T Techclick ← Vision One hub
Trend Vision One · XDR factory · Interactive lesson

Vision One is an XDR factory. Sensor, inventory, then Workbench / OAT.

The ticket says “Trend missed vssadmin.” The tray icon is green. Workbench is empty. That is not a missing feature. The factory either never printed telemetry, never listed the host, stamped only an Observed Attack Techniques filter, or had the detection model / EDR switch off. This lesson is the official line: sensor → inventory → Workbench / OAT → policy. Proof is Last agent status reported, a Workbench ID or a Detection filter, and a named policy — not a screenshot of a red tile.

20 min read · L2 primary · Quiz at end · Dummy lab only · Blog 2 · Evidence desk

⚡ Quick Answer

Vision One is an XDR factory: sensor → inventory → Workbench / OAT → policy. Official docs.trendmicro.com only.

After this page you can

Quick answer

Trend Vision One is an XDR factory. A protection or sensor agent on the host prints telemetry. Endpoint Inventory is the live table — official column Last agent status reported. If a detection model correlates the events, Workbench (Agentic SIEM and XDR → Workbench) prints a ticket with Status, Score, Model name. If only a granular filter fired, Observed Attack Techniques lists the event — and official Help says that event might not generate a Workbench insight or alert. Detection Model Management and Endpoint Security Policies (XDR for Endpoints (EDR)) are the switches. Success is a live last-seen, then a Workbench ID or a named Detection filter, then a named policy — not “the icon is green.”

Say this out loud

I do not start with isolate. I ask whether the sensor checked in, which product family Inventory lists, whether Workbench printed an ID or only OAT stamped a filter, and whether the detection model and XDR for Endpoints (EDR) were even on. An OAT row is not a Workbench ID. A Successful isolate task is managing-server receipt, not agent finish.

1. Why a green last-seen is not a Workbench ID

Every other briefing starts with the filename. vssadmin.exe. “Trend missed it.” That is why students freeze in interviews. The real object is the telemetry the sensor printed. Workbench, OAT, and policy are only stamps the factory puts on that telemetry before anyone isolates.

Official factory floor: a protection or sensor agent on the endpoint, Endpoint Inventory as the live list of those agents, then Agentic SIEM and XDR apps that turn events into Observed Attack Techniques rows and — sometimes — Workbench alerts. The console only knows what the agent last reported. Official Inventory column: Last agent status reported is the last time the agent connected with Vision One, as a range plus an exact timestamp. Hours old is a dark factory floor. Seconds old is a live worker.

Hero · the factory floor
Teaches: a host event becomes a Vision One ticket that walks sensor, inventory, Workbench or OAT, then policy
Notice: Vision One does not “miss a file.” It tries to manufacture telemetry, list the host, and stamp a Workbench ID or an OAT filter.

What the ticket asked

“Trend missed vssadmin.” That sentence is a hypothesis. The factory may already have stamped an OAT filter, or printed Workbench WB-1042, and you have not opened either.

What you prove first

Identity of the host, then Last agent status reported, then Workbench ID or OAT Detection filter, then the assigned policy / EDR switch. The evidence desk is the night-shift version of this order.

The lie every L1 repeats

“The tray is green, so Trend is working — we need a wider exception.” A green icon only means a local process is running. If Last agent status reported is five days old, or Available Actions says Sensor disabled, or XDR for Endpoints (EDR) is off on the assigned policy, the factory did not print the ticket you think it printed. Widening an exception just stamps more events as invisible.

Hard words before the runbook

Sensor / product family

Official Security Deployment tiles: Standard Endpoint Protection, Server & Workload Protection, Sensor only, Connected Endpoint Protection. Quote the product, not “Apex is installed.”

Sensor disabled vs Unmanaged

Sensor disabled = sensor installed but not enabled via sensor or policy settings. Unmanaged endpoints = discoverable, no protection or sensor agent. Those are different tickets.

Workbench vs OAT

Workbench is a correlated or standalone alert (Insights / All Alerts). OAT is the individual filter event. Official: OAT events might not generate a Workbench insight or alert.

Policy switch

Detection Model Management turns models and exceptions on or off. Endpoint security policy + XDR for Endpoints (EDR) is whether the host can even emit EDR telemetry.

Official Isolate Endpoint task statuses: Pending approval, Rejected, In progress, Queued (agent offline), Successful, Unsuccessful. Official wording: Task status means the managing server received the command — not that the Security Agent finished it. Restore connection is a later task on that isolate record. Use those words in the ticket.

2. Mental model — four factory stations

Hold four parts. Interviews fail when people mix them. Skipping a station is how you isolate a five-day last-seen, or hunt a Workbench ID that a filter was never going to create.

1. The worker is the sensor

A protection or sensor agent on the host. It sees the endpoint. Last agent status reported is the heartbeat. Sensor disabled means the worker is installed and the switch is off. A green tray is not this column.

2. The live table is Inventory

Endpoint Security → Endpoint Inventory. Official: manage, locate, take action. Columns you quote: Endpoint name, Endpoint GUID, product family, last-seen, Isolation status, Endpoint security policy, XDR for Endpoints (EDR).

3. The stamps are Workbench / OAT

Workbench = Status, Score, Model name, Workbench ID. OAT = Event severity, Detected, Detection filter, Tactic / Technique ID. One is an alert. The other is a filter fire. Do not swap them.

4. The switch is policy

Detection Model Status decides whether filters become Workbench alerts. Endpoint Security Policies decide whether EDR is even on. Empty Workbench after a change window is often this station, not a miss.

Path · last-seen diamond
Teaches: a last-seen diamond splits a live factory path from a dark sensor rebuild path
Notice: the diamond is not “did Trend miss it?” It is “did this host print telemetry Vision One could stamp?”
Flow 1 · one ticket, four stations
SENSOR-LAB-17 · last-seen 14s · Isolation off 1 Sensor prints telemetry SEP / SWP / sensor disabled ≠ unmanaged dark = no ticket 2 Inventory live host table Last agent status GUID · policy · EDR not a Workbench ID 3 Workbench / OAT alert ID or filter Score · Model name OAT may never be WB empty WB is data 4 Policy model Status XDR for Endpoints exception owner off = expected quiet Workbench stamp ID · Status · Score · Model Insights / All Alerts OAT stamp Detection filter · severity may not create Workbench Isolate is later Response Management task Successful ≠ agent finished XDR Data Explorer sits beside station 3 — it proves the event, it does not replace Inventory or policy. Inventory is the live table. Workbench is the alert. OAT is the filter. Policy is the switch. Isolate is a Response Management task after those exist.

Read left → right. Station 1–2 are last-seen plus product. Station 3 is Workbench or OAT. Policy is last before you isolate.

Concept: Vision One manufactures telemetry on a sensor and writes alerts or filter events in the cloud. Path: sensor → inventory → Workbench / OAT → policy. Do: never open Isolate Endpoint first.

Sensor answers “is this host talking?” Official: Last agent status reported, product family, Available Actions (Sensor disabled, Unmanaged endpoints, Sensor update recommended, Immediate action required). Source: Endpoint Inventory + table columns.

Workbench / OAT answers “what did the factory stamp?” Official Workbench: Insights for high-priority correlated alerts; All Alerts for root-cause and impact. Official OAT: granular predefined or custom detection filters; those events might not generate a Workbench insight or alert. Source: Workbench + Observed Attack Techniques.

Policy answers “was the switch on?” Official: Detection Model Management configures how Vision One detects events in OAT and generates alerts in Workbench. XDR for Endpoints (EDR) is configured in Endpoint Security Policies or a policy override. Source: Detection Model Management + Inventory columns.

3. First telemetry vs empty Workbench

The first event of a new process has no Workbench ID yet. It walks the factory: sensor observes → Inventory still shows a live last-seen → assigned detection filters stamp OAT → a detection model may correlate a Workbench alert. Later events of the same story ride that filter. That is why “I enabled the model” sometimes does nothing until the next matching event, and why “I isolated the leftover hostname” does nothing if you picked the stale Endpoint GUID.

Flow 2 · official factory order (student labels)
Sensor → last-seen? → Inventory → Workbench or OAT → policy 1 Sensor observe host last-seen? seconds? yes 2 Inventory row live product · Isolation off Workbench alert exists? yes 3a Workbench ID · Score · Model no / stale Stop. Sensor ticket first. Unmanaged · Sensor disabled · last-seen days no 3b Observed Attack Techniques Detection filter · Event severity · may never become Workbench 4 XDR Data Explorer Data source · Log type · hits 5 Policy switch Model Status · EDR on policy 6 Isolate? later Response Management task Official facts students invert 1. OAT events might not generate a Workbench insight or Workbench alert. That is Help, not a miss. 2. Workbench Score = model severity + impact scope. Max 99 on alerts created after 18 Jan 2021. 3. Isolate task Queued means the agent was offline. Successful means the managing server got the command. 4. Detection Model Management is how filters become OAT events and how models generate Workbench alerts. Sources: Observed Attack Techniques · Alert details · Isolate Endpoint task · Detection Model Management

Read left → right, then the yellow sensor stop. Decision diamonds = last-seen, then Workbench-exists. Empty Workbench is a branch, not a crash.

#1 student trap — OAT is not a miss

IR chat: “vssadmin ran, why is Workbench empty?” Official Observed Attack Techniques Help: events listed there might not generate a Workbench insight or alert. Quote Detection filter + Event severity. Next click is Query in XDR Data Explorer or Add to Workbench Insight — not Isolate Endpoint, not “Trend is broken.”

4. How to choose the stamps

You are not choosing a product. You are choosing which station is allowed to write on the ticket.

ChoiceUse whenDo not use whenProof you were right
Endpoint Inventory first Anyone asks “is Vision One seeing this?” Last-seen unknown. Tray-icon argument. You already have a Workbench ID and last-seen was proved this shift. Last agent status reported + product family + Sensor disabled vs Unmanaged
Workbench All Alerts Ticket already names an ID, or you need Status / Score / Model name. Inventory last-seen is days old. Isolate will sit Queued. Workbench ID, Status (Open / In progress / Closed), Score, Model name
Observed Attack Techniques Host looks dirty, Workbench is empty, last-seen is live. You treat the filter row as a Sev-1 Workbench case and page SOC. Detection filter + Event severity + Technique ID. Official: may never become Workbench.
XDR Data Explorer You have a Highlight or Event UUID and need the event, not the title. You use Search as a substitute for last-seen or for a policy switch. Data source / processor + Log type (Detection / Telemetry / System) + hits
Detection Model on You want matching filters to be able to generate Workbench alerts. You disable the Workbench app because Finance is angry about daily noise. Model Status + applicable products. Exceptions have an owner and an expiry.
XDR for Endpoints (EDR) on The assigned Endpoint security policy should emit EDR telemetry. You hunt a missing Workbench ID after a change window turned EDR off. Inventory columns: Endpoint security policy + XDR for Endpoints (EDR)
Isolate Endpoint Last-seen is live, Workbench or OAT+Search proved staging, owner accepts the blast radius. Unmanaged host, Sensor disabled, last-seen five days, or CREM-only High tile. Response Management Action = Isolate Endpoint + task status. Restore is a second task.

Workbench Score is not a vibe. Official Alert details: Vision One calculates the score from the severity of the matched detection model and the impact scope. Starting 18 January 2021 the maximum is 99, and that model only applies to new alerts. Quote Score next to Model name. Source: Alert details.

5. Runbook Side A → B → C

Lab values only. Hostname SENSOR-LAB-17, Workbench WB-1042, product Standard Endpoint Protection, policy Lab-Standard-EDR, last-seen 14s, Isolation off. Nothing here is a live tenant.

Side A — sensor and inventory (building the factory floor)

Primary source: Endpoint Inventory + table columns.

  1. Open Endpoint Inventory on the failing name

    Path: Endpoint Security → Endpoint Inventory. Filter Endpoint name SENSOR-LAB-17. If two rows share a name, quote Endpoint GUID. Do not trust a colleague’s row from a different hostname.

  2. Read Available Actions, not the wallpaper

    Official tiles: Immediate action required, Unmanaged endpoints, Sensor disabled, Sensor update recommended. Sensor disabled = installed but not enabled via sensor or policy settings. Unmanaged = no protection or sensor agent. Those are different tickets. Sensor-only endpoints are not in endpoint groups — use Add filters.

  3. Quote the live columns

    Copy Last agent status reported (range + exact timestamp), product family (Standard Endpoint Protection / Server & Workload / Sensor only / Connected Endpoint Protection), Isolation status, Endpoint security policy, XDR for Endpoints (EDR). Lab: 14s, SEP, Isolated = No, Lab-Standard-EDR, EDR enabled.

https://portal.lab.visionone.example / endpoint-security / endpoint-inventory / SENSOR-LAB-17
Training mock · not live

Endpoint Security → Endpoint Inventory → SENSOR-LAB-17

Endpoint SENSOR-LAB-17

SENSOR-LAB-17
EP-LAB-17-0001
Standard Endpoint Protection
14s · 2026-08-16 10:41:08Z
Isolated = No
Enabled
Lab-Standard-EDR

Available Actions for this host: none of Unmanaged · Sensor disabled · Sensor update recommended. Isolation off means isolate is still a decision.

Source: Endpoint Inventory + table columns. Dummy lab host only. Next click: Workbench if you have an ID; OAT if Workbench is empty. Do not isolate from this screen until Side B exists.

Side B — Workbench and OAT (printing the ticket)

Primary source: Workbench + Observed Attack Techniques + Alert details.

  1. Open the alert before you tune

    Path: Agentic SIEM and XDR → Workbench. Insights is the high-priority correlated view. All Alerts is the full list for root-cause and impact. Quote Workbench ID, Status, Score, Model name, Impact scope, Data source / processor. Lab: WB-1042, Open, High / Score 81, Possible ransomware staging, 1 endpoint, Standard Endpoint Protection.

  2. If Workbench is empty, open OAT — do not declare a miss

    Path: Agentic SIEM and XDR → Observed Attack Techniques. Filter Event severity + last Detected, then Add filter on Detection filter / Technique ID / endpoint name. Official: these events might not generate a Workbench insight or alert. Lab filter: Volume shadow copy deletion.

  3. Prove the event in XDR Data Explorer

    Path: Agentic SIEM and XDR → XDR Data Explorer. Select Data source / processor and Log type (Detection events, then Telemetry events if Detection is empty). Investigate host = SENSOR-LAB-17, or Search Event UUID from Highlights. Confirm query fields in the tenant. Saved queries store the string, not the results (cap 200).

https://portal.lab.visionone.example / siem-xdr / workbench / all-alerts / WB-1042
Training mock · not live

Agentic SIEM and XDR → Workbench → All Alerts → WB-1042

Alert WB-1042

SummaryHighlightsTimelineObservable Graph
WB-1042
Open
81 · model + impact scope
Possible ransomware staging
1 endpoint · SENSOR-LAB-17
Standard Endpoint Protection
Volume shadow copy deletion · Technique T1490

Findings stay “—” until you set True positive / False positive / Benign true positive / Noteworthy / Other findings. Change Status only after these identity fields are on the ticket.

Source: Workbench + Alert details. Lab values only. Next click: Search Event UUID or Investigate host in XDR Data Explorer. Do not open CREM from this screen.

Dummy lab · Techclick simulator key trendvisionone · not a live tenant
V1-LAB > show inventory SENSOR-LAB-17
endpoint=SENSOR-LAB-17 guid=EP-LAB-17-0001
product='Standard Endpoint Protection'
last_agent_status_reported=14s isolation=off
policy=Lab-Standard-EDR xdr_for_endpoints=enabled

V1-LAB > show workbench WB-1042
id=WB-1042 status=Open score=81
model='Possible ransomware staging' endpoints=1
data_source='Standard Endpoint Protection'

V1-LAB > show oat endpoint=SENSOR-LAB-17
filter='Volume shadow copy deletion' severity=High
technique=T1490 detected=10:41Z
note='OAT events might not generate a Workbench alert'

Side C — policy, then isolate only if Side A + B exist

Primary source: Detection Model Management + Isolate Endpoint task.

  1. Read the switches before you hunt a missing ID

    Path: Agentic SIEM and XDR → Detection Model Management. Tabs: Detection Models, Custom Models, Custom Filters, Exceptions. Official: this app configures how Vision One detects events in OAT and generates alerts in Workbench. Quote model Status, severity, applicable products.

  2. Read EDR on the assigned policy

    From the Inventory row: Endpoint security policy + XDR for Endpoints (EDR). Overrides live under Endpoint security policy on the selected endpoints. If EDR is disabled, empty Workbench is expected. Do not invent an isolate to “make Trend see it.”

  3. Tune with owner + expiry — do not disable Workbench

    Daily noise is Exceptions (Detection Model Management → Exceptions), scoped, with an owner and an expiry. Do not disable the Workbench app. Do not delete the model so Finance can work.

  4. Isolate is a Response Management task

    Context menu → Isolate Endpoint → Description → Create. Monitor under Workflow and Automation → Response Management. Statuses: Pending approval, Rejected, In progress, Queued (agent offline), Successful, Unsuccessful. Official: Successful is managing-server receipt, not agent finish. Restore connection is a later task. Critical endpoints can be excluded; isolated infra can get inbound/outbound exceptions.

https://portal.lab.visionone.example / siem-xdr / detection-model-management
Training mock · not live

Agentic SIEM and XDR → Detection Model Management → Detection Models

Possible ransomware staging

Detection ModelsCustom ModelsCustom FiltersExceptions
Enabled
High
Standard Endpoint Protection
OAT events · Workbench alerts
Enabled · no override on SENSOR-LAB-17
Add exception (owner + expiry) Keep model on

If Status were off, or EDR disabled on the policy, empty Workbench is the factory working as configured — not a miss.

Source: Detection Model Management + Isolate Endpoint task. Dummy lab only. Next: if you isolate, open Response Management and plan Restore connection.

Green success on this runbook

Inventory: SENSOR-LAB-17, last-seen 14s, SEP, Isolation off, policy Lab-Standard-EDR, EDR enabled. Workbench: WB-1042 Open, Score 81, Model name Possible ransomware staging — or OAT Detection filter named with Event severity. Search: Data source + Log type + hits. Isolate only after those exist; task status quoted as managing-server receipt. Restore plan named.

6. Runtime — isolate, restore, old filters

Once sensors are connected, every night-shift ticket is the same walk. Do not invent a new order because a tile is red.

Proof · last-seen then the stamp
Teaches: operators prove last-seen and a named stamp on a monitor, not from a tray icon
Notice: juniors stare at a High tile. Seniors stare at Last agent status reported, then Workbench ID or Detection filter.
Flow 3 · runtime IR path
1 Sensor last-seen 2 Inventory product · EDR 3 WB / OAT ID or filter 4 Policy model · EDR 5 Isolate? task status Restore Keep Workbench or the OAT row open until isolate + hash block + restore plan exist.

After go-live this is the only order. Policy is station 4, not station 1. Restore is a second task, not a reboot.

Later events of the same filter ride the existing OAT story. Adding the event to a Workbench Insight (official OAT action) updates impact scope and highlighted object — it does not invent a sensor that was never talking.

Hide Value on an OAT Detection filter is temporary. Official: you cannot save the Hidden objects list; leaving Observed Attack Techniques resets it. That is not an exception. Exceptions live under Detection Model Management and need an owner.

If you clicked View Event from an old Workbench ID and OAT is empty, do not declare the filter dead on this page — confirm retention and the date in your tenant Help before you tune. Night-shift field map: evidence desk.

Network, email, and endpoint degrade independently. A delayed network source is a caveat on the story, not a reason to stop IR when the endpoint sensor is healthy and Search already has the hash. Sensor health is not a message verdict: a green Cloud Email sensor does not make that one document clean.

7. Traps + factory proof

SymptomLooks likeActuallyFirst move
Empty Workbench, host looks dirty Trend missed it OAT-only filter, or model / EDR off OAT Detection filter, then policy Status
Tray green, last-seen 5 days Sensor is fine Dark factory floor Inventory Last agent status reported
Sensor disabled Laptop is off Installed, switch off via sensor or policy Available Actions — not a Workbench hunt
Unmanaged Isolate from context menu No protection or sensor agent Deploy an agent. Do not isolate.
Isolate Successful Host is off the wire Managing server received the command Quote official task-status wording; restore is later
Isolate Queued Platform bug Agent offline — last-seen already told you Sensor ticket first
EDR disabled after change window Silent miss Switch off — expected quiet Endpoint security policy + EDR column
Daily Workbench noise Disable Workbench Exception without owner Scoped exception, owner + expiry
High CREM tile, no Workbench Page SOC Exposure queue, not this factory stamp Do not isolate from CREM-only
OAT Hide Value Permanent tune List resets when you leave OAT Detection Model exception if it must persist
Proof checklist — the factory printed a real ticket
Interview close you can steal

Vision One is an XDR factory. The sensor prints telemetry. Endpoint Inventory proves the host with Last agent status reported. Workbench stamps a correlated alert — or Observed Attack Techniques stamps a filter that official Help says might never become a Workbench ID. Detection Model Management and XDR for Endpoints (EDR) are the switches. I isolate only after those stations exist, and I treat a Successful task as managing-server receipt, not agent finish.

Next: run the five night-shift tickets on the evidence desk. Practice console: Vision One hub simulator (key trendvisionone).

Knowledge check

Six judgment questions. Map each miss back to the section named in the reason.

Q1

What is Trend Vision One, as a factory, in one line?

Correct: b. Sensor → inventory → Workbench / OAT → policy. Re-read Quick answer and Mental model.
Q2

WFH user: “Is Vision One even seeing this laptop?” You have not opened Workbench. First proof?

Correct: a. Official Inventory path and columns. There is no Workbench ID to chase until the sensor is talking. Re-read Side A and Why a green last-seen is not a Workbench ID.
Q3

Last-seen is 14 seconds. Workbench is empty. IR chat says the host looks dirty. First stamp?

Correct: c. Official OAT Help. A filter fire is not a Workbench ID. Hide Value resets when you leave OAT. Re-read First telemetry vs empty Workbench and Side B.
Q4

Response Management shows Isolate Endpoint = Successful on SENSOR-LAB-17. What is that sentence allowed to mean?

Correct: d. Isolate Endpoint task Help. Queued = agent offline. Restore is a later task. Re-read Side C and the traps table.
Q5

XDR for Endpoints (EDR) is disabled on the assigned Endpoint security policy. Empty Workbench is expected. What do you quote?

Correct: b. Official Inventory columns plus Detection Model Status when the named model is off. Re-read How to choose and Side C.
Q6

Endpoint Inventory shows Sensor disabled for a discoverable laptop. What does that mean?

Correct: c. Official Available Actions wording. Unmanaged is the other trap — no agent at all. Re-read Hard words and Side A.

Sources

Related: Blog 2 · Evidence desk — first tool + proof field · Trend Vision One interview hub · Dummy lab

Dummy lab data only. Confirm live syntax, permissions and change-control on the production release before you type on a real tenant.