Trend Micro Deep Discovery vs Vectra AI comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Trend Micro Deep Discovery
Ranking in Intrusion Detection and Prevention Software (IDPS)
6th
Average Rating
8.2
Number of Reviews
24
Ranking in other categories
Advanced Threat Protection (ATP) (18th)
Vectra AI
Ranking in Intrusion Detection and Prevention Software (IDPS)
2nd
Average Rating
8.6
Number of Reviews
42
Ranking in other categories
Network Traffic Analysis (NTA) (2nd), Network Detection and Response (NDR) (2nd), Identity Threat Detection and Response (ITDR) (6th)
 

Mindshare comparison

As of June 2024, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Trend Micro Deep Discovery is 5.6%, up from 5.3% compared to the previous year. The mindshare of Vectra AI is 13.3%, down from 15.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
Unique Categories:
Advanced Threat Protection (ATP)
1.9%
Network Traffic Analysis (NTA)
22.0%
Network Detection and Response (NDR)
23.9%
 

Featured Reviews

NaveedAli - PeerSpot reviewer
Apr 25, 2024
Reliable product with efficient endpoint detection capabilities
Overall, Trend Micro Deep Discovery has proven to be a reliable solution that enhances our security posture while minimizing operational disruptions. Regular updates and improvements can further solidify its effectiveness in various IT environments. The endpoint detection capabilities are particularly effective, especially in identifying malware and antivirus threats. Integration with our existing systems was straightforward, requiring minimal effort beyond configuring IP addresses. I rate it an eight out of ten. There is always room for improvement in any product or service. Given the current market conditions, with new technologies and emerging threats, it's essential to implement updates and enhancements continuously. It ensures that the product remains effective against new challenges. Despite its robust features and reliable support, no solution is perfect, and that's why there is always potential for further improvement. This ongoing need for innovation and adaptation is why I rated it an 8, reserving the remaining points for future enhancements.
NH
May 10, 2024
Offers real-time threat detection, notices some of the exfiltration techniques and alerts us, and AI uses models to detect abnormal behavior
The detection algorithms can be improved at the sensor level rather than doing all the things at the brain. For example, if the sensor has some directional algorithm or detects repeating traffic, it can drop those packets at the beginning itself. There is no need to send that traffic to the brain in order to reduce the bandwidth. AI is picking up a lot now. There is no manual intervention needed. Whenever a detection happens, it can automatically summarize and give it to you. But Vectra doesn't have those kinds of capabilities. It still needs manual intervention to analyze, and they don't have a summarized kind of output. So that can be improved. But apart from that, the detection models and all the other categories have good support for that. In future releases, I would like to see Vectra AI to generate a summary of the instance.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that the user can customize images of virtual machines in the sandbox functionality. The other vendors only use images that were created by the vendor but not the customer, end-user or partner. This helps to detect advanced threats and attacks."
"The product's initial setup phase was not difficult."
"The performance and stability are great."
"The tool's most valuable feature is its collaboration with other products. Integrating with other security products was simple and easy."
"The tool's stability and performance are good."
"The platform provides all essential features for discovery and administration."
"The product is very easy to install."
"The solution has extension-based features that help it to analyze the environment. The environment can have different platforms like Windows, Linux, and Mac. The tool will give a report which can confirm the analysis of the issues. You can also get clear information on threats or suspicious files."
"One of the most valuable features is all the correlation that it does using AI and machine learning. An example would be alerting on a host and then alerting on other things, like abnormal behavior, that it has noticed coming from the same host. It's valuable because we're a very lean team."
"We particularly like the user experience around the dashboard, which we find to be much more straightforward than the dashboard of some of the competitive products... Vectra is a really easy system to understand and use to prioritize where we need to focus our security resources."
"The dashboard gives me a scoring system that allows me to prioritize things that I should look at. I may not necessarily care so much about one event, whereas if I have a single botnet detection or a brute force attack, I really want to get on top of those."
"The initial setup was pretty straightforward."
"The automatic filtering that they provide is valuable. The logic inside that makes some detections instead of us is very useful. We are confident that if we are just looking into it and there is nothing, nothing could happen."
"I like the way that Vectra AI focuses on the internal network. Nowadays, most of the attackers are already inside, and they can be inside for many years before they start attacking. With normal monitoring, it's quite difficult to find them."
"The most valuable feature for Cognito Detect, the main solution, is that external IDS's create a lot of alerts. When I say a lot of alerts I really mean a lot of alerts. Vectra, on the other hand, contextualizes everything, reducing the number of alerts and pinpointing only the things of interest. This is a key feature for me. Because of this, a non-trained analyst can use it almost right away."
"It's easy to manage, and I love the UX. It's very well designed. When we are looking for something, it's quite easy to find it."
 

Cons

"There are certain aspects of flexibility in the policies that should be added to Deep Discovery."
"Scalability becomes an issue when managing a higher number of customers."
"The product's security features need enhancement."
"Additionally, better scanning capabilities for third-party applications would ensure comprehensive security without the need for exclusions."
"The solution could be more stable and offer more security."
"I would like to see them create a rule where It could integrate with the network and start mitigating with auto-detection."
"Trend Micro Deep Discovery is a very expensive solution, making it very hard to sell."
"I would like to see integration with third-party tools to improve the visibility of the dashboards."
"Other alternatives, like Darktrace, have a fancier UI."
"Vectra is still limited to packet management. It's only monitoring packet exchanges. While it can see a lot of things, it can't see everything, depending on where it's deployed. It has its limits and that's why I still have my SIEM."
"One of the things I am not so happy about when it comes to Vectra is the scoring board."
"In comparison with a lot of systems I used in the past, the false positives are really a burden because they are taking a lot of time at this moment."
"You are always limited with visibility on the host due to the fact that it is a network based tool. It gives you visibility on certain elements of the attack path, but it doesn't necessarily give you visibility on everything. Specifically, the initial intrusion side of things that doesn't necessarily see the initial compromise. It doesn't see stuff that goes on the host, such as where scripts are run. Even though you are seeing traffic, it doesn't necessarily see the malicious payload. Therefore, it's very difficult for it to identify these type of host-driven complex attacks."
"We would like to see more information with the syslogs. The syslogs that they send to our SIEM are a bit short compared to what you can see. It would be helpful if they send us more data that we can incorporate into our SIEM, then can correlate with other events."
"In education as a sector, we are looking at AI a lot in terms of how it can be used as part of the teaching and learning side of things. It would be great to have Vectra AI look at a better way to enhance the security posture related to the AI tools in our portfolio."
"The main improvement I can see would be to integrate with more external solutions."
 

Pricing and Cost Advice

"The licensing cost is a bit pricey. We pay a yearly subscription."
"The price of the solution is lower compared to the competition."
"Overall, Trend Micro Deep Discovery has proven to be a reliable solution that enhances our security posture while minimizing operational disruptions."
"Compared to its competitors, Trend Micro Deep Discovery is a little expensive."
"The tool's licensing costs are yearly. There are no additional costs associated with the product."
"The pricing is okay for some, and sometimes, some people find it expensive."
"Its price is fine, but Trend Micro can improve the pricing in general. It is a hardware solution. It is based on the number of nodes, and according to the number of nodes, clients decide which box they should acquire. They have to renew their license every year. It is subscription-based."
"Trend Micro Deep Discovery is quite expensive compared to other endpoint security products."
"We are running at about 90,000 pounds per year. The solution is a licensed cost. The hardware that they gave us was pretty much next to nothing. It is the license that we're paying for."
"The license is based on the concurrent IP addresses that it's investigating. We have 9,800 to 10,000 IP addresses."
"We have a desire to increase our use. However, it all comes down to budget. It's a very expensive tool that is very difficult to prove business support for. We would like to have two separate networks. We have our corporate network and PCI network, which is segregated due to payment processing. We don't have it for deployed in the PCI network. It would be good to have it fully deployed there to provide us with additional monitoring and control, but the cost associated with their licensing model makes it prohibitively expensive to deploy."
"Vectra is a bit on the higher side in terms of price, but they have always been transparent. The reason that they are this good is that they invest, so they need to charge accordingly."
"It is an expensive solution, but it's not the most expensive we've seen. We also know how much we're going to pay, unlike with some other providers where all of a sudden our license explodes."
"It's relatively on the pricier side, but when compared to other solutions. It's not the most budget-friendly option, but it can be considered somewhat more cost-effective in comparison to other alternatives."
"Its cost is too much. It's an investment that we can afford. It's a lot, but it's worth it."
"The solution is low-cost and affordable."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
20%
Manufacturing Company
10%
Financial Services Firm
9%
Government
6%
Computer Software Company
16%
Financial Services Firm
12%
Government
7%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Trend Micro Deep Discovery?
The tool's most valuable feature is its collaboration with other products. Integrating with other security products was simple and easy.
What is your experience regarding pricing and costs for Trend Micro Deep Discovery?
The pricing is okay for some, and sometimes, some people find it expensive. It can definitely be more expensive than Sophos. However, it is not very expensive. OEMs also include support charges.
What needs improvement with Trend Micro Deep Discovery?
They could improve the product's ability to control normal traffic and prevent attacks like SQL injection and cross-site scripting. Additionally, better scanning capabilities for third-party applic...
What is the biggest difference between Corelight and Vectra AI?
The two platforms take a fundamentally different approach to NDR. Corelight is limited to use cases that require the eventual forwarding of events and parsed data logs to a security team’s SIEM or ...
What do you like most about Vectra AI?
The solution is currently used as a central threat detection and response system.
 

Also Known As

Trend Micro Deep Discovery Inspector, Trend Micro Deep Discovery Analyzer
Vectra Networks, Vectra AI NDR
 

Overview

 

Sample Customers

Allied Telesis, Atma Jaya Catholic University of Indonesia, Babou, Blekinge County Council, Delacour, Hiroshima Prefectural Government, Live Nation Entertainment Inc., Mazda Motor Logistics Europe, McGill University Health Centre, Mikuni Corporation, OKWAVE, Sinar Mas Land, SWICA, UTOC Corporation
Tribune Media Group, Barry University, Aruba Networks, Good Technology, Riverbed, Santa Clara University, Securities Exchange, Tri-State Generation and Transmission Association
Find out what your peers are saying about Trend Micro Deep Discovery vs. Vectra AI and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.