What is it and how does it work? I've got it installed but there is no documentation that I can find...
There is indeed no link to docs on any kind provided with the app on Splunkbase.
Judging by the description though (haven't downloaded the app myself) it's meant to run a scheduled search which will get the CIM-compliant data from one or more datamodels and then upload it to Trend Micro's environment for further processing.