
Trend Vision One - Remove IOC from Suspicious Object List
Details
This atomic belongs to the Trend Vision One atomic group.
Removes an IOC from the "Suspicious Object List" in Trend Vision One. Supported observables include: URL, domain, SHA-1 file has, SHA-256 file hash, sender email address, and IP address. This atomic requires the following API scopes: Response Management, Suspicious Object Management.
Target: Trend Vision One integration target or an HTTP endpoint for "api.xdr.trendmicro.com" with a path of "/v3.0/"
Account Key: None if using an integration-provided target, bearer token if using an HTTP Endpoint
Steps:
- Check the required input
- Build the request payload
- Build the authorization header
- Request the IOC be removed from the object list
- Check if the request was successful:
- If it was, parse the status and set the output variables
- If it wasn't, output an error
More information about this API: https://automation.trendmicro.com/xdr/api-v3/#tag/Suspicious-Object-List/paths/~1v3.0~1threatintel~1suspiciousObjects~1delete/post
About
Integration
Authorship
Cisco Managed