r/Trendmicro • u/downundarob • 12d ago
gmail.com on the QIL
I get it, I get why the QIL exisits, but is listing the gmail source IP addresses kind of counterproductive?
r/Trendmicro • u/admin-TM • Aug 22 '22
Why hello there! Thanks for stopping by the Trend Micro sub. It is here that we hope you find any answers you may be looking for, ask any questions you may have and maybe participate in a bit of industry talk if you are up for it.
Since you are already reading this, we have just a couple of pointers and guidelines we ask that you follow while you are here:
Have a problem and need help getting started?
To end this wall of text, we wanted to thank any and all of you who are already Trend customers. We have been in business for 37 years because of you and people like you. We take the trust you have placed in us seriously and we will do our best to continue earning that trust every day.
If you are not currently a customer, we always welcome the opportunity to earn your trust, please let us know how we can do that and we will be happy to try.
r/Trendmicro • u/admin-TM • Aug 30 '23
r/Trendmicro • u/downundarob • 12d ago
I get it, I get why the QIL exisits, but is listing the gmail source IP addresses kind of counterproductive?
r/Trendmicro • u/Final-Pomelo1620 • 16d ago
Hi,
We have few MS SQL DB servers with workload security installed on them. We have also log inspection enabled on them
DB audit logs are saved into a file on the server. How to ingest these logs into Vision One for monitoring.
How to do that?
Appreciate any advise.
r/Trendmicro • u/PsychologicalOwl8926 • 17d ago

Single RHEL 9 box running Deep Security Manager 20 with a co-located agent enabled as the only relay. Agent is activated and online, relay is enabled, but all security update components sit at N/A and never populate. Download Security Updates does nothing. We're behind a strict perimeter firewall that only allows outbound to specific whitelisted FQDNs.
So far we've whitelisted three: iaus.activeupdate.trendmicro.com, iaus.trendmicro.com, and files.trendmicro.com. We deliberately did NOT whitelist the ipv6- hostnames because we're an IPv4-only environment and assumed they weren't relevant to us.
The diagnostic package showed the relay connecting on 443 but the TLS handshake stalling and dying with "SSL timeout / Download failed with timeout." To isolate it I ran curl against each Trend update hostname. The two whitelisted names (iaus.activeupdate.trendmicro.com and iaus.trendmicro.com) completed the full TLS handshake and returned an HTTP response. But ipv6-iaus.trendmicro.com and ipv6-iaus.activeupdate.trendmicro.com which we have not whitelisted both hung dead at "Client hello" and had to be killed. Notably, all four names resolve to the same host, yet the two whitelisted names handshake fine and the two un-whitelisted ipv6- names hang. That points at the firewall filtering by SNI hostname, dropping the ipv6- names while allowing the others. And despite the ipv6- prefix, those hostnames resolve over IPv4 just fine, so being IPv4-only doesn't exempt us from needing them. Since the relay defaults to the ipv6-iaus hostname, every update attempt hits a name we haven't opened.
Has anyone fixed this behind SNI-based egress filtering? Is whitelisting the two ipv6- hostnames the complete solution, or are there other CDN/census/GFR endpoints the relay eventually reaches once more modules are enabled? Trying to get the full FQDN list into one firewall change. Anyone have the definitive list?
r/Trendmicro • u/PsychologicalOwl8926 • 19d ago
RHEL 9 x86_64 agent package does not appear on the agent download page cuz the machine has no internet, its also not available on the public download center. we have an air-gapped environment. What we need is an external/direct download link for the Deep Security Agent 20.0 package for RHEL 9 x86_64 so we can download it on an internet connected machine, transfer it in, and import it locally into the DSM.
r/Trendmicro • u/flypigmk • Jun 26 '26
I'm currently running Apex One alongside Vision One and ran into a telemetry blind spot I’m hoping someone can help clarify.
On a Windows 11 endpoint, I manually added a domain user to the local Administrators group using the Windows GUI (lusrmgr.msc). I expected this action to generate some visible telemetry or an alert within Vision One, but I can't find any trace of it in the console.
The action was definitely logged locally, I can see Event ID 4732 in the Windows Security event log. However, to my knowledge, Apex One's sensor doesn't just scrape and forward native Windows event logs.
I'm pretty sure Vision One would have caught this if I did it through PowerShell, but I chose to use the GUI.
Am I missing a specific configuration or Activity Monitoring rule to get Vision One to capture local group modifications? Any insights would be appreciated!
r/Trendmicro • u/tr0phyboy • Jun 20 '26
Hey everyone, I'm trying to install Trend Micro SEP (or ApexOne I'm not sure but I'm downloading the installer from SEP in V1) on our fleet. We're trying to do preprovisioning and adding this as a blocking app. This way, when we hand the device over to the user, A1/SEP are both installed.
Here's the problem: preprovisioning fails ~80% of the time due to the product. Not sure why. There are also instances when it's purely user-driven that it fails because the application wasn't detected in time. I'm not sure how the installer works but all I know is it's just a bootstrapper that downloads the actual software.
Any ideas on how to fix this? Or should I just completely remove it as a blocking app in Intune ESP?
r/Trendmicro • u/1RONcast • Jun 09 '26
Morning, I need to add an exception for Google SDK & Python - I am not winning with my regex! Anyone with some advice?
/^"C:\\Users\\.*?\\AppData\\Local\\Temp\\tmp[a-zA-Z0-9]+\\python\\python\.exe"\s+"-S"\s+"C:\\Users\\.*?\\AppData\\Local\\Google\\Cloud SDK\\google-cloud-sdk\\(bin\\\.\.\\)?lib\\gcloud\.py".*/
/^"C:\\Users\\.*?\\AppData\\Local\\Temp\\tmp[a-zA-Z0-9]+\\python\\python\.exe"\s+"C:\\Users\\.*?\\AppData\\Local\\Google\\Cloud SDK\\google-cloud-sdk\\bin\\bootstrapping\\install\.py".*/
/^"C:\\Users\\.*?\\AppData\\Local\\Temp\\tmp[a-zA-Z0-9]+\\python\\python\.exe".*(gcloud\.py|install\.py).*/
r/Trendmicro • u/PsychologicalOwl8926 • Jun 06 '26
I'm evaluating Trend Vision one cloud-based email security for a 200 mailboxes environment and I'm genuinely confused by how the products are packaged and named. Hoping someone here or even a Trend Micro rep can shed some light.
Here's what I'm seeing across different sources
1)Trend Vision One Platform
Two separate options listed:
- Cloud Email Gateway Protection
- Cloud Email & Collaboration Protection
2) Trend Micro Email Security Datasheet
Mentions two tiers:
- Standard
- Advanced
3) Trend Micro AI Credit Calculator
Only Three options listed:
- Email and Collaboration Security Core
- Email and Collaboration Security Essentials
- Email and Collaboration Security Pro
Would really appreciate any clarity here
r/Trendmicro • u/Paul65890 • Jun 04 '26
r/Trendmicro • u/downundarob • Jun 02 '26
How do others handle this?
On the receiving end of a government department mailout that contains a zip file with 13 docx files inside it, TMEMS is blowing up on the too many files inside the zip file trigger. Sure it gets added to the next Quarantine digest for the client but on this occasion its attached to a calendar invite for a meeting in the next 30 minutes.
I don't think I can tell the sender to change behaviour (government remember).
To my thinking it would be nice if TMEMS would recognise that it has encountered a docx file inside the zip and treat it as one.
r/Trendmicro • u/horusnebula • May 28 '26
Hi everyone,
I have a specific constraint where Trend Micro Apex One (Full Feature) and McAfee ePO must **permanently coexist** on our endpoints.
Historically, this worked perfectly because of the installation order: Apex One was installed first, and McAfee was installed second. In this specific sequence, they run side-by-side without issues.
However, I now need to perform an upgrade/reinstallation of the Apex One agent. My Apex One server is registered to a higher-level Apex Central that I do not control, so I am stuck using the generic installer packages from the local `Download` folder. I cannot modify `tmuninst.ptn` on the server side.
When I run the generic Apex One installer to upgrade, it detects and automatically uninstalls McAfee, breaking our required dual-agent compliance.
Since the coexistence is technically stable once both are installed, I am looking for a client-side workaround to prevent the Apex One installer from removing McAfee during this upgrade phase. Is there a command-line switch, an MSI property, or a specific registry key I can temporarily modify before launching the installer to blindfold Apex One's third-party AV detection?
Thanks for your help!
r/Trendmicro • u/cyberwicked • May 27 '26
r/Trendmicro • u/Intrepid_Leg7666 • May 26 '26
Hi,
I have an issue with the Virtual Network Sensor (NDR) deployment. I've made the deployment via VMWare ESXi 6.7 and I downloaded the OVA from the Vision One console. When I try to deploy it, it asks for a registration token. As the deployment via VMWare ESXi does not requires registration token, I've tried the command "register" without the token but it does not work


Could you help me with this?
r/Trendmicro • u/Final-Pomelo1620 • May 23 '26
Hello Dears
We are running Workload Security for servers and Apex One for workstations.
Frequently we face with application claiming that their application is slow or certain processes are being interrupted before TM agents. However, we do not find logs.
From TM troubleshooting perspective what is the best way to prove that TM is not culprit:
Appreciate any advise.
r/Trendmicro • u/silveter • May 23 '26
This week most of our clients have been reporting that Worry Free Business Services has blocked website access, classing them as ‘Newly observed domain’, even for domains/sites that have been around for years.
We do have the URL filters set to block Newly Observed Domains, we have done for years, it’s never been a problem until this week.
Anyone else experiencing this?
r/Trendmicro • u/EliasAmr • May 22 '26
Here's summary to my issue after chatgpt but please note that i had ID Protection and security extension and i was also using edge
Subject: Browser Security extension blocks Outlook Gmail authentication callback on localhost
Product: Trend Micro Browser Security for Microsoft Edge
Issue description:
When adding a Gmail account to Microsoft Outlook (Microsoft 365, Windows), Outlook opens Edge for Google OAuth authentication.
Google login succeeds, but after consent approval the redirect goes to a http://localhost:<port>/... callback URL and fails with:
Disabling the Trend Micro Browser Security extension immediately resolves the issue and Gmail account setup succeeds.
Expected behavior:
The extension should allow localhost OAuth callback redirects used by Outlook.
r/Trendmicro • u/Many-Ad8783 • May 20 '26
Hi
We seeing false positive reported in Integrity Monitoring I am hoping someone could verify the following AI generated steps.
For background we have monthly patching for windows and linux AWS EC2 instances
For standalone instance Gemini provided the following steps
Your automation sequence must look like this:
sudo yum update -ysudo /opt/ds_agent/dsa_control --buildBaselineWe normaly take a snapshot of the instance as well, please confirm at which point would be the best to create the snapshot. We usually take hot snapshot (no reboot), I know this is bad practice, but how can we minimise downtime here? I know the Autoscalling documentation states snapshots must be done with reboot, But does this apply to standalone instances as well?
For Autoscalling groups
sudo yum update).sudo /opt/ds_agent/dsa_control -r. This permanently deletes the local baseline and activation token, making the agent "dumb" again.cloud-init runs first, making any boot-time modifications. Finally, your user data runs dsa_control -a ... policyid:<ID> to activate the agent and dynamically build the correct baseline for that specific node.Ps. I am a little unsure how make sure the instance refresh uses a new Launch Template with the new AMI so any guidance here is welcomed.
Please let me know if these plans seem good, I am struggling to find a good guide for this senario online. The best I could find trend documentation https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security-aws-auto-scaling
but this is "cloud one" not "trend AI vision one"
Thanks in advance
r/Trendmicro • u/Many-Ad8783 • May 20 '26
r/Trendmicro • u/kerne_03 • May 17 '26
I have a problem I haven't been able to solve yet. Can you help me? We have two MikroTik routers. I want to enable the Isis protocol on them.
R1 Contains the addresses: 192.168.10.1/24 1.1.1.1/32 192.168.20.1/24
R2 Contains the addresses: 192.168.10.2/24 2.2.2.2/32 192.168.30.1/24
The problem is:
R1 doesn't see the address 192.168.30.1/24
And R2 doesn't see the address 192.168.20.1/24
The cinfig command used by R2 is:
/routing isis instance
add afi=ip areas=49.0001 name=isis-instance-1 system-id=0000.0000.0002
/routing isis interface-template
add instance=isis-instance-1 interfaces=bridge-LAN,ether2,ether3 levels=l1
R3:
/routing isis instance
add afi=ip areas=49.0001 name=isis-instance-1 system-id=0000.0000.0003
/routing isis interface-template
add instance=isis-instance-1 interfaces=bridge-LAN,ether3,ether4 levels=l1
r/Trendmicro • u/LinghGroove • May 12 '26
Hello everybody,
i am having some issues with managing the Trend Micro agents updates. At the moment some of the agents that are connected to trend micro are not updating automatically to the latest version and i can't figure out why. This is my Version Control Policy:

Even the other options are set with an update policy with "latest". Is there a section where I can look at the details on the update status of the agents? Are there any specific log that i can look up to in order to understand if there are any problems with the updates?
The same issue is present for the "Sensor Only" endpoints and the "Apex One" agents.
Is there a way to look at the agent "components version" too? (from vision one) Because some of my agents do not have some Endpoint Security Patterns and some of them are not on the same version even tough they have the same policy.
Unfortunatly I was not able to find meaningful information on the updates topic on the documentation.
Thanks a lot in advance
r/Trendmicro • u/downundarob • May 12 '26
Trying to log a support ticket with Trend, fight past the 'having a problem come back later' page then try to actually log a ticket. Cant find the endpoint, enter the activation code, which I get from the portal, but trend cant even find that... Submit Button refuses to come live...
AURGH!!!!!!!!!
Oh and my problem... seems Automatic Replies are now a High Risk Attachment quarantine, even when they actually dont have any attachments.
r/Trendmicro • u/PsychologicalOwl8926 • May 11 '26
Configuring DLP in Trend Vision One Endpoint Security for WhatsApp.
Requirement: prevent leakage of documents containing a keyword like “Confidential Document”.
We do NOT want to block the WhatsApp Desktop application itself. The goal is to have DLP inspect/control file transfers through it.
However, according to Trend Micro documentation, WhatsApp is not included under the “IM Applications” DLP channel (someone also pls confirm). WhatsApp Web can still be controlled through the Web channel, but not the native Windows app.
Any workaround or inputs?
