---
title: 'TrendAI Vision One Endpoint Security alert: Virus or malware detected'
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > TrendAI Vision One Endpoint Security
  alert: Virus or malware detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# TrendAI Vision One Endpoint Security alert: Virus or malware detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attackTactic:[TA0002-execution](https://attack.mitre.org/tactics/TA0002)Technique:[T1204-user-execution](https://attack.mitre.org/techniques/T1204) 
## Goal{% #goal %}

Detect events generated by TrendAI Vision One Endpoint Security that identify a virus or malware.

## Strategy{% #strategy %}

Monitor endpoint security events for virus or malware detections, analyzing the provided details to evaluate the potential impact and nature of the threat. This detection rule aims to understand the event's context, including the affected endpoints and the specific malware or virus identified. These events could signal the presence of harmful software that might compromise the security of the endpoint, necessitating immediate action.

## Triage and Response{% #triage-and-response %}

1. Verify the type of event detected, focusing on virus or malware name - `{{@malware_name}}`.
1. Review the impacted endpoint, considering host name - `{{@source_host_name}}` and endpoint IP - `{{@endpoint_ip}}`.
1. If the event confirms the presence of malware or a virus, quarantine or isolate the affected endpoint from the network if necessary.
1. Continue monitoring the affected endpoint for additional suspicious activity or further threats.

## Changelog{% #changelog %}

- 8 July 2026 - Rebranded Trend Micro to TrendAI and broadened the query to also match the `vendor_endpoint` tag.
