Trend Micro Vision One Attribute Reference
This reference lists the attributes that Device Security collects from Trend Micro Vision One,
their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Trend Micro Vision One, it
imports endpoint and agent attributes from the Trend Micro Vision One XDR platform
to enrich the device inventory. The attributes in this reference cover endpoint
identifiers, agent and component status, policy configuration, and protection state.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Trendmicrovisionone Device Details Attributes
Device Security collects trendmicrovisionone device details attributes from Trend Micro Vision One. The following table lists each Trend Micro Vision One attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Trend Micro Vision One Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
"Trend Micro" | — | Endpoint Protection Vendor | "Trend Micro" |
endpointName.value | trend_micro_vision_one.endpointName | hostname | Value |
primaryMacAddress | — | id; MAC | PrimaryMacAddress |
primaryIpAddress | — | IP Address | PrimaryIpAddress |
os.kernelVersion | trend_micro_vision_one.os.kernelVersion | OS Kernel Version | KernelVersion |
osName | trend_micro_vision_one.osName | OS Name | OsName |
osVersion | trend_micro_vision_one.osVersion | OS Version | OsVersion |
serialNumber | trend_micro_vision_one.serialNumber | Serial Number | SerialNumber |
agentGuid | trend_micro_vision_one.agentGuid | — | AgentGuid |
agentUpdatePolicy | trend_micro_vision_one.agentUpdatePolicy | — | AgentUpdatePolicy |
agentUpdateStatus | trend_micro_vision_one.agentUpdateStatus | — | AgentUpdateStatus |
componentUpdatePolicy | trend_micro_vision_one.componentUpdatePolicy | — | ComponentUpdatePolicy |
componentUpdateStatus | trend_micro_vision_one.componentUpdateStatus | — | ComponentUpdateStatus |
componentVersion | trend_micro_vision_one.componentVersion | — | ComponentVersion |
cpuArchitecture | trend_micro_vision_one.cpuArchitecture | — | CpuArchitecture |
edrSensor.advancedRiskTelemetryStatus | trend_micro_vision_one.edrSensor.advancedRiskTelemetryStatus | — | AdvancedRiskTelemetryStatus |
edrSensor.componentUpdatePolicy | trend_micro_vision_one.edrSensor.componentUpdatePolicy | — | ComponentUpdatePolicy |
edrSensor.componentUpdateStatus | trend_micro_vision_one.edrSensor.componentUpdateStatus | — | ComponentUpdateStatus |
edrSensor.connectivity | trend_micro_vision_one.edrSensor.connectivity | — | Connectivity |
edrSensor.endpointGroup | trend_micro_vision_one.edrSensor.endpointGroup | — | EndpointGroup |
edrSensor.kernelSupportPackageVersion | trend_micro_vision_one.edrSensor.kernelSupportPackageVersion | — | KernelSupportPackageVersion |
edrSensor.lastConnectedDateTime | trend_micro_vision_one.edrSensor.lastConnectedDateTime | — | LastConnectedDateTime |
edrSensor.productNames | trend_micro_vision_one.edrSensor.productNames | — | ProductNames |
edrSensor.status | trend_micro_vision_one.edrSensor.status | — | Status of the device |
edrSensor.version | trend_micro_vision_one.edrSensor.version | — | Version |
eppAgent.componentUpdatePolicy | trend_micro_vision_one.eppAgent.componentUpdatePolicy | — | ComponentUpdatePolicy |
eppAgent.componentUpdateStatus | trend_micro_vision_one.eppAgent.componentUpdateStatus | — | ComponentUpdateStatus |
eppAgent.componentVersion | trend_micro_vision_one.eppAgent.componentVersion | — | ComponentVersion |
eppAgent.domainHierarchy | trend_micro_vision_one.eppAgent.domainHierarchy | — | DomainHierarchy |
eppAgent.endpointGroup | trend_micro_vision_one.eppAgent.endpointGroup | — | EndpointGroup |
eppAgent.kernelSupportPackageVersion | trend_micro_vision_one.eppAgent.kernelSupportPackageVersion | — | KernelSupportPackageVersion |
eppAgent.lastConnectedDateTime | trend_micro_vision_one.eppAgent.lastConnectedDateTime | — | LastConnectedDateTime |
eppAgent.lastScannedDateTime | trend_micro_vision_one.eppAgent.lastScannedDateTime | — | LastScannedDateTime |
eppAgent.policyName | trend_micro_vision_one.eppAgent.policyName | — | PolicyName |
eppAgent.protectionManager | trend_micro_vision_one.eppAgent.protectionManager | — | ProtectionManager |
eppAgent.status | trend_micro_vision_one.eppAgent.status | — | Status of the device |
eppAgent.version | trend_micro_vision_one.eppAgent.version | — | Version |
installedProductCodes | trend_micro_vision_one.installedProductCodes | — | InstalledProductCodes |
isolationStatus | trend_micro_vision_one.isolationStatus | — | IsolationStatus |
loginAccount.value | trend_micro_vision_one.loginAccount | — | Value |
loginAccount.updatedDateTime | trend_micro_vision_one.loginAccount.updatedDateTime | — | UpdatedDateTime |
loginAccount.value | trend_micro_vision_one.loginAccount.value | — | Value |
os.architecture | trend_micro_vision_one.os.architecture | — | Architecture |
os.platform | trend_micro_vision_one.os.platform | — | Platform |
osDescription | trend_micro_vision_one.osDescription | — | OsDescription |
policyName | trend_micro_vision_one.policyName | — | PolicyName |
productCode | trend_micro_vision_one.productCode | — | ProductCode |
protectionManager | trend_micro_vision_one.protectionManager | — | ProtectionManager |
securityPolicy | trend_micro_vision_one.securityPolicy | — | SecurityPolicy |
securityPolicyOverriddenStatus | trend_micro_vision_one.securityPolicyOverriddenStatus | — | SecurityPolicyOverriddenStatus |
serviceGatewayOrProxy | trend_micro_vision_one.serviceGatewayOrProxy | — | ServiceGatewayOrProxy |
type | trend_micro_vision_one.type | — | Type |
versionControlPolicy | trend_micro_vision_one.versionControlPolicy | — | VersionControlPolicy |
Trendmicrovisionone Interface Details Attributes
Device Security collects trendmicrovisionone interface details attributes from Trend Micro Vision One. The following table lists each Trend Micro Vision One attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Trend Micro Vision One Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
primaryIpAddress | — | IP Address | PrimaryIpAddress |
primaryMacAddress | — | MAC; id | PrimaryMacAddress |
interfaces | — | third_party_learned_network_interfaces | Interfaces |
Trendmicrovisionone Vulnerability Details Attributes
Device Security collects trendmicrovisionone vulnerability details attributes from Trend Micro Vision One. The following table lists each Trend Micro Vision One attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Trend Micro Vision One Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
id | trend_micro_vision_one.id | cve | Id |
cvssScore | trend_micro_vision_one.cvssScore | cvss_base_score | CvssScore |
publishedDateTime | trend_micro_vision_one.publishedDateTime | detected_time | PublishedDateTime |
primaryMacAddress | — | id | PrimaryMacAddress |
eventRiskLevel | trend_micro_vision_one.eventRiskLevel | risk_level | EventRiskLevel |
mitigationStatus | trend_micro_vision_one.mitigationStatus | state | MitigationStatus |
exploitAttemptCount | trend_micro_vision_one.exploitAttemptCount | — | ExploitAttemptCount |
globalExploitActivityLevel | trend_micro_vision_one.globalExploitActivityLevel | — | GlobalExploitActivityLevel |
* Only some attributes map to a Device Security Common Attribute.