MDR partner · TrendAI Vision One

MDR for Trend Vision One, with analysts who contain.

For teams running Trend Micro Vision One, now TrendAI Vision One, with nobody to act on the Workbench at night, or a provider that opens tickets instead of isolating. The Fortgale MDR service works on your console with the mandate to contain, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Vision One
MDR · live
Vision One sensor activeEndpoint · cloud · identity telemetry
Vision One
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Vision One responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Vision One + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
TrendAI Vision One
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Vision One.

The Vision One XDR components the SOC operates. The vendor name changed, the modules did not: if the platform is not in place yet, licensing and agent rollout are part of the service.

01

XDR for Endpoints

Agent telemetry on endpoints and servers, the protection that grew out of Apex One and Workload Security, with alerts landing in the Workbench.

02

XDR for Email

Exchange Online and Gmail: suspicious messages are quarantined or deleted from the affected mailboxes, straight from the console.

03

XDR for Identity

Active Directory, Entra ID and Okta: anomalous sign-ins read in the same Workbench as the endpoint, with actions on the account.

04

XDR for Networks

Vision One network sensors for the traffic agents cannot see, correlated with endpoint and email.

05

XDR for Cloud

Cloud workloads and activity monitored with the platform's cloud components, in the same console.

06

Cyber Risk Exposure Management

Exposure and risk by asset and identity (formerly Attack Surface Risk Management), used to decide where to look first.

What we add

What Fortgale adds on top of Vision One.

What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.

On Vision One the analyst responds with the console's native tasks: Isolate Endpoint, process termination and a Remote Shell session on the host to collect artefacts or run remediation.

On email the tasks quarantine or delete the message; on identity they disable the account in Active Directory, Entra ID or Okta and force sign-out and password reset. A block on a third-party firewall is not a native task: it goes through the integrations agreed at onboarding.

Fortgale CTI indicators, 34,000 IOCs a week, enter Vision One as Custom Intelligence and feed the Suspicious Object List; Fortgale rules live as filters and custom models, including ones imported from Sigma, and raise alerts in the Workbench.

Takeover

How we take over your Vision One environment.

Agents already deployed stay untouched: takeover works on your Vision One tenant, with no reinstallation and no console change.

Analysts see the Workbench as soon as accounts are live, and technical onboarding closes in one week: roles, playbooks, custom models and response authorisations.

On your side: console accounts with the agreed roles, the endpoints and users where isolation and account disabling are pre-authorised, and the escalation contacts.

From the field

Kits that get past MFA: the target is the session.

In April 2026 Fortgale CTI published an analysis of phishing kits that bypass MFA: EvilProxy, Rockstar 2FA, FlowerStorm and Evilginx2 act as reverse proxies and steal the session once authenticated, EvilTokens abuses the Microsoft device code flow, BlackForce injects code into the browser. After access no malware is needed: inbox rules that hide security alerts, searches for financial threads via Graph API, fraud emails and payroll redirection.

The article is not about Vision One, but responding to those attacks relies on tasks the console already has: quarantining the message in every mailbox it reached and, on the affected account, forced sign-out together with a password reset, because changing the password alone does not close a stolen session.

FAQ

What buyers running Vision One actually ask.

Do we need Trend's MDR service to work with Fortgale?

No. The TrendAI Vision One MDR service, part of TrendAI Service One, is the vendor's own. Fortgale works independently on the Vision One platform you already have, with analysts in a SOC in Milan who operate in European time zones and under European rules.

Does the move from Trend Micro to TrendAI change anything?

Not for the service. Since 23 March 2026 the Trend Micro enterprise business is called TrendAI and the platform TrendAI Vision One; console, agents and tenant stay the same, and the SOC keeps working on them with the same access.

What happens to our console and our access?

The tenant, its policies and its data remain yours. Our analysts log in with the roles agreed at onboarding, and every response task they run stays in the Response Management history, where your team can review it.

How do we move from another provider without a gap in coverage?

If the previous provider already worked on Vision One, the agents do not move: only accounts and authorisations change hands. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.

Do we buy the Vision One licences, or do you?

Either way. Vision One runs on credits: if you already have them, Fortgale operates your tenant; if not, licensing is included in the MDR service. At onboarding we check that the credits cover the XDR components needed.

See a real runbook

A real runbook on your Workbench.

We walk through a Vision One alert step by step: the model that raised it, the Fortgale indicators involved, the endpoint isolation and the account disabling. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.