Sora Yazılım
English
Custom software solutions from Türkiye
Trend Micro · Cybersecurity

Deep Discovery (Network Detection)

An NDR platform that detects targeted attacks, lateral movement and data exfiltration at the network layer.

Quick answer

Trend Deep Discovery is an NDR solution that analyses enterprise network traffic in real time to detect targeted attacks (APT), lateral movement and data exfiltration attempts. Deep Discovery Inspector monitors all network ports and more than 100 protocols, runs suspicious files in a sandbox built from organization-specific images, and feeds its findings into the Trend Vision One platform as a network sensor.

Trend Deep Discovery NDR is a network detection and response product family that passively listens to enterprise network traffic to detect targeted attacks (APT), lateral movement and data exfiltration attempts. The enterprise business unit of Trend Micro, which develops the product, has been known as TrendAI™ since March 2026; product names, existing licences and the parent company name (Trend Micro Incorporated) are unchanged. The core of the family, Deep Discovery Inspector, connects to the network through a SPAN port or a TAP; it monitors all network ports and more than 100 network protocols, covering both north-south and east-west traffic (Trend Micro Deep Discovery Inspector Datasheet, 2024). Every asset that connects to the network falls into that field of view, including printers, IP cameras, OT controllers, medical devices and guest devices on which no endpoint agent can be installed.

Breach data shows why this layer is needed. According to the Verizon 2025 Data Breach Investigations Report, vulnerability exploitation as an initial access step grew 34% in a year and now accounts for 20% of breaches (Verizon 2025 DBIR, 2025). According to the measurement IBM published the same year, the global average time until a breach is identified and contained is 241 days (IBM Cost of a Data Breach Report 2025, 2025). If an attacker can stay in the environment for months, the problem is not only prevention but visibility — and where there is no endpoint agent, the only witness is the network itself.

Which attack behaviours does Deep Discovery actually detect?

Its detections work through behaviour and context rather than signature matching: command-and-control (C&C) communication, use of covert channels, internal reconnaissance, lateral movement, unusually large outbound data volumes and confirmation of unknown malware in the sandbox. The engines look not at a single packet but at the sequence of events belonging to the same asset; the output is therefore not a list of alerts but an attack narrative.

In practice, the behaviour clusters monitored are as follows:

  • Command-and-control traffic: callback channels established over web, name resolution and lesser-known protocols, together with fixed-interval (beaconing) connection patterns.
  • Covert communication channels: data flows hidden inside DNS, ICMP or permitted web protocols; this is precisely the category PCI DSS v4.0 explicitly requires service providers to detect.
  • Lateral movement: attempts to spread from server to server over file sharing, remote desktop, remote administration and directory service protocols.
  • Data exfiltration: transfers to unusual destinations, at unusual hours and in unusual volumes; compressed and fragmented egress patterns.
  • Unknown malware: behavioural classification of executables, scripts and document attachments crossing the network by running them in the sandbox.
  • Agentless assets: anomalous traffic and unexpected external connections generated by devices on which endpoint protection cannot be installed.

What these behaviour clusters have in common is that none of them can be reduced to the question of whether a single file is malicious. Most of the tools used in a targeted attack are legitimate components already present on the system; what is anomalous is not the tool but the context in which it is used. The network layer is the only place that records that context — who is talking to whom, when and at what volume.

Why is an organization-specific sandbox more effective than a standard cloud sandbox?

Because targeted malware recognizes the environment it runs in. Deep Discovery's customized sandbox uses virtual images that exactly match the organization's own operating system configuration, drivers, installed applications and language versions; threats designed to evade standard images are caught this way (Trend Micro Deep Discovery Inspector Datasheet, 2024).

A team developing a targeted attack first tries the sample in common analysis environments. Virtual machine artifacts, missing drivers, an English system language, the absence of corporate applications, a machine image not joined to the domain — when any one of these signals is seen, the malware terminates without doing anything and the analysis produces a "clean" verdict. Once the organization's golden image is moved into the sandbox, that evasion disappears: a Turkish Windows installation, the in-house ERP or banking client, the VPN client and the certificate store all become part of the image. If the same sample is also seen on the endpoint, blocking is enforced on the Apex One endpoint protection side.

The second difference emerges after the analysis. The sandbox does not produce only a "malicious" or "clean" verdict; it also reports the domains the sample contacted, the files it dropped, the processes it created and the registry changes it made. These indicators (IoCs) can be turned directly into a hunting query: which other device connected to the same domain, on which other server was the same file name created. Detection thus moves beyond closing a single incident to sweeping the entire campaign.

How does lateral movement become visible at the network layer?

Lateral movement is by definition traffic between two internal systems; it therefore never passes the perimeter firewall. Because Deep Discovery Inspector also covers east-west traffic (Deep Discovery Inspector Datasheet, 2024), it can see a file-sharing session opened from one server to another, an unexpected remote desktop connection, or a service account reaching shares it has never touched before.

This visibility is decisive for supply chain risk too. The Verizon 2025 DBIR reported that the share of breaches involving a third party doubled in a year, rising from 15% to 30% (Verizon 2025 DBIR, 2025). Movement arriving through a supplier session connected to your network for maintenance purposes does not show up in your endpoint inventory; it shows up in the network flow.

In a ransomware scenario, the reconnaissance and propagation phase before encryption is the only time window you have to respond. According to Trend Zero Day Initiative data, 59 zero-day vulnerabilities have been used in ransomware attacks since 2020 (Trend 2025 Cyber Risk Report, 2025); in other words, initial access can happen through a vulnerability that has no patch yet. Since blocking initial access is not always possible, being able to see the second step becomes decisive.

Which Deep Discovery capacity suits which network?

In a Trend Deep Discovery NDR deployment, the choice depends on two parameters: the peak rate of the traffic to be monitored and the number of suspicious files expected to be analysed per day. Deep Discovery Inspector hardware models deliver between 500 Mbps and 40 Gbps of inspection throughput and support 2 to 40 concurrent sandbox (Virtual Analyzer) instances per model; the virtual appliance version is offered at 100, 250, 500 and 1,000 Mbps capacities and runs on VMware vSphere 5 and above or on KVM (Deep Discovery Inspector Datasheet, 2024).

Comparison criterionVirtual applianceHardware appliance
Inspection capacity100 / 250 / 500 / 1,000 Mbps500 Mbps – 40 Gbps depending on model
Sandbox (Virtual Analyzer)Cloud analysis via the Sandbox as a Service add-on2 – 40 concurrent analysis instances per model
PlatformVMware vSphere 5 and above, or KVMOn its own hardware
Hardware investmentNot requiredRequired
Network connectionSPAN port or TAP (out-of-band)SPAN port or TAP (out-of-band)
Typical placementBranch, remote site, pilot deployment, virtualized data center edgeInternet egress point, data center core, campus backbone, IT-OT boundary

The virtual appliance option is a practical starting point for organizations that want to run a pilot without a hardware investment; in this model, sandbox analysis is performed in the cloud through the Sandbox as a Service add-on (Deep Discovery Inspector Datasheet, 2024). For organizations that do not want suspicious files to leave the corporate network, we recommend the hardware deployment, which keeps analysis in local Virtual Analyzer instances on the appliance itself. We base the capacity decision on peak traffic measurements taken on the segments to be monitored rather than on assumptions; where the SPAN port itself is the bottleneck, we recommend a TAP or an aggregation TAP placement.

What role does Deep Discovery play within Trend Vision One?

The role of network sensor. Trend Vision One has six native security sensors — endpoint, cloud, email, network, server and identity (Trend Micro Newsroom, 2025) — and Trend Deep Discovery NDR feeds the network leg of those six. A standalone NDR product tells you "this address is talking to that address"; XDR correlation combines the same event with which user opened which email attachment, which process started on which server and which identity was used.

That correlation has a measured counterpart: in the MITRE ATT&CK Evaluations round announced in December 2024, Trend Vision One achieved 100% analytic coverage across all major attack steps and 99% across all substeps (Trend Micro Newsroom, 2024). The platform's Agentic SIEM component became available on 1 August 2025, supports more than 900 data sources and offers up to 2 years of analytic and up to 7 years of archive data retention (Trend Micro Newsroom, 2025). The network events Deep Discovery produces flow into that retention and query layer, which also covers the need for audit and post-incident investigation.

On the independent analyst side, Deep Discovery Inspector was positioned as a Leader in the Forrester Wave Network Analysis and Visibility Q2 2023 evaluation and was named a Representative Vendor in the 2024 Gartner Market Guide for Network Detection and Response (Deep Discovery Inspector Datasheet, 2024). You can review the platform as a whole on the Trend Vision One XDR platform page and the other components on the Trend Micro solution family page.

How do TippingPoint, Deep Security and Deep Discovery divide the work?

The three do not do the same job; they complement each other as layers. TippingPoint stands on the link and blocks, Deep Security stands inside the server and protects the workload, Deep Discovery stands beside the link and sees. For a mid-sized or large organization, needing all three is not the exception but the typical architecture.

CriterionDeep Discovery (NDR)TippingPoint (IPS)Deep Security (server / workload)
PlacementOut-of-band — SPAN port or TAPInline — in the traffic pathAgent-based — in the server operating system
Primary functionDetection, sandbox analysis and investigationBlocking and virtual patchingServer protection modules and virtual patching
Impact on network trafficNone (passive listening)Requires a latency budgetNone (runs on the host)
Field of viewNorth-south + east-west, more than 100 protocolsTraffic on the inspected linkThe protected server itself
Sandbox analysisLocally or in the cloud with organization-specific imagesOut of scopeOut of scope
Agentless device coverageYes — printers, cameras, OT, medical devices, guestsYes if on the inspected linkNo
Typical justificationAPT and lateral movement visibilityShielding unpatchable systems on the linkServer and cloud workload compliance

For the prevention layer see the TippingPoint next-generation IPS page, and for the server and cloud workload layer the Deep Security server protection page. The shared intelligence source behind these three products is the Trend Zero Day Initiative: ZDI has coordinated the disclosure of more than 15,000 vulnerabilities since 2007, and more than 19,000 independent researchers contribute to the program (Zero Day Initiative — About, 2026). The answer to why an exploit attempt seen on the network is recognized at all lies largely in that research chain.

Why should email security and network detection be positioned together?

Because a targeted attack usually begins with email and continues on the network. According to ENISA Threat Landscape 2025, phishing is by far the most common initial access vector in Europe at 60%, followed by vulnerability exploitation at 21.3% (ENISA Threat Landscape 2025, 2025). The same report examined 4,875 incidents targeting the EU between 1 July 2024 and 30 June 2025 and noted that 53.7% of the incidents concerned essential entities within the scope of the NIS2 Directive (ENISA Threat Landscape 2025, 2025).

An attachment that the email layer fails to catch gives itself away at the network layer through callback traffic. Trend's email and collaboration protection detected and blocked 57 million high-risk email threats in 2024, a 27% increase over the 45 million in 2023 (Trend 2025 Cyber Risk Report, 2025). For organizations that want to design both layers together, we recommend also evaluating the scope of Trend Email Security; a threat stopped in email never becomes an incident to investigate on the network.

Which KVKK and PCI DSS requirements does Deep Discovery map to?

Trend Deep Discovery NDR maps directly to two headings: intrusion detection and log records. In the KVKK (Turkey's data protection law) Personal Data Security Guide (Technical and Administrative Measures), "Intrusion Detection and Prevention Systems" and "Log Records" are explicitly listed among the technical measures a data controller may take (KVKK Personal Data Security Guide). The same guide states that the view that full security can be achieved with a single cybersecurity product is not always correct, and recommends applying layered measures that are reviewed regularly.

On the PCI DSS v4.0 side the connection is even clearer. Requirement 11.5.1 requires intrusion detection and/or prevention techniques to monitor all traffic at the perimeter of the cardholder data environment (CDE) and at critical points within the CDE, and requires signatures and baselines to be kept current; Requirement 11.5.1.1 makes detection of covert malware communication channels mandatory for service providers as of 31 March 2025 (PCI Security Standards Council, PCI DSS v4.0). Deep Discovery's covert channel and command-and-control detection maps precisely to that requirement.

In Turkey, the question we hear most often from finance, public sector, healthcare and manufacturing organizations is where the data goes. In organizations that do not want suspicious samples to leave the corporate network, we stay in the local analysis mode on the appliance and enable the cloud sandbox only with the organization's explicit approval. Log retention periods, the reporting that may be requested in a KVKK audit and the incident response procedure are all defined together within the scope of the rollout; these are topics decided on day one of the project, not added later.

How does Sora Yazılım run a Deep Discovery project?

In four phases: traffic discovery, sizing, commissioning and operations. First we establish which segments will be monitored, the peak traffic volume and the existing SPAN/TAP infrastructure; then we determine the capacity model, the sandbox image and the placement points.

During commissioning, the organization's golden image is moved into the sandbox, noise reduction (tuning) work is carried out in the first week and the event stream is connected to the XDR console. If changes are required on the network architecture, virtualization or monitoring infrastructure, the same project team carries them out under our DevOps and infrastructure services. In the operations phase we provide a monthly detection summary, engine and signature updates, version upgrades and incident response support.

Sora Yazılım is an authorized Trend Micro channel partner; Deep Discovery licensing, sizing, deployment and KVKK-compliant operation are handled end to end from a single source. The vendor's enterprise security business works with 6,000 experts in 75 countries (Trend Micro Newsroom, 2026); vendor support and the escalation chain run through that structure.

Summary: Trend Deep Discovery NDR passively listens to network traffic to detect targeted attack, lateral movement and data exfiltration behaviour across more than 100 protocols; with an organization-specific sandbox it surfaces malware that evades standard analysis environments, and it connects to Vision One as a network sensor. Let us work out together which segments of your network have visibility gaps. Because the capacity model, sandbox design and licence items vary with the volume of traffic to be monitored and the subscription term, we prepare a project-specific quote instead of a standard price list — request a quote and our engineers will review your network topology and come back with a SPAN/TAP plan and a sizing recommendation.

Key features

What it offers

  • Deep traffic inspection across all network ports and more than 100 network protocols
  • Coverage of north-south and east-west traffic together with a single sensor
  • Customized sandbox (Virtual Analyzer) running the organization's own image
  • Command-and-control (C&C) communication and covert channel detection
  • Detection of lateral movement and internal reconnaissance behaviour
  • Volume- and destination-based detection of data exfiltration patterns
  • Out-of-band SPAN/TAP deployment — adds no latency to production traffic
  • Coverage of devices where no endpoint agent can be installed (printers, cameras, OT, medical devices, guests)
  • Telemetry feed into Trend Vision One as a network sensor with XDR correlation
  • Two deployment options: physical appliance and virtual appliance
  • Local Virtual Analyzer on the hardware appliance, cloud analysis with Sandbox as a Service on the virtual appliance
  • Threat intelligence fed by the Zero Day Initiative research chain
Tech Summary

Important technical data

Deployment model
Out-of-band — passive listening via SPAN port or TAP
Hardware capacity
500 Mbps – 40 Gbps inspection throughput depending on model
Virtual appliance capacity
100 / 250 / 500 / 1,000 Mbps
Virtualization support
VMware vSphere 5 and above, KVM
Sandbox (Virtual Analyzer)
2 – 40 concurrent analysis instances per model
Cloud sandbox
Sandbox as a Service add-on (optional, subject to organizational approval)
Protocol coverage
All network ports, more than 100 network protocols
Traffic direction
North-south and east-west
Platform integration
Trend Vision One network sensor (one of six native sensors)
Analyst recognition
Forrester Wave NAV Q2 2023 Leader; 2024 Gartner NDR Market Guide Representative Vendor
Use Cases

When would you choose this product?

Public sector

Detecting covert communication channels and data egress

In public sector organizations, targeted attacks tend to be long-running and quiet; data egress is hidden inside name resolution or permitted web protocols. Deep Discovery turns these covert channels into alerts through protocol anomalies and connection patterns, giving the SOC team the investigative context that shows which asset the incident started from.

Banking and finance

Continuous monitoring around the cardholder data environment

PCI DSS v4.0 Requirement 11.5.1 mandates that all traffic at the perimeter of and at critical points within the cardholder data environment be monitored with intrusion detection techniques; 11.5.1.1 makes detection of covert malware communication channels mandatory for service providers. Deep Discovery establishes a monitoring layer that meets both requirements with a single sensor and produces evidence for audit.

Manufacturing and energy

Lateral movement visibility at the IT-OT boundary

No endpoint agent can be installed on OT controllers, PLCs or industrial HMI stations; the behaviour of these assets is visible only on the network. Positioned at the IT-OT boundary, Deep Discovery uses passive listening to surface sessions attempting to cross from the office network into the production network and unexpected remote administration connections, without adding latency to production traffic.

Healthcare

Agentless visibility in the medical device segment

Imaging systems, laboratory devices and bedside monitors mostly run vendor-locked operating systems and accept no agent. Deep Discovery monitors this segment through its traffic to detect unexpected external connections and unusually large data egress; the egress of special categories of personal data under KVKK is thereby recorded.

Retail and logistics

Monitoring supplier and dealer connections

Third-party sessions connected to the network for maintenance, integration or order transfer do not appear in the organization's endpoint inventory. By monitoring these connections from the network side, Deep Discovery makes visible any access that goes beyond the scope defined in the contract, as well as attempts to spread from branch networks toward headquarters.

Holdings and multi-site organizations

Phased rollout with virtual appliances

In organizations with many branches, placing hardware at every location is not economical. A phased architecture is built with a hardware appliance at headquarters and virtual appliances in the 100–1,000 Mbps tiers at the branches; the events from all sensors converge in a single console in Vision One, and attack patterns common across branches become visible centrally.

Who is it for?

Critical infrastructure, public sector, finance, healthcare and manufacturing organizations with a mature SOC team or a managed security service. Particularly suited to networks with a high number of devices that cannot host an endpoint agent and with an IT-OT boundary.

Frequently Asked Questions

Frequently asked questions

Does Deep Discovery run inline or out-of-band?
It runs out-of-band. It listens passively to traffic through a SPAN port or a TAP and does not enter the network path. A device failure therefore does not turn into a network outage and does not consume your latency budget. In return it does not block directly; to block a detected threat, an inline IPS such as TippingPoint or the response capability on the endpoint side comes into play.
What is the difference between TippingPoint and Deep Discovery?
TippingPoint is an inline intrusion prevention system: it sits in the traffic path and blocks known exploit attempts on the link. Deep Discovery is an out-of-band network detection and response solution: it analyses a copy of the traffic, confirms unknown malware in the sandbox and shows how the attack moved through the network. One closes the door, the other explains what happened inside; in enterprise architecture the two are positioned together.
How is the organization-specific sandbox prepared?
Virtual images matching the organization's own operating system configuration, drivers, installed applications and language versions are loaded into the sandbox (Deep Discovery Inspector Datasheet, 2024). The Turkish Windows installation, the in-house ERP or banking client, the VPN configuration and the certificate store are all moved into the image. Targeted malware that recognizes standard analysis environments and goes dormant therefore shows its real behaviour.
Are suspicious files sent abroad for analysis?
That depends on the deployment model you choose. In a hardware appliance deployment, analysis is performed in local Virtual Analyzer instances on the appliance; 2 to 40 concurrent instances are supported per model. In a virtual appliance deployment, cloud analysis comes into play through the Sandbox as a Service add-on (Deep Discovery Inspector Datasheet, 2024). For public sector, finance and healthcare organizations with data residency sensitivities under KVKK, we recommend the local analysis model in which samples never leave the corporate network.
Which protocols and traffic directions are monitored?
Deep Discovery Inspector monitors all network ports and more than 100 network protocols; it covers both north-south and east-west traffic (Deep Discovery Inspector Datasheet, 2024). Web, email, file sharing, name resolution, remote desktop and directory service protocols are within that scope. Because the exact protocol list varies by version, we verify against the current list before commissioning.
Does it have a negative impact on network performance?
No. Because the appliance listens to a copy of the traffic, it adds no latency to the production flow; performance is only a question of the SPAN port's capacity. On busy segments we recommend a TAP instead of a SPAN, and an aggregation TAP if several segments are to be monitored. The capacity plan is derived from peak traffic measurements taken on the segments to be monitored.
Which platforms does the virtual appliance version run on?
The virtual Deep Discovery Inspector is offered in 100, 250, 500 and 1,000 Mbps capacity tiers and runs on VMware vSphere 5 and above or on KVM; the cloud sandbox is added through the Sandbox as a Service add-on (Deep Discovery Inspector Datasheet, 2024). Because it requires no hardware, it enables fast commissioning in branch networks and pilot projects.
Do we really need network detection when we already have endpoint protection?
Yes, because the two close different gaps. An endpoint agent cannot be installed on a printer, an IP camera, an OT controller, a medical device or a guest laptop; the behaviour of these assets is visible only on the network. Moreover, an endpoint whose agent has been disabled still leaves traces in network traffic. Apex One and Deep Discovery confirm the same event from two different sources.
Can Deep Discovery be used without Trend Vision One?
It can; Deep Discovery is also positioned as a standalone NDR product. But its real value emerges in correlation: Vision One has six native sensors — endpoint, cloud, email, network, server and identity (Trend Micro Newsroom, 2025) — and it combines the network event with the other five sources. If your existing investment is in a different XDR, we evaluate the integration options together.
How is detection performed on encrypted (TLS) traffic?
The contents of encrypted sessions are not visible to passive listening; this is a constraint that applies to every network detection product. In practice we follow two routes: positioning the sensor behind a load balancer or security gateway that performs decryption, or detecting on the basis of connection pattern, destination reputation, session duration and flow volume rather than content. Endpoint telemetry is the second source that completes this gap.
What kind of team is needed to operate Deep Discovery?
You need SOC capacity to triage the alerts; otherwise detections pile up unread. In organizations without their own SOC, we carry out the tuning work in the first week and then sustain the monthly detection summary and incident response support as a managed service. If there is an in-house team, we provide knowledge transfer and threat hunting training after commissioning.
Which compliance requirements does it map to?
PCI DSS v4.0 Requirement 11.5.1 mandates that intrusion detection/prevention techniques monitor all traffic at the perimeter of and at critical points within the cardholder data environment; 11.5.1.1 makes detection of covert malware communication channels mandatory for service providers as of 31 March 2025 (PCI Security Standards Council). The KVKK Personal Data Security Guide likewise lists intrusion detection and prevention systems and log records among technical measures (KVKK).
How are Deep Discovery licensing and pricing determined?
Price varies with the traffic capacity to be monitored, whether hardware or a virtual appliance is preferred, the number of concurrent sandbox instances and the subscription term. We therefore prepare a project-specific quote rather than a list price. If you share your network topology and peak traffic measurement, we will come back with a sizing recommendation — request a quote.
How does it work with our existing SIEM and SOAR investment?
Network events flow into the central analysis layer through Vision One. The platform's Agentic SIEM component became available on 1 August 2025, supports more than 900 data sources and provides up to 2 years of analytic and up to 7 years of archive data retention (Trend Micro Newsroom, 2025). If you want to keep your existing SIEM, we design the event forwarding together as part of the rollout.
Can we run a pilot deployment before buying?
Yes. We usually set up a two- to four-week observation period on a single segment with a virtual appliance. During that time we measure what is actually detected on your network, the daily alert volume and the tuning effort required; the capacity model is finalized on the basis of that measurement. The pilot output lets you make the investment decision with data from your own traffic rather than with assumptions.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

Trend MicroDeep Discovery (Network Detection)
Related Services

Services we deliver alongside this product

Deep Discovery (Network Detection) licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support