Trend Vision One allows you to build custom intelligence by importing your own reports and retrieving data from third-party intelligence sources.
The following table outlines the actions available on the Custom screen.
Action
|
Description
|
||
Filter intelligence reports
|
Use the search text box and the following drop-down lists to filter custom intelligence
reports:
|
||
Add intelligence reports
|
Click Add and choose to import CSV and STIX files or retrieve data
from third-party intelligence as custom intelligence reports.
When importing CSV and STIX files, you can choose to extract suspicious object
information, select a risk level, specify actions that connected products apply upon
detection, and select an expiration option for the extracted objects.
|
||
Extract suspicious objects from intelligence reports
|
Select one or more intelligence reports and click Extract
Suspicious Objects. Finish the risk level, action, and expiration settings and
click Submit.
|
||
Delete intelligence reports
|
Select one or more intelligence reports and click Delete.
|
||
Take additional actions
|
Click the options button () at the end of the row and choose to take additional actions on the
intelligence report:
|
||
Check the indicator count and matches
|
Under Indicators for sweeping, check the number of
indicators that can be used for sweeping from the intelligence report.
Under Matched sweeps, check the number of tasks
that have indicator matches and the total number of sweeping tasks that have been
created.
For example, the message 1 out of 7 means one sweeping task has
indicator matches among a total of seven sweeping tasks.
|
||
View sweeping task details
|
Click the right arrow () at the beginning of the row to expand sweeping tasks and check
the basic information about each task.
To further explore the tasks that have indicator matches,
do the following:
|