Connect your own Trend Micro Vision One XDR tenant to manage Workbench alerts, Endpoint Security (isolate/restore, scan), Suspicious Object Lists (IOCs), Observed Attack Techniques, and XDR data lake Search queries.
connect_trend_microwriteConnect your own Trend Micro Vision One tenant (data-center region + Authentication Token), verifying the credentials with a real call before saving.
list_connectionsreadList the connected Trend Micro Vision One tenants.
disconnect_trend_microwriteDisconnect a Trend Micro Vision One tenant: deletes the saved Authentication Token. Nothing in Vision One itself is changed.
list_workbench_alertsreadList Trend Micro Vision One Workbench alerts on the connected tenant, optionally filtered by status.
get_workbench_alertreadRead one Trend Micro Vision One Workbench alert in full.
update_workbench_alertwriteUpdate a Trend Micro Vision One Workbench alert's status and/or investigation result.
list_endpointsreadList endpoints enrolled in the connected Trend Micro Vision One tenant.
isolate_endpointwriteIsolate a Trend Micro Vision One endpoint from the network. The endpoint stays protected but loses almost all network access -- confirm the target host before running.
restore_endpointwriteRestore network connection for a previously isolated Trend Micro Vision One endpoint.
scan_endpointwriteTrigger an on-demand malware scan on a Trend Micro Vision One endpoint.
list_suspicious_objectsreadList Suspicious Objects (fleet-wide indicators) configured on the connected Trend Micro Vision One tenant.
create_suspicious_objectwriteAdd a Suspicious Object (hash, IP, domain, or URL) to the connected Trend Micro Vision One tenant. scan_action defaults to 'log' (monitor only) -- pass 'block' explicitly to actively deny it fleet-wide.
remove_suspicious_objectwritePermanently remove a Suspicious Object from the connected Trend Micro Vision One tenant. Cannot be undone.
list_attack_techniquesreadList ATT&CK-mapped Observed Attack Techniques detected on the connected Trend Micro Vision One tenant.
run_search_queryreadRun a Search query (Vision One's XDR data lake query engine) against the connected tenant's telemetry within a bounded time window.
audit_trend_micro_tenantreadBuild one aggregated health report across the connected Trend Micro Vision One tenant: open Workbench alerts by severity, isolated endpoints, and active-block Suspicious Objects.
Install Trend Micro Vision One and let Webbee use it across your workflow.
Open in panel