Trend Micro Vision One Endpoint Security alert: Virus or malware detected

This rule is part of a beta feature. To learn more, contact Support.
이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect events generated by Trend Micro Vision One Endpoint Security that identify a virus or malware.

Strategy

Monitor endpoint security events for virus or malware detections, analyzing the provided details to evaluate the potential impact and nature of the threat. This detection rule aims to understand the event’s context, including the affected endpoints and the specific malware or virus identified. These events could signal the presence of harmful software that might compromise the security of the endpoint, necessitating immediate action.

Triage and Response

  1. Verify the type of event detected, focusing on virus or malware name - {{@malware_name}}.
  2. Review the impacted endpoint, considering host name - {{@source_host_name}} and endpoint IP - {{@endpoint_ip}}.
  3. If the event confirms the presence of malware or a virus, quarantine or isolate the affected endpoint from the network if necessary.
  4. Continue monitoring the affected endpoint for additional suspicious activity or further threats.