Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Trend Vision One

Trend Micro | 1

Reviews from AWS customer

2 AWS reviews
  • 5 star
    0
  • 2
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

259 reviews
from and

External reviews are not included in the AWS star rating for the product.


    reviewer2735652

Helps secure endpoints and quickly respond to incidents

  • July 04, 2025
  • Review provided by PeerSpot

What is our primary use case?

Our use cases for Trend Vision One are monitoring and alerts.

How has it helped my organization?

The biggest challenges we wanted to address with Trend Vision One were securing endpoints and enabling us to quickly respond to incidents or threats. This is the main goal for using this solution.

Trend Vision One has improved the way our organization functions by acting as both a monitoring tool and an antivirus, giving us insight on potential threats and enhancing our response time to security incidents. It is hard to measure the time savings but we save a significant amount of time in responding to potential threats. For example, we don't expect employees to respond to emails, chat, or calls outside of working hours. Trend Vision One has a feature where we can block all access to the laptop or endpoints. It allows us to take immediate action without waiting for the user to respond.

In terms of reducing noise from false positives, unfortunately, some behaviors can be mistaken for bad behaviors, but that isn't the fault of the software itself. It largely depends on how the developers of other applications implement their software and how it is run. We encountered an issue with another software called Rapid7, which periodically runs a command on MacBooks or Apple operating systems. This command, which is quite lengthy, searches for any unsecured credentials or API keys related to GitHub on the laptop. The way the application triggers is significant: it runs under root privileges, executing that command in the terminal for the user. Trend Vision One picks this up as a suspicious command, interpreting it as an attempt to find unsecured credentials. Despite having whitelisted the entire command in Rapid7, Trend Vision One still flagged it. We went back and forth on this issue, but ultimately we decided that it wasn't worth further troubleshooting to silence this alert due to the potential for actual malicious use of such commands. While we could whitelist it, we did not want to risk it being exploited maliciously. In the end, we chose to ignore the alert. They helped us reduce some other noise, but there was some noise that we weren't able to reduce.

Vision One AI has been very useful. All IT people stay up to date with security risks, exposures, alerts, or attacks. Vision One AI helps us explain or understand the alerts and what actions are recommended.

What is most valuable?

The workbench alerts are something we find very useful, as they help us stay informed about various activities. Not all alerts are positive, but they provide valuable insights into the detection methods and help us understand how certain issues arise. For example, if someone attempts to run a piece of software that encrypts a file, one of our tools, which is used for evidence gathering in surveillance systems, may encrypt the file too quickly. As a result, Trend Vision One may trigger an alert. Although this is a false positive, it still gives us insight into the behavior involved. This allows us to investigate the alert further and provide feedback to the user or development team, letting them know that similar triggers are likely to occur with other security systems or software.

Other useful features include intrusion and mailbox alerts, suspicious unauthorized access, tracing logs, website clicks, and email filtering for bad attachments.

What needs improvement?

The improvement I have been asking for is an easier way to create MDR requests. Not all alerts that come through Trend Vision One receive an investigation, and we would like the ability to easily request an investigation on lower-scored alerts without logging into the support portal to create a ticket.

I would like to see Trend Vision One and OfficeScan consolidated into one platform. Currently, it is the same space but two different layers. It would be nice to have both combined instead of having two clients.

There is room for improvement when it comes to support.

For how long have I used the solution?

I've been working with Trend Vision One for three years.

What do I think about the stability of the solution?

Trend Vision One is stable enough. We don't see many performance impacts on our endpoints, except for when our weekly scheduled scans happen. Our developers express that it limits how freely they can develop, but I personally appreciate the insight it gives us and the actions that allow us to take on our devices.

How are customer service and support?

I would rate their support a six out of ten. We encountered an issue with one of our tools—specifically, Visual Studio. One of our developers faced difficulties debugging code because Trend Vision One was blocking the debugging application or causing it to crash. This problem stemmed from a Windows update, and it took us a month and a half to identify the root cause. After we opened a ticket either at the end of March or early April, we waited several more weeks for a solution. Although the Windows update occurred back in February, we didn’t receive the fix until the end of May. The interaction between Windows and the application played a significant role in the issue, as the debugging application starts the code and injects itself into the running application, which Trend Micro flagged as problematic after the latest Windows update. Fortunately, this issue has now been resolved, but it was indeed a painful experience. Our developers were understandably frustrated that they couldn’t debug code for a month and a half, which impacted our project timelines.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

The company previously had SentinelOne before my time, and I can say that SentinelOne was not effective. 

We currently use Rapid7 as our Managed Detection and Response (MDR) service. In my experience, both Rapid7 and Trend Vision One serve similar purposes, but they have distinct differences. There are times when Rapid7 provides us with more detailed information, while at other times, Trend Vision One offers greater insights. This is partly because Trend Vision One collects more data from the devices, allowing it to better identify the root causes of alerts compared to Rapid7. 

Additionally, I find that the MDR team at Trend is generally more responsive than that of Rapid7. However, there are some disadvantages as well. For instance, we haven't yet set up cloud monitoring capabilities with Trend Vision One. Rapid7 currently handles our cloud infrastructure monitoring and manages services like Office and Okta. While Rapid7 is equipped to monitor these services, Trend Vision One is not yet at that level. We are exploring ways to enhance its capabilities, and if it can provide the same level of service as Rapid7, we might consider discontinuing our use of Rapid7 altogether.

How was the initial setup?

We use the SaaS solution. I was not involved in the initial setup and deployment process, which occurred prior to my time here, but I have readjusted some policies.

Previously, it was difficult to understand some alerts. However, as time goes by, we differentiate better between them, and the AI feature is an extremely good tool that explains things that are gibberish to the regular user. The learning curve is quite steep.

What was our ROI?

It has helped us understand some of the alerts that we did not comprehend.

What other advice do I have?

It is an all-around solution that includes various modules for comprehensive security monitoring and alerting. This solution is particularly effective when integrated with other hardware or on-premises solutions, such as Deep Discovery Inspector, which monitors your network.

The interface is adequate, but it is constantly changing. New features are being added, and items are being rearranged almost daily. We might have missed some announcements regarding these frequent updates. As it is an evolving solution, such changes are to be expected. However, there are still features that are buried within menus, which previously required extensive searching to locate. For instance, until last year, isolating endpoints was only possible through the search function. Now, they have added a feature within the endpoint inventory that allows you to select devices and isolate them immediately, rather than having to jump through multiple hoops to access that option.

The application has also become slightly more responsive. Regarding its functionality, the insights it provides are quite useful. The application displays various actions, and you can drill down into alerts to view the execution path associated with them. For example, if an application triggers an alert, you can right-click on that alert and select "Check Execution Profile." This feature shows you where the process started, what actions it took, and where it ended. This improvement is beneficial for understanding how tasks are executed.

I would rate Trend Vision One an eight out of ten.


    Robert B.

App notifications enable us to respond immediately and centralized information contributes to fast decision-making

  • June 27, 2025
  • Review provided by PeerSpot

What is our primary use case?

My use case for the solution is primarily for EDR purposes, but we are also starting to use the CREM.  This technology allows us to see our endpoints within seconds to ensure they are NIST 800-83 compliant.  This technology is critical in today's world as there are many customers requiring this now.  

How has it helped my organization?

We have used advanced threat intelligence, and we continue to do so. There is a way to run a threat query to find where a certain item is located. For example, Quick Assist from Microsoft was used a while back to gain access to our environment, and we didn't know it at the time. Of course, we've since locked that down. Now, we can also use that query we created to monitor if someone tries to use it again. I recently saw an attempt to use it, but they couldn't succeed because we have it blocked. It's really good to know these things, and without the available technology, we wouldn’t be able to do this.

Trend Vision One's automation capabilities have helped, for example, with atypical travel. We have a playbook set up. When Trend Vision One finds someone signed on in the United States and then catches them signed on in Africa, it will immediately run a playbook. This will disable that profile and prohibit that person from logging in. That is huge when you consider the possibilities of what could happen if we didn’t have that feature.

Our response time is greatly enhanced because of all the features that Trend Vision One offers. It simplifies things and makes it clear what’s going on inside our environment. With just a click of a button, we can get the information we need. We can mitigate issues very quickly using Trend Vision One. We can isolate endpoints, effectively removing them from the network while still accessing them through the Trend Vision One console. Additionally, we can run malware scans instantly on computers, and there are so many features available that it can be hard to keep track of them sometimes. Overall, Trend Vision One has really helped a lot. When it comes to time savings, I would estimate that our response time has improved by at least 40%.

Using this solution has benefited our business greatly. It keeps me informed of everything happening in our environment. We have site admins at every location with specific admin authority to do certain things. Trend Vision One monitors that, allowing me to validate actions taken by admins. Trend Vision One caught various incidents, and it gives me a clear understanding of our environment and its activities, with quick searches and deeper capabilities.

What is most valuable?

With Trend Vision One, my favorite feature is the app they provide. You can turn on different features and notifications. The other night I was sitting at supper when the app went off, and I got an alert that was very strange. It turned out to be an event, and we got our cyber team together to mitigate the issue with Trend's IR Teams help, preventing any major problems. That app is a lifesaver.

The dashboard provides extensive information. It gives detailed information regarding endpoints and servers, tracking everything. You can search for things and run threat analysis. There are many features within there, and it's difficult to pinpoint one because all the features work very effectively together.

The centralized management feature contributes to faster decision-making within our security operations, greatly enhancing our response time. With all the features that Trend Vision One offers, it simplifies things. It clarifies what's going on inside your environment; with a click of a button, you can see what's happening and mitigate very fast.

What needs improvement?

In Trend Vision One, there is always room for improvement. The console is well done, but there might be a bit of improvement needed with the app's capabilities. I know they are constantly working on it, and they have regular Webinars "What's New In Trend Vision One" to share updates and enhancements that are taking place.  

Trend also allows its VIP customers to pretest new features or products and enables us to give feedback on those we test.  This is an incredible benefit to Trend's VIP program.  I do not know of any other product like Trend Micro.

For how long have I used the solution?

I've been using this solution for quite a while. It was about eight years ago when our company had Trend implemented at every location. We have eleven locations overall. In my opinion, it wasn't managed properly; the situation was quite poor. There were many updates that were needed. I approached management and expressed my desire to take over the project. I said, "I want this. I will do it, fix it, and make it work." Management agreed and gave me the responsibility.

What I did next was take all the servers, fix and upgrade them, and prepare them for migration to one on-site server. After that, we decided to move to the cloud. I gathered everything together and worked with Trend to get all of our endpoints and servers transitioned to the cloud. It's been an ongoing process with Trend, as there is always something that needs to be done.

What do I think about the stability of the solution?

I rate the stability of Trend Vision One as a ten out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Trend Vision One as nine out of ten.

How are customer service and support?

It is really good. They even have a feedback system to report suggestions or problems, which are addressed promptly. We also benefit from 24/7 monitoring, and we have direct contacts for technical issues and ongoing weekly support calls.

I would rate them a nine out of ten. There's always room for improvement. Five years ago, I would rate it as a five, but support has significantly improved in availability, responsiveness, and keeping me updated.

How would you rate customer service and support?

How was the initial setup?

We purchased the software through CDW, which used to be called Sirius. That's how we acquired it. I have several contacts at Trend that I can reach out to directly, as I have been working with them for about eight years. They have helped me implement the software directly. I worked with Trend through the entire process. They have a learning platform with videos that break down each product. They show you step-by-step how to implement or use each solution. Trend Micro Service One, monitors our corporation, 24/7/365 support service. We can contact a representative, and they’ll get back to us if we encounter any problems or technical issues in our environment. They’ll even join us on a conference call to help. We also have a weekly call with them, where we can ask questions, and they guide us to the right resources and documentation. It’s really an incredible support package.

It wasn’t complicated to deploy. Now they offer a product called Server and Workload Protection, which is tailored specifically for servers. We're in the process of upgrading our servers to use this product. It’s more focused on server-specific security and functionality. When I used it about five years ago, the process was quite complex. I had problems and issues. Over the years, we moved away from the product — about four years ago — and we’re only now starting to return to it. The changes made in those four years are incredible. It’s like night and day. What used to take me days to deploy to one server now takes about half an hour. Trend is constantly updating, enhancing, and improving how things are done. It’s a continually evolving package. They’re even integrating AI capabilities now, which will greatly enhance what Trend products can do.

The capability of Trend Vision One to be deployed both on-premises and in the cloud has been extremely beneficial to my organization in terms of flexibility and scalability. Being in the cloud eliminates the need for on-prem servers. With several divisions, managing all of those on-prem servers was a nightmare. It was not an option, so I migrated to the cloud, which is a one-stop shop. We have our entire corporation in the cloud, making it easy to see everything without logging onto multiple servers; this saves a lot of time.

The solution itself does require some maintenance. The updates are automatic, so we don't need to manually check. However, some endpoints have to be maintained more carefully, ensuring they are fully updated because missing MS updates can prevent Trend Vision One from working correctly. It's good practice to keep everything up to date, which is crucial for managing over 1,000 endpoints and 200 servers. Trend Vision One allows us to see all software on a person's computer, even outdated web browsers, and it flags potential threats, which is an incredible feature.

What about the implementation team?

In my organization, approximately three people work with Trend Vision One.

What was our ROI?

In terms of return on investment, I've seen a 100% return. It has paid for itself. Our company went through a ransomware event, and if Trend Vision One's IR Team had not stopped it, that could've closed the company's doors.

What's my experience with pricing, setup cost, and licensing?

Trend Vision One is definitely cost-efficient compared to other solutions. I have seen others that are double or triple the price. I'm surprised Trend Vision One hasn't raised their prices, considering everything offered. Depending on the features selected, cost varies, but overall, endpoint and server security is very reasonable.

Which other solutions did I evaluate?

Comparing Trend Vision One to other solutions, I've seen other vendors with complicated software requiring extensive training to understand. If software is that hard to learn, I don't find it to be a viable solution. Learning takes weeks or months, potentially creating holes in security instead of securing it.

What other advice do I have?

I would absolutely recommend Trend Vision One to other users because it's cost-efficient and it just works. It tells you what you need to do, alerts you of threats, and informs you about software needing updates. They have an IR team that is exceptional and works on the mitigation and remediation until all issues have been resolved!  Over time, it becomes easier to understand, especially moving from on-prem to cloud deployment; there's no comparison. 

I would rate the solution overall as a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud


    pranab1 p.

Best Product

  • June 27, 2025
  • Review provided by G2

What do you like best about the product?
Unified XDR Platform
Consolidates telemetry across endpoints, email, servers, cloud, network, identity, and more into a single pane of glass. This removes security silos and helps analysts connect the dots across alerts and incidents
What do you dislike about the product?
Complex & Time-Consuming Setup
Many users report that deploying and configuring the platform can feel overwhelming, especially if you're integrating it across multiple domains or environments. It often requires extensive customization and a solid technical grasp to optimize effectively
What problems is the product solving and how is that benefiting you?
Problem: Traditional security tools (endpoint, email, network, cloud) often operate in isolation, making it hard to connect the dots during attacks.

Solution: Trend Vision One unifies telemetry from multiple layers (endpoint, email, server, cloud, identity, network) into a single XDR platform.


    Insurance

Not refined completely, But capable

  • June 27, 2025
  • Review provided by G2

What do you like best about the product?
The features they offer is well and good
What do you dislike about the product?
The product is not fully redefined in the state where it works flawlessly
What problems is the product solving and how is that benefiting you?
finding the threats with xdr and edr makes the work easier


    Nana1 s.

Vision one - Unified strategy for a smarter future

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
Its easy to understand the console and Unified XDR Platform, Strong Detection & Threat Intelligence, Automation & Response Capabilities, Advanced Analytics & Risk Insights.
What do you dislike about the product?
Some Features Locked Behind Add-Ons,Performance Lag in Large Environments
What problems is the product solving and how is that benefiting you?
Too Many Alerts, Not Enough Context, Helps analysts focus on what matters most, Improved incident response time with a centralized view of threats.


    Samir M.

Effective malware protection

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
Trend Vision One boasts the widest native XDR sensor coverage in the market. This means it collects and correlates deep activity data not just detection data across a vast array of security layers.
What do you dislike about the product?
Some feedback suggests a lack of robust integration with Microsoft products, which can be a drawback for organizations heavily invested in the Microsoft ecosystem.
What problems is the product solving and how is that benefiting you?
Trend Vision One is designed to address a multitude of complex cybersecurity challenges that organizations face in today's evolving threat landscape. Here's a breakdown of the key problems it solves and the resulting benefits


    mayur m.

Best product

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
Trend Vision One, from Trend Micro, is a comprehensive cybersecurity platform designed to provide extended detection and response (XDR) across various security layers.
What do you dislike about the product?
1: 1. Steep Learning Curve,2. Complex Initial Setup, 3: 3. User Interface Limitations, 4: 4. Alert Noise (Without Fine-Tuning.
What problems is the product solving and how is that benefiting you?
Helping to fix Zero day vulnerability,


    Rakesh A.

Trend Micro Vision is a good Product

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
I’d say it’s the comprehensive, unified approach it offers to cybersecurity. It integrates multiple security layers—endpoint, network, cloud, and more—into a single platform, which really helps streamline threat detection and response. Plus, its advanced AI-driven analytics provide clear, actionable insights, making it easier for security teams to prioritize and tackle threats effectively.
What do you dislike about the product?
it might be that the platform’s complexity can sometimes feel overwhelming, especially for smaller teams or organizations without dedicated cybersecurity experts.
What problems is the product solving and how is that benefiting you?
Traditional tools often provide siloed views (endpoint, email, cloud, etc.). Trend Vision One unifies these into a single view, reducing blind spots.
Manual investigation is time-consuming. Trend Vision One uses AI and automation to speed up detection, investigation, and response (XDR).
With the rise of hybrid environments, protecting workloads and data in the cloud is more complex. Trend Vision One integrates cloud workload protection and posture management.


    Ashish C.

Excellent Product

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
User friendly and inbuilt security is Robust
What do you dislike about the product?
I do not think there is anything that I don't like about Trend Vision one.
What problems is the product solving and how is that benefiting you?
Email DLP


    sharath k.

Trend Vision One

  • June 24, 2025
  • Review provided by G2

What do you like best about the product?
Implemented Trend Vision One to unify threat detection and response across Endpoints, email, and cloud workloads. Its extensive feature set including XDR capabilities, risk visibility, automated response provided a centralized and proactive security measures. The customer support is highly reliable, technically sound and fast to act, especially during security incidents.
What do you dislike about the product?
As Vision One can generate a high volume of alerts, leading to potential alert fatigue without proper tuning. Some advanced configuration options lack in - depth documentation, which may slow down custom integration or automation.
What problems is the product solving and how is that benefiting you?
Trend Vision One consolidates alerts from endpoint email, network, and cloud into single view, helping SOC teams to respond faster. Contextual threat intelligence , correlating telemetry across environment helping identify hidden threats and stop lateral movement. Platforms feature of providing deep investigation and automated response across various vectors reducing Mean time to detect and respond. Sand boxing and behaviour based analytics helping the workload / ease the work of a Security admin.