Execute a PowerShell or Bash script on a target endpoint during an investigation.
Remote custom scripts allows Master Administrator and Security Analyst roles to
directly access target endpoints to run a previously uploaded PowerShell and Bash
script files.
This task is supported by the following services:
-
Trend Vision One
-
Windows agent
-
Mac agent
-
Linux agent
-
-
Trend Cloud One - Endpoint & Workload Security
-
Windows agent
-
Mac agent
-
Linux agent
-
ImportantThe following recommendations apply only to PowerShell scripts executed on
Windows endpoints:
To learn more about the above settings, please consult the Microsoft PowerShell
official documentation site.
|
Procedure
- After identifying the endpoint to investigate, access the context or response
menu and click Run Remote Custom Script.The Run Remote Custom Script Task screen appears and Trend Vision One attempts to connect to the endpoint.
Note
Trend Vision One only permits you to execute one custom script file per session. The target endpoint must be online in order to connect successfully. - Select the previously uploaded custom script file from the drop-down
list.To add a new custom script, go to Custom Scripts on the Response Scripts tab of Response Management. Click Add script to upload a new script file.
- (Optional) Specify the arguments that are added onto the script during script
execution.
Note
You can specify a maximum of 8,000 characters. - Specify a Description for the response or event.
- Click Create.Trend Vision One creates the task and displays the current task status in Response Management.
- Monitor the task status.
- Open Response Management.
- (Optional) Locate the task using the Search field or by selecting Run Remote Custom Script from the Action drop-down list.
- View the task status.
-
In progress (): Trend Vision One sent the command and is waiting for a response.
-
Successful (): The command was successfully executed.
-
Unsuccessful (): An error or time-out occurred when attempting to send the command to the managing server, the Security Agent is offline for more than 12 hours, or the command execution timed out.
-
- Click the Task ID to open the Details panel and
Download the session history.
Note
Use an external decompression program (such as 7-zip) to extract the file contents.