
Trend Vision One - Add IOC to Suspicious Object List
This atomic belongs to the Trend Vision One atomic group.
Adds an IOC to the "Suspicious Object List" in Trend Vision One. Supported observables include: URL, domain, SHA-1 file has, SHA-256 file hash, sender email address, and IP address. This atomic requires the following API scopes: Response Management, Suspicious Object Management.
Target: Trend Vision One - v3.0 integration target or an HTTP endpoint for "api.xdr.trendmicro.com" with a path of "/v3.0/"
Account Key: None if using an integration-provided target, bearer token if using an HTTP Endpoint
Steps:
[] Check the required input
[] Build the request payload
[] Build the authorization header
[] Request the IOC be added to the object list
[] Check if the request was successful:
[]> If it was, parse the status and set the output variables
[]> If it wasn't, output an error
More information about this API: https://automation.trendmicro.com/xdr/api-v3#tag/Suspicious-Objects/paths/~1v3.0~1response~1suspiciousObjects/post