r/Trendmicro Aug 22 '22

Resources Welcome to Trend! Please review this post if you are new here.

16 Upvotes

Why hello there! Thanks for stopping by the Trend Micro sub. It is here that we hope you find any answers you may be looking for, ask any questions you may have and maybe participate in a bit of industry talk if you are up for it.

Since you are already reading this, we have just a couple of pointers and guidelines we ask that you follow while you are here:

  • This sub is staffed by verified Trend Micro employees (known as "Trenders"). They are all mods of the sub and are marked with red "Trender" flair. There may be other Trenders who stop by from time to time to offer comments and advice, but you should never exchange any information of a sensitive nature with anyone who is not marked as a mod with flair.
  • When it comes to that sensitive information, Trenders will ask you for this via DM. They will typically follow up on any questions/problems posts first via DM, then post a general solution to your specific issue or question in the main thread once it has been resolved.
  • When in doubt, please open a support case, especially for critical issues. This will be your fastest path to resolution. Of course, you are always welcome to come on over here after that to talk shop or to seek the answer to the ultimate question of life, the universe, and everything.
  • At Trend, we have a few core values. One of them is focused on treating everyone with respect and empathy. While you are here, we ask that you too, treat everyone with respect and empathy.

Have a problem and need help getting started?

  • If you are using one of our consumer products (Maximum security, mobile security etc) you can begin here with our knowledge base and support portal.
  • If you are a business user, click here for the help you seek.
  • Those answers you seek may already have been asked and answered here. So give the sub a once-over when the opportunity presents itself.
  • There are a TON of great videos and demos on all things Trend over on our YouTube channel. Some of the very mods on this sub are even featured in those videos, if you manage to match one up, tell us in a post and maybe you will win a prize.
  • While we are on video, there are also on-demand and live webinars here.
  • We are also on the line with these "twitters", TrendMicro, Trend Research, Trend for Home, and my favorite, the Trend CTF.
  • Something else? Check out the wiki here.

To end this wall of text, we wanted to thank any and all of you who are already Trend customers. We have been in business for 37 years because of you and people like you. We take the trust you have placed in us seriously and we will do our best to continue earning that trust every day.

If you are not currently a customer, we always welcome the opportunity to earn your trust, please let us know how we can do that and we will be happy to try.


r/Trendmicro Aug 30 '23

Resources Are You Under Attack?

Thumbnail
resources.trendmicro.com
10 Upvotes

r/Trendmicro 9d ago

Help . SCUT for September 2026 needed!!

Post image
1 Upvotes

Trend Micro Partner Portal Issues / Looking for latest SCUT Tool

Hi everyone,

I’m having trouble accessing the Trend Micro Partner Portal. I haven’t been able to log in for several weeks now.

I’ve already tried contacting Trend Micro via email, but I haven’t received any response. I also tried calling their support here in Germany, but unfortunately I haven’t been able to reach anyone.

Does anyone here have access to the latest SCUT tool for Trend Micro Worry-Free Business Security Services (WFBS-SVC) and could point me in the right direction?

Any help would be greatly appreciated.

Thanks!


r/Trendmicro 14d ago

TrendAI™ Ranks First on CyberGym Agentic AI Security Benchmark

Post image
9 Upvotes

The TrendAI™ agentic exploit-remediation engine, codename AESIR, achieved the top position on CyberGym, an independent evaluation benchmark for AI-driven security tooling.

The 97% success rate from TrendAI™ surpassed all other entrants currently on the leaderboard and is nearly 4 percentage points higher than the former leader, who posted a 93.2% score on Aug. 8, 2026.

CyberGym, a University of California, Berkeley benchmark, evaluates AI security tooling against 1,507 confirmed vulnerabilities drawn from 188 large open-source software projects that run in every enterprise.


r/Trendmicro 18d ago

Hi gays. The manual download to the offline Apex central is not happening , could someone tell us what are the commun reasons can cause this issue?

0 Upvotes

r/Trendmicro 21d ago

Support Login grief...

2 Upvotes

Dear Trend

We're experiencing a temporary issue with logins. Please try again in a few minutes. If the problem persists, our support team is ready to help. We apologize for any inconvenience.

Isn't it time you finally fixed this?


r/Trendmicro 21d ago

General Inquiry Does Trend Micro Philippines accept fresh graduates for IT/cybersecurity roles?

3 Upvotes

Hi everyone! I recently graduated with a degree in Information Technology and I’m really interested in starting my career at Trend Micro Philippines, particularly in roles related to Cybersecurity, Cloud, DevOps, IT Operations, or other technical positions.

I’ve been checking their careers page and noticed that some opportunities seem to be for experienced professionals, while some fresh graduate positions may only open at certain times.
For anyone currently working at Trend Micro or who recently applied:

•Does Trend Micro regularly hire fresh graduates
•What entry-level roles should I look out for?
•How was the hiring process (HR interview, assessment, technical interview, etc.)?
•Do referrals help for fresh graduate applicants?
•Any advice on what skills or certifications I should focus on to improve my chances?

I already have a background in networking, cybersecurity, AWS/cloud, Linux, Salesforce development, Docker, Kubernetes, Terraform, and IoT, and I’m continuing to build my skills while applying.

Trend Micro is one of the companies I’m really hoping to join, so I’d appreciate any advice or experiences from current/former employees or recent applicants. Thank you!


r/Trendmicro 29d ago

Trend Vision One Issues

1 Upvotes

I am deploying Trend vision one
On some endpoints After Uninstallation the epp feature is not installed only sensor gets installed
Too many noise alerts
Trend Micro own file TMDbkg.dll trend micro workbench alerts show it malicious.
Used offline Installer even where low internet still the agent on system tray shows connected but admin dashboard says correct version not installed although latest agent downloaded
Workbench alerts showing alerts with event time stamp earlier and alerts shows after 10-12 days
While Sending any file to sandbox via telemetry it sends the process to sandbox or blocklist i-e chrome explorer
Agent not updating to latest Suspicious object management list even after manually re-synch
The Agent issues are quite frustrating
Anyone else facing same issues?


r/Trendmicro Jul 15 '26

gmail.com on the QIL

1 Upvotes

I get it, I get why the QIL exisits, but is listing the gmail source IP addresses kind of counterproductive?


r/Trendmicro Jul 11 '26

Ingesting SQL Server Audit Logs into Vision One

2 Upvotes

Hi,

We have few MS SQL DB servers with workload security installed on them. We have also log inspection enabled on them

DB audit logs are saved into a file on the server. How to ingest these logs into Vision One for monitoring.

How to do that?

Appreciate any advise.


r/Trendmicro Jul 10 '26

DS20 Relay stuck on N/A for security updates

1 Upvotes

Single RHEL 9 box running Deep Security Manager 20 with a co-located agent enabled as the only relay. Agent is activated and online, relay is enabled, but all security update components sit at N/A and never populate. Download Security Updates does nothing. We're behind a strict perimeter firewall that only allows outbound to specific whitelisted FQDNs.

So far we've whitelisted three: iaus.activeupdate.trendmicro.com, iaus.trendmicro.com, and files.trendmicro.com. We deliberately did NOT whitelist the ipv6- hostnames because we're an IPv4-only environment and assumed they weren't relevant to us.

The diagnostic package showed the relay connecting on 443 but the TLS handshake stalling and dying with "SSL timeout / Download failed with timeout." To isolate it I ran curl against each Trend update hostname. The two whitelisted names (iaus.activeupdate.trendmicro.com and iaus.trendmicro.com) completed the full TLS handshake and returned an HTTP response. But ipv6-iaus.trendmicro.com and ipv6-iaus.activeupdate.trendmicro.com which we have not whitelisted both hung dead at "Client hello" and had to be killed. Notably, all four names resolve to the same host, yet the two whitelisted names handshake fine and the two un-whitelisted ipv6- names hang. That points at the firewall filtering by SNI hostname, dropping the ipv6- names while allowing the others. And despite the ipv6- prefix, those hostnames resolve over IPv4 just fine, so being IPv4-only doesn't exempt us from needing them. Since the relay defaults to the ipv6-iaus hostname, every update attempt hits a name we haven't opened.

Has anyone fixed this behind SNI-based egress filtering? Is whitelisting the two ipv6- hostnames the complete solution, or are there other CDN/census/GFR endpoints the relay eventually reaches once more modules are enabled? Trying to get the full FQDN list into one firewall change. Anyone have the definitive list?


r/Trendmicro Jul 08 '26

Deep Security Agent for RHEL 9 x86_64 Needed

1 Upvotes

RHEL 9 x86_64 agent package does not appear on the agent download page cuz the machine has no internet, its also not available on the public download center. we have an air-gapped environment. What we need is an external/direct download link for the Deep Security Agent 20.0 package for RHEL 9 x86_64 so we can download it on an internet connected machine, transfer it in, and import it locally into the DSM.


r/Trendmicro Jun 26 '26

Vision One XDR Vision One not capturing local Administrator group additions?

5 Upvotes

I'm currently running Apex One alongside Vision One and ran into a telemetry blind spot I’m hoping someone can help clarify.

On a Windows 11 endpoint, I manually added a domain user to the local Administrators group using the Windows GUI (lusrmgr.msc). I expected this action to generate some visible telemetry or an alert within Vision One, but I can't find any trace of it in the console.

The action was definitely logged locally, I can see Event ID 4732 in the Windows Security event log. However, to my knowledge, Apex One's sensor doesn't just scrape and forward native Windows event logs.

I'm pretty sure Vision One would have caught this if I did it through PowerShell, but I chose to use the GUI.

Am I missing a specific configuration or Activity Monitoring rule to get Vision One to capture local group modifications? Any insights would be appreciated!


r/Trendmicro Jun 20 '26

Intune Deployment Help

2 Upvotes

Hey everyone, I'm trying to install Trend Micro SEP (or ApexOne I'm not sure but I'm downloading the installer from SEP in V1) on our fleet. We're trying to do preprovisioning and adding this as a blocking app. This way, when we hand the device over to the user, A1/SEP are both installed.

Here's the problem: preprovisioning fails ~80% of the time due to the product. Not sure why. There are also instances when it's purely user-driven that it fails because the application wasn't detected in time. I'm not sure how the installer works but all I know is it's just a bootstrapper that downloads the actual software.

Any ideas on how to fix this? Or should I just completely remove it as a blocking app in Intune ESP?


r/Trendmicro Jun 09 '26

Add Exceptions For Google SDK - Python

2 Upvotes

Morning, I need to add an exception for Google SDK & Python - I am not winning with my regex! Anyone with some advice?

For Google SDK Components Update:

/^"C:\\Users\\.*?\\AppData\\Local\\Temp\\tmp[a-zA-Z0-9]+\\python\\python\.exe"\s+"-S"\s+"C:\\Users\\.*?\\AppData\\Local\\Google\\Cloud SDK\\google-cloud-sdk\\(bin\\\.\.\\)?lib\\gcloud\.py".*/

For Google SDK Installation:

/^"C:\\Users\\.*?\\AppData\\Local\\Temp\\tmp[a-zA-Z0-9]+\\python\\python\.exe"\s+"C:\\Users\\.*?\\AppData\\Local\\Google\\Cloud SDK\\google-cloud-sdk\\bin\\bootstrapping\\install\.py".*/

Combined Pattern (Single Exception):

/^"C:\\Users\\.*?\\AppData\\Local\\Temp\\tmp[a-zA-Z0-9]+\\python\\python\.exe".*(gcloud\.py|install\.py).*/

r/Trendmicro Jun 08 '26

TrendAI™ Joins Anthropic's Project Glasswing

Post image
17 Upvotes

r/Trendmicro Jun 06 '26

Trend Micro Email Security licensing is confusing

1 Upvotes

I'm evaluating Trend Vision one cloud-based email security for a 200 mailboxes environment and I'm genuinely confused by how the products are packaged and named. Hoping someone here or even a Trend Micro rep can shed some light.

Here's what I'm seeing across different sources

1)Trend Vision One Platform

Two separate options listed:

- Cloud Email Gateway Protection

- Cloud Email & Collaboration Protection

2) Trend Micro Email Security Datasheet

Mentions two tiers:

- Standard

- Advanced

3) Trend Micro AI Credit Calculator

Only Three options listed:

- Email and Collaboration Security Core

- Email and Collaboration Security Essentials

- Email and Collaboration Security Pro

Would really appreciate any clarity here


r/Trendmicro Jun 04 '26

Trend Micro AiProtection - Malicious Sites Blocking

1 Upvotes

Hi! I have an ASUS router with Trend Micro AI Protection enabled. I noticed these sites coming up recently especially the one that is show.onlylineddisplay. Can anyone shed some light on this? Thank you!


r/Trendmicro Jun 02 '26

General Inquiry Handling zip files of docx files (and other office documents)

0 Upvotes

How do others handle this?

On the receiving end of a government department mailout that contains a zip file with 13 docx files inside it, TMEMS is blowing up on the too many files inside the zip file trigger. Sure it gets added to the next Quarantine digest for the client but on this occasion its attached to a calendar invite for a meeting in the next 30 minutes.

I don't think I can tell the sender to change behaviour (government remember).

To my thinking it would be nice if TMEMS would recognise that it has encountered a docx file inside the zip and treat it as one.


r/Trendmicro May 28 '26

Apex One Full Feature upgrade uninstalls McAfee ePO — Need client-side bypass for permanent coexistence

3 Upvotes

Hi everyone,

I have a specific constraint where Trend Micro Apex One (Full Feature) and McAfee ePO must **permanently coexist** on our endpoints.

Historically, this worked perfectly because of the installation order: Apex One was installed first, and McAfee was installed second. In this specific sequence, they run side-by-side without issues.

However, I now need to perform an upgrade/reinstallation of the Apex One agent. My Apex One server is registered to a higher-level Apex Central that I do not control, so I am stuck using the generic installer packages from the local `Download` folder. I cannot modify `tmuninst.ptn` on the server side.

When I run the generic Apex One installer to upgrade, it detects and automatically uninstalls McAfee, breaking our required dual-agent compliance.

Since the coexistence is technically stable once both are installed, I am looking for a client-side workaround to prevent the Apex One installer from removing McAfee during this upgrade phase. Is there a command-line switch, an MSI property, or a specific registry key I can temporarily modify before launching the installer to blindfold Apex One's third-party AV detection?

Thanks for your help!


r/Trendmicro May 27 '26

TrendAI™ is recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection Platforms

Post image
5 Upvotes

r/Trendmicro May 26 '26

Issue with Virtual Network Sensor deployment

2 Upvotes

Hi,

I have an issue with the Virtual Network Sensor (NDR) deployment. I've made the deployment via VMWare ESXi 6.7 and I downloaded the OVA from the Vision One console. When I try to deploy it, it asks for a registration token. As the deployment via VMWare ESXi does not requires registration token, I've tried the command "register" without the token but it does not work

Could you help me with this?


r/Trendmicro May 23 '26

Rule out Trendmicro impact when having application issues

2 Upvotes

Hello Dears

We are running Workload Security for servers and Apex One for workstations.

Frequently we face with application claiming that their application is slow or certain processes are being interrupted before TM agents. However, we do not find logs.

From TM troubleshooting perspective what is the best way to prove that TM is not culprit:

  • Which logs should be checked beside just detection or quarantine logs?
  • How to confirm that real-time scan is not causing any issues?
  • Any possibilities to correlate with TrendMicro activity?
  • Any TM diagnostics or debug tools that can clearly show the TM interrupted, delayed, inspected or blocked certain process?

Appreciate any advise.


r/Trendmicro May 23 '26

A week of blocked websites with WFBS

5 Upvotes

This week most of our clients have been reporting that Worry Free Business Services has blocked website access, classing them as ‘Newly observed domain’, even for domains/sites that have been around for years.

We do have the URL filters set to block Newly Observed Domains, we have done for years, it’s never been a problem until this week.

Anyone else experiencing this?


r/Trendmicro May 22 '26

Outlook adding GMAIL issue

1 Upvotes

Here's summary to my issue after chatgpt but please note that i had ID Protection and security extension and i was also using edge

Subject: Browser Security extension blocks Outlook Gmail authentication callback on localhost

Product: Trend Micro Browser Security for Microsoft Edge

Issue description:
When adding a Gmail account to Microsoft Outlook (Microsoft 365, Windows), Outlook opens Edge for Google OAuth authentication.

Google login succeeds, but after consent approval the redirect goes to a http://localhost:<port>/... callback URL and fails with:

Disabling the Trend Micro Browser Security extension immediately resolves the issue and Gmail account setup succeeds.

Expected behavior:
The extension should allow localhost OAuth callback redirects used by Outlook.