Trend Deep Discovery NDR is a network detection and response product family that passively listens to enterprise network traffic to detect targeted attacks (APT), lateral movement and data exfiltration attempts. The enterprise business unit of Trend Micro, which develops the product, has been known as TrendAI™ since March 2026; product names, existing licences and the parent company name (Trend Micro Incorporated) are unchanged. The core of the family, Deep Discovery Inspector, connects to the network through a SPAN port or a TAP; it monitors all network ports and more than 100 network protocols, covering both north-south and east-west traffic (Trend Micro Deep Discovery Inspector Datasheet, 2024). Every asset that connects to the network falls into that field of view, including printers, IP cameras, OT controllers, medical devices and guest devices on which no endpoint agent can be installed.
Breach data shows why this layer is needed. According to the Verizon 2025 Data Breach Investigations Report, vulnerability exploitation as an initial access step grew 34% in a year and now accounts for 20% of breaches (Verizon 2025 DBIR, 2025). According to the measurement IBM published the same year, the global average time until a breach is identified and contained is 241 days (IBM Cost of a Data Breach Report 2025, 2025). If an attacker can stay in the environment for months, the problem is not only prevention but visibility — and where there is no endpoint agent, the only witness is the network itself.
Which attack behaviours does Deep Discovery actually detect?
Its detections work through behaviour and context rather than signature matching: command-and-control (C&C) communication, use of covert channels, internal reconnaissance, lateral movement, unusually large outbound data volumes and confirmation of unknown malware in the sandbox. The engines look not at a single packet but at the sequence of events belonging to the same asset; the output is therefore not a list of alerts but an attack narrative.
In practice, the behaviour clusters monitored are as follows:
- Command-and-control traffic: callback channels established over web, name resolution and lesser-known protocols, together with fixed-interval (beaconing) connection patterns.
- Covert communication channels: data flows hidden inside DNS, ICMP or permitted web protocols; this is precisely the category PCI DSS v4.0 explicitly requires service providers to detect.
- Lateral movement: attempts to spread from server to server over file sharing, remote desktop, remote administration and directory service protocols.
- Data exfiltration: transfers to unusual destinations, at unusual hours and in unusual volumes; compressed and fragmented egress patterns.
- Unknown malware: behavioural classification of executables, scripts and document attachments crossing the network by running them in the sandbox.
- Agentless assets: anomalous traffic and unexpected external connections generated by devices on which endpoint protection cannot be installed.
What these behaviour clusters have in common is that none of them can be reduced to the question of whether a single file is malicious. Most of the tools used in a targeted attack are legitimate components already present on the system; what is anomalous is not the tool but the context in which it is used. The network layer is the only place that records that context — who is talking to whom, when and at what volume.
Why is an organization-specific sandbox more effective than a standard cloud sandbox?
Because targeted malware recognizes the environment it runs in. Deep Discovery's customized sandbox uses virtual images that exactly match the organization's own operating system configuration, drivers, installed applications and language versions; threats designed to evade standard images are caught this way (Trend Micro Deep Discovery Inspector Datasheet, 2024).
A team developing a targeted attack first tries the sample in common analysis environments. Virtual machine artifacts, missing drivers, an English system language, the absence of corporate applications, a machine image not joined to the domain — when any one of these signals is seen, the malware terminates without doing anything and the analysis produces a "clean" verdict. Once the organization's golden image is moved into the sandbox, that evasion disappears: a Turkish Windows installation, the in-house ERP or banking client, the VPN client and the certificate store all become part of the image. If the same sample is also seen on the endpoint, blocking is enforced on the Apex One endpoint protection side.
The second difference emerges after the analysis. The sandbox does not produce only a "malicious" or "clean" verdict; it also reports the domains the sample contacted, the files it dropped, the processes it created and the registry changes it made. These indicators (IoCs) can be turned directly into a hunting query: which other device connected to the same domain, on which other server was the same file name created. Detection thus moves beyond closing a single incident to sweeping the entire campaign.
How does lateral movement become visible at the network layer?
Lateral movement is by definition traffic between two internal systems; it therefore never passes the perimeter firewall. Because Deep Discovery Inspector also covers east-west traffic (Deep Discovery Inspector Datasheet, 2024), it can see a file-sharing session opened from one server to another, an unexpected remote desktop connection, or a service account reaching shares it has never touched before.
This visibility is decisive for supply chain risk too. The Verizon 2025 DBIR reported that the share of breaches involving a third party doubled in a year, rising from 15% to 30% (Verizon 2025 DBIR, 2025). Movement arriving through a supplier session connected to your network for maintenance purposes does not show up in your endpoint inventory; it shows up in the network flow.
In a ransomware scenario, the reconnaissance and propagation phase before encryption is the only time window you have to respond. According to Trend Zero Day Initiative data, 59 zero-day vulnerabilities have been used in ransomware attacks since 2020 (Trend 2025 Cyber Risk Report, 2025); in other words, initial access can happen through a vulnerability that has no patch yet. Since blocking initial access is not always possible, being able to see the second step becomes decisive.
Which Deep Discovery capacity suits which network?
In a Trend Deep Discovery NDR deployment, the choice depends on two parameters: the peak rate of the traffic to be monitored and the number of suspicious files expected to be analysed per day. Deep Discovery Inspector hardware models deliver between 500 Mbps and 40 Gbps of inspection throughput and support 2 to 40 concurrent sandbox (Virtual Analyzer) instances per model; the virtual appliance version is offered at 100, 250, 500 and 1,000 Mbps capacities and runs on VMware vSphere 5 and above or on KVM (Deep Discovery Inspector Datasheet, 2024).
| Comparison criterion | Virtual appliance | Hardware appliance |
|---|
| Inspection capacity | 100 / 250 / 500 / 1,000 Mbps | 500 Mbps – 40 Gbps depending on model |
| Sandbox (Virtual Analyzer) | Cloud analysis via the Sandbox as a Service add-on | 2 – 40 concurrent analysis instances per model |
| Platform | VMware vSphere 5 and above, or KVM | On its own hardware |
| Hardware investment | Not required | Required |
| Network connection | SPAN port or TAP (out-of-band) | SPAN port or TAP (out-of-band) |
| Typical placement | Branch, remote site, pilot deployment, virtualized data center edge | Internet egress point, data center core, campus backbone, IT-OT boundary |
The virtual appliance option is a practical starting point for organizations that want to run a pilot without a hardware investment; in this model, sandbox analysis is performed in the cloud through the Sandbox as a Service add-on (Deep Discovery Inspector Datasheet, 2024). For organizations that do not want suspicious files to leave the corporate network, we recommend the hardware deployment, which keeps analysis in local Virtual Analyzer instances on the appliance itself. We base the capacity decision on peak traffic measurements taken on the segments to be monitored rather than on assumptions; where the SPAN port itself is the bottleneck, we recommend a TAP or an aggregation TAP placement.
What role does Deep Discovery play within Trend Vision One?
The role of network sensor. Trend Vision One has six native security sensors — endpoint, cloud, email, network, server and identity (Trend Micro Newsroom, 2025) — and Trend Deep Discovery NDR feeds the network leg of those six. A standalone NDR product tells you "this address is talking to that address"; XDR correlation combines the same event with which user opened which email attachment, which process started on which server and which identity was used.
That correlation has a measured counterpart: in the MITRE ATT&CK Evaluations round announced in December 2024, Trend Vision One achieved 100% analytic coverage across all major attack steps and 99% across all substeps (Trend Micro Newsroom, 2024). The platform's Agentic SIEM component became available on 1 August 2025, supports more than 900 data sources and offers up to 2 years of analytic and up to 7 years of archive data retention (Trend Micro Newsroom, 2025). The network events Deep Discovery produces flow into that retention and query layer, which also covers the need for audit and post-incident investigation.
On the independent analyst side, Deep Discovery Inspector was positioned as a Leader in the Forrester Wave Network Analysis and Visibility Q2 2023 evaluation and was named a Representative Vendor in the 2024 Gartner Market Guide for Network Detection and Response (Deep Discovery Inspector Datasheet, 2024). You can review the platform as a whole on the Trend Vision One XDR platform page and the other components on the Trend Micro solution family page.
How do TippingPoint, Deep Security and Deep Discovery divide the work?
The three do not do the same job; they complement each other as layers. TippingPoint stands on the link and blocks, Deep Security stands inside the server and protects the workload, Deep Discovery stands beside the link and sees. For a mid-sized or large organization, needing all three is not the exception but the typical architecture.
| Criterion | Deep Discovery (NDR) | TippingPoint (IPS) | Deep Security (server / workload) |
|---|
| Placement | Out-of-band — SPAN port or TAP | Inline — in the traffic path | Agent-based — in the server operating system |
| Primary function | Detection, sandbox analysis and investigation | Blocking and virtual patching | Server protection modules and virtual patching |
| Impact on network traffic | None (passive listening) | Requires a latency budget | None (runs on the host) |
| Field of view | North-south + east-west, more than 100 protocols | Traffic on the inspected link | The protected server itself |
| Sandbox analysis | Locally or in the cloud with organization-specific images | Out of scope | Out of scope |
| Agentless device coverage | Yes — printers, cameras, OT, medical devices, guests | Yes if on the inspected link | No |
| Typical justification | APT and lateral movement visibility | Shielding unpatchable systems on the link | Server and cloud workload compliance |
For the prevention layer see the TippingPoint next-generation IPS page, and for the server and cloud workload layer the Deep Security server protection page. The shared intelligence source behind these three products is the Trend Zero Day Initiative: ZDI has coordinated the disclosure of more than 15,000 vulnerabilities since 2007, and more than 19,000 independent researchers contribute to the program (Zero Day Initiative — About, 2026). The answer to why an exploit attempt seen on the network is recognized at all lies largely in that research chain.
Why should email security and network detection be positioned together?
Because a targeted attack usually begins with email and continues on the network. According to ENISA Threat Landscape 2025, phishing is by far the most common initial access vector in Europe at 60%, followed by vulnerability exploitation at 21.3% (ENISA Threat Landscape 2025, 2025). The same report examined 4,875 incidents targeting the EU between 1 July 2024 and 30 June 2025 and noted that 53.7% of the incidents concerned essential entities within the scope of the NIS2 Directive (ENISA Threat Landscape 2025, 2025).
An attachment that the email layer fails to catch gives itself away at the network layer through callback traffic. Trend's email and collaboration protection detected and blocked 57 million high-risk email threats in 2024, a 27% increase over the 45 million in 2023 (Trend 2025 Cyber Risk Report, 2025). For organizations that want to design both layers together, we recommend also evaluating the scope of Trend Email Security; a threat stopped in email never becomes an incident to investigate on the network.
Which KVKK and PCI DSS requirements does Deep Discovery map to?
Trend Deep Discovery NDR maps directly to two headings: intrusion detection and log records. In the KVKK (Turkey's data protection law) Personal Data Security Guide (Technical and Administrative Measures), "Intrusion Detection and Prevention Systems" and "Log Records" are explicitly listed among the technical measures a data controller may take (KVKK Personal Data Security Guide). The same guide states that the view that full security can be achieved with a single cybersecurity product is not always correct, and recommends applying layered measures that are reviewed regularly.
On the PCI DSS v4.0 side the connection is even clearer. Requirement 11.5.1 requires intrusion detection and/or prevention techniques to monitor all traffic at the perimeter of the cardholder data environment (CDE) and at critical points within the CDE, and requires signatures and baselines to be kept current; Requirement 11.5.1.1 makes detection of covert malware communication channels mandatory for service providers as of 31 March 2025 (PCI Security Standards Council, PCI DSS v4.0). Deep Discovery's covert channel and command-and-control detection maps precisely to that requirement.
In Turkey, the question we hear most often from finance, public sector, healthcare and manufacturing organizations is where the data goes. In organizations that do not want suspicious samples to leave the corporate network, we stay in the local analysis mode on the appliance and enable the cloud sandbox only with the organization's explicit approval. Log retention periods, the reporting that may be requested in a KVKK audit and the incident response procedure are all defined together within the scope of the rollout; these are topics decided on day one of the project, not added later.
How does Sora Yazılım run a Deep Discovery project?
In four phases: traffic discovery, sizing, commissioning and operations. First we establish which segments will be monitored, the peak traffic volume and the existing SPAN/TAP infrastructure; then we determine the capacity model, the sandbox image and the placement points.
During commissioning, the organization's golden image is moved into the sandbox, noise reduction (tuning) work is carried out in the first week and the event stream is connected to the XDR console. If changes are required on the network architecture, virtualization or monitoring infrastructure, the same project team carries them out under our DevOps and infrastructure services. In the operations phase we provide a monthly detection summary, engine and signature updates, version upgrades and incident response support.
Sora Yazılım is an authorized Trend Micro channel partner; Deep Discovery licensing, sizing, deployment and KVKK-compliant operation are handled end to end from a single source. The vendor's enterprise security business works with 6,000 experts in 75 countries (Trend Micro Newsroom, 2026); vendor support and the escalation chain run through that structure.
Summary: Trend Deep Discovery NDR passively listens to network traffic to detect targeted attack, lateral movement and data exfiltration behaviour across more than 100 protocols; with an organization-specific sandbox it surfaces malware that evades standard analysis environments, and it connects to Vision One as a network sensor. Let us work out together which segments of your network have visibility gaps. Because the capacity model, sandbox design and licence items vary with the volume of traffic to be monitored and the subscription term, we prepare a project-specific quote instead of a standard price list — request a quote and our engineers will review your network topology and come back with a SPAN/TAP plan and a sizing recommendation.