T Techclick ← All lessons
Trend Vision One · Evidence desk · Interactive lesson

Is Vision One seeing this endpoint — first tool + proof field

02:11. Slack: “Is Vision One even seeing this laptop? Why no Workbench alert?” The CIO is already in the channel. A red CREM tile is not proof. This desk is five official tools — Endpoint Inventory, Workbench, XDR Data Explorer, Observed Attack Techniques, Detection Model / Endpoint Security policy — each mapped to one ticket, one first click, and one field you paste before you isolate or tune.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

⚡ Quick Answer

Night-shift Trend Vision One evidence desk. Is Vision One seeing this endpoint, and why is there no Workbench alert? Five official tools, first click, one proof field.

After this page you can

Quick answer (say this out loud)

Endpoint Inventory answers “is this host talking to Vision One?” Workbench answers “did a detection model correlate an alert — and which one?” XDR Data Explorer answers “what telemetry or detection events exist for this host / Event UUID?” Observed Attack Techniques answers “did a filter fire even though Workbench stayed empty?” Policy (Detection Model Management + Endpoint Security Policies) answers “was the model or XDR for Endpoints (EDR) even on?” A green last-seen is not a Workbench case. An OAT row is not a Workbench ID. A High CREM tile is the factory queue, not this desk.

1. Why “is it seeing this?” is five questions

Operators collapse five failures into one sentence. The sensor never checked in. The host is unmanaged. A filter fired and never became a Workbench alert. The detection model is off. XDR for Endpoints (EDR) is disabled on the assigned policy. Those are five first clicks.

Concept: Vision One can only correlate what a connected product actually sent. Path: prove the sensor, then the alert, then the event, then the filter, then the policy. Do: quote one official field before you isolate or add an exception.

The factory taught Workbench versus CREM. This page is the night-shift desk for proof. When someone asks whether Vision One is seeing the endpoint — or why Workbench is empty — you open one of five official apps, in order, and you paste a named field.

Hero · sensor on the desk, techniques on the wall
Night-shift desk: endpoint laptop talking to a cloud sensor, attack-technique tiles on the wall
Notice: the laptop is only “seen” if the sensor is on the wire. Wall tiles are techniques, not Workbench IDs. Pick the tile that matches the question, then quote one field.
Interview line

If they say “prove Vision One is seeing this host,” do not say “I opened the console.” Say: “I prove the sensor with Endpoint Inventory Last agent status reported, the alert with Workbench Status + Score + Model name, the event with XDR Data Explorer Data source / processor + Log type, the filter with Observed Attack Techniques Detection filter, and the switch with Detection Model Status or XDR for Endpoints (EDR).”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you isolate a host that Vision One never saw, or hunt a Workbench ID that a filter was never going to create.

1 · Endpoint Inventory

Endpoint Security → Endpoint Inventory. Proves the agent is (or is not) talking: Last agent status reported, product family, Sensor disabled vs Unmanaged. Does not prove a Workbench case.

2 · Workbench

Agentic SIEM and XDR → Workbench (Insights / All Alerts). Proves a correlated or standalone alert: Workbench ID, Status, Score, Model name. Empty list is data.

3 · XDR Data Explorer

Agentic SIEM and XDR → XDR Data Explorer. Proves events exist: Data source / processor + Log type (Detection / Telemetry / System) + Investigate host or Search Event UUID. Confirm query fields in your tenant.

4 · Observed Attack Techniques

Agentic SIEM and XDR → Observed Attack Techniques. Proves a filter fired: Event severity, Detected time, Detection filter, Tactic / Technique ID. Official: OAT events might not generate a Workbench insight or alert.

5 · Policy

Detection Model Management (Status, severity, applicable products) and Endpoint Security Policies (Endpoint security policy, XDR for Endpoints (EDR)). Proves the switch was on.

Hard words, once

Sensor disabled = sensor installed but not enabled via sensor or policy settings. Unmanaged = discoverable, no protection or sensor agent. Score = model severity + impact scope (max 99 on alerts created after 18 Jan 2021). Isolate Endpoint is a Response Management task; restore is a second task.

Flow 1 · five tools, one question each
Write host + UTC first · then pick the tool Is Vision One seeing this? five questions, not one Endpoint Inventory On the wire? Last agent status Endpoint Security → Endpoint Inventory not a Workbench ID Workbench This alert? ID · Status · Score Model name SIEM and XDR → WB not an OAT row XDR Data Explorer This event? Data source Log type · hits Investigate host not a policy edit Observed Attack This filter? Detection filter Event severity may not create WB not an isolate Policy Was it on? Model Status XDR for Endpoints DMM + ESP not a CREM page Empty Workbench is data. It usually means the sensor, the filter, or the model never landed an alert. Do not invent an Isolate Endpoint from an empty queue. Start at Endpoint Inventory or Observed Attack Techniques.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the sensor, then the Workbench alert, then the XDR event, then the OAT filter, then the policy switch. I do not isolate, disable a model, or open CREM until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open Isolate Endpoint or Detection Model Management until a diamond says so.

Path · pick the branch before the menu
Four-panel path: Client, then Steer, then Policy, then Event
Notice: client first (is Vision One seeing this host?), then steer (which tool), then policy (was the model or EDR on?), then the event. Do not hunt a Workbench ID before the client is on the wire.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Sensor talking? or already inside? Host unseen Endpoint Inventory Last agent status Alert exists Workbench ID · Status · Score Need the event XDR Data Explorer Log type · source No WB, host dirty Observed Attack Detection filter Expected empty Model / EDR policy Status · EDR Sensor disabled or last-seen stale → stop. There is no Workbench ID to chase. Enable the sensor / fix last-seen. Then re-open Workbench or Observed Attack Techniques. Diamond = decision. Do not Isolate Endpoint from the bottom box. Official Help path is Agentic SIEM and XDR → Workbench / XDR Data Explorer / Observed Attack Techniques.

Read the diamond first. “No Workbench, host looks dirty” never starts in Isolate Endpoint. “Expected empty after a policy change” never starts in CREM. Stale last-seen never starts in Model name.

4. How to choose — first tool + proof field

Print this next to the Vision One console. If you cannot recite the proof field, you are not ready to isolate or tune anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
“Is Vision One seeing this laptop / server?” Endpoint Security → Endpoint Inventory Last agent status reported + product family (Standard Endpoint Protection / Server & Workload / Sensor only / Connected Endpoint Protection) + Available Action (Sensor disabled vs Unmanaged) A new Isolate Endpoint, CREM
Workbench ID already on the ticket (High / New / Open) Agentic SIEM and XDR → Workbench → All Alerts (or Insights) Workbench ID + Status (Open / In progress / Closed) + Score + Model name Detection Model Management
Need the process / Event UUID behind a Workbench highlight Agentic SIEM and XDR → XDR Data Explorer Data source / processor + Log type (Detection events / Telemetry events / System events) + Investigate host or Search Event UUID hits A global exception
“Why no Workbench alert?” host still looks dirty Agentic SIEM and XDR → Observed Attack Techniques Event severity + Detected + Detection filter (+ Tactic ID / Technique ID). Official: OAT events might not generate a Workbench insight or alert Isolate Endpoint
Empty Workbench after a model or EDR change; expected silence Detection Model Management and/or Endpoint Security Policies Model Status (whether Vision One triggers the alert) + Endpoint security policy + XDR for Endpoints (EDR) enabled/disabled A new Workbench hunt
OAT ≠ Workbench (official)

Trend Vision One Online Help on Observed Attack Techniques: events listed there might not generate a Workbench insight or Workbench alert. Detection models are built from granular predefined or custom detection filters. A filter fire is not a correlated alert. Quote the Detection filter. Do not invent a missing Workbench ID, and do not Isolate Endpoint from an OAT row alone.

5. Runbook Side A → B → C

Side A proves the sensor is talking. Side B proves the Workbench alert and the XDR event. Side C proves the filter and the policy switch. On a messy Sev-2, do them in this order until a field lights up.

Side A — Endpoint Inventory (the sensor)

Primary source: Endpoint Inventory and Endpoint Inventory table columns.

  1. Open Endpoint Inventory, not Workbench

    Path: Endpoint Security → Endpoint Inventory. Filter the hostname on the ticket. Quote the product family under Security Deployment: Standard Endpoint Protection, Server & Workload Protection, Sensor only, or Connected Endpoint Protection.

  2. Read the two columns that close a “seeing this?” ticket

    Last agent status reported — the last time the agent connected (range plus exact timestamp). Official columns retired Sensor last connected / Sensor connectivity in favour of this field. Add Isolation status so you know whether Isolate Endpoint already ran.

  3. Name the Available Action if the host is sick

    Immediate action required — issue needs user intervention. Unmanaged endpoints — discoverable, no protection or sensor agent. Sensor disabled — sensor installed but not enabled via sensor or policy settings. Sensor update recommended — older Endpoint Sensor (including Activity Monitoring and Apex One Endpoint Sensor). Those four labels are official Available Actions wording.

  4. If last-seen is stale, stop

    A Workbench story on a host whose last status is five days old is a sensor ticket, not an isolate debate. Isolation commands sit in Response Management as Queued when the agent is offline. Fix check-in first.

portal.xdr.trendmicro.com · Endpoint Security → Endpoint Inventory
Training mock · not live

Endpoint Security / Endpoint Inventory / SENSOR-LAB-17

Endpoint details · SENSOR-LAB-17

SENSOR-LAB-17
Standard Endpoint Protection
2 minutes ago · 2026-08-16 20:41:12 UTC
Not isolated
Lab-Standard-EDR
Enabled
AVAILABLE ACTIONS (the other outcomes):
Sensor disabled — sensor installed, not enabled via sensor or policy settings
Unmanaged endpoints — discoverable, no protection or sensor agent

Source: Trend Vision One Online Help — Endpoint Inventory; Endpoint Inventory table columns (Last agent status reported, Isolation status, Endpoint security policy, XDR for Endpoints (EDR)). Lab host only. Training mock · not live.

Side B — Workbench and XDR Data Explorer

Primary source: Workbench, Alert details, XDR Data Explorer.

  1. Open Workbench, not CREM

    Path: Agentic SIEM and XDR → Workbench. Workbench insights is the high-priority correlated-alert view (filter by Severity and score, Case status). All Alerts is the full standalone-alert list for root-cause and impact. Click the Workbench ID.

  2. Read the four fields that identify the alert

    Workbench ID. Status — Open (new, not under investigation), In progress, Closed. Score — overall severity from matched-model severity plus impact scope (maximum 99 for alerts created after 18 January 2021). Model name + Model severity + Impact scope + Data source / processor. Official Help format note (Success KA-0015503): WB-<company>-<date created>-<order of WB per day>. Lab label on this page stays WB-1042.

  3. Use Highlights, then Search Event UUID

    Investigate an alert: Highlights lists the detection filters that triggered it. Every event starts with the filter name. Click Search Event UUID to open a new XDR Data Explorer query for that event. Right-click objects for the context menu (Isolate Endpoint is here only after the fields above exist).

  4. Prove the event in XDR Data Explorer

    Path: Agentic SIEM and XDR → XDR Data Explorer. Select Data source / processor and Log type — All, Detection events, Telemetry events, or System events — then Run query. Or use Investigate host with hostname / IP. Quote source + log type + hit count + time. Confirm live query field names in your tenant; do not invent columns from memory.

portal.xdr.trendmicro.com · Agentic SIEM and XDR → Workbench → All Alerts
Training mock · not live

Agentic SIEM and XDR / Workbench / All Alerts / WB-1042

Alert details · WB-1042

WB-1042
Open
72
Possible ransomware staging
High
1 endpoint
Standard Endpoint Protection
FilterTechniqueData sourceDetected
Volume shadow copy deletionT1490Standard Endpoint Protection20:38 UTC
Suspicious process chainT1059Standard Endpoint Protection20:37 UTC

Source: Trend Vision One Online Help — Workbench; All Alerts; Alert details (Status, Score, Workbench ID, Model name, Impact scope, Data source / processor, Highlights). Lab identities only. Next click: Search Event UUID in XDR Data Explorer.

Side C — Observed Attack Techniques and policy

Primary source: Observed Attack Techniques, Detection Model Management, Success KA-0015503.

  1. If Workbench is empty, open OAT — do not isolate

    Path: Agentic SIEM and XDR → Observed Attack Techniques. Filter Event severity and last Detected time. Add filter: Asset group, Custom tag, Data source / processor, Detection filter, Endpoint group, Tactic ID, or Technique ID. Search box: endpoint or container name.

  2. Quote the filter, then decide whether Workbench was ever going to fire

    Expand the row. Official Help: OAT events might not generate a Workbench insight or alert. You may Query in XDR Data Explorer, View Event in XDR Data Explorer, or right-click Add to Workbench Insight. Adding an event updates impact scope and highlighted objects — it is not Isolate Endpoint.

  3. If silence was expected, prove the switch

    Detection Model Management (Agentic SIEM and XDR → Detection Model Management): review Status (whether Vision One triggers alerts for that model), Severity, and Applicable products. You cannot enable a trigger when the required product is not connected. Defaults: Vision One enables supported models as you add products.

  4. If the host is present but EDR is off, quote the policy

    Back in Endpoint Inventory, read Endpoint security policy (the assignment in Endpoint Security Policies) and XDR for Endpoints (EDR) enabled/disabled. EDR off explains empty Detection events. Do not hunt a missing Workbench ID first. Scoped exceptions live under Detection Model Management → Exceptions — owner and expiry, not “turn Workbench off.”

portal.xdr.trendmicro.com · Agentic SIEM and XDR → Observed Attack Techniques
Training mock · not live

Agentic SIEM and XDR / Observed Attack Techniques / SENSOR-LAB-17

Observed Attack Techniques

High
Last 24 hours
Volume shadow copy deletion
T1490
OFFICIAL HELP LINE:
Events listed in Observed Attack Techniques might not generate a Workbench insight or Workbench alert.
Next: Query in XDR Data Explorer · or Add to Workbench Insight — not Isolate Endpoint.

Source: Trend Vision One Online Help — Observed Attack Techniques (Event severity, Detected, Detection filter, Tactic ID / Technique ID; OAT may not create Workbench). Lab host only.

Pilot checklist — Side A / B / C
Proof · four stamps, then the switch
Night SOC desk: green health check on one monitor, highlighted log lines on the other
Notice: green last-seen is the left monitor. The highlighted log line is the proof field. Isolate is a later decision. CREM is not on either screen.

6. Five tickets as full stories

Same five tools, written as night-shift stories. Lab host SENSOR-LAB-17 and lab alert WB-1042 match the factory. They are training labels, not a customer tenant.

IDTicketFirst toolProof field
TV1D-01WFH laptop: “Is Vision One even seeing this?”Endpoint InventoryLast agent status reported + product + Sensor disabled / Unmanaged
TV1D-02Workbench High Open on SENSOR-LAB-17Workbench All AlertsWorkbench ID + Status + Score + Model name
TV1D-03Need the event behind the highlightXDR Data ExplorerData source / processor + Log type + hits / Event UUID
TV1D-04“Why no Workbench?” host looks dirtyObserved Attack TechniquesDetection filter + Event severity (OAT ≠ Workbench)
TV1D-05Empty Workbench after an EDR / model changeDetection Model + Endpoint Security policyModel Status and/or XDR for Endpoints (EDR)

TV1D-01 — “Is Vision One seeing this laptop?”

02:11. Priya on hotel Wi-Fi. Slack screenshot of a spinning Office tab. Someone says “Trend is down.” First tool is not Workbench.

Do: Endpoint Security → Endpoint Inventory → her hostname. Quote Last agent status reported. If the row is missing, check Available Actions: Unmanaged endpoints means discoverable with no agent. Sensor disabled means the sensor is installed and the switch is off.

If last-seen is minutes ago and Standard Endpoint Protection is listed, Vision One is seeing the host. “No Workbench” is now a different ticket (TV1D-04 or TV1D-05). If last-seen is days old, stop. Isolate Endpoint will sit Queued in Response Management. That is a sensor ticket.

Say the close

I do not trust a colleague’s Inventory row from a different hostname. The proof is Last agent status reported on the failing device. A green tray icon on her laptop is not this column.

TV1D-02 — Workbench High, status Open

Bridge already has WB-1042 in the title. First tool is Workbench, not Inventory — unless last-seen was never proved.

Path: Agentic SIEM and XDR → Workbench → All Alerts → click the ID. Proof field: Workbench ID, Status = Open, Score, Model name (lab: Possible ransomware staging), Impact scope = 1 endpoint, Data source / processor = Standard Endpoint Protection.

Change Status only after you have those four identity fields on the ticket. Findings stay “—” until the investigation actually has one (True positive / False positive / Benign true positive / Noteworthy / Other findings).

TV1D-03 — Prove the event, not the title

Highlights named a Volume shadow copy deletion filter. A title is not evidence. Do: Search Event UUID, or XDR Data Explorer → Investigate host = SENSOR-LAB-17, Log type = Detection events (then Telemetry events if Detection is empty).

Proof field: Data source / processor + Log type + at least one hit in the UTC window. If both Detection and Telemetry are empty while last-seen is fresh, you have a policy / EDR ticket (TV1D-05), not a missing isolate.

Confirm query syntax in the tenant. Saved queries store the string, not the results (cap 200). Export is a later evidence pack, not the first proof.

TV1D-04 — “Why no Workbench alert?”

IR chat: “vssadmin ran, why is Workbench empty?” Empty Workbench is allowed. Official OAT Help says those events might not generate a Workbench insight or alert.

First tool: Observed Attack Techniques. Filter endpoint name + last Detected. Proof field: Detection filter + Event severity + Technique ID. Next click is Query in XDR Data Explorer or Add to Workbench Insight — not Isolate Endpoint, not “Trend is broken.”

Success KA-0015503: if you clicked View Event from an old Workbench ID and OAT is empty, XDL data are kept about 30 days. Read the date out of the official Workbench ID format before you declare the filter dead.

TV1D-05 — Expected silence after a policy change

Change window an hour ago. Someone disabled XDR for Endpoints (EDR) on Lab-Standard-EDR, or turned a model Status off, and now Finance asks why Workbench is quiet.

First tool: Detection Model Management for the named model (Status, Severity, Applicable products). Then Endpoint Inventory → Endpoint security policy + XDR for Endpoints (EDR). Quote the switch. Do not hunt a Workbench ID that the switch cannot create.

Daily noise is the inverse ticket: tune or add a scoped exception with owner and expiry. Do not disable the Workbench app. Success KA-0015503 documents wildcard exception escaping for Workbench / OAT — that is a change-control task, not a night-shift disable.

Isolate is not a proof field

Isolate Endpoint is a Response Management task after Side A + B exist. Official task statuses: Pending approval, Rejected, In progress, Queued (agent offline), Successful, Unsuccessful. Task status means the managing server received the command — not that the Security Agent finished it. Restore connection is a second task on that isolate record. Critical endpoints can be excluded from response actions; isolated infrastructure can get inbound/outbound exceptions. None of that answers “is Vision One seeing this?”

7. Traps + close-the-ticket proof

Every trap is a wrong first tool. The fix is always one official field on a timestamp.

What you sawWrong first moveProof that closes
Empty Workbench“Trend is down” / Isolate EndpointEndpoint Inventory last-seen, or OAT Detection filter, or model Status / EDR off
Sensor disabledHunt Workbench Model nameAvailable Actions: sensor installed, not enabled via sensor or policy settings
UnmanagedResponse Management isolateNo protection or sensor agent — deploy, do not isolate
OAT High, no Workbench IDDeclare a missed Sev-1Official: OAT might not generate Workbench; quote Detection filter
Workbench ID older than ~30 days, OAT empty“Filter is dead”Success KA-0015503 — XDL retention; read the date in the Workbench ID
Last-seen 5 daysIsolate anywayResponse task will be Queued; fix the sensor
XDR for Endpoints (EDR) disabledNew Workbench huntEndpoint security policy + EDR column
High CREM tilePage SOC / isolateWrong desk — that is the factory (Workbench vs CREM)
Daily Workbench noiseDisable WorkbenchModel tune or scoped exception, owner + expiry
Isolate Successful in Response Management“The agent executed it”Official: task status is managing-server receipt, not agent finish
Close-the-ticket checklist
Interview close

I name the question, then the first tool, then one official field. Endpoint Inventory proves the sensor. Workbench proves the correlated or standalone alert. XDR Data Explorer proves the event. Observed Attack Techniques proves the filter — and official Help says that filter might never become a Workbench ID. Policy proves the switch. I do not isolate, disable a model, or open CREM until that field is on the ticket. Queue model: Workbench vs CREM factory.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

WFH user: “Is Vision One even seeing this laptop?” You have not opened Workbench yet. First proof?

Correct: b. Official Endpoint Inventory path and columns. There is no Workbench ID to chase until the sensor is talking. Re-read Side A and TV1D-01.
Q2

IR chat: the host looks dirty, Workbench is empty. What is the first tool + field?

Correct: c. Official OAT Help. A filter fire is not a Workbench ID. Re-read Side C and TV1D-04.
Q3

The ticket already names WB-1042. Which fields identify the alert before you isolate?

Correct: a. Official Alert details elements. Score is model severity + impact scope. Re-read Side B and TV1D-02.
Q4

Workbench Highlights named a filter. You need the event, not the title. Next proof?

Correct: d. Official Investigate an alert + XDR Data Explorer actions. Confirm query fields in the tenant. Re-read Side B step 4 and TV1D-03.
Q5

Endpoint Inventory shows Sensor disabled for a discoverable laptop. What does that mean?

Correct: b. Official Available Actions wording. Unmanaged is the other trap — no agent at all. Re-read Side A step 3 and the hard-words box.
Q6

XDR for Endpoints (EDR) is disabled on the assigned Endpoint security policy. Empty Workbench is expected. What is that sentence allowed to mean?

Correct: a. Official Endpoint Inventory columns plus Detection Model Status when the named model is off. Re-read Side C step 4, TV1D-05, and the diamond bottom box.

Sources

Related: Blog 1 · Workbench vs CREM factory · Trend Vision One interview hub · Dummy lab