Trend Vision One: "Observed Attack Techniques" missing in API logs ingestion method

Good day Team,

I trust this message meets you well.

With the built-in Trend Vision One Event source plugin on InsightIDR, many true-positive alerts from the "Observed Attack Techniques" portion of Trend Vision One don't get ingested to the SIEM. The built-in Rapid7 API Ingestion method only ingests "Workbench Insights" or "Workbench Alerts" and leaves out "Observed Attack Techniques". Due to this gap in missed alerts we've resulted to relying on the Custom Logs ingestion method despite Trend Vision One Plugin already being supported by InsightIDR.

Please kindly help fix this by adjusting the API ingestion method to also ingest alerts from the "Observed attack techniques" section of Trend Vision One asides only the Workbench. These alerts also triggering built-in detection rules would be super great and much appreciated as it enhances security detection coverage.

https://automation.trendmicro.com/xdr/api-fedramp/#tag/Observed-Attack-Techniques

Looking forward to your feedback and many thanks in anticipation.

We have the same issue here.

Our account manager Iraised this as a formal product feature request with the InsightIDR team: IDEA-28743 — "Trend Vision One Event Source: Extend API ingestion to include Observed Attack Techniques (OATs)". This request covers:

  • Extending the connector to pull OAT data via the Trend Micro API alongside Workbench Alerts.
  • Mapping OAT data into the Third Party Alerts log set for built-in detection rules to utilize.
  • Improving out-of-the-box detection coverage for customers using the native connector.