Views:

View information about the Public cloud app activity risk factor, which is determined by user and endpoint access to suspicious public cloud applications.

Operations Dashboard assesses user accounts and endpoints for any public cloud app activity to detect potentially risky public cloud apps. If the assessment of public cloud app access indicates a risk, the public cloud app access information displays in the Top 5 High Risk Public Cloud Apps with the Most Visits and the High Risk Public Cloud App Visits widgets. The Cloud App Activity risk factor contributes to your exposure level.
When viewing risk events, click the number in the case column to view current cases involving the specified risk event. Click the options icon (options=ddb0b67f-0654-4aa5-8bc7-48ec554c5448.png) to open a new case for the risk event or add the case to an existing risk event.
Note
Note
For customers that have updated to the Foundation Services release, information on the Public cloud app activity risk factor is only available for users with the Applications asset visibility scope.
The following table describes the risk indicators associated with the Public cloud app activity risk factor.
Indicator
Description
Data sources
Target
Reputation
Calculated by Trend Micro threat experts based on historical app data, known security features, and community knowledge
  • Endpoint Sensor
  • Trend Micro Apex One as a Service
  • Trend Micro Deep Security
  • Trend Micro Web Security
  • Trend Micro Mobile Security
  • Microsoft Entra ID
  • Okta
  • Splunk - Network Firewall / Web Gateway Logs
  • Public cloud app