Listing Thumbnail

    TrendAI Vision One™

     Info
    Sold by: Trend Micro 
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    Stop threats before they strike with TrendAI Vision One™ - the AI-powered enterprise cybersecurity platform built to predict, prevent, and respond to threats across AWS, hybrid, and multi-cloud environments. Gain unified visibility, streamline cloud risk management, accelerate cloud investigations, and empower your security teams with proactive, layered protection that works at cloud speed. Proactive security starts here.
    4.6

    Overview

    Play video

    TrendAI Vision One™ gives enterprises and security leaders the power to see, secure, and control their entire multi-cloud and hybrid environments from a single, unified platform. Gain complete visibility with real-time risk scoring, threat exposure mapping, and centralized monitoring all from one intuitive dashboard.

    Backed by AI, machine learning, and predictive analytics, TrendAI Vision One™ empowers proactive cloud security by automating threat detection, risk mitigation, and response. Streamline operations, reduce security complexity, and offload the pressure on your teams with modern CNAPP capabilities so you can stay ahead of every attack.

    Trusted by industry leaders and recognized as a 2024 Gartner Peer Insights™ Customers' Choice for CNAPP, Trend Vision One is proven to reduce operational costs by up to 79% and accelerate detection and response times by 70%. It's also a Leader in the 2025 Gartner® Magic Quadrant for Endpoint Protection Platforms, delivered a 100% detection rate in MITRE evaluations, and was named a Leader in the IDC MarketScape for Cloud-Native Application Protection Platforms 2025, solidifying its position as the most trusted platform for securing the cloud.

    Confidently secure your cloud transformation with a platform built for the modern enterprise. From hybrid to multi-cloud, TrendAI Vision One™ delivers unmatched protection, visibility, and control - wherever your workloads live.

    Trend provides custom pricing via Private Offer. Please contact us if you're interested in personalized pricing options.

    Highlights

    • Identify and eliminate hidden cloud risks with unified Cyber Risk Exposure Management - discover assets, prioritize vulnerabilities, and manage posture and attack surface all from one place.
    • Stay steps ahead of threats with XDR for Cloud, which extends visibility into cloud environments and streamlines SOC investigations through powerful correlation and alerting.
    • Secure every application and workflow - from containers and code to S3 files and cloud workloads - with holistic protection via the integrated stack: Container Security, File Security, Workload Security, and Code Security.

    Get personalized pricing in minutes - New

    If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (4)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    TrendAI™ Flex (credits)
    A credit-based licensing model that offers flexibility, simplifying purchasing, deployment, and management of Trend Vision One solutions.
    $1.00

    Additional usage costs (14)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Description
    Cost/unit
    Cyber Risk Exposure Management - Cloud Risk Management
    Per 500 resources per cloud account per hour
    $0.12
    Container Security
    Per Amazon ECS instance or Kubernetes node per hour
    $0.168
    Container Security
    Per serverless container pod or task per hour
    $0.017
    File Security SDK
    Per file scan
    $0.013
    File Security Storage
    Per cloud storage per hour
    $1.155
    Endpoint Security - Essentials
    Per workload (Anti-Malware, Web Reputation, and XDR only) per hour
    $0.007
    Endpoint Security - Small
    Per EC2 instance (micro to medium), WorkSpace, or other cloud (1 vCPU) per hour
    $0.011
    Endpoint Security - Medium
    Per EC2 instance (large), WorkSpace, or other cloud (2 vCPU) per hour
    $0.032
    Endpoint Security - Large
    Per EC2 instance (XL), WorkSpace, or other cloud (4 vCPU) per hour
    $0.047
    Endpoint Security - Non-Cloud
    Per data center or non-cloud instance per hour
    $0.047

    AI Insights

     Info

    Dimensions summary

    You buy this platform through a contract and mix independent security modules based on what you protect. Cloud Risk Management bills per 500 resources per cloud account per hour. Container Security bills per node, instance, pod, or task per hour. Endpoint Security scales by workload type and size, from Essentials through Small, Medium, Large, and Non-Cloud units. File Security bills per file scan or per storage per hour across several deployment options. XDR for Cloud bills per gigabyte ingested. TrendAI Flex uses credits, letting you purchase and allocate across solutions flexibly.

    Top-of-mind questions for buyers

    Each protected instance counts as one unit. Small covers EC2 instances from micro to medium, WorkSpaces, or other cloud with 1 vCPU. Medium covers large EC2 or 2 vCPU instances. Large covers XL EC2 or 4 vCPU instances. Essentials covers a workload with anti-malware, web reputation, and XDR only.
    You are billed separately for each type. Protected Kubernetes nodes or Amazon ECS instances meter per node or instance per hour. Serverless container pods or tasks meter per pod or task per hour. The two rates run independently, so your bill reflects the mix of container types you actually run.
    File Security SDK, Storage, Virtual Appliance, and Containerized Scanner all meter per file scan, so scan volume drives cost. Storage also offers per cloud storage per hour billing. Appliance and Containerized Scanner options add a per-scanner charge. You pick the deployment that matches where your files live.
    docs.trendmicro.com
    Helpful?

    Vendor refund policy

    No refunds

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Your purchase also includes 24x7 support from Trend Micro. You can log a support ticket for any issues directly from your TrendAI Vision One™ console. If you experience any issues or have questions, please contact our AWS Security experts by email at aws.marketplace@trendmicro.com .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Security
    Top
    10
    In Vulnerability and Patch Management, Data Governance
    Top
    25
    In Observability, Software Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Unified Risk Management Platform
    Centralized cyber risk exposure management with asset discovery, vulnerability prioritization, and attack surface management from a single dashboard
    Extended Detection and Response for Cloud
    XDR capabilities that extend visibility into cloud environments with correlation and alerting to streamline security operations center investigations
    AI-Powered Threat Detection
    Machine learning and predictive analytics for automated threat detection, risk mitigation, and response across multi-cloud and hybrid environments
    Comprehensive Application Security
    Integrated security stack covering container security, file security, workload security, and code security for end-to-end application protection
    Real-Time Risk Scoring and Monitoring
    Real-time risk scoring and threat exposure mapping with centralized monitoring capabilities across AWS, hybrid, and multi-cloud environments
    Attack Surface Management
    Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to provide 360-degree view of entire attack surface
    Vulnerability Management
    Delivers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities, misconfigurations, and risks
    Cloud Security
    Provides code-to-cloud protection for cloud-native applications with CI/CD pipeline integration and agentless risk assessment based on reachability, exploitability, and potential impact
    Next-Generation SIEM and XDR
    Delivers accelerated detection and response with SaaS deployment, out-of-the-box detections informed by MDR SOC, and built-in automation capabilities
    Threat Intelligence
    Delivers high-fidelity actionable threat intelligence infused with proprietary threat and vulnerability research from Rapid7 Labs and community-driven tools
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are truly reachable by outside attackers, reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    344 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    78%
    21%
    1%
    0%
    0%
    25 AWS reviews
    |
    319 external reviews
    External reviews are from G2  and PeerSpot .
    Kadir Yetiş

    Unified security has improved threat prevention and simplifies managing endpoints and email

    Reviewed on Sep 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for TrendAI Vision One is catching threats across all XDR channels like email, endpoint, Windows server, and Linux server, collecting the alerts so that we can defend against attacks using these channels.

    My main use case for TrendAI Vision One is the protection of server-side and email-side infrastructure, where we can use capabilities across all channels. We can prevent attacks and monitor endpoints, check reports, and review workbenches, alerts, and the MITRE attack framework.

    Prevention of attacks is more important than just catching threats. The deep security module with IPS protects servers from zero-day vulnerabilities. All alerts and prevention-related information are available in the report.

    TrendAI Vision One has different modules, such as the attack surface module, which enables me to see alerts from sites, networks, and email. I can manage my attack surface and understand how to protect internal data more easily with Trend Micro.

    What is most valuable?

    The best features TrendAI Vision One offers include strong endpoint protection, endpoint asset management, and the ability to monitor and respond to actions. It prevents issues from the email side and different channels, allows me to start antivirus protection, and makes managing endpoints, computers, and servers straightforward.

    TrendAI Vision One positively impacts my organization by providing a budget-friendly solution for security products. Since I am paying for security licenses, I can be confident in my protection with Trend Micro's monthly payment options, including managed detection and response for more secure protection.

    These features make my job easier because I can create my own directory structure, establish policies for different organizational units, and easily enable or disable different antivirus modules, such as scheduled scans or script protections, making management straightforward.

    What needs improvement?

    TrendAI Vision One can be improved in some areas. I wish the scan modules were better when it comes to patching and following critical zero-day threats. A different dashboard for security assessments would be beneficial and make the solution stronger.

    TrendAI Vision One needs additional improvements, but it is already very useful due to the AI and Trend Micro combination.

    For how long have I used the solution?

    I have been working with cybersecurity for five years.

    What do I think about the stability of the solution?

    TrendAI Vision One is very stable and easy to manage.

    What do I think about the scalability of the solution?

    The scalability of TrendAI Vision One is good and can support thousands of clients or servers.

    How are customer service and support?

    Customer support for TrendAI Vision One is very good, and we can reach the support portal and receive help easily.

    Which solution did I use previously and why did I switch?

    I previously used different solutions such as Symantec and Kaspersky, but they were less complex and provided fewer security modules compared to Trend Micro.

    What was our ROI?

    I have not explicitly calculated the money saved, but it is clear that using one solution on one platform combines the capabilities of different email gateways and network NDRs into one, which offers perhaps two to three times the cost-benefit for overall savings.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for TrendAI Vision One is that it is easy to manage, and we can take credits.

    Which other solutions did I evaluate?

    I evaluated other options such as CrowdStrike before choosing TrendAI Vision One.

    What other advice do I have?

    My impressions of TrendAI Vision One's ability to provide centralized visibility and management across protection layers are positive, especially regarding XDR, Deep Discovery inspection, and email inspection.

    TrendAI Vision One has helped consolidate my use of security vendors and reduced silos by providing email protection and MDR capabilities, making it very useful without the need to purchase numerous solutions.

    It is important for my organization that TrendAI Vision One has AI built into its platform because it enhances our security capabilities significantly.

    My organization uses TrendAI Vision One for consolidated security across hybrid environments, which has improved our ability to manage risk by offering solutions that protect both cloud and on-premises services.

    TrendAI Vision One has helped reduce my time to detect and respond to threats, though I do not quantify the exact reduction.

    My advice to others looking into TrendAI Vision One is that if it is important to manage email, attack surfaces, server-side IPS, and zero-day protection, it is the best choice with Trend Micro. I would rate this product an eight out of ten.

    reviewer2385126

    Centralized threat views have improved detection and response but support and AI still need work

    Reviewed on Aug 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We work for Tenable, AWS, Azure, GCP, and CrowdStrike, and we are also working on Trend Micro, though we are currently in a transition phase with a few Trend Micro products.

    We work on TrendAI Vision One as a customer. We are using TrendAI Vision One for overall threat management, including endpoint XDR, Apex Central, and Trend Micro web proxy, which is now ZTNA. Overall, I would say we use it from an overall threat management perspective.

    What is most valuable?

    I like that TrendAI Vision One is a single pane of glass, which gives me near real-time security posture information of my environment, and it correlates everything. Since we have most of our items on Trend Micro, it correlates logs and gives me a real security posture of my environment.

    TrendAI Vision One provides a single platform that gives me a deep dive of my environment. If I want to know something about any of my servers, I can go to the deepest level and see what software is installed and how it is working. The deep drill capability is something I really appreciate because I can exactly find out what I need. I also really like that it has more than 800 playbooks that are preventive.

    Whenever any type of attack or malicious activity occurs, they preventively work and block malicious activity. When I mention playbooks, whenever any threat activity is activated or just starts, they prevent it at the beginning. This definitely prevents and reduces my mean time to detect and mean time to respond.

    If something happens that I have not enabled any playbook, then it gives me an email and alert, and I have a SOC monitoring team that helps me respond to this. Overall, it helps a lot in both mean time to detect, mean time to prevent, and response.

    It has helped me to reduce silos, as it gives me visibility into what is inside my environment. Sometimes we provide admin access to users to do their jobs, and during that time, they install other software and many other things. TrendAI Vision One also discovers across my cloud because it has integration with cloud environments.

    Whenever I have some rules and configurations in place, if something is not discovered by IT and created by someone, it really helps me a lot to reduce the silos.

    What needs improvement?

    TrendAI Vision One is still struggling in some areas. There are a few false positives that are not actually false positives at all but have been reported multiple times to the Trend Micro team, and they have not been rectified, which is sometimes irritating.

    I would say TrendAI Vision One is expensive as of now because the competitive market in India has some better solutions at a lower cost.

    From the technical side, the innovation in TrendAI Vision One is less. When you configure it at the back end, for example, it says that it will run X and Y rules, but sometimes they do not work, and that happens across multiple places in the platform.

    The major disadvantages of TrendAI Vision One would be the CREM feature, the price being slightly pricey, and the backend rules sometimes having problems. There is one more thing to mention: support is not good.

    AI built into TrendAI Vision One is something that is a fancy feature, but they have not integrated it effectively.

    For how long have I used the solution?

    We have been using TrendAI Vision One since 2020, and during this time, it has changed. It has been with platform TrendAI Vision One, and then it became TrendAI.

    What do I think about the stability of the solution?

    TrendAI Vision One is stable.

    What do I think about the scalability of the solution?

    Scaling up and down with TrendAI Vision One is manageable.

    How are customer service and support?

    Support for TrendAI Vision One does not respond adequately. They respond, but they do not understand, and when they do understand, they do not resolve the issues. The support experience is inadequate.

    How was the initial setup?

    The installation of TrendAI Vision One is straightforward, and I have never faced any issues.

    What was our ROI?

    I would say that in the last four years since I joined this organization in 2021, as TrendAI Vision One has been innovated and matured, there is tremendous time savings, more than 50% saving of time when we conduct security activities.

    I would say the risk reduction from switching to TrendAI Vision One is quite good because we have everything integrated here. It is difficult to say in percentage, but the incidents have reduced significantly, achieving a coverage of about 7 to 8 out of 10.

    Which other solutions did I evaluate?

    TrendAI Vision One is more expensive than its competitors.

    What other advice do I have?

    There are a few false positives that are not actually false positives at all but have been reported multiple times to the Trend Micro team, and they have not been rectified. Sometimes these false positives are irritating and cause disruptions in the workflow. We are working with AWS and GCP. I have not purchased any TrendAI Vision One products from the AWS marketplace, as I think they have discontinued one product I purchased from AWS, which was Trend Micro Cloud Conformity. My overall review rating for TrendAI Vision One is 7 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Vivekkumar Jaiswal

    Centralized detection has reduced false positives and improves ransomware and email threat response

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    A common use case for TrendAI Vision One is ransomware detection and response, and we also use it for business email compromise. Our SOC team uses it for advanced threat hunting and insider threat detections.

    Recently, my team used TrendAI Vision One for ransomware detection and response when a user executed a malicious attachment, leading to the detection of suspicious process executions. TrendAI Vision One helps us by correlating emails with endpoints, identifying host details, network activity, user device activity, and infected sources, allowing for quick resolution of threats in the organization.

    We have also been using TrendAI Vision One for identifying suspicious or compromised emails and insider threat detections, which aids us in quickly identifying and investigating malicious emails.

    What is most valuable?

    TrendAI Vision One offers excellent extended detection and response capabilities through EDR and XDR solutions, as it is a complete package for organizational threat protection across email, endpoints, cloud networks, servers, and data centers. It helps us quickly identify attacks and provides deep insights into attacker movements as well as a centralized investigation workbench from a single dashboard.

    Having everything in one dashboard allows our SOC team to quickly identify details across the network or organization level, such as the number of created tickets, false positives, true positives, actions taken, SLAs, threat metrics, and attack path details. It reduces alert fatigue for SOC analysts by providing a consolidated view of all details across the organization.

    TrendAI Vision One has positively impacted our organization by identifying real-time threats and proactively isolating threats while alerting the SOC team for further investigations and remediation actions.

    Since implementing TrendAI Vision One, it has reduced noise from false positive alerts by 80% and enabled the SOC team to focus on true positives, thus improving incident response and operational efficiency. TrendAI Vision One is highly reliable; it provides centralized visibility across protection layers and is stable and scalable, making it a suitable solution for organizations looking for thorough threat detection and response capabilities.

    What needs improvement?

    I believe that if the reporting features of TrendAI Vision One could be improved, it would help SOC analysts retrieve comprehensive reports detailing true positive incidents, top email threats, quarantined emails, and common malware, enhancing our analytics capabilities.

    The TrendAI Vision One support system is not very good. They charge extra for premium support, while basic support does not adequately assist with investigations and troubleshooting. Improvements in this area are needed, and there should also be enhancements in third-party integrations to reduce alert noise and false positives.

    TrendAI Vision One's governance and security capabilities are excellent, and while the security is always very good, they can still improve on compliance and regulations.

    If they fix automated root cause analysis reports and AI-generated incident summaries, it can enhance capabilities further and reduce investigation times.

    For how long have I used the solution?

    I have been using TrendAI Vision One for more than two years.

    What do I think about the stability of the solution?

    TrendAI Vision One is stable.

    What do I think about the scalability of the solution?

    TrendAI Vision One is highly scalable as per our requirements, as user licenses can be improved if we have a greater number of users.

    How are customer service and support?

    The customer support is not very good, and they need to improve their premium license support.

    Which solution did I use previously and why did I switch?

    Previously we were using a different endpoint solution due to setup cost and support issues, so we switched to TrendAI Vision One for better SOC capabilities for threat detection.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing was very good. The top leadership is engaged in identifying pricing and licensing features, although licensing renewal is challenging and the setup cost can be high, but it remains manageable for quality solutions.

    Which other solutions did I evaluate?

    We evaluated other options such as FireEye Helix, Symantec, and Microsoft Sentinel during our assessment process.

    What other advice do I have?

    My advice to others looking into using TrendAI Vision One is to definitely proceed with this solution as it is a complete package for SOC teams regarding threat identification and remediation, although there is room for improvement in support. This review has a rating of 9.

    Niranjan Prajapati

    Integrated security platform has strengthened threat detection and improved risk prioritization

    Reviewed on Aug 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    In terms of the VDR, we are doing the Sophos entire solutions. We are doing the firewall, as well as endpoint, as well as email security.

    When it comes to SophosLabs Intelix or Sophos Cloud Optix, basically, we are working with Sophos XDR and MDR right now.

    As a partner, we have so many clients who are serving the Extended Detection and Response, and some users are just selling the Sophos Managed Detection and Response services. Basically, it's XDR, it's a tool, and MDR is managed by the Sophos security team 24/7. So, we are selling the Sophos MDR.

    On the firewall side, we are doing the Sophos firewall, SonicWall firewall, and FortiGate.

    We are dealing with Trend Micro for EDR and XDR.

    We have been doing this product for the last 10 years, actually. Ten plus years we have been doing this product—Sophos entire solution and Trend Micro entire solution. Trend Micro has so many products, including anti-APT and IDS, IPS device.

    For TrendAI Vision One, I have many corporate users who are using it for their servers' security, as well as the IDS, IPS device and TippingPoint, SMS gateway, and so on.

    TrendAI Vision One has core features, such as endpoint, email, identity, servers, cloud workloads, and networks. When we talk about endpoint security, it includes anti-malware, anti-ransomware, behavioral analysis, exploit protections, device control, application control, post firewall, and EDR capabilities for the threat investigation and response. These are the TrendAI Vision One features.

    Regarding TrendAI CReM capabilities, the threat hunting includes searching across telemetry data, IOC sweeping, root cause analysis, and advanced investigation tools. When we talk about the CReM features, they provide visibility into endpoints, server, cloud workloads, and identities. They help to identify unknown or exposed assets in the environment, then asset discovery, vulnerability management, and attack surface management.

    My impressions of TrendAI Vision One include risk prioritization analysis, security posture, and assessment. Right now, I am working with Sophos in Sophos XDR.

    I just appreciate the Sophos server protection and its lockdown features. When I whitelisted some applications, other executable files or any files do not run in the environment. I compare Sophos EDR with Sophos XDR, Endpoint Detection and Response, and Extended Detection and Response. When we're going with Sophos XDR, they have email, identity, firewall, cloud, and any third-party integrations.

    I am focusing on the Sophos product, but as per the client requirement, I recommend Sophos because the clients are using a parameter gateway with a Sophos firewall. I pitch Sophos because they enable Heartbeat security, so the firewall and endpoint communicate effectively. It's a good bundle when combining Sophos firewall with Sophos endpoint.

    Some users using Sophos require on-premises solutions and do not move to the cloud. So many reasons exist for this, which is why we pitch server solutions. Trend Micro server protection is a really good product, but my query always relates to support; I cannot get immediate support from Trend Micro.

    What is most valuable?

    For TrendAI Vision One, I have many corporate users who are using it for their servers' security, as well as the IDS, IPS device and TippingPoint, SMS gateway, and so on.

    TrendAI Vision One has core features, such as endpoint, email, identity, servers, cloud workloads, and networks. When we talk about endpoint security, it includes anti-malware, anti-ransomware, behavioral analysis, exploit protections, device control, application control, post firewall, and EDR capabilities for the threat investigation and response. These are the TrendAI Vision One features.

    Regarding TrendAI CReM capabilities, the threat hunting includes searching across telemetry data, IOC sweeping, root cause analysis, and advanced investigation tools. When we talk about the CReM features, they provide visibility into endpoints, server, cloud workloads, and identities. They help to identify unknown or exposed assets in the environment, then asset discovery, vulnerability management, and attack surface management.

    I appreciate the Sophos server protection and its lockdown features. When I whitelisted some applications, other executable files or any files do not run in the environment. I compare Sophos EDR with Sophos XDR, Endpoint Detection and Response, and Extended Detection and Response. When we're going with Sophos XDR, they have email, identity, firewall, cloud, and any third-party integrations.

    I am focusing on the Sophos product, but as per the client requirement, I recommend Sophos because the clients are using a parameter gateway with a Sophos firewall. I pitch Sophos because they enable Heartbeat security, so the firewall and endpoint communicate effectively. It's a good bundle when combining Sophos firewall with Sophos endpoint.

    What needs improvement?

    From my perspective, the only disadvantage in TrendAI Vision One is the support size.

    The support takes too much time. When I email, I have to collect logs and submit them to the engineer, then wait for their reply. It takes too much time. The product is really good, but the support is not good in my perspective since it takes too long to receive help, especially when all the devices are in production.

    The price is high when compared to the features. After installing the product, support is always required. Whenever we deploy any product, we need support, especially if an issue arises, support is a must.

    We face lots of challenges, but the product itself is good. The main issues arise from support.

    Some users using Sophos require on-premises solutions and do not move to the cloud. So many reasons exist for this, which is why we pitch server solutions. Trend Micro server protection is a really good product, but my query always relates to support; I cannot get immediate support from Trend Micro.

    Trend Micro is a really good product, but I face challenges when not getting proper support; hence I feel helpless at times. The product itself is really good; I have no doubts about that.

    For how long have I used the solution?

    We have been doing this product for the last 10 years. Ten plus years we have been doing this product—Sophos entire solution and Trend Micro entire solution.

    How are customer service and support?

    The support takes too much time. When I email, I have to collect logs and submit them to the engineer, then wait for their reply. It takes too much time. The product is really good, but the support is not good in my perspective since it takes too long to receive help, especially when all the devices are in production.

    From my perspective, the only disadvantage in TrendAI Vision One is the support size. Sophos support is really good, but when I require immediate support from Trend Micro, it is a challenge.

    How was the initial setup?

    TrendAI Vision One is easy; deployment is not a problem.

    What other advice do I have?

    We are dealing with Trend Micro for EDR and XDR.

    My impressions of TrendAI Vision One include risk prioritization analysis, security posture, and assessment. Right now, I am working with Sophos in Sophos XDR.

    When we talk about the CReM features, they provide visibility into endpoints.

    I would rate Trend Micro support a six to seven, possibly seven to eight.

    The interface and everything are good; my only query is on the support, which is not good from my perspective.

    Some limited corporate users and some government users choose Trend Micro instead of Sophos.

    Trend Micro is a really good product, but I face challenges when not getting proper support; hence I feel helpless at times. The product itself is really good; I have no doubts about that.

    I would rate this review an eight overall.

    Alex-Chen

    XDR dashboard has unified threat response and has reduced false-positive noise across endpoints

    Reviewed on Jul 31, 2026
    Review from a verified AWS customer

    What is our primary use case?

    TrendAI Vision One, the XDR platform, includes endpoint protection, EDR, mail protection as a mail gateway, mail access, and access integration with API for Office 365 and Google Workspace. The endpoint protection and mail protection features work seamlessly, and integration with cloud solutions is very simple.

    The solution provides endpoint protection, identity protection, mail protection, and XDR workbench solution with automatic playbooks all in one dashboard. TrendAI Vision One has been a historic solution from my previous work, which is the reason I chose it. It is one piece of the solution focused on XDR with an EDR agent and sensor agent. Sensor agents provide information about the endpoint, which demonstrates how critical this coverage is for my company network.

    What is most valuable?

    The product is very helpful for responding to threats and helps reduce time to detect and time to respond to threats significantly. It helps reduce noise from false positives, although you need to work with the system continuously to manage exclusions and manage the suspicion object list. There are false positives in mail, but under these managed conditions, the noise is reduced by approximately forty percent of the time.

    Even though it is expensive, it helps consolidate the use of security vendors and reduce silos. TrendAI Vision One provides one dashboard that can be used for many things, and it is also a network monitoring solution.

    What needs improvement?

    The agent for endpoints is very large and not easy to install, which is a significant disadvantage of the product. It is not one agent; you need to install two agents, and sometimes you have connectivity problems when installing and connecting to the XDR server, which presents a challenge during the installation process.

    TrendAI Vision One is not a cheap system and is very expensive when considering value for money and return on investment. It is possible to track any ROI with TrendAI Vision One. The two main problems are that the endpoint agent is very large and the price is very expensive. Apart from these problems, everything else functions well.

    For how long have I used the solution?

    I started using TrendAI Vision One five or six years ago.

    What do I think about the stability of the solution?

    I would rate the stability of the product as seven out of ten, where ten points represents very stable. I think the agent is very heavy, which is why I rate it seven.

    What do I think about the scalability of the solution?

    TrendAI Vision One is not optimized for scalability, where ten points represents very easy to scale up, and this is not my use case. I never had a chance to scale it.

    How are customer service and support?

    I am very happy with the customer support and customer service from TrendAI. I work closely with the Israel team, and it is very helpful. I would rate support as ten out of ten points.

    Which solution did I use previously and why did I switch?

    I have not worked closely with any similar products to TrendAI Vision One. I have the most experience with TrendAI, and with other products, not as much.

    What was our ROI?

    TrendAI Vision One is not a cheap system and is very expensive when considering value for money and return on investment. It is possible to track any ROI with TrendAI Vision One.

    What other advice do I have?

    TrendAI Vision One is an established solution and not new. The TrendAI Vision One XDR solution has a new name, but I continue to work with it. I have not been using the Cyber Risk Exposure Management, CREM capability.

    AWS and GCP are the cloud providers I am using. I did not purchase any TrendAI products from the AWS marketplace. I was working with TrendAI Vision One sensors.

    I do not know how much risk was reduced by switching to TrendAI Vision One platform. I know they have an AI model, but I do not use it currently because I do not need it.

    My overall review rating for this product is eight out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews