- Each alert will begin with one of the following two subjects:
- Subject: [MDR Alert]
- Subject: [MDR Incident Alert]
- Every alert notification references a case number, which is listed at the top of the alert email.
- The body of every initial alert starts off with a template containing these common sections:
Section: Observation
- A Managed XDR observation, containing the triggering detection plus an overall investigative determination of the event, classified as an: “Incident”, “Noteworthy” and “Not Noteworthy.”
- Examples:
- Trend Micro Managed XDR observed a NOTEWORTHY Trend Vision One alert with the model name [Heuristic Attribute] Possible Event Triggered Execution and Workbench ID WB-*****.
- Trend Micro Managed Services observed a NOTEWORTHY Trend Vision One alert with the model name Potential Ransomware Encryption and Workbench ID WB-******.
From our investigation so far, we have declared this as an INCIDENT. - This alert is sent to inform you that the Trend Vision One alert with the model name [Heuristic Attribute] Possible Abuse Elevation Control Mechanism and Workbench ID WB-***** is NOT NOTEWORTHY and categorized as Benign based on Managed XDR's investigation.
A Noteworthy “Threat Hunting” alert will contain an additional “Threat Hunting” disclaimer at the top of the email.Section: Summary
Section: Event Details / Investigation Notes
Section: Action Items
All contacts listed on the Trend Vision One Managed Services Contact Information page tagged for Alert Notifications will receive the MDR alert. The first contact listed is also considered the primary contact, and as a result will be assigned as the “case owner” for all MDR Alerts.
However, all other contacts in the Trend Vision One Managed Services Contact Information list will be copied on all outbound case correspondence, receive alerts in the same way, and can respond to alerts in the same way as the primary contact.
You can respond to an MDR alert several ways:
- Via the case number in the Trend Micro Business Success Portal
- Via a reply to the original MDR email alert (keeping subject header reference intact)
- Via the case number visible in the Trend Vision One platform, under Workflow and Automation > Case Management > MDR tab