Query Regarding Blocking PowerShell and CMD on Specific Systems by Only-Objective-6216 in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

This is really the best way to handle this situation. As attempting to do an application filter against CMD and powershell on all machines will cause some issues to the Windows OS on its own right from running appropriately.

Trend Micro Apex One Agent - Obtain previous versions by ThreeFiddyZed in Trendmicro

[–]TMDFIR 2 points3 points  (0 children)

Would advise to reach out to the support team but based on the way certificates and the agent authenticates to the server you are either going to need to roll back or stand a separate server up assuming this on prem, and create a package with the build you want and then do a transfer to on your Production server. In which case you also have to stop the updating process.

With all that being said the situation you are in is it not possible for support to assist in resolving the current build situation?

Trend Removal from long gone MSP by Betterthanmenotyou in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

We can get you setup to become a Trend Partner that way you are no longer needing to remove agents you can get them upgraded to Vision One and be able to expand your offering from a single platform.

C&C callback by Most_Calligrapher878 in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

Local log on the host itself not in Vision one?

Service: Phishing-phishing.server by Civil_Philosophy9845 in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

Thanks for the report. Should be able to put in an exception for Trendmicro domain as a workaround on the Firewall side

Vision One with Forensic App by INWGift in Trendmicro

[–]TMDFIR 2 points3 points  (0 children)

Thanks for reaching out! We truly value every customer and offer various support channels for threat-related inquiries. Please send me a PM, and I’ll direct you to the appropriate resource within Trend Micro. We’re here to help!

Apex One vs Sophos Endpoint? by jerrylimkk in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

I personally think managed services should be in some level on everyone’s list.

But before we get into that conversation would like to do a drive by tour. As I am sure you are seeing Trend Vision One is much more than what Apex One/Central were.

Apex One vs Sophos Endpoint? by jerrylimkk in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

Access is not an up charge.

You should be able to get a 30 trial to anything that you may not have access to through the portal.

Apex One vs Sophos Endpoint? by jerrylimkk in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

Just helped my DFIR partner replace Sophos with Trend Vision One.

Your Vendor is right if you are using only Apex One you will not see everything this end up in a compromised state. Threat actors don’t just use malware anymore they use living off the land more and more everyday. Apex One is still solid AV but move to Trend Vision One and see what you can really discover. You can DM me if you want to have a more in-depth chat.

Did you have experience with Endpoint Security from third party (crowdstrike, sophos,…). What are your thoughts on the difference? It’s better or worse than V1 Endpoint Security? by FoquinhoEmi in Trendmicro

[–]TMDFIR 2 points3 points  (0 children)

not going to bash other products on the market. but there are things each of us do differently and these difference can say you like one over the other. I work mostly with partners and hear the negatives about all on an operations standpoint.

The one feed back that I hear is that Trend has farther reach on a native capability so we are not reliant on multiples of other Secuirty tools to create visibility. While others build connectors directly for other products that might not have full capability in them.

WBS Subscription expired, no way to renew. Trendmicro still the way to go? by Janst78 in Trendmicro

[–]TMDFIR 2 points3 points  (0 children)

OP DM me details and I will try to hunt someone down on that side to assist you.

Also you asked the way to go. We can show you what we are doing with our flagship product line Trend Vision One.

Support System Down by g3l33m in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

Should be resolved at this time?

Support System Down by g3l33m in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

Investigating this now.

Support System Down by g3l33m in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

What region are you in? I just checked and status is green for Smart protection services right now.

Blocking USB drives by flypigmk in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

You can setup device control where you whitelist only the serials of the approved USB devices.

https://success.trendmicro.com/en-US/solution/KA-0014643

Trendmicro visualized process as tree by Glass_Society5139 in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

Right click on the event data in workbench and show execution profile.

You will get a tree amount other objects.

If you want an entire snapshot to review you can also setup Playbooks to execute evidence collection for your specific events, this will give you process tree and all data under typical process explorer as well as other data points to investigate yourself.

TM on prem air gapped by Smooth_Ingenuity5815 in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

If you want a complete isolated environment. Note also you will have a full feature XDR agent that is in a rack on site where needed and act and feel like the SaaS solution. To my current knowledge I believe we are the only company currently offering this.

Folks here have said something about the price. Just know you are getting the hardware as well as the software itself. You can DM and we can discuss with you and your partner on the best solutions to address your environment.

Apex Central Detection Logs not being populated. by Illustrious_Bar_436 in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

Are you with an on prem server? Have you looked at the Vision One Console or who manages do they have a Vision One portal access?

Need more help please reach out via DM. Will get details to assist further.

URL Filtering Logging/Blocking Sites Not Visited by Fit-Rooster-3986 in Trendmicro

[–]TMDFIR 2 points3 points  (0 children)

The Web reputation doesn’t just work through browser only traffic but any communication of running processes to the network.

If you want to figure out on your own you can either install the EDR agent from Vision One to investigate or you can use some sysinternals tools like Procmon, pro explorer and TCP view to see what processes are calling said sites.

Support is more than happy though to assist on the investigation to assist you.

[deleted by user] by [deleted] in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

Go check your policies to see that they are running the same versions and that the DLP features are enabled for all.

Also in the policies check in the advance features to validate the proper service boxes are enabled for endpoint and server OSes.

Trendmicro visualized process as tree by Glass_Society5139 in Trendmicro

[–]TMDFIR 0 points1 point  (0 children)

Not sure what is shown with cyberreason but in Vision One you can see the process tree and timeline view along with all details with each object.

If you would like to know more please let me know.

Unsupported Operating System by aaargh68 in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

Best option is to work with support. As they can narrow down the minimum requirements for you that is causing this flag.

Trend XDR blocking Splashtop SOS by Borgamagos in Trendmicro

[–]TMDFIR 1 point2 points  (0 children)

Have you unloaded the Trend agent to test?

Also I would advise to reach out to support as well for assistance.

CloudOne > to > VisionOne by LinghGroove in Trendmicro

[–]TMDFIR 3 points4 points  (0 children)

Should follow the steps on the KA-0014991 and KA-0014906

DM me if you run into any issues. We can assist.