Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Information Security Manager at a legal firm with 1,001-5,000 employees
Vendor
The built-in auto tuning system does a great job of detecting legitimate services and devices on the network.

What is most valuable?

Ease of use, just connect to a span port on your core switch and you're ready to go. Of course, you will see a bunch of white noise, but the built-in auto tuning system does a great job of detecting legitimate services and devices on the network, and from there you white-list the ones which you've confirmed to be known goods. Built in sandboxing provides an additional layer of defense to shake out suspicious objects and processes. This works especially well if you're running Trend Micro's Office Scan Endpoint Protection, where DDi is able to generate a new virus definition via the sandbox, and push it out to the Office Scan AV engine to provide protection across your network.

How has it helped my organization?

DDi rapidly discovers C2 traffic and pinpoints the offenders, source and recipient. It also provides a set of eyes to keep track of suspicious lateral movements between nodes. The out of the box rule set does a great job of hunting down previously unflagged threats, but can easily be customized for those that like to tweak and refine.

What needs improvement?

Not too much to complain about, really. There were a few instances where legitimate traffic (WPAD) was flagged as C2 communication. There were some challenges in white-listing it, which resulted in a bunch of alerts/noise.

For how long have I used the solution?

2 years

Buyer's Guide
Trend Micro Deep Discovery
May 2025
Learn what your peers think about Trend Micro Deep Discovery. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No

What do I think about the stability of the solution?

Never

What do I think about the scalability of the solution?

It can get expensive if you wish to monitor all core switches across many satellite offices. My suggestion is to put one or more DDi appliances at core switches nearest to where your critical data is housed.

How are customer service and support?

Customer Service:

Customer service is very good.

Technical Support:

Very good.

Which solution did I use previously and why did I switch?

FireEye. Fire Eye is incredibly expensive, and requires multiple appliances which together, scan far less protocols than DDi. It also hasn't fared so well in terms of detection rates, in independent tests against competing products.

How was the initial setup?

Straightforward setup.

What about the implementation team?

Implemented in-house along with Trend's team.

What other advice do I have?

Be sure to implement Trend's Control Manager module (free) for more flexible reporting, along with integration with other Trend products (strongly suggest using this along with Office Scan and Deep Discovery Endpoint Sensor, which is an EDR solution).

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Abdulahad Kawaf - PeerSpot reviewer
Network security engineer at Safe Decision Co. LLC
Real User
Top 5
Integration with other products is easy and simple
Pros and Cons
  • "The tool's most valuable feature is its collaboration with other products. Integrating with other security products was simple and easy."
  • "The tool's configuration can be made easier."

What is most valuable?

The tool's most valuable feature is its collaboration with other products. Integrating with other security products was simple and easy. 

What needs improvement?

The tool's configuration can be made easier.

For how long have I used the solution?

I have been using the product for a year. 

What do I think about the stability of the solution?

I rate the tool's stability a ten out of ten. 

What do I think about the scalability of the solution?

Trend Micro Deep Discovery is scalable. My company has more than 1000 users. 

How are customer service and support?

I haven't contacted technical support yet. I use the tool's documentation. 

Which solution did I use previously and why did I switch?

I've also had experience using Cisco products. However, I found that Cisco's solutions can be quite expensive. Additionally, the integration between their various products tends to be more complex than Trend Micro Deep Discovery. One significant advantage of Trend Micro Deep Discovery is its centralized console, which allows us to manage almost all their products from a single location.

How was the initial setup?

My company has ten technical staff for Trend Micro Deep Discovery. 

What other advice do I have?

Trend Micro Deep Discovery can cover all security requirements. I rate it a seven out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Trend Micro Deep Discovery Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free Trend Micro Deep Discovery Report and get advice and tips from experienced pros sharing their opinions.