Try our new research platform with insights from 80,000+ expert users

NetWitness NDR vs Trend Vision One comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 15, 2024
 

Categories and Ranking

NetWitness NDR
Ranking in Endpoint Detection and Response (EDR)
50th
Ranking in Network Detection and Response (NDR)
15th
Ranking in Extended Detection and Response (XDR)
28th
Average Rating
8.0
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (53rd), Threat Intelligence Platforms (24th), Security Orchestration Automation and Response (SOAR) (22nd)
Trend Vision One
Ranking in Endpoint Detection and Response (EDR)
4th
Ranking in Network Detection and Response (NDR)
3rd
Ranking in Extended Detection and Response (XDR)
7th
Average Rating
8.6
Number of Reviews
48
Ranking in other categories
Attack Surface Management (ASM) (3rd)
 

Featured Reviews

SupravatMaji - PeerSpot reviewer
Jun 23, 2022
Beneficial single unified dashboard, good native application integration, and high availability
The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good RSA NetWitness Network could improve on integration with non-native application…
GF
Dec 12, 2023
Provides centralized visibility, alerts us of potential risks, and enhances security posture
Trend Vision One streamlines our security by centralizing data collection and threat management. It pulls data from Exchange, SharePoint, endpoints, and servers to the cloud, providing a unified view of our IT environment. This centralized data feeds into advanced playbooks that automatically block URLs and files based on predefined conditions, reducing our reliance on manual intervention. For potential threats requiring further analysis, Vision One flags them for human review, allowing security personnel to quickly approve or deny access to specific URLs or files. These decisions then inform the suspicious object lists used across all deployed Trend Micro products, maximizing our overall security posture. In short, Vision One effectively automates routine tasks while empowering security teams to focus on critical decisions, making it a valuable asset for our organization. Vision One grants us centralized visibility and management across our protection layers. With its ongoing development, Trend Micro has steadily consolidated this visibility into a single pane of glass. Centralized visibility significantly improves our efficiency. Instead of scouring endpoints or hopping between the mail server and data lake, we can consolidate our search for malicious activity into one central location. Vision One empowers us to leverage comprehensive search parameters and scan all data within the data lake, not just data limited to specific products. For me, the executive dashboard is always the first one I check. Then, I turn to the operations dashboard for a more detailed look. These two dashboards provide a comprehensive overview of our security posture, drawing data from internal and external assets, application agents without vulnerability assessments, and detected account compromises. Vision One also excels at alerting us to potential risks, including accounts exposed to data breaches. I've personally experienced this when the executive dashboard's risk score suddenly spiked due to flagged accounts. After investigating and confirming the risk, we dismiss the alert and the score adjusts accordingly. The attack surface risk management capability has identified several vulnerability issues in external assets, necessitating immediate action. It has also shed light on blind spots within our environment. When we identify blind spots, we need to implement measures to address them and mitigate, reduce, or even eliminate the associated risk from our environment. Our team is relatively small, so dedicating someone to focus intensively on a single issue can be challenging. Vision One has alleviated this burden. Vision One's playbook and built-in automation features help us by proactively alerting us to issues requiring immediate attention, enhancing our overall security posture. Vision One offers a feature where, if it detects a phishing email with high confidence, it automatically locks the email, removes it from the Exchange database, quarantines it, and disables any links within the email or similar emails. For emails requiring human intervention or immediate action, Vision One flags them for review. We can then approve or deny the actions on the URLs and emails within the system. We use Vision One as a secondary measure if something slips through our other security layers. It allows us to see exactly what happens when users click on a malicious link, even if it wasn't flagged beforehand. To some extent, Vision One helps us reduce the time we spend investigating false positive alerts generated by our firewalls. While firewalls throw out many alerts, I often turn to Vision One for clients flagged as compromised. Jumping over the firewall report, I check Vision One's insights on those specific endpoints and the sites flagged by the firewall. Previously, I'd spend time on the machine itself, sifting through cookies and deleting temporary files to track the source of the suspicious traffic. But with Vision One, I can quickly see if the endpoint is trying to reach those flagged endpoints. In most cases, it turns out to be just Google searches – images or other elements loading as part of a search. Vision One has become my go-to spot every morning because of the dashboards. They put everything I needed in one place, saving me the hassle of jumping between multiple platforms. It's a half-hour ritual that sets me up for success, allowing me to review everything efficiently and tackle the rest of my day with confidence. Vision One has probably saved me several hours of valuable time per day. We currently have some playbooks in place, and we're exploring the option of adding more automation features to them. Our limited IT support staff is one factor that makes a managed XDR solution particularly appealing. However, we recognize the need to invest time in learning and understanding the available automation features, of which there are many.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good."
"We've contacted technical support several times. They've been very good. They have been able to help us resolve our issues."
"The most valuable feature is the way it captures the traffic, and it contains every detail of the communication."
"The stability of the RSA NetWitness Endpoint is very good."
"The log correlation is good."
"Ability to isolate the machine when there are malicious files."
"It is very easy to use, and its usability is great. The use cases are also very easy. The visualizations of the use cases are magnificent. You cannot find this in any other solution. From my point of view, it is great."
"This solution allows us to locate the malware in real-time."
"We haven't had any issues with configurations or customizations."
"We are very impressed with the single pane of glass visibility that Trend Micro XDR provides."
"It has good vulnerability protection."
"It is a stable product. It works very well."
"XDR provided a much more deep view into what is actually happening."
"We had a quick deployment. The solution is easy to set up."
"The setup is fairly simple."
"We can scale the product as needed."
 

Cons

"Threat detection could be better."
"The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"The solution lacks a reporting engine."
"Its price could be improved. It is an expensive product. Its training is also too expensive. It would be great if they can have a better pricing scheme for the training."
"The initial setup requires a high level of skill."
"I would like to see Security Orchestration and Response Automation (SOAR) integration."
"RSA NetWitness Network could improve on integration with non-native application integration."
"The solution lacks compatibility with other products. It needs to integrate better with other surrounding solutions."
"The information captured by Trend Vision One needs to be more detailed."
"Trend Micro doesn't have the next-generation firewall."
"The support should be improved."
"It would be ideal if they could improve the control of connectivity between sensors."
"They have a DLP module in Tredn Moicros and they need to enhance its capabilities."
"Having more variables within the playbook would be useful. It would allow us to have more refined playbooks for the business. It would allow us to take stronger action through a playbook. It will give us confidence to target a particular area of business where our risk tolerance might be higher or lower. We would like to have more granular playbooks."
"The area for improvement is mobile security. We have just finished a proof of concept for Zero Trust Secure Access. We withdrew from this PoC because it does not have that many points for proxy across Europe. Our organization is across Europe... At this time, they are only located in Germany and the UK."
 

Pricing and Cost Advice

"It is an expensive product."
"They can easily adjust if you have the requirements which are required. If you have a budget cut or a budget constraint, they can bend."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"The pricing is not very economical. It is a quite costly product for India. One thing is that when you purchase it, you have to purchase a module separately."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"I do not have any opinion on the pricing or licensing of the product."
"Trend Micro XDR is expensive, and you have to pay for it yearly."
"The pricing for Trend Vision One is reasonable."
"It is definitely not cheap. I do believe you get what you pay for to some degree. It is cost-effective."
"The pricing is competitive, and the cost aligns with the features we receive."
"The price for Trend Vision One is reasonable compared to Microsoft and Symantec."
"Vision One's pricing is extremely competitive. They're probably the lowest-cost provider that has this feature set."
"It would be nice if it was a little bit cheaper, but I think it has a fair price. It is comparable to others in the market."
"It's relatively well-priced."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
801,634 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
7%
Educational Organization
29%
Computer Software Company
18%
Healthcare Company
5%
Financial Services Firm
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness XDR?
The solution is expensive. I'd rate it at a one or two out of five. They need to adjust it to keep up with the competition. I cannot speak to the exact pricing of the product.
What needs improvement with NetWitness XDR?
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to n...
What do you like most about Trend Micro XDR?
I appreciate the value of real-time activity monitoring.
What is your experience regarding pricing and costs for Trend Micro XDR?
Product names are changing all the time. Lots of changes in the last three years. They introduced the concept of credits, too, which did not make anything easier. It's also easy to underestimate th...
What needs improvement with Trend Micro XDR?
The SOAR features (Security Playbooks) are quite limited. At the moment, it is impossible to execute a simple piece of Python code that would pull or push something to an API, for example. While yo...
 

Also Known As

RSA ECAT, NetWitness Network
Trend Micro XDR, Trend Micro XDR for Users, Trend Vision One - XDR for Networks
 

Learn More

Video not available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

ADP, Ameritas, Partners Healthcare
Panasonic North America, Decathlon, Fischer Homes, Banijay Benelux, Unigel, DHR Health,
Find out what your peers are saying about NetWitness NDR vs. Trend Vision One and other solutions. Updated: September 2024.
801,634 professionals have used our research since 2012.