Cortex XDR (formerly Traps) replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.
N/A
Trend Micro Deep Discovery
Score 10.0 out of 10
N/A
Trend Micro Deep Discovery is a family of advanced threat protection products that enables users to detect, analyze, and respond to today’s stealthy, targeted attacks. Deep Discovery blends specialized detection engines, custom sandboxing, and global threat intelligence from the Trend Micro Smart Protection Network, boasting a high detection rate against attacks that are invisible to standard security products. Deployed individually or as an integrated solution, Deep Discovery works with Trend…
In a scenario where EDR is a requirement or necessity XDR performs well with or without a SIEM. There are millions of events and logs to parse through and XDR is capable of handling the large load. On top of the large data that is being parsed, features such as Live Terminal, File Retrieval, OS support, and general Metrics, the tool has room to grow and provide a lot for a Security team or organization. Incident Response is a great example of how XDR can shine
If you are using TrendMicro IMSVA then [Deep Discovery Email Inspector] is a must-have add-on. This is the most comprehensive email security protection you will need. However, if you want next-gen email security like reactive security like where the email is deleted from the user inboxes once the analysis determines that the email is phishing after it is delivered. Then this is not what you are looking for.
We encountered some glitch in a certain version of the agent. When we deployed newer version, the policy set on the previous version was white-listed/overwritten.
Moving to encrypted based connection (communication between agent to server) is troublesome, coz we need to uninstall the agent first.
Need to have a more flexible reports/dashboard where we can customize it
We feed Traps log to our SIEM, however the information sent to the SIEM was not complete, but we need to investigate more probably some faults are on us
Cortex XDR does a very good job of blocking suspicious and threatening items. However, as with all software of this nature, it will sometimes block known-good items. The difficulty is in manually whitelisting these known-good items. The interface to whitelist is confusing even for a seasoned IT professional and has been the single most frustrating experience of using Cortex XDR
The support we receive from Palo Alto is one of the best aspects of Traps. It is very easy to recommend their support. It seems much easier to connect directly with someone with a deep understanding of the product rather than other companies where you basically have to make an airtight case that it is some kind of non-standard issue that can't be solved with existing documentation. Palo Alto digs deep and helps with advanced troubleshooting to get things working.
Traps provided us with a cloud-based platform that made our lives a lot simpler. Nothing like Traps exists in the market and I've never used anything like it. Others, on the other hand, were a lot slower to respond. Malwarebytes and other enterprise-level malware software are also available, but they do not fall under the same heading.
When you use Trend Micro Deep Discovery, it feels like you are running the SOC team of a company like Trend Micro in your own office. Other companies can also provide this, but the feeling it gives feels like they are providing service by phone from a distant city.