VMware vDefend Advanced Threat Prevention

VMware vDefend Advanced Threat Prevention

Brand: VMware | Category: Network Security

SKU: VDEFEND-ATP-C-SUB | Part #: VDEFEND-ATP-C-SUB | MPN: VDEFEND-ATP-C-SUB

Contact for Pricing — Request a Quote

Request a Quote Contact Us

About the VMware vDefend Advanced Threat Prevention

VMware vDefend Advanced Threat Prevention is a purpose-built network security solution designed to detect and prevent advanced threats traversing east-west (lateral) traffic within software-defined data centers and multi-cloud environments. Formerly part of the VMware NSX security portfolio and rebranded under the vDefend product line in 2025-Q1, it delivers integrated Intrusion Detection and Prevention System (IDS/IPS) capabilities alongside Network Detection and Response (NDR) functions directly at the workload level, without requiring dedicated physical appliances or network hairpinning.

The solution operates as a distributed security service tightly coupled with VMware NSX, inspecting traffic flows between virtual machines, containers, and bare-metal workloads at line rate. Its threat-detection engine combines signature-based IDS/IPS rules with behavioral analytics and network traffic analysis (NTA) to identify lateral movement, command-and-control callbacks, malware propagation, and zero-day exploitation attempts. Threat intelligence feeds are continuously updated through VMware's threat research infrastructure, and detected events are correlated and surfaced through a unified security console integrated with NSX Manager.

VMware vDefend Advanced Threat Prevention is targeted at enterprise organizations seeking to enforce micro-segmentation security postures with active threat prevention rather than passive monitoring alone. It is particularly suited to regulated industries—including financial services, healthcare, and government—that require deep packet inspection of internal traffic to satisfy compliance mandates such as PCI-DSS, HIPAA, and NIST frameworks. The solution is offered under a subscription licensing model (part number VDEFEND-ATP-C-SUB), enabling flexible term-based procurement aligned to organizational capacity requirements.

Ideal for

  • Detecting and blocking lateral movement by threat actors who have breached a perimeter control and are attempting to propagate across internal workloads within a VMware NSX-segmented data center.
  • Enforcing active IDS/IPS inspection on east-west traffic between application tiers (web, application, and database layers) without redirecting traffic to out-of-band physical security appliances.
  • Satisfying PCI-DSS Requirement 11.4 and similar compliance mandates that require intrusion detection and prevention mechanisms on internal network segments handling cardholder or sensitive data.
  • Providing network detection and response (NDR) visibility into encrypted and unencrypted lateral traffic flows for security operations center (SOC) teams conducting threat hunting and incident investigation.
  • Integrating east-west threat event data with SIEM and SOAR platforms to enable automated response playbooks triggered by confirmed IDS/IPS alerts within the virtualized infrastructure.
  • Extending consistent advanced threat prevention policy across hybrid and multi-cloud environments where workloads span on-premises NSX deployments and VMware Cloud instances.

Technical specifications

ManufacturerVMware
BrandVMware
Product NameVMware vDefend Advanced Threat Prevention
Manufacturer Part NumberVDEFEND-ATP-C-SUB
Product LineVMware vDefend
CategoryNetwork Security
Licensing ModelSubscription (term-based)
Primary Security FunctionIntrusion Detection and Prevention System (IDS/IPS) with Network Detection and Response (NDR)
Traffic Inspection PlaneEast-west (lateral) traffic within NSX-managed environments
Deployment ArchitectureDistributed, kernel-integrated service on NSX-prepared hypervisor hosts; no dedicated physical appliance required
Platform DependencyVMware NSX (required as underlying network virtualization platform)
Workload SupportVirtual machines, containerized workloads, and bare-metal servers managed within NSX
Inspection MethodDistributed deep packet inspection (DPI) at the vNIC level
Detection CapabilitiesSignature-based IDS/IPS, behavioral network traffic analysis (NTA), lateral movement detection, command-and-control (C2) identification
Threat Intelligence UpdatesContinuous signature and threat intelligence feed updates via VMware threat research infrastructure
Management IntegrationVMware NSX Manager unified console; API-accessible for SIEM and SOAR integration
Deployment ModelSoftware-only; delivered as a licensed feature set activated on existing NSX infrastructure
AvailabilityGenerally available from 2025-Q1
Supported EnvironmentsOn-premises VMware vSphere/NSX deployments; VMware Cloud environments

Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.

Technical Specifications

BrandVMware
CategoryNetwork Security
SKUVDEFEND-ATP-C-SUB
Part NumberVDEFEND-ATP-C-SUB
ConditionNew
Product NameVMware vDefend Advanced Threat Prevention
Manufacturer Part NumberVDEFEND-ATP-C-SUB
Product LineVMware vDefend
Licensing ModelSubscription (term-based)
Primary Security FunctionIntrusion Detection and Prevention System (IDS/IPS) with Network Detection and Response (NDR)
Traffic Inspection PlaneEast-west (lateral) traffic within NSX-managed environments
Deployment ArchitectureDistributed, kernel-integrated service on NSX-prepared hypervisor hosts; no dedicated physical appliance required
Platform DependencyVMware NSX (required as underlying network virtualization platform)
Workload SupportVirtual machines, containerized workloads, and bare-metal servers managed within NSX
Inspection MethodDistributed deep packet inspection (DPI) at the vNIC level
Detection CapabilitiesSignature-based IDS/IPS, behavioral network traffic analysis (NTA), lateral movement detection, command-and-control (C2) identification
Threat Intelligence UpdatesContinuous signature and threat intelligence feed updates via VMware threat research infrastructure
Management IntegrationVMware NSX Manager unified console; API-accessible for SIEM and SOAR integration
Deployment ModelSoftware-only; delivered as a licensed feature set activated on existing NSX infrastructure
AvailabilityGenerally available from 2025-Q1
Supported EnvironmentsOn-premises VMware vSphere/NSX deployments; VMware Cloud environments