What is our primary use case?
Basically, you use it to check the complete telemetry for the endpoints, cloud network, and email solutions. If you integrate this product with your endpoints and on a third product that is available. It can completely share the telemetry of that. Trend Micro will apply the AI and ML of that. On that, we will get the Workbench. Therefore, it is just helping us to check the attack factor, et cetera, in detail, in a complete view in one single platform.
How has it helped my organization?
From the user's end, the implementation is okay. The development is ongoing.
They are already working on the development and then planning to add new features. They're also fixing the feature request. Currently, there's a feature like remote shell and we can take the Remote Shell of the machine directly from the console with no need to take the machine on the access or IDP. They have enough feature sets out there.
What is most valuable?
The solution has multiple useful features. For example, the endpoint Isolation is great. The remote shell has been very helpful as well.
We can directly disable a user account or delete a user account if we find any malicious activity with the domain account. This feature is available and quite useful. One of the most important features is third-party integration. We can integrate our firewall, DAD, and our Sandboxing solution.
There are multiple third-party products we can integrate, and we can transfer that tech there.
The solution is stable.
It can scale.
The setup is fairly simple.
What needs improvement?
For some time, if you were installing this XDR solution, there is a Sensor. Sometimes we need backend support for some scripting parts. They're applying it from the backend for us. Therefore, there's a dependency on the backend from that point of view. I don't like that feature. The option for deploying the scripts should be available on the platform itself, so there is no need to raise the case with the backend team.
We'd like to see some security playbooks. Currently, Auto-Remediation is not there. Only Manual-Remediation is there. We have to create a Security Playbook. However, they are just planning to add the Auto-Remediation part.
They are just also planning on adding the Security Playbooks as a complete feature. In the preview mode, it is available; however, it is not released.
For how long have I used the solution?
I've been using the solution for more than a year.
What do I think about the stability of the solution?
We haven't had any issues with stability. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We can scale the solution. We just have to provide a request to our sales team.
How are customer service and support?
I haven't escalated anything to the support team yet.
That said, the product is pretty new, and if we do get stuck, we may reach out to get clarification. We can raise a ticket and get support within 24 hours. Within one or two days, we will get an answer.
Which solution did I use previously and why did I switch?
I only work with Trend Micro products at this time.
How was the initial setup?
The initial setup is very straightforward. We just enable two or three steps to check boxes, and we can deploy this sensor easily. It is very simple. Any user can understand what they have to do within five to ten minutes. It is very easy to understand the product.
We can deploy the sensor on the endpoint on-premises. We can deploy on the cloud as well. The sensor can be enabled anywhere. That said, the platform itself is hosted on the cloud, including Azure.
The maintenance is completely taken care of by the Trend Micro backend team. We don't need to do any management.
What's my experience with pricing, setup cost, and licensing?
I don't manage the pricing aspect of the solution.
Which other solutions did I evaluate?
I've recently been looking into CrowdStrike Falcon for a client.
What other advice do I have?
I'm the implementer. I'm working with the operation, and I'm working as an implementation engineer here.
I'm working with the latest version of the solution.
If a customer is planning on using the cloud solution, they should definitely purchase this product. That said, if it is on their own device, I would not recommend this product. Also, if you're integrating with anything on-premises, you cannot completely utilize it and will not receive the ROI for this investment. If you are on-premises, it's better to go for EDR, not XDR.
I'd rate the product nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner