A real case, not a hypothetical
In a real Trend Vision One alert (WB-18765, July 2026), Defend's reasoning engine correctly closed a benign UltraViewer detection in seconds — asset context, 8 months of clean history, and normal-hours timing all cited in the audit trail — with zero analyst interruption. Trend, Darktrace, and CrowdStrike remain excellent detection engines; Defend is the layer that decides what happens next.
The real 3-mode dashboard (Tactical / Operational / Strategic) replaying the Trend Vision One case above — not a screenshot.
Works alongside the tools you already run
Trend Micro Vision One · Darktrace · Fortinet · Microsoft 365 Defender · Wazuh · Cortex XSOAR
Aggregation mode works with zero new agents deployed — Defend correlates across every connected source, it doesn’t replace any of them.
PB-13, LD-24: reversible, evidence-preserving steps run behind one confirm. Session termination is never bundled — it's a separate, explicit human decision, gated until capture actually completes.
No. Defend is built to sit above your existing stack — Darktrace, Trend Micro, Fortinet, and others connect in as-is via XDR connectors. Aggregation mode works with zero new agents deployed.
Every response action goes through an auditable approval gate. Automated response steps that are reversible and evidence-preserving can fire on a one-click confirm; anything that terminates a session or takes an irreversible action always requires an explicit human confirmation, logged to an append-only audit trail.
A single vendor's console only sees that vendor's own telemetry. Defend correlates across every connected tool, translates the result into a board-level business risk score, and runs a PDPA-aware breach workflow on top — none of which a single-vendor console does natively.