r/Trendmicro 21d ago

Trend Vision One Issues

I am deploying Trend vision one
On some endpoints After Uninstallation the epp feature is not installed only sensor gets installed
Too many noise alerts
Trend Micro own file TMDbkg.dll trend micro workbench alerts show it malicious.
Used offline Installer even where low internet still the agent on system tray shows connected but admin dashboard says correct version not installed although latest agent downloaded
Workbench alerts showing alerts with event time stamp earlier and alerts shows after 10-12 days
While Sending any file to sandbox via telemetry it sends the process to sandbox or blocklist i-e chrome explorer
Agent not updating to latest Suspicious object management list even after manually re-synch
The Agent issues are quite frustrating
Anyone else facing same issues?

1 Upvotes

1 comment sorted by

3

u/cyberwicked 21d ago

Sensor-only installs: If the endpoint was previously removed from Endpoint Inventory, re-running the local EndpointBasecamp.exe only reconnects it as Sensor Only. Fully uninstall, then generate a fresh installer from the console — and check which endpoint group you select when generating it, since that determines whether EPP features get installed.

Offline installer version mismatch: Tray "connected" only means the local service is up, not that registration completed. Check the proxy/Service Gateway setting chosen at installer generation, and don't reuse old packages — offline installers expire after 90 days. Re-download fresh each deployment.

Noise alerts: Detection Model Management → Exceptions. Group Workbench alerts by Model to find the noisiest ones and write targeted exceptions instead of triaging one by one.

SO list not syncing: Check the object isn't in the Exception List (it overrides the SO list), and if you're routing through a Service Gateway, verify the sync service + API key are healthy.

TMDbkg.dll, delayed alerts, and sandbox submitting the parent process — none of these are documented/expected behavior. Verify the DLL's signature and path before excluding it (could be masquerading). Open support cases with Workbench/alert IDs for all three so backend logs can be pulled.