Execute a PowerShell or Bash script on a target endpoint during an investigation.
Remote custom scripts allows Master Administrator and Security Analyst roles to
                  directly access target endpoints to run a previously uploaded PowerShell and Bash
                  script files.
The following services this task:
- 
Trend Vision One- 
Linux agent
- 
macOS agent
- 
Windows agent
 
- 
- 
Trend Cloud One - Endpoint & Workload Security- 
Linux agent
- 
macOS agent
- 
Windows agent
 
- 
|  | ImportantThe following recommendations apply only to PowerShell scripts executed on
                                 Windows endpoints: 
 To learn more about the above settings, please consult the Microsoft PowerShell official documentation. | 
Procedure
- After identifying the endpoint to investigate, select Run Remote Custom Script from  the context or response menu. You can execute only one custom script file per
                        session. The target endpoint must be online to connect successfully.The Run Remote Custom Script Task screen appears and Trend Vision One attempts to connect to the endpoint.
- Select a custom script file.To add a new custom script, go to Custom Scripts on the Response Scripts tab of Response Management. Click Add script to upload a new script file.
- Specify the arguments to added to the script during script execution. You can specify a maximum of 8,000 characters.
- Specify a Description for the response or event.
- Click Create.Trend Vision One creates the task and displays the current task status in Response Management.
- Monitor the task status.- Go to .
- Locate the task.
 - 
Use the Search to find the task.
- 
Select .
 - View the task status.- 
In progress ( ): Trend Vision One sent the command
                                       and is waiting for a response. ): Trend Vision One sent the command
                                       and is waiting for a response.
- 
Successful ( ): The command was successfully
                                       executed. ): The command was successfully
                                       executed.
- 
Unsuccessful ( ): An error or time-out occurred when attempting to send
                                       the command to the managing server, the Security Agent is offline for more than 12
                                       hours, or the command execution timed out. ): An error or time-out occurred when attempting to send
                                       the command to the managing server, the Security Agent is offline for more than 12
                                       hours, or the command execution timed out.
 
- 
- Click the Task ID to display Details and Download the session history. Use an external decompression program (for example, 7-zip) to extract the file contents.
 
 
		