Apex One EDR is the enterprise endpoint protection product from Trend Micro (whose enterprise business unit has been known as TrendAI™ since March 2026): it combines the EPP (Endpoint Protection Platform) and EDR (Endpoint Detection and Response) layers under a single Security Agent, is managed from an on-premises server or a SaaS console, and acts as the endpoint sensor for the Trend Vision One XDR platform. It is positioned for mid-sized and large endpoint fleets that need a detailed policy hierarchy, virtual patching, application control and retrospective threat hunting.
The product's standing in independent assessments is measurable. Trend's endpoint protection portfolio was positioned as a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms for the 21st consecutive time, and no other vendor has been named a Leader 21 consecutive times in this category (Trend Micro Newsroom, 2026). In the Gartner Critical Capabilities for EPP report published the same year, it received the highest score among all vendors in two of the three use cases — Workspace Security and On-premises Endpoint Protection Management — and the second-highest score in the third (Core Endpoint Protection) (Trend Micro Newsroom, 2026). The name of the second use case is notable: on-premises endpoint management is retained as a separate evaluation heading despite the spread of cloud consoles.
Why this protection layer is needed is clear in the threat data. In the Verizon 2025 Data Breach Investigations Report, 44% of the breaches analysed involved ransomware, an increase of 37% over the previous year; the median ransom paid was 115,000 US dollars, while 64% of victim organisations did not pay (Verizon 2025 DBIR). In IBM's measurement published the same year, the global average time until a breach is detected and contained is 241 days (IBM Newsroom, 2025). Shortening the distance between detection and response at the endpoint means, in practice, narrowing that 241-day window.
Which protection layers make up Apex One?
Apex One runs complementary layers under a single Security Agent: signature-based malware scanning, file and web reputation services, file and process analysis with Predictive Machine Learning, Behaviour Monitoring, ransomware protection with rollback for encrypted files, memory and exploit prevention, application control, device control, an endpoint firewall and an optional DLP module. The Apex One EDR side is provided by the Endpoint Sensor component; it records at the level of the process tree, command line arguments and network connections, enabling retrospective threat hunting queries.
The layered design is not just a product design choice but also a regulatory expectation. The KVKK Personal Data Security Guide — KVKK being Turkey's data protection law — states that the assumption that a single cybersecurity product will deliver full security is not always correct and recommends layered, regularly reviewed complementary measures; the same guide lists up-to-date antivirus and antispam products among the technical measures and stresses that merely installing them is not enough, as they must be kept up to date and the required files scanned regularly (KVKK Personal Data Security Guide).
How much visibility these layers produce in real attack chains is measured through MITRE ATT&CK Evaluations. In the round published in December 2024, Trend Vision One achieved 100% analytic coverage across all major attack steps and 99% across all substeps; the same round showed 100% analytic coverage across all substeps on Linux and macOS and included ransomware scenarios targeting Linux and macOS (Trend Micro Newsroom, 2024). Trend products have achieved a 100% detection rate in these evaluations since 2020 (Trend Micro Newsroom, 2024). These results were measured at platform level; the quality of endpoint telemetry is the fundamental input to that score.
What is the difference between Apex One's on-premises and SaaS deployment?
Short answer: the protection engines come from the same agent; the difference is where the management plane runs and who carries the infrastructure burden. In an on-premises installation, the organisation operates the Apex One server, the database, backups, certificates and version upgrades; in the SaaS model the console is hosted by the vendor and maintenance responsibility shifts to the provider. Organisations that must keep the console internal because of data residency, isolated networks or existing on-premises management standards choose the on-premises model.
The concrete burden of the on-premises installation is visible in the official system requirements: the Apex One Service Pack 1 Patch 4 server requires at least 3 GB of RAM and 7.0 GB of disk; used together with Endpoint Sensor those figures rise to 8 GB of RAM and 8.0 GB of disk, and Endpoint Sensor additionally requires SQL Server 2016 SP1 (Enterprise or Standard) or later, with SQL Server Express not supported (Apex One SP1 Patch 4 System Requirements, Trend Micro official documentation). In other words, running Apex One EDR on-premises also brings with it a SQL Server licence and database maintenance responsibility. We can take over the operation of this layer as part of our DevOps and infrastructure services.
Organisations that want to manage off-premises laptops from an on-premises console deploy the Edge Relay Server component. This component is installed on Windows Server 2016, 2019 or 2022, with a 2 GHz dual-core processor, 1 GB of memory, 60 GB of disk and two network cards (Apex One SP1 Patch 4 System Requirements, Trend Micro official documentation). In a hybrid working model, if this component is skipped, endpoints that never connect to the VPN cannot receive policy and pattern updates; the real level of protection in the field then differs from the report in the console.
On the SaaS side none of these components are installed, agents connect directly to the cloud management plane and version upgrades are performed by the provider. That said, the feature sets of the two models should not be assumed to be identical; which module exists in which model must be verified from the official documentation for the version you will use. In our sizing work we share that difference line by line in writing so that no unexpected module gap appears halfway through the project.
What does virtual patching solve in Apex One?
Direct answer: virtual patching is a host-based intrusion prevention approach that blocks the exploitation of a known vulnerability on a rule basis until the vendor patch is installed. In Apex One this function is performed by the Vulnerability Protection module; the agent recognises exploit attempts against known vulnerabilities and stops the attack while the operating system is still unpatched. It does not replace patch management; it closes the patch window.
The width of that window has been measured. According to the Verizon 2025 DBIR, vulnerability exploitation as an initial access step grew by 34% in one year and now accounts for 20% of breaches; only about 54% of vulnerabilities in edge devices were fully remediated, and doing so took a median of 32 days (Verizon 2025 DBIR). On the compliance side, PCI DSS v4.0 Requirement 6.3.3 mandates that critical or high-severity security patches be installed within one month of release (PCI Security Standards Council, PCI DSS v4.0). Virtual patching is a technical measure that reduces the risk in that interval; however, PCI DSS pre-approves no technology as a compensating control — using a compensating control is possible only for organisations with a documented technical or business constraint and only with QSA assessment.
The source of the rules is Trend's Zero Day Initiative (ZDI) programme. ZDI has coordinated the disclosure of more than 15,000 vulnerabilities since 2007 — according to Omdia data it accounted single-handedly for 73% of all global disclosures in 2024 — and behind the programme stand more than 19,000 independent researchers and 14 global threat centres (Zero Day Initiative, 2026). While the ZDI disclosure policy grants the vendor a standard 120-day patch period, it explicitly states that protection filters may be distributed to customers simultaneously with the notification to the vendor (ZDI Disclosure Policy, 2026). That is the basis on which virtual patching can come into effect before the vendor patch; thanks to research within Pwn2Own, Trend reports that it can protect customers against zero-day exploits an average of 71 days earlier than the industry (Trend Micro Newsroom, 2025).
On the ransomware side the chain works the same way: according to ZDI data, 59 zero-day vulnerabilities have been used in ransomware attacks since 2020; before 2020 it was extremely rare for ransomware groups to use zero-day vulnerabilities (Trend 2025 Cyber Risk Report). TippingPoint next-generation IPS, which uses the same filter research at the network layer, and Deep Security server protection, which provides virtual patching for servers and workloads, draw on the same intelligence pool as the endpoint layer. Positioning all three layers together means the same vulnerability is shielded at both the network and the endpoint level.
What role does Apex One play in the Trend Vision One XDR architecture?
Direct answer: Apex One is Vision One's endpoint sensor. Trend Vision One has six native security sensors — endpoint, cloud, email, network, server and identity (Trend Micro Newsroom, 2025) — and the endpoint leg of that architecture is fed by the Apex One / Trend Vision One Endpoint Security agent. The agent on the endpoint is the same; what changes is where the telemetry flows and which correlation it enters.
Running standalone, Apex One EDR sees the incident chain within the endpoint and responds within that scope. When Vision One is added, the same incident merges into a single timeline with phishing detections on the enterprise email security side and with the records of the network and server sensors. The difference is the difference between "a suspicious PowerShell ran on this machine" and "the chain that began with an attachment delivered to the same user 40 minutes ago ran PowerShell on this machine" — and that is exactly where the response decision starts to change.
On the licensing side, Vision One supports the Flex credit model: credits are activated for a solution, purchased for a defined term and drawn down monthly according to actual usage; unused credits can be transferred to another solution within the contract term, and no separate licence key is required per product (TrendAI Flex Licensing, 2026). For organisations planning to start at the endpoint and expand into email, server or identity modules, this model removes the need to open a new procurement process at every step.
On operational gains, the vendor reports that the Vision One Companion AI assistant can accelerate incident response times by 30%, save up to two hours per incident report, and reduce the time spent on manual risk assessment and threat research by 50% or more (Trend Micro Newsroom, 2023). These are vendor-stated figures; we recommend measuring their equivalent in your own environment during a pilot deployment.
Should you choose Apex One or Worry-Free Business Security?
Short answer: your management resources and your need for policy depth decide. Worry-Free Business Security is a quick-to-deploy package that ships with ready-made policies for small and mid-sized businesses without a dedicated security team. Apex One is for enterprise fleets that want a detailed policy hierarchy, virtual patching, application control, an on-premises deployment option and the XDR sensor role. The table below summarises the distinctions most frequently asked about at the quotation stage.
| Criterion | Apex One | Worry-Free Business Security |
|---|
| Target organisation | Mid-sized and large fleets with a dedicated IT or security team | Small and mid-sized businesses with limited or outsourced IT resources |
| Deployment model | On-premises server or SaaS | Predominantly cloud console; an on-premises edition also exists |
| Policy depth | Detailed hierarchy by department, location and device role | Predominantly ready-made templates, a simplified policy set |
| Virtual patching | Host-based intrusion prevention with the Vulnerability Protection module | An enterprise layer; not part of the core scope of the SMB package |
| EDR and threat hunting | Retrospective querying at process, command line and network connection level with Endpoint Sensor | Detection and quarantine focused, limited retrospective analysis |
| Application and device control | Detailed rule definition by group | Basic level |
| Email protection | Provided by a separate enterprise email security product | Messaging Security Agent, running on the Microsoft Exchange server |
| Role in the XDR architecture | Trend Vision One's endpoint sensor | For enterprise XDR correlation, the Apex One line is preferred |
| Typical rollout effort | Requires pilot deployment, policy tuning and phased rollout | Quick start via an installation link |
Reduced to a single sentence: the deciding factor is not the number of endpoints but the management model. If you need to separate your policies by department, location and device role, if you have systems that cannot be patched, or if you want to move endpoint telemetry into an XDR or SIEM platform, Apex One is the right layer. Email protection remains a separate decision item in both cases; on the Worry-Free side the Messaging Security Agent component runs on the Microsoft Exchange server (Worry-Free Business Security 10.0 SP1 System Requirements), while on the enterprise side a standalone email security product is positioned.
What system requirements does an Apex One deployment have?
Direct answer: an on-premises installation requires a supported Windows Server, a suitable SQL Server instance if EDR will be used, and supported Windows versions on the agent side. All values in the table below are taken from the official Apex One Service Pack 1 Patch 4 system requirements document (Apex One SP1 Patch 4 System Requirements, Trend Micro official documentation).
| Component | Requirement verified in the official document |
|---|
| Apex One server — operating system | Windows Server 2016, 2019, 2022 and Windows MultiPoint Server (the full supported list varies by patch level) |
| Server hardware — without Endpoint Sensor | At least 3 GB RAM, 7.0 GB disk space |
| Server hardware — with Endpoint Sensor | At least 8 GB RAM, 8.0 GB disk space |
| Database — Endpoint Sensor | SQL Server 2016 SP1 (Enterprise/Standard) or later; SQL Server Express is not supported |
| Security Agent — client | Windows 10 (version 22H2 and earlier), Windows 11 (version 24H2 and earlier), Windows 10/11 IoT Enterprise |
| Security Agent — server | Windows Server versions up to and including Windows Server 2025 |
| Edge Relay Server | Windows Server 2016/2019/2022; 2 GHz dual-core processor, 1 GB memory, 60 GB disk, two network cards |
| Virtual desktop support | VMware vCenter 5.x–8.x and Horizon View 6.x–8.x, Citrix XenServer 6.x–7.x, Microsoft Hyper-V (Windows Server 2012–2022) |
| Unsupported configuration | Security Agent installation on Windows systems with Unified Write Filter (UWF) enabled |
One point in the document deserves particular attention: the Apex One SP1 Patch 4 system requirements do not list a macOS or Linux platform for the Security Agent (Apex One SP1 Patch 4 System Requirements, Trend Micro official documentation). In organisations with a macOS fleet, Mac protection should be planned through a separate component or through the scope of Trend Vision One Endpoint Security, and verified against the official compatibility matrix of the version to be used at the start of the project. For server operating systems and cloud workloads, a server-oriented protection line is preferred instead of the endpoint agent.
In virtual desktop (VDI) environments the Virtual Desktop Support component comes into play; it queues the scanning and update operations of virtual machines on the same physical server to prevent resource peaks. It should also be remembered that Security Agent installation on Windows systems with Unified Write Filter enabled is not supported — in kiosk and thin client scenarios this constraint directly affects the architecture and requires an alternative protection approach.
What does Apex One provide in KVKK and sector-specific compliance audits?
Direct answer: Apex One does not by itself mean "KVKK compliance"; it makes several of the technical measures listed by the law and by the Authority's guide applicable and demonstrable. Article 12 of Law No. 6698 obliges the data controller to prevent the unlawful processing of and unlawful access to personal data and to safeguard its retention; to that end, all technical and administrative measures necessary to ensure an appropriate level of security must be taken (KVKK — Obligations Regarding Data Security).
The counterparts on the Apex One side are concrete: malware scanning with up-to-date patterns, host-based intrusion prevention with Vulnerability Protection, event logging and retrospective querying with Endpoint Sensor, USB and external media restriction with device control, and sensitive data classification and egress control with the DLP module. The KVKK guide states that merely installing these measures is not enough and that you must ensure they are kept up to date and that regular scanning is performed (KVKK Personal Data Security Guide). What matters in an audit is not the presence of the product but the policy being written down and producing evidence; pattern and version compliance reports, policy exception records and the incident timeline constitute that evidence. We prepare this documentation as part of the project deliverables.
Log retention planning is a separate heading. Vision One's Agentic SIEM component offers up to 2 years of analytic and up to 7 years of archive data retention (Trend Micro Newsroom, 2025). Sector-specific retention expectations and post-incident forensic needs are planned around that window. In cardholder data environments within PCI DSS scope, intrusion prevention and change detection requirements extend beyond the endpoint layer, so scoping should be done at the start of the project.
The risk that falls outside scope should also be stated plainly: Apex One only sees managed endpoints. In the infostealer analysis in the Verizon 2025 DBIR, 46% of the systems holding corporate session information were unmanaged personal devices, while 30% of compromised systems were corporate-licensed devices (Verizon 2025 DBIR). Mobile Security for Enterprise must be planned separately for personal devices and the mobile fleet; otherwise the compliance report will not reflect the real attack surface.
Which services does Sora Yazılım provide in Apex One projects?
As an authorised Trend Micro channel partner, we run licensing, sizing, deployment, policy design, SIEM and SOAR integration and ongoing operations management for Apex One projects from a single source. The process runs in this order: inventory mapping and detection of existing agents, sizing and licence model selection, deployment on a pilot group, policy tuning and false positive cleanup, phased rollout, followed by monthly health reporting and incident response support. In a migration from an existing antivirus, removing the old agent, migrating exclusion lists and planning the outage window are a separate work item.
We also track the product line's enterprise standing: in the Gartner Magic Quadrant for Endpoint Protection Platforms report dated 14 July 2025 the product evaluated was Trend Vision One Endpoint Security, and Trend had been positioned as a Leader for the 20th consecutive time in that report (Trend Micro Newsroom, 2025). On the brand side, Trend Micro's enterprise security business took the name TrendAI on 23 March 2026; the company works with 6,000 TrendAI experts in 75 countries (Trend Micro Newsroom, 2026). We review the impact of this transition in licence, support and documentation naming on your contracts together with you before renewal. The same engineering team serves the entire Trend Micro solution family.
In summary, Apex One is an enterprise protection layer that combines EPP and EDR in a single agent, can protect unpatchable systems through virtual patching and application control, runs on-premises or as SaaS, and provides the endpoint sensor for Trend Vision One XDR. Once the size of your fleet, where the console will run, your EDR retention needs and your existing SIEM integration expectations are clear, we can produce the right licence model and deployment plan. Licence cost varies with the number of users and devices, the modules selected and the licence term; share your inventory and request a quote — let us prepare the pilot deployment plan together as well.