Details

This atomic belongs to the Trend Vision One atomic group.

Adds an IOC to the "Suspicious Object List" in Trend Vision One. Supported observables include: URL, domain, SHA-1 file has, SHA-256 file hash, sender email address, and IP address. This atomic requires the following API scopes: Response Management, Suspicious Object Management.

Target: Trend Vision One - v3.0 integration target or an HTTP endpoint for "api.xdr.trendmicro.com" with a path of "/v3.0/"

Account Key: None if using an integration-provided target, bearer token if using an HTTP Endpoint

Steps:
[] Check the required input
[] Build the request payload
[] Build the authorization header
[] Request the IOC be added to the object list
[] Check if the request was successful:
[]> If it was, parse the status and set the output variables
[]> If it wasn't, output an error

More information about this API: https://automation.trendmicro.com/xdr/api-v3#tag/Suspicious-Objects/paths/~1v3.0~1response~1suspiciousObjects/post

About
Integration
Authorship
Cisco Managed