Trend Micro Vision One Attribute Reference
Focus
Focus
Device Security

Trend Micro Vision One Attribute Reference

Table of Contents

Trend Micro Vision One Attribute Reference

This reference lists the attributes that Device Security collects from Trend Micro Vision One, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Trend Micro Vision One, it imports endpoint and agent attributes from the Trend Micro Vision One XDR platform to enrich the device inventory. The attributes in this reference cover endpoint identifiers, agent and component status, policy configuration, and protection state.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Device Attributes

Device Security collects device attributes from Trend Micro Vision One. The following table lists each Trend Micro Vision One attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Trend Micro Vision One Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
"Trend Micro"
Endpoint Protection Vendor
"trend micro"
endpointName.value
trend_micro_vision_one.endpointName
hostname
Value
primaryMacAddress
id; MAC Address
Primary MAC address
primaryIpAddress
IP Address
Primary IP address
os.kernelVersion
trend_micro_vision_one.os.kernelVersion
OS Kernel Version
Kernel version
osName
trend_micro_vision_one.osName
OS Name
Os name
osVersion
trend_micro_vision_one.osVersion
OS Version
OS version
serialNumber
trend_micro_vision_one.serialNumber
Serial Number
Serial number
agentGuid
trend_micro_vision_one.agentGuid
Agent guid
agentUpdatePolicy
trend_micro_vision_one.agentUpdatePolicy
Agent update policy
agentUpdateStatus
trend_micro_vision_one.agentUpdateStatus
Agent update status
componentUpdatePolicy
trend_micro_vision_one.componentUpdatePolicy
Component update policy
componentUpdateStatus
trend_micro_vision_one.componentUpdateStatus
Component update status
componentVersion
trend_micro_vision_one.componentVersion
Component version
cpuArchitecture
trend_micro_vision_one.cpuArchitecture
CPU architecture
edrSensor.advancedRiskTelemetryStatus
trend_micro_vision_one.edrSensor.advancedRiskTelemetryStatus
Advanced risk telemetry status
edrSensor.componentUpdatePolicy
trend_micro_vision_one.edrSensor.componentUpdatePolicy
Component update policy
edrSensor.componentUpdateStatus
trend_micro_vision_one.edrSensor.componentUpdateStatus
Component update status
edrSensor.connectivity
trend_micro_vision_one.edrSensor.connectivity
Connectivity
edrSensor.endpointGroup
trend_micro_vision_one.edrSensor.endpointGroup
Endpoint group
edrSensor.kernelSupportPackageVersion
trend_micro_vision_one.edrSensor.kernelSupportPackageVersion
Kernel support package version
edrSensor.lastConnectedDateTime
trend_micro_vision_one.edrSensor.lastConnectedDateTime
Last connected date time
edrSensor.productNames
trend_micro_vision_one.edrSensor.productNames
Product names
edrSensor.status
trend_micro_vision_one.edrSensor.status
Status of the device
edrSensor.version
trend_micro_vision_one.edrSensor.version
Version
eppAgent.componentUpdatePolicy
trend_micro_vision_one.eppAgent.componentUpdatePolicy
Component update policy
eppAgent.componentUpdateStatus
trend_micro_vision_one.eppAgent.componentUpdateStatus
Component update status
eppAgent.componentVersion
trend_micro_vision_one.eppAgent.componentVersion
Component version
eppAgent.domainHierarchy
trend_micro_vision_one.eppAgent.domainHierarchy
Domain hierarchy
eppAgent.endpointGroup
trend_micro_vision_one.eppAgent.endpointGroup
Endpoint group
eppAgent.kernelSupportPackageVersion
trend_micro_vision_one.eppAgent.kernelSupportPackageVersion
Kernel support package version
eppAgent.lastConnectedDateTime
trend_micro_vision_one.eppAgent.lastConnectedDateTime
Last connected date time
eppAgent.lastScannedDateTime
trend_micro_vision_one.eppAgent.lastScannedDateTime
Last scanned date time
eppAgent.policyName
trend_micro_vision_one.eppAgent.policyName
Policy name
eppAgent.protectionManager
trend_micro_vision_one.eppAgent.protectionManager
Protection manager
eppAgent.status
trend_micro_vision_one.eppAgent.status
Status of the device
eppAgent.version
trend_micro_vision_one.eppAgent.version
Version
installedProductCodes
trend_micro_vision_one.installedProductCodes
Installed product codes
isolationStatus
trend_micro_vision_one.isolationStatus
Isolation status
loginAccount.value
trend_micro_vision_one.loginAccount
Value
os.architecture
trend_micro_vision_one.os.architecture
Architecture
os.platform
trend_micro_vision_one.os.platform
Platform
osDescription
trend_micro_vision_one.osDescription
OS description
policyName
trend_micro_vision_one.policyName
Policy name
productCode
trend_micro_vision_one.productCode
Product code
protectionManager
trend_micro_vision_one.protectionManager
Protection manager
securityPolicy
trend_micro_vision_one.securityPolicy
Security policy
securityPolicyOverriddenStatus
trend_micro_vision_one.securityPolicyOverriddenStatus
Security policy overridden status
serviceGatewayOrProxy
trend_micro_vision_one.serviceGatewayOrProxy
Service gateway or proxy
type
trend_micro_vision_one.type
Type
versionControlPolicy
trend_micro_vision_one.versionControlPolicy
Version control policy

Interface Attributes

Device Security collects interface attributes from Trend Micro Vision One. The following table lists each Trend Micro Vision One attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Trend Micro Vision One Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
primaryIpAddress
IP Address
Primary IP address
primaryMacAddress
MAC Address; id
Primary MAC address
interfaces
third_party_learned_network_interfaces
Interfaces

Vulnerability Attributes

Device Security collects vulnerability attributes from Trend Micro Vision One. The following table lists each Trend Micro Vision One attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Trend Micro Vision One Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
id
trend_micro_vision_one.id
cve
Unique identifier
cvssScore
trend_micro_vision_one.cvssScore
cvss_base_score
Cvss score
publishedDateTime
trend_micro_vision_one.publishedDateTime
detected_time
Published date time
primaryMacAddress
id
Primary MAC address
eventRiskLevel
trend_micro_vision_one.eventRiskLevel
risk_level
Event risk level
mitigationStatus
trend_micro_vision_one.mitigationStatus
state
Mitigation status
exploitAttemptCount
trend_micro_vision_one.exploitAttemptCount
Number of exploit attempts
globalExploitActivityLevel
trend_micro_vision_one.globalExploitActivityLevel
Global exploit activity level
* Only some attributes map to a Device Security Common Attribute.