TrendAI Email Security alert: Phishing email detected

This rule is part of a beta feature. To learn more, contact Support.
Esta página aún no está disponible en español. Estamos trabajando en su traducción.
Si tienes alguna pregunta o comentario sobre nuestro actual proyecto de traducción, no dudes en ponerte en contacto con nosotros.

Goal

Detect when TrendAI Email Security identifies a threat-related email.

Strategy

Monitor TrendAI Email Security logs for specific threat detection events. This rule aims to identify and respond to potential email threats promptly, ensuring the security of the email infrastructure and recipients.

Triage and Response

  1. Threat event of {{@eventType}} type detected.
  2. Review the email’s headers, body, and attachments for any indicators of malicious activity.
  3. If malicious activity is confirmed, block the sender’s email address and quarantine the affected email(s) to prevent further access and distribution of harmful content.

Changelog

  • 8 July 2026 - Rebranded Trend Micro to TrendAI and broadened the query to also match the @vendor.endpoint attribute.