XDR for Endpoints
Agent telemetry on endpoints and servers, the protection that grew out of Apex One and Workload Security, with alerts landing in the Workbench.
For teams running Trend Micro Vision One, now TrendAI Vision One, with nobody to act on the Workbench at night, or a provider that opens tickets instead of isolating. The Fortgale MDR service works on your console with the mandate to contain, at a median TTC of <30 minutes.
The Vision One XDR components the SOC operates. The vendor name changed, the modules did not: if the platform is not in place yet, licensing and agent rollout are part of the service.
Agent telemetry on endpoints and servers, the protection that grew out of Apex One and Workload Security, with alerts landing in the Workbench.
Exchange Online and Gmail: suspicious messages are quarantined or deleted from the affected mailboxes, straight from the console.
Active Directory, Entra ID and Okta: anomalous sign-ins read in the same Workbench as the endpoint, with actions on the account.
Vision One network sensors for the traffic agents cannot see, correlated with endpoint and email.
Cloud workloads and activity monitored with the platform's cloud components, in the same console.
Exposure and risk by asset and identity (formerly Attack Surface Risk Management), used to decide where to look first.
What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.
On Vision One the analyst responds with the console's native tasks: Isolate Endpoint, process termination and a Remote Shell session on the host to collect artefacts or run remediation.
On email the tasks quarantine or delete the message; on identity they disable the account in Active Directory, Entra ID or Okta and force sign-out and password reset. A block on a third-party firewall is not a native task: it goes through the integrations agreed at onboarding.
Fortgale CTI indicators, 34,000 IOCs a week, enter Vision One as Custom Intelligence and feed the Suspicious Object List; Fortgale rules live as filters and custom models, including ones imported from Sigma, and raise alerts in the Workbench.
Agents already deployed stay untouched: takeover works on your Vision One tenant, with no reinstallation and no console change.
Analysts see the Workbench as soon as accounts are live, and technical onboarding closes in one week: roles, playbooks, custom models and response authorisations.
On your side: console accounts with the agreed roles, the endpoints and users where isolation and account disabling are pre-authorised, and the escalation contacts.
In April 2026 Fortgale CTI published an analysis of phishing kits that bypass MFA: EvilProxy, Rockstar 2FA, FlowerStorm and Evilginx2 act as reverse proxies and steal the session once authenticated, EvilTokens abuses the Microsoft device code flow, BlackForce injects code into the browser. After access no malware is needed: inbox rules that hide security alerts, searches for financial threads via Graph API, fraud emails and payroll redirection.
The article is not about Vision One, but responding to those attacks relies on tasks the console already has: quarantining the message in every mailbox it reached and, on the affected account, forced sign-out together with a password reset, because changing the password alone does not close a stolen session.
No. The TrendAI Vision One MDR service, part of TrendAI Service One, is the vendor's own. Fortgale works independently on the Vision One platform you already have, with analysts in a SOC in Milan who operate in European time zones and under European rules.
Not for the service. Since 23 March 2026 the Trend Micro enterprise business is called TrendAI and the platform TrendAI Vision One; console, agents and tenant stay the same, and the SOC keeps working on them with the same access.
The tenant, its policies and its data remain yours. Our analysts log in with the roles agreed at onboarding, and every response task they run stays in the Response Management history, where your team can review it.
If the previous provider already worked on Vision One, the agents do not move: only accounts and authorisations change hands. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.
Either way. Vision One runs on credits: if you already have them, Fortgale operates your tenant; if not, licensing is included in the MDR service. At onboarding we check that the credits cover the XDR components needed.
We walk through a Vision One alert step by step: the model that raised it, the Fortgale indicators involved, the endpoint isolation and the account disabling. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.