- On Trend Vision One Console, hover on to the gear icon and select Third-Party Integration. Select "Check Point Open Platform for Security".
Click the image to enlarge.
- Configure the Sharing Settings, then Add the Service Gateway to the list as its bridge.
Click the image to enlarge.
- Select the Service Gateway available on the network, then add the Check Point details:
- Check Point OPSEC Server Address
- Port Used
- OPSEC Application Name
- SIC One-time password
Click the image to enlarge.
- Click the Test Connection Button below, then Add Button afterward.
- On Trend Vision One Console, hover on to the gear icon and select Third-Party Integration. Select "Broadcom".
Click the image to enlarge.
- Configure the Share Settings based on preference, then Add the Service Gateway to the list as its bridge.
Click the image to enlarge.
- Select the Service Gateway available and configure the other details.
Click the image to enlarge.
- Successful Integration would be like this.
Click the image to enlarge.
- On Trend Vision One Console, hover on to the gear icon and select Third-Party Integration. Select Palo Alto Networks.
Click the image to enlarge.
- Configure the Share Settings based on preference, then Add the Service Gateway to the list as its bridge.
Click the image to enlarge.
- Select the Service Gateway available and configure the other details.
Click the image to enlarge.
Some products encounter integration issues with HTTPS self-signed certificates, thus HTTP is available. (Ex. Malware Information Sharing Platform or MISP). - Successful Integration would be like this.
Click the image to enlarge.
- On Trend Vision One Console, hover on to the gear icon, click Third-Party Integration, and select "Fortinet".
Click the image to enlarge.
- Configure the Share Settings based on preference, then Add the Service Gateway to the list as its bridge.
Click the image to enlarge.
- Select the Service Gateway available and configure the other details.
Click the image to enlarge.
Some products encounter integration issues with HTTPS self-signed certificates, thus HTTP is available. (Ex. Malware Information Sharing Platform or MISP). - Copy the Service Gateway IP Address, URL, and Domain and save it on a text document for later use.
Click the image to enlarge.
- In Fortigate Fabric Connector add a new threat feed (Fortiguard, IP Address or Domain Name). Trend Vision One does not support Malware Hash in plain text yet.
Click the image to enlarge.
- Fill up the Connector settings based on the copied information from the Trend Vision One Console. Click Save afterward.
Click the image to enlarge.
- Successful Integration should create three new fabric connectors.
Click the image to enlarge.
- Verify if the information is being forwarded to Fortigate after a couple of minutes.
Click the image to enlarge.
- Setup the firewall policy to block the entries from going outside.
Click the image to enlarge.
- On Trend Vision One Console, hover on to the gear icon and select Third-Party Integration. Select "MISP Project".
Click the image to enlarge.
- Configure the Share Settings based on preference, then Add the Service Gateway to the list as its bridge.
Click the image to enlarge.
- Select the Service Gateway available and configure the other details.
Click the image to enlarge.
- Copy the Service Gateway IP Address, URL, and Domain and save it on a text document for later use.
- Add a custom Trend Micro tag.
- Name the Event Trend Vision One – Suspicious Objects.
- Submit and Publish.
Click the image to enlarge.
- Once done, it should now create the Event ID.
Click the image to enlarge.
- Add a MISP Feed using the following details:
- Check: Enabled
- Name: Trend Vision One UDSO URL
- The Service Gateway publishes 3 URLs. Create 1 MISP Feed Per URL
- http://192.168.1.77/pal/pal_so_ip.txt
- http://192.168.1.77/pal/pal_so_domain.txt
- http://192.168.1.77/pal/pal_so_url.txt
- Provider: Trend Vision One
- Use the HTTP for the URLs
Click the image to enlarge.
Click the image to enlarge.
- Repeat the Process for adding IP and Domains.
- Successful feed creation should show each Service Gateway URL. Fetch the feeds after.
Click the image to enlarge.
- On Trend Vision One Console, hover on to the gear icon and select Third-Party Integration. Select "Microsoft". Look for "Trend Vision One for Azure".
Click the image to enlarge.
- Use the Endpoint Address of Trend Vision One and the generated Authentication Token for your Trend Vision One instance. Note that the Authentication Token has an expiration date (Hover on the tooltip to determine the exact expiration date):
Click the image to enlarge.