Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Trend Vision One™

Trend Micro

Reviews from AWS customer

14 AWS reviews

External reviews

273 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    reviewer2735652

Helps secure endpoints and quickly respond to incidents

  • July 04, 2025
  • Review provided by PeerSpot

What is our primary use case?

Our use cases for Trend Vision One are monitoring and alerts.

How has it helped my organization?

The biggest challenges we wanted to address with Trend Vision One were securing endpoints and enabling us to quickly respond to incidents or threats. This is the main goal for using this solution.

Trend Vision One has improved the way our organization functions by acting as both a monitoring tool and an antivirus, giving us insight on potential threats and enhancing our response time to security incidents. It is hard to measure the time savings but we save a significant amount of time in responding to potential threats. For example, we don't expect employees to respond to emails, chat, or calls outside of working hours. Trend Vision One has a feature where we can block all access to the laptop or endpoints. It allows us to take immediate action without waiting for the user to respond.

In terms of reducing noise from false positives, unfortunately, some behaviors can be mistaken for bad behaviors, but that isn't the fault of the software itself. It largely depends on how the developers of other applications implement their software and how it is run. We encountered an issue with another software called Rapid7, which periodically runs a command on MacBooks or Apple operating systems. This command, which is quite lengthy, searches for any unsecured credentials or API keys related to GitHub on the laptop. The way the application triggers is significant: it runs under root privileges, executing that command in the terminal for the user. Trend Vision One picks this up as a suspicious command, interpreting it as an attempt to find unsecured credentials. Despite having whitelisted the entire command in Rapid7, Trend Vision One still flagged it. We went back and forth on this issue, but ultimately we decided that it wasn't worth further troubleshooting to silence this alert due to the potential for actual malicious use of such commands. While we could whitelist it, we did not want to risk it being exploited maliciously. In the end, we chose to ignore the alert. They helped us reduce some other noise, but there was some noise that we weren't able to reduce.

Vision One AI has been very useful. All IT people stay up to date with security risks, exposures, alerts, or attacks. Vision One AI helps us explain or understand the alerts and what actions are recommended.

What is most valuable?

The workbench alerts are something we find very useful, as they help us stay informed about various activities. Not all alerts are positive, but they provide valuable insights into the detection methods and help us understand how certain issues arise. For example, if someone attempts to run a piece of software that encrypts a file, one of our tools, which is used for evidence gathering in surveillance systems, may encrypt the file too quickly. As a result, Trend Vision One may trigger an alert. Although this is a false positive, it still gives us insight into the behavior involved. This allows us to investigate the alert further and provide feedback to the user or development team, letting them know that similar triggers are likely to occur with other security systems or software.

Other useful features include intrusion and mailbox alerts, suspicious unauthorized access, tracing logs, website clicks, and email filtering for bad attachments.

What needs improvement?

The improvement I have been asking for is an easier way to create MDR requests. Not all alerts that come through Trend Vision One receive an investigation, and we would like the ability to easily request an investigation on lower-scored alerts without logging into the support portal to create a ticket.

I would like to see Trend Vision One and OfficeScan consolidated into one platform. Currently, it is the same space but two different layers. It would be nice to have both combined instead of having two clients.

There is room for improvement when it comes to support.

For how long have I used the solution?

I've been working with Trend Vision One for three years.

What do I think about the stability of the solution?

Trend Vision One is stable enough. We don't see many performance impacts on our endpoints, except for when our weekly scheduled scans happen. Our developers express that it limits how freely they can develop, but I personally appreciate the insight it gives us and the actions that allow us to take on our devices.

How are customer service and support?

I would rate their support a six out of ten. We encountered an issue with one of our tools—specifically, Visual Studio. One of our developers faced difficulties debugging code because Trend Vision One was blocking the debugging application or causing it to crash. This problem stemmed from a Windows update, and it took us a month and a half to identify the root cause. After we opened a ticket either at the end of March or early April, we waited several more weeks for a solution. Although the Windows update occurred back in February, we didn’t receive the fix until the end of May. The interaction between Windows and the application played a significant role in the issue, as the debugging application starts the code and injects itself into the running application, which Trend Micro flagged as problematic after the latest Windows update. Fortunately, this issue has now been resolved, but it was indeed a painful experience. Our developers were understandably frustrated that they couldn’t debug code for a month and a half, which impacted our project timelines.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

The company previously had SentinelOne before my time, and I can say that SentinelOne was not effective.

We currently use Rapid7 as our Managed Detection and Response (MDR) service. In my experience, both Rapid7 and Trend Vision One serve similar purposes, but they have distinct differences. There are times when Rapid7 provides us with more detailed information, while at other times, Trend Vision One offers greater insights. This is partly because Trend Vision One collects more data from the devices, allowing it to better identify the root causes of alerts compared to Rapid7.

Additionally, I find that the MDR team at Trend is generally more responsive than that of Rapid7. However, there are some disadvantages as well. For instance, we haven't yet set up cloud monitoring capabilities with Trend Vision One. Rapid7 currently handles our cloud infrastructure monitoring and manages services like Office and Okta. While Rapid7 is equipped to monitor these services, Trend Vision One is not yet at that level. We are exploring ways to enhance its capabilities, and if it can provide the same level of service as Rapid7, we might consider discontinuing our use of Rapid7 altogether.

How was the initial setup?

We use the SaaS solution. I was not involved in the initial setup and deployment process, which occurred prior to my time here, but I have readjusted some policies.

Previously, it was difficult to understand some alerts. However, as time goes by, we differentiate better between them, and the AI feature is an extremely good tool that explains things that are gibberish to the regular user. The learning curve is quite steep.

What was our ROI?

It has helped us understand some of the alerts that we did not comprehend.

What other advice do I have?

It is an all-around solution that includes various modules for comprehensive security monitoring and alerting. This solution is particularly effective when integrated with other hardware or on-premises solutions, such as Deep Discovery Inspector, which monitors your network.

The interface is adequate, but it is constantly changing. New features are being added, and items are being rearranged almost daily. We might have missed some announcements regarding these frequent updates. As it is an evolving solution, such changes are to be expected. However, there are still features that are buried within menus, which previously required extensive searching to locate. For instance, until last year, isolating endpoints was only possible through the search function. Now, they have added a feature within the endpoint inventory that allows you to select devices and isolate them immediately, rather than having to jump through multiple hoops to access that option.

The application has also become slightly more responsive. Regarding its functionality, the insights it provides are quite useful. The application displays various actions, and you can drill down into alerts to view the execution path associated with them. For example, if an application triggers an alert, you can right-click on that alert and select "Check Execution Profile." This feature shows you where the process started, what actions it took, and where it ended. This improvement is beneficial for understanding how tasks are executed.

I would rate Trend Vision One an eight out of ten.


    pranab1 p.

Best Product

  • June 27, 2025
  • Review provided by G2

What do you like best about the product?
Unified XDR Platform
Consolidates telemetry across endpoints, email, servers, cloud, network, identity, and more into a single pane of glass. This removes security silos and helps analysts connect the dots across alerts and incidents
What do you dislike about the product?
Complex & Time-Consuming Setup
Many users report that deploying and configuring the platform can feel overwhelming, especially if you're integrating it across multiple domains or environments. It often requires extensive customization and a solid technical grasp to optimize effectively
What problems is the product solving and how is that benefiting you?
Problem: Traditional security tools (endpoint, email, network, cloud) often operate in isolation, making it hard to connect the dots during attacks.

Solution: Trend Vision One unifies telemetry from multiple layers (endpoint, email, server, cloud, identity, network) into a single XDR platform.


    Nana1 s.

Vision one - Unified strategy for a smarter future

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
Its easy to understand the console and Unified XDR Platform, Strong Detection & Threat Intelligence, Automation & Response Capabilities, Advanced Analytics & Risk Insights.
What do you dislike about the product?
Some Features Locked Behind Add-Ons,Performance Lag in Large Environments
What problems is the product solving and how is that benefiting you?
Too Many Alerts, Not Enough Context, Helps analysts focus on what matters most, Improved incident response time with a centralized view of threats.


    Samir M.

Effective malware protection

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
Trend Vision One boasts the widest native XDR sensor coverage in the market. This means it collects and correlates deep activity data not just detection data across a vast array of security layers.
What do you dislike about the product?
Some feedback suggests a lack of robust integration with Microsoft products, which can be a drawback for organizations heavily invested in the Microsoft ecosystem.
What problems is the product solving and how is that benefiting you?
Trend Vision One is designed to address a multitude of complex cybersecurity challenges that organizations face in today's evolving threat landscape. Here's a breakdown of the key problems it solves and the resulting benefits


    Ashish C.

Excellent Product

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
User friendly and inbuilt security is Robust
What do you dislike about the product?
I do not think there is anything that I don't like about Trend Vision one.
What problems is the product solving and how is that benefiting you?
Email DLP


    Kushal H.

Good product

  • June 24, 2025
  • Review provided by G2

What do you like best about the product?
Trend Vision One assists organizations in comprehending, prioritizing, and mitigating their cyber risk exposure through ongoing monitoring, predictive functionalities, and practical insights. This process encompasses the identification and prioritization of vulnerabilities and misconfigurations.
What do you dislike about the product?
Policy Deployment Speed: There have been mentions that applying or deploying policies to endpoints can take a longer time (e.g., 10-15 minutes) than desired, which can be frustrating for administrators.
What problems is the product solving and how is that benefiting you?
Comprehensive XDR (Extended Detection and Response,
Faster Detection and Response:


    fattesinh D.

Trend Micro Vision one review

  • June 24, 2025
  • Review provided by G2

What do you like best about the product?
Good Advanced Threat Detection with XDR-Excellent for tracking lateral movement and multi-stage attacks, Strong Integration Capabilities,
User-Friendly Interface & Reporting & Gives security teams a single pane of glass view
What do you dislike about the product?
Require more stability & more enhancement
What problems is the product solving and how is that benefiting you?
Problems Solved by Trend Vision One-Alert Fatigue,Slow Incident Response,Limited Visibility into Advanced Threats & Compliance & Reporting Challenges.
Benefits -Faster, more accurate threat detection and response,Reduced workload for SOC teams,Improved security posture across hybrid environments & Proactive defense against zero-day threats and ransomware.


    Venkatachalapathi N.

Good experience using Vision One XDR

  • June 10, 2025
  • Review provided by G2

What do you like best about the product?
We are using multiple solutions from Trend micro. we upgraded to the XDR last year, the implementation was fairly easy and found it to be useful in our day to day operations. Good thing we saw was the features has increased from the time we have onboarded the solution.
What do you dislike about the product?
Can improve technical support Turn around time
What problems is the product solving and how is that benefiting you?
We wanted a central visibility for email & endpoint security. This solution has solved exactly that without much changes in the environment


    Michal Panszczyk

Centralized management and quick threat response improve security posture

  • May 20, 2025
  • Review provided by PeerSpot

What is our primary use case?

My use cases for Trend Vision One are typically reactive, letting it scan and monitor our environment, and we typically respond quickly to any workbenches that come up.

We also try to adapt to the Cyber Risk Index or the security score, keeping that at the lowest amount possible on a weekly or bi-weekly basis as we push out updates and do maintenance.

What is most valuable?

My favorite features in Trend Vision One include the Cyber Risk Index, which breaks down various pieces of info into one easily digestible score. I appreciate the workbenches. They provide a visual of how they operate for the most part, and I value the in-depth details they offer since we can mostly operate off of that, giving us enough info to crunch and figure out what's happening.

While it's not an actual feature of the application, I appreciate the clinics and seminars that Trend provides, as I went to one last year that got me from zero to beginner, and I hope to advance to intermediate with another seminar series this year.

Trend Vision One helps reduce my mean time to detect and respond to threats as without it, we would be scrambling and confused with not much information to go off of for threat hunting. I'm not sure what we were using previously. As long as I've been here, it's been Trend Vision One, and we're very happy with it. We're hesitant to shop around for any other provider since we think it's a very good product, and we appreciate the speed and breadth of data we receive from it.

I sometimes see noise from false positives with Trend Vision One. One clear instance involved the AI deep fake feature, which would throw up false positives whenever someone had a Teams meeting with a blurred background, leading us to turn it off as it activated for every meeting. Additionally, there were minor false positives throughout the year related to Microsoft update files and certain DLLs, however, they don't clutter Trend Vision One much and have essentially gone away in recent months.

I am very happy with Trend Vision One's platform ability to provide centralized visibility and management across protection layers. The platform extends into various categories, offering oversight over email and even flagging suspicious activities that occur on a server, despite not having a Trend Vision One agent on it. For instance, an admin setting up remote access on that server was flagged as suspicious, and I appreciate the reach that Trend Vision One has across different scattered categories it monitors.

What needs improvement?

In terms of improving Trend Vision One, it might sound silly, yet it seems notoriously uncooperative with middle clicks and opening sections in new tabs. I'm a big tab browser, and it feels hitting a brick wall when I have to refresh in a new tab or make a copy of a tab to move forward. If we can enable middle clicks to open sections in new tabs, it would greatly benefit me personally.

For how long have I used the solution?

I've been using Trend Vision One for a few months, approximately eight to ten months at this point.

What do I think about the stability of the solution?

Regarding stability, I don't think Trend Vision One has ever caused any lagging, crashing, or downtime. There was one situation where we may have misconfigured something, forgetting a checkbox, and Trend Vision One's scheduled scans might have used some CPU resources, however, that's on our end. Besides that, Trend Vision One works exactly as intended and has never hindered our operations, feeling more a collaborator than a roadblock.

What do I think about the scalability of the solution?

I don't think I've encountered any issues with scalability; we're growing steadily, and I believe Trend Vision One can keep up with our demand. Our company has about 200 employees in Canada, and I can foresee that if we doubled in size, Trend Vision One would accommodate that very easily.

How are customer service and support?

I have contacted the technical support before. We're very happy with the technical support from Trend Vision One, feeling we have our own dedicated technician who knows the entire suite of applications. They are very intelligent and responsive, and as we submit feature requests, they seem to make it into the actual list of features in Trend Vision One, so we maintain a good relationship with their technical support and development teams.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I'm not sure what we were using previously. As long as I've been here, it's been Trend Vision One, and we're very happy with it. We're hesitant to shop around for any other provider as we consider it a very good product.

How was the initial setup?

The experience of first using Trend Vision One is really difficult due to the steep learning curve. Thankfully, I attended a Trend Vision One seminar that got me from zero to beginner, as without that, it involves a lot of guesswork with little grounding to go off of. I really recommend their seminars and tutorials.

What's my experience with pricing, setup cost, and licensing?

I do not know much about the pricing of Trend Vision One. My understanding is it's expensive. We pay for it anyway, and there's always sticker shock. Still, we feel it's necessary as this product covers all our needs.

Which other solutions did I evaluate?

We're hesitant to shop around for any other provider. Trend Vision One is a very good product, and we appreciate the speed and breadth of data we receive from it.

What other advice do I have?

I'm not sure if I use the cyber risk exposure management capabilities. Trend Vision One requires very little maintenance on my end, mostly just keeping up with refreshing the license, which is about all I hear related to Trend Vision One maintenance.

Some top security challenges in my industry include securing anything exposed to the internet, especially since we were previously hit with ransomware. The ability of Trend Vision One to detect and cut off threats early, clean up files before they execute, and address phishing emails helps us significantly. We also have their email and collaborative security, which is crucial along with having zero-day protections to receive early warnings of threats, allowing us to act immediately outside our maintenance windows.

I'm not completely sure where we use the Trend Vision One sensors, as I didn't set them up. However, we do have a DDI that we paid a lot for, which is one of our biggest data sources and populates much of the information in Trend Vision One. We also have a network sensor at our different location in the United States, which is a temporary holdover until we can upgrade to something more robust.

It's not critical for my company that Trend Vision One has AI built into its platform in terms of needing a language model to explain things, however, AI is actually critical for threat detection and behavioral analysis. That aspect of behavior monitoring and action based on behavior is very important.

Trend Vision One has helped my organization reduce its cyber risk. For instance, even prior to acquiring the DDI, the DDI's presence on our network found a threat actively in progress, and we were able to act on it, demonstrating its effectiveness from day zero.

On a scale from one to ten, I would rate Trend Vision One a nine overall.


    reviewer2706279

Centralized visibility improves threat detection and response

  • May 16, 2025
  • Review provided by PeerSpot

What is our primary use case?

Our use case for Trend Vision One is for our security platform. We use it for antivirus, XDR, and network telemetry purposes.

How has it helped my organization?

Trend Vision One helped us to consolidate our use of security vendors and reduce silos. We had three or four consoles from different products, and we consolidated them into one console with this product.

Trend Vision One helped reduce the time to detect and respond to threats by 70% to 80%.

Trend Vision One has helped us reduce noise from false positives.

We have been using cyber risk exposure management for 2 months since upgrading in April. It helps us identify blind spots by providing more visibility and insights into our environment, making it a valuable feature.

We use the network sensor, and its coverage is critical. With SIEM, we gain substantial insights into our environment, and having a complete 360 view is necessary in today's security world. It reduces the risk by 50%.

Having AI built into the Trend Vision One platform is important for our organization. It reduces many manual steps, resulting in more and quicker detections and advanced automation for remediation, improving efficiency by 60% to 70%. The solution aims to reduce risks and enhance detection.

What is most valuable?

I like how easy it is, and there is a single pane of glass. We have one console for everything.

Trend Vision One provides centralized visibility and management across protection layers. It has the functionality of different products and management of a single pane of glass. We have one console for everything. As a security engineer, it's easier to check the alerts and find everything. It consolidates a lot of consoles into one, and that's what we like most about it.

What needs improvement?

Vulnerability scanning could be improved. They need to see more CVEs and scan products for known vulnerabilities, allowing for better display and review of potentially exploitable servers by hackers or through configuration settings.

For how long have I used the solution?

We have been using Trend Vision One for approximately 18 months.

What do I think about the stability of the solution?

We haven't experienced any stability issues. It has proven to be stable.

What do I think about the scalability of the solution?

The scalability of Trend Vision One is good.

How are customer service and support?

I have contacted technical support from Trend Micro. The quality and speed of support are good.

How would you rate customer service and support?

Positive

How was the initial setup?

It was easy. It took us one day to fully deploy Trend Vision One.

Some maintenance is required for updating agents on the servers.

What about the implementation team?

The deployment involved just one person working with the vendor in one day.

What was our ROI?

Trend Vision One has reduced risks by 50%. We have reduced the response time by approximately 70%-80%.

What's my experience with pricing, setup cost, and licensing?

When we have a good product such as Trend Vision One, the price is fine.

Which other solutions did I evaluate?

We have used Trend Micro products for many years, and we upgraded to Trend Vision One. We didn't test any alternatives, staying with what we've used for years.

What other advice do I have?

I would rate Trend Vision One an eight out of ten.