---|---|
| TrendMicroCAS | - | TrendMicroCASV2_CL (read)TrendMicroCAS_CL (read) |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.1.2 | 23-07-2026 | Updated CCF Data Connector graph queries pattern. |
| 3.1.1 | 17-07-2026 | Promoted CCF connector (TrendMicroCASConnector) to General Availability: set isPreview to false and removed Preview disclaimer from solution description. |
| 3.1.0 | 02-07-2026 | Updated Underlying Microsoft Technologies list in the solution description to include Codeless Connector Framework (CCF), Log Ingestion API, and Data Collection Rules (DCR) for the CCF data connector. |
| 3.0.0 | 29-05-2026 | Added dual-schema parser support for CLv1 (TrendMicroCAS_CL) and CLv2 (TrendMicroCASV2_CL) data, introduced Codeless Connector Framework (CCF) Data Connector alongside the legacy Azure Function connector. |
| 2.0.0 | 23-08-2023 | Initial release. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊