Overview
Trellix Helix Connect helps accelerate your SOC maturity with 100% alert triage, prioritization of threats and GenAI powered insights. Analysts of any level are empowered to prioritize investigations, get straight forward summaries and guidance to remediate or hunt for threats. Helix Connect integrates security controls from the Trellix Security Platform and over 500 third-parties (including 13 AWS integrations) to create deep multi-vector threat detections. Data is ingested from multiple sources, then correlated by pre-built analytics and rules so that you can rapidly see the complete story of an attack. UI-driven, point and click automation helps you to offload repetitive tasks and boost your SecOps team efficiency. Most customers will prefer an AWS Private Offer be extended, which may include customizations to the offering or additional pricing considerations. Not all purchasing options are shown due to the common requirement to customize each deployment of Trellix Helix Connect.
Highlights
- Improve SOC efficiency - Adding AI can do the work of several SOC analysts who are overwhelmed with logs and alerts.
- Reduce Risk - AI can help organizations focus on the most important threats.
- Revolutionize your SOC with AI-powered speed, adaptive threat insights, and AI-guided investigations.
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Helix-Connect-100 | Trellix Helix Connect - 100 users - Annual | $6,300.00 |
Helix-Connect-1000 | Trellix Helix Connect - 1000 users - Annual | $56,700.00 |
Trellix-OpenXDR-50GB | Trellix Open XDR for External Data add-on - 50GB addon | $21,971.25 |
EDR Wise Add-on 1:1TE | QTY Range 5-250 per user/annual | $24.15 |
EDR Wise Add-on 1:1TE | QTY Range 251-1000 per user/annual | $21.60 |
EDR Wise Add-on 1:1TE | QTY Range 1001-2000 per user/annual | $19.20 |
Vendor refund policy
Refunds are handled on a per case basis.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Please reach out to us at support@trellix.com with any questions or concerns, and our support team will be more than happy to help.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Continuous monitoring has strengthened real-time threat detection and automated incident response
What is our primary use case?
My main use case for Trellix Endpoint Detection and Response (EDR)Â is for real-time detection, response, and threat visibility. Trellix Endpoint Detection and Response (EDR)Â continuously monitors our endpoint activity and applies analytics plus behavioral monitoring to detect suspicious behavior, malware, ransomware, fileless attacks, and many more.
Once a threat is detected, it triggers automated or manual response where the security team takes action.
In addition to my main use case, Trellix Endpoint Detection and Response (EDR) also provides data collection and investigation tools so that security teams can investigate how an attack happened, what artifacts or behavior were involved, and scope the damage.
What is most valuable?
The best features Trellix Endpoint Detection and Response (EDR) offers include real-time detection, response, threat visibility, forensic and post-incident investigation plus threat hunting, and unified endpoint protection.
The forensic investigation and threat hunting features of Trellix Endpoint Detection and Response (EDR) have helped my security team by providing data collection and investigation tools so that our security teams can investigate how an attack happened, what artifacts or behaviors were involved, and scope the damage.
Trellix Endpoint Detection and Response (EDR) has positively impacted my organization by improving our security. We have experienced no more data breaches and no more threats from outside. I measure the improvement in security by noting that our security has improved by eighty percent.
What needs improvement?
One of the common criticisms that I find about Trellix Endpoint Detection and Response (EDR) is its high resource consumption, where it is significantly consuming a lot of CPU and RAM usage, which sometimes affects the performance on endpoints.
There is also limited integration with external platforms which has reduced flexibility in my organization.
For how long have I used the solution?
I have been using Trellix Endpoint Detection and Response (EDR) for three years.
What do I think about the stability of the solution?
Trellix Endpoint Detection and Response (EDR) is very stable.
What do I think about the scalability of the solution?
The scalability of Trellix Endpoint Detection and Response (EDR) is very good. It grows with our organization's needs.
How are customer service and support?
The customer support for Trellix Endpoint Detection and Response (EDR) is amazing and very responsive.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did not use another platform before.
How was the initial setup?
My experience with pricing, setup cost, and licensing was that the cost was effective and the setup was straightforward, not particularly challenging.
What was our ROI?
I have seen a return on investment where the threat detection speed and response automation has brought operational savings, reducing time spent on manual investigating alerts, limiting downtime, and containing incidents more quickly.
Which other solutions did I evaluate?
I evaluated other options before selecting Trellix Endpoint Detection and Response (EDR), including Microsoft Defender for Endpoint and Palo Alto Networks Cortex XDR .
What other advice do I have?
My advice to others looking into using Trellix Endpoint Detection and Response (EDR) is that it is the best EDR platform as it brings threat detection speed and response automation, automatically saving on operational cost while reducing time spent. I believe it is the best EDR solution in today's market.
A specific example of how I have used Trellix Endpoint Detection and Response (EDR) in my day-to-day work is that it isolates or quarantines a device or kills malicious processes instantly. This is very crucial for compliance, forensic analysis, and it has improved our defense in my organization. There is a need for better integration with external platforms. I would rate this review as nine out of ten.
Advanced threat detection has reduced breaches and supports fast forensic investigations
What is our primary use case?
My main use case for Trellix Endpoint Detection and Response (EDR)Â is detecting advanced threats, malware, ransomware, fileless attacks, zero-day exploits, and suspicious or anomalous behaviors.
I also use it for forensic investigation and root cause analysis, capturing endpoint state, processes, connections, memory, or files for post-attack analysis and compliance.
An example of how I have used Trellix Endpoint Detection and Response (EDR)Â for a forensic investigation is that it does not rely solely on signature-based malware detection. It can detect known, unknown, or novel threats, including zero-day, polymorphic, and fileless attacks by analyzing behavior and anomalies.
Trellix Endpoint Detection and Response (EDR) has reduced the risk of breaches and data loss by catching advanced threats early and enabling fast containment. It also helps avoid costs associated with a breach or data loss, remediation costs, legal compliance fines, reputation damage, and more.
What is most valuable?
The best features Trellix Endpoint Detection and Response (EDR) offers are advanced detection and behavior-based analytics, comprehensive endpoint visibility and context, and faster detection and response.
Out of those features, I rely on faster detection the most day-to-day, as it has reduced the risk of breaches and data loss.
Trellix Endpoint Detection and Response (EDR) has positively impacted my organization by reducing the risk of breaches and data loss by 80%.
What needs improvement?
Trellix Endpoint Detection and Response (EDR) can be improved in terms of complex deployment and administration.
Additionally, there is high resource consumption, especially with CPU memory, and it is not a lightweight platform.
For how long have I used the solution?
I have been working in my current field for five years.
What do I think about the stability of the solution?
In my experience, Trellix Endpoint Detection and Response (EDR) is stable with no major issues and no downtime. It is very stable.
What do I think about the scalability of the solution?
Trellix Endpoint Detection and Response (EDR) is very scalable and can handle my organization's growth.
How are customer service and support?
My experience with the customer support for Trellix Endpoint Detection and Response (EDR) was great because they are solution-oriented and resolve any issues that we have in my organization faster than expected.
I would rate the customer support nine out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
I have seen a return on investment with Trellix Endpoint Detection and Response (EDR) by having reduced risk of breaches and data loss, lower operational costs over time, and faster detection, response, and forensic investigation in my organization.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Trellix has been focused on pricing.
What other advice do I have?
My advice to others looking into using Trellix Endpoint Detection and Response (EDR) is that it is a great tool that reduces the risk of breaches and data loss. I would rate this product nine out of 10.
Enhancements needed for security alerts while ongoing training strengthens defenses
What is our primary use case?
I use César for our endpoints, our users, and the services from email and web services, back and forth, and also at the edge of our network. We have contracted firewalls and everything else for networking.
What is most valuable?
The product and the services we have are quite good. However, I cannot stay at this level forever. I have to improve continuously and dynamically.
Everything is working, and the company is training its personnel. I have had in a few months in the past some attacks on personnel—so phishing, for example. I have spent efforts on training our managers and others - what can software do if the knowledge base is low?
What needs improvement?
This year, I am going to improve some tools to be installed or maybe acquire some services to better manage our web services and work with my coworkers.
Application fiber also needs attention. Nowadays I am making applications that are publicly seen on the Internet. I need some protection, possibly multi-factor authentication improvements. I am seeing, for workflows, some sort of ethical hacking to test our environment.
Knowledge of everything, not only the product - maybe some kind of alerts - needs to emerge. I see the current ones as very low-tier, and they must improve.
For how long have I used the solution?
I have used Trellix for some years.
What do I think about the stability of the solution?
I haven't had any issues. The pricing is very fine and according to the service. Trellix has done a good job reducing threats.
How are customer service and support?
I have spent a lot of time with this product. I have contracted support and also have an operating control so I can get various types of support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have used Trellix for some years. In the past, the EDR was McAfee. I have worked with it for around 20 years.
How was the initial setup?
The initial setup is a hard issue.
What about the implementation team?
I have two contractors that help me support the infrastructure here. One is at the edge of networking, and the other is in the endpoints of our company.
What was our ROI?
I don't have any return on this investment. This is just a security policy for everything.
What's my experience with pricing, setup cost, and licensing?
I haven't had any really great problems with pricing in the past two or three years.
Which other solutions did I evaluate?
Maybe another level of product and support from manufacturers would be better.
What other advice do I have?
I have seen companies without any EDR services, and we were lacking information. I started with IDR around four years ago, and the support services were very light. I remember doing many tickets for Trellix support, and my EDR was not properly functioning. I didn't feel the detection or the real protection. My company is one among 17 others that are part of a corporation. I am a member of the IT Security Council.
Overall product rating is five out of ten.
Helpful to detect malware and threats
What is our primary use case?
I use the solution in my company for malware detection. My customers are mostly banking and government organizations.
What is most valuable?
The most valuable feature of the solution is its area for threat detection.
What needs improvement?
When it comes to some unknown fileless attacks, the tool is not able to detect them properly, making it an area where improvements are required.
The tool's support needs to improve in the areas of response it provides to users.
For how long have I used the solution?
I have been using Trellix Endpoint Detection and Response (EDR) for two and a half years.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution an eight out of ten.
How are customer service and support?
I rate the technical support a seven and a half out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution is SaaS-based, and we have deployed it using the hybrid cloud model.
The tool's deployment phase is a lengthy process. For one endpoint, it takes 15 to 20 minutes.
What was our ROI?
The tool is cost-effective. Many agents need to be installed, and on-premises integration is required.
What other advice do I have?
I haven't worked on the tool to see how it works for security workflow.
My customers have not seen any challenges while working with Trellix Endpoint Detection and Response (EDR) in terms of integrations.
The tool does not support any AI and security initiatives.
The tool is suitable for enterprise companies.
If businesses are completely on the cloud, then the tool is not required. If a company has a hybrid cloud model with an on-premises model, then it will be a good tool to use.
I rate the tool an eight out of ten.
Has behavior monitoring, DLP, and access control
What is our primary use case?
I've used Trellix EDR to improve endpoints and servers' security and feed into MDR solutions.
What is most valuable?
The most useful features are behavior monitoring, DLP, and access control. The automation has gotten much better in the last two years than when it was McAfee. It works better now and integrates more smoothly.
What needs improvement?
I'd like the tool to become more like an XDR, with one management system and endpoint activation.
For how long have I used the solution?
I have been using the solution for seven years.
What do I think about the stability of the solution?
Sometimes, stability issues come from incorrect partner deployments, not Trellix EDR itself.
What do I think about the scalability of the solution?
I rate the tool a seven out of ten. To improve it, I'd like a cloud-based management system where I only need to put a correlator at the client's site, as CyberArk does. The best setup would be cloud management, a manager in a VM, and super agents on endpoints.
How are customer service and support?
My opinion about technical support might be biased because I have direct access to top-level senior staff. I know some people struggle with support if they go through normal channels.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting up the solution is easy for me because I've been in cybersecurity for almost 30 years, but new users might find it hard. Depending on the client's needs, it can be set up on-premises, in a private or hybrid cloud, or fully in the cloud. Setting it up can take a few days for small environments or months for big companies with thousands of endpoints.
What's my experience with pricing, setup cost, and licensing?
Pricing is a problem in South Africa. It could be cheaper here. The rand-to-dollar exchange rate makes it expensive for us. A 25 dollar endpoint cost becomes quite significant when converted to rand.
What other advice do I have?
Our clients are usually medium-sized and enterprise businesses. Overall, I would recommend Trellix EDR to others. I'd rate it eight and a half out of ten. No EDR or XDR solution gets a nine from me right now because they all have room for improvement.