Views:
The deployment template includes tagging when connecting your AWS account, allowing you to identify which services are associated with Trend Vision One security applications and resources. You can also add custom tags when connecting an account using the CloudFormation template. For more information, see Connect an AWS account using CloudFormation.

Feature name
AWS tag
Services deployed (number)
Core features and Cyber Risk Exposure Management
"TrendMicroProduct": "cam"
  • Cloudformation Stack (1)
  • Cloudformation Stack Nested (0~3)
  • IAM Managed Policy (3~4)
  • IAM OIDC Provider (1)
  • IAM Policy (2~4)
  • IAM role (3~5)
  • Lambda (2~4)
  • LogGroup (2~3)
  • Custom (4)
  • SSM (1)
Cloud Detection for AWS CloudTrail
"TrendMicroProduct": "ct"
Single Account:
  • Lambda (10-12)
  • EventBridge (1)
  • IAM (7)
  • SQS (1)
Control Tower:
  • Lambda (10-12)
  • EventBridge (1)
  • IAM (7)
  • SQS (1)
  • EventBridge (1) (User provided)
  • SNS (1) (User provided)
Cloud Response for AWS
n/a
  • Only uses IAM permissions
  • Creates one IAM Policy to revoke an IAM user's permissions.
Container Protection for AWS ECS
"TrendMicroProduct": "cs"
  • Cloudformation Stackset (1)
  • IAM Roles (8)
  • Lambda (4)
  • Log group (5)
  • Custom resources (4)
  • SQS (1)
  • ECS task def (1)
  • SSM parameters (1)
Agentless Vulnerability & Threat Detection
"TrendMicroProduct": "avtd"
This feature deploys a base stack to the region you select when connecting the account, as well as additional resources to each monitored region. The number of resources deployed depends of the number of regions monitored.
  • Lambda (8 in base stack, plus 24 per region)
  • S3 Buckets (2 per region)
  • IAM Roles (9 in base stack, plus 25 per region)
  • Event Rules (2 in base stack, plus 10 per region
  • SQS (5 per region)
  • Custom (5 in base stack, plus 4 per region)
  • Secrets (1 in base stack, plus 1 per region)
  • Parameter Store Parameter (1 per region)
  • Step Function (1 per region)
File Security Storage
"TrendMicroProduct": "fss"
  • CloudFormation StackSets (1)
  • CloudFormation Stack (1 per region)
  • EventBridge (1)
  • IAM Roles (13)
  • IAM Policies (4)
  • SNS Topics (1)
  • SNS Subscriptions (2)
  • Lambda Permissions (3)
  • Lambda Functions (10)
  • Lambda EventSourceMapping (4)
  • SQS Queue (4)
  • SQS Queue Policy (4)
  • CloudWatch LogGroup (6)
  • System Manager Parameter Store (3)
  • Custom (10)
Data Security Posture
"TrendMicroProduct": "dspm"
Uses IAM permissions only.
Real-Time Posture Monitoring
"TrendMicroProduct": "rtpm"
  • CloudFormation StackSets (1)
  • CloudFormation Stack (1 per region)
  • EventBridge (1)
  • IAM Role (3)
  • IAM Policy (1)
Cloud Detections for VPC Flow Logs
"TrendMicroProduct": "vpcflow"
  • Lambda Functions (6 in base stack, plus 14 per region)
  • S3 Buckets (2 per region)
  • IAM roles (6)
  • Event Rules (2 in base stack, plus 6 per region)
  • SQS (4 per region)
  • Custom (3 in base stack, plus 5 per region)
  • Secrets (1 in base stack, plus 1 per region)
  • AppConfig (1 per region)
  • CloudWatch Log Group (6 in base stack, plus 14 per region)
Cloud Detections for Amazon Security Lake
"TrendMicroProduct": "seclake"
  • CloudFormation StackSets (1)
  • CloudFormation Stack (1 per region)
  • Event Rules (2)
  • IAM roles (10)
  • Lambda Permissions (2)
  • Lambda Functions (8)
  • Lambda EventSourceMapping (3)
  • SQS Queue (2)
  • System Manager ParameterStore (3)
  • S3 Bucket (1)
  • SecurityLake Subscriber (1)
  • SecurityLake SubscriberNotification (1)
  • Custom Resource (3)