Configure for Arctic Wolf Active Response

You can configure to allow Arctic Wolf® to perform email-based response actions, such as deleting or quarantining malicious emails, in your organization's environment.

supports these response actions:

  • Delete a malicious email
  • Quarantine an email/Remove from quarantine
For more information, see Response action descriptions.

These resources are required:

  • An admin user account
  • A Trend Vision One license with XDR for Email

Create a user role for Active Response

  1. Sign in to the Trend Vision One console.
  2. Click Administration > User Roles.
  3. Click + Add Role.
  4. In the General Information tab, in the Role name field, enter a descriptive name for the role.
  5. Under Control flags, configure these settings:
    1. Select Yes for Can be assigned to API keys.
    2. Select No for Can be assigned to user accounts.
  6. Click the Permissions tab, and then under Platform Capabilities > Workflow and Automation > Response Management, select these permissions:
    • View, filter, and search (Task List tab)
    • Delete messages
    • Quarantine/Restore messages
  7. Click Save.

Generate an API key

  1. Sign in to the Trend Vision One console.
  2. Click Administration > API Keys.
  3. Click Add API Key.
  4. In the Add API Key window, configure these settings:
    • Name — Enter a unique and descriptive name for the API key.
    • Role — Select the role created in Create a user role.
    • Expiration Time — Select an expiration date that meets your security governance requirements.
    • Status — Enabled.
  5. Click Add.
  6. Copy the API key, and then save it in a safe, encrypted location. You will provide this value to Arctic Wolf later.

Provide Active Response credentials to Arctic Wolf

  1. Sign in to the Portail unifié Arctic Wolf.
  2. In the navigation menu, click Organization Profile > Integrations.
  3. On the Active Response tab, click New Active Response Integration +.
  4. Click Trend Vision One Email and Collaboration Security.
  5. On the New Active Response Integration page, configure these settings:
    • Integration Name — Enter a unique and descriptive name for the integration.
    • API Token — Enter the API key generated in Generate an API key.
    • API URL — Enter the appropriate Trend Vision One URL for your region.
      Tip:

      For more information about Trend Vision One regional domains, see Trend Vision One Regional Domains.

    • Action Action Timeout (Hours) — Enter the number of hours that Arctic Wolf should continue checking for a command response. We recommend 1.
  6. Click Save Integration.
  • Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.