Listing Thumbnail

    Trellix Helix with GenAI

     Info
    Sold by: Trellix 
    Deployed on AWS
    Trellix Helix unifies threat events across the security stack and applies AI-driven analytics, alert triage, and automation to accelerate detection, investigation, and response. By correlating data from Trellix and 500+ third-party tools, Helix reveals the full attack story while reducing manual pivots and analyst workload. Key capabilities include AI-driven detection and triage, no-code hyperautomation for investigation and response, and an open integration ecosystem that supports cloud, hybrid, and air-gapped deployments.
    4

    Overview

    Trellix Helix helps accelerate your SOC maturity with 100% alert triage, prioritization of threats and GenAI powered insights. Analysts of any level are empowered to prioritize investigations, get straight forward summaries and guidance to remediate or hunt for threats. Helix Connect integrates security controls from the Trellix Security Platform and over 500 third-parties (including 13 AWS integrations) to create deep multi-vector threat detections. Data is ingested from multiple sources, then correlated by pre-built analytics and rules so that you can rapidly see the complete story of an attack. UI-driven, point and click automation helps you to offload repetitive tasks and boost your SecOps team efficiency. Most customers will prefer an AWS Private Offer be extended, which may include customizations to the offering or additional pricing considerations. Not all purchasing options are shown due to the common requirement to customize each deployment of Trellix Helix Connect.

    Highlights

    • Improve SOC efficiency - Adding AI can do the work of several SOC analysts who are overwhelmed with logs and alerts.
    • Reduce Risk - AI can help organizations focus on the most important threats.
    • Revolutionize your SOC with AI-powered speed, adaptive threat insights, and AI-guided investigations.

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Trellix Helix with GenAI

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (6)

     Info
    Dimension
    Description
    Cost/12 months
    Helix-Connect-100
    Use Request Private Offer (To Be Removed - Do Not Use)
    $6,300.00
    Helix-Connect-1000
    Use Request Private Offer (To Be Removed - Do Not Use)
    $56,700.00
    Trellix-OpenXDR-50GB
    Use Request Private Offer (To Be Removed - Do Not Use)
    $21,971.25
    EDR Wise Add-on 1:1TE
    Use Request Private Offer (To Be Removed - Do Not Use)
    $9,999.00
    EDR Wise Add-on 1:1TE
    Use Request Private Offer (To Be Removed - Do Not Use)
    $9,999.00
    EDR Wise Add-on 1:1TE
    Use Request Private Offer (To Be Removed - Do Not Use)
    $9,999.00

    Vendor refund policy

    Refunds are handled on a per case basis.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Please reach out to us at support@trellix.com  with any questions or concerns, and our support team will be more than happy to help.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Education & Research
    Top
    10
    In Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    4 reviews
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Source Threat Data Integration
    Correlates security events from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
    AI-Driven Alert Triage and Prioritization
    Applies artificial intelligence-driven analytics to perform 100% alert triage, prioritize threats, and provide GenAI-powered insights for threat investigation and remediation guidance.
    No-Code Automation for Investigation and Response
    Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
    Pre-Built Analytics and Correlation Rules
    Ingests data from multiple sources and correlates events using pre-built analytics and rules to reconstruct complete attack narratives and reduce manual investigation pivots.
    Multi-Deployment Architecture Support
    Supports cloud, hybrid, and air-gapped deployment models with an open integration ecosystem for flexible security infrastructure configurations.
    Endpoint Detection and Response
    Sophisticated EDR capabilities enabling detection, investigation, and response to multi-stage threats across all key attack vectors
    Extended Detection and Response
    Unified XDR platform detecting and responding to multi-stage threats across network, cloud, endpoint, identity, and email data sources
    Managed Detection and Response
    24/7 ransomware and breach prevention services delivered as a managed service with breach warranty and integration capabilities
    Threat Prevention Technology
    Prevention-first approach using sophisticated technologies to block a broad range of attacks across multiple vectors
    Security Posture Management
    Deployment capabilities with default-enabled strong protection and drift identification for security posture assessment
    Extended Detection and Response
    Managed XDR capabilities for detecting and responding to threats across multiple security domains
    AI-Driven Threat Analytics
    Artificial intelligence-powered analytics for threat detection and analysis across enterprise environments
    Unified Security Platform
    Centralized platform providing single source of truth for security operations across workloads, identities, endpoints, and networks
    Threat Intelligence Integration
    Deep threat intelligence capabilities integrated into security operations for enhanced threat context and decision-making
    Multi-Domain Protection
    Security coverage spanning AI, cloud, networks, endpoints, and devices within complex enterprise environments

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4
    22 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    27%
    64%
    9%
    0%
    0%
    4 AWS reviews
    |
    18 external reviews
    External reviews are from PeerSpot .
    Domit-Molina

    Advanced detection has transformed threat hunting and now delivers rapid, AI-guided investigations

    Reviewed on Jun 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am using Trellix Endpoint Detection and Response (EDR) for threat detection and response and incident response. In Mexico, I am looking for robust and scalable protection and deep visibility without overwhelming my security teams. Trellix Endpoint Detection and Response (EDR) is not just a product we sell; it is the solution we trust to protect our own business in Grupo Salinas every single day. Trellix Endpoint Detection and Response (EDR) is deployed in my organization in the public cloud.

    What is most valuable?

    The integration capability through Trellix Endpoint Detection and Response (EDR) is seamless because we have installed native solutions that correlate endpoint data with threat intelligence. It effectively eliminates the usual noise and alert fatigue that plagues many SOCs today.

    The best features Trellix Endpoint Detection and Response (EDR) offers are the advanced telemetry and behavior-based detection, high-fidelity alerts, and native ecosystems with in-depth forensics and rapid remediation.

    The behavior-based detection engine in Trellix Endpoint Detection and Response (EDR) is incredibly precise. It monitors many different telemetry sources across endpoints and actively maps attacker tactics, techniques, and procedures (TTPs) directly to the MITRE ATT&CK framework. This allows us to think in the mindset of an attacker and catch sophisticated living-off-the-land techniques or data exfiltration attempts before they cause real damage.

    Another massive advantage of Trellix Endpoint Detection and Response (EDR) is how it correlates endpoint data with threat intelligence to deliver high-fidelity alerts. It filters out the noise because we distribute and use the broader Trellix ecosystem. We see firsthand how smoothly it integrates with network, cloud, and third-party solutions. It gives us an enterprise-wide, unified security posture from a single console.

    The in-depth forensics and real-time search capability in Trellix Endpoint Detection and Response (EDR) are outstanding. We can instantly take a non-persistent endpoint snapshot, capturing an up-to-the-moment view of active processes, network connections, services, and autorun entries, even if the machine goes offline. This allows us to confidently isolate threats, find indicators of compromise (IOCs), and rapidly execute a pre-configured response to return the device to a known good state.

    For our SOC team, the absolute best feature of Trellix Endpoint Detection and Response (EDR) is AI-guided investigations. Unlike traditional playbooks that just automate simple scripted tasks, Trellix uses AI to automatically ask and answer questions behind the scenes. It tests multiple hypotheses in parallel, gathers and visualizes the evidence, and presents a summarized case to the analyst. It drastically cuts down investigation time and fights analyst burnout.

    What needs improvement?

    From an operational standpoint, the first area of improvement would be agent resource optimization, especially for high-load servers, because Trellix Endpoint Detection and Response (EDR) captures an incredible depth of telemetry and real-time forensics. It can sometimes experience high CPU or RAM spikes during intensive scans. Streamlining the agent to have an even lighter footprint on critical infrastructure would be a massive win for performance-sensitive environments.

    Another highly technical area that could be improved in Trellix Endpoint Detection and Response (EDR) is expanding the native data retention window for historical threat hunting. While Trellix Endpoint Detection and Response (EDR) provides incredible real-time capabilities and detailed snapshots, digging deeply into historical behavioral telemetry from months ago often requires offloading logs to an external SIEM or their broader XDR data lake. Extending the out-of-the-box long-term historical search directly inside the EDR console would make retrospective threat hunting much faster for compliance and long-tail breach investigations.

    Trellix Endpoint Detection and Response (EDR) scores highly because of its sheer depth of endpoint visibility, the precision of its behavior-based detection, and the massive time savings we get from its AI-guided investigations. It does exactly what a top-tier EDR is supposed to do. It stops sophisticated attacks and drastically reduces our mean time to response (MTTR) for our own infrastructure and for our clients in Mexico. It is a highly trusted solution. However, the reason it is a nine and not a perfect 10 comes down to a specific architectural limitation regarding API log streaming and data offloading. In modern enterprise environments, security teams want to stream raw, high-fidelity endpoint telemetry directly to external SIEMs, data lakes, or third-party orchestration tools via APIs in real time. Currently, Trellix Endpoint Detection and Response (EDR) can sometimes hit bottlenecks or throttling limits when handling massive volumes of raw log exports over standard APIs. To achieve seamless, large-scale data forwarding without friction, you often have to rely heavily on their broader, native EDR data lake or specific ePO configuration rather than a completely open, high-throughput streaming API. If Trellix optimized its API infrastructure to allow unrestricted, high-volume log streaming for third-party integrations, it would easily be a perfect 10. But even with this limitation, its core detection and response capabilities are among the absolute best in the industry.

    For how long have I used the solution?

    I have been working with this solution for approximately one year.

    What do I think about the stability of the solution?

    Trellix Endpoint Detection and Response (EDR) is stable.

    What do I think about the scalability of the solution?

    When it comes to scalability, Trellix Endpoint Detection and Response (EDR) completely dominates the market. Trellix Endpoint Detection and Response (EDR) is built on top of the ePO (ePolicy Orchestrator) management architecture, which is globally recognized as the most scalable endpoint management platform in cybersecurity history.

    How are customer service and support?

    Customer support is a critical component of any enterprise EDR deployment, and my experience with Trellix has been highly positive, largely because of how they structured their ecosystem through Trellix Thrive.

    Which solution did I use previously and why did I switch?

    We evaluated other options, including CrowdStrike, Microsoft Defender, SentinelOne, and Trend Micro, in addition to Trellix Endpoint Detection and Response (EDR).

    How was the initial setup?

    My first piece of advice is to go cloud-native with Trellix Endpoint Detection and Response (EDR) ePO SaaS if your compliance allows it. By basing the configuration on cloud infrastructure rather than traditional on-premises infrastructure setup, it removes a massive amount of engineering overhead. It allows your team to focus entirely on threat monitoring and response from day one, rather than patching servers or managing database sizing.

    What's my experience with pricing, setup cost, and licensing?

    Regarding setup cost, Trellix has a massive advantage because of its unified single-agent architecture. If a client is already running Trellix Endpoint Security for standard next-generation antivirus, adding EDR capabilities does not require deploying a brand new agent or paying for massive professional installation services. It is essentially a cloud policy activation via the management console. This drastically reduces deployment friction and slashes the traditional setup and engineering costs associated with rolling out a new EDR solution.

    From a pricing standpoint, Trellix is highly competitive in the enterprise market because they offer aggressive volume-tiered discounting levels, such as levels A through D. The only variable cost to keep in mind during setup is the management infrastructure. While Trellix ePO Cloud SaaS has zero hardware setup costs, some of our highly regulated clients in Mexico, particularly in banking or government sectors, still opt for an on-premises or IaaS deployment. That choice dictates whether they incur internal server infrastructure costs or enjoy the immediate out-of-the-box cloud setup.

    What other advice do I have?

    When evaluating the AI capabilities in Trellix Endpoint Detection and Response (EDR), specifically Trellix Wise, governance and data security are actually its strongest selling points. Trellix has built its GenAI framework with a strict, responsible AI approach that directly addresses the main concerns of corporate legal and security teams.

    When it comes to the accuracy and reliability of Trellix Wise within the EDR platform, I would rate it as exceptionally high, but it is important to understand why it is reliable. In cybersecurity, generic AI often struggles with accuracy because it lacks context. Trellix solves this by anchoring its AI to three specific guardrails that ensure reliable outputs. I rate this solution with a review rating of 9.

    Ibrahim Mennanoglu

    Centralized monitoring has improved malware protection and streamlined incident response

    Reviewed on Jun 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Trellix Endpoint Detection and Response (EDR)  is for blocking malware and catching unusual behavior to process, while also monitoring all processes we have for our company, the clients, the computer, and the servers. Our process behavior is crucial, and Trellix Endpoint Detection and Response (EDR)  helps to protect our systems from malware.

    What is most valuable?

    The best features Trellix Endpoint Detection and Response (EDR) offers me are the management of all hosts from the EDR, allowing me to disable the network to a computer when necessary. I can check all processes and do what I want from the EDR tools, eliminating the need to physically go to the computer.

    I think the reporting part is the best feature of Trellix Endpoint Detection and Response (EDR), as it is very useful for reporting. The Trellix reporting site is easy to manage, with useful menus and a user-friendly interface.

    Trellix Endpoint Detection and Response (EDR) has positively impacted my organization by allowing us to protect our servers from malware and attacks, ensuring we can safeguard our clients. We can trust Trellix Endpoint Detection and Response (EDR) and conduct weekly or monthly scans to see what we have on our file servers and what clients save or download, including identifying malware behavior files. This is useful for us, providing a benefit where we can report and then take action.

    What needs improvement?

    Trellix Endpoint Detection and Response (EDR) could be improved as I find that, since FireEye  and McAfee became Trellix, I still have to exclude elements from each other when using Trellix HX alongside Trellix ATP or Trellix Antivirus; I believe there should be no need for these exclusions.

    I also think performance needs improvement, especially for servers, as the Trellix HX module uses high CPU, scans constantly, and negatively impacts the performance for our clients' users or our servers. This could be made more efficient.

    For how long have I used the solution?

    I have been using Trellix Endpoint Detection and Response (EDR) for almost seven years.

    What do I think about the stability of the solution?

    Trellix Endpoint Detection and Response (EDR) is stable.

    What do I think about the scalability of the solution?

    Trellix Endpoint Detection and Response (EDR) is scalable.

    How are customer service and support?

    The customer support is great; I have used it many times, and they genuinely care about us.

    Which solution did I use previously and why did I switch?

    Before using Trellix Endpoint Detection and Response (EDR), I used Sophos.

    How was the initial setup?

    I have seen a return on investment with Trellix Endpoint Detection and Response (EDR), as the money saved is satisfactory. They also assist us with licensing and provide timely reminders for license renewals, which means we require fewer employees to manage these tasks. I find it easy to locate what I need on Trellix Endpoint Detection and Response (EDR), such as articles in the knowledge base and documents on their portal.

    What was our ROI?

    I have seen a return on investment with Trellix Endpoint Detection and Response (EDR), as the money saved is satisfactory.

    What's my experience with pricing, setup cost, and licensing?

    I find licensing to be one of the best aspects of Trellix Endpoint Detection and Response (EDR), but I am unsure about pricing.

    Which other solutions did I evaluate?

    While choosing Trellix Endpoint Detection and Response (EDR), I evaluated other options, but I prefer to use Trellix Endpoint Detection and Response (EDR) as it is very good and useful. I manage Trellix Endpoint Detection and Response (EDR) easily, and it effectively protects our clients and servers, achieving high scores from outsourced scanning companies that assess our systems.

    What other advice do I have?

    I have seen faster response times with Trellix Endpoint Detection and Response (EDR); for example, when I receive alerts for malware detection, I can immediately take action directly from Trellix Endpoint Detection and Response (EDR), starting by disabling the network to the affected machine and then investigating further.

    My advice for others considering Trellix Endpoint Detection and Response (EDR) is to use it, or any other Trellix products, as I believe they are excellent. It is easy to set up, share the models, follow necessary steps, and its effectiveness in protecting against malware, ransomware, and other threats is remarkable for all clients and servers, which I find manageable.

    I appreciate Trellix Endpoint Detection and Response (EDR). I have managed Trellix modules for almost seven years, not just EDR, but also DLP , ATP, TAI, and others. We find it useful, and the best part is that I can easily find the answers I need from Trellix Endpoint Detection and Response (EDR) document systems, which is very beneficial. I have given this review a rating of 8 out of 10.

    Vivek_Jaiswal

    Advanced detection has transformed threat response and now improves forensic investigations

    Reviewed on Apr 21, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Trellix Endpoint Detection and Response (EDR)  is the automatic detection of threats and automatic threat detections and response, as there are many use cases that we are currently working with for this Trellix Endpoint Detection and Response (EDR)  solution.

    For a quick specific example of how I use Trellix Endpoint Detection and Response (EDR) for threat detection and response in my day-to-day work, Trellix Endpoint Detection and Response (EDR) solution is integrated with our organization's endpoint, monitoring all endpoint activity and detecting advanced threats such as ransomware, fileless malware, exploits, and living-off-the-land attacks. It uses behavior-based analysis as well as machine learning advanced threat intelligence to identify suspicious activity across the traditional antivirus solutions, making it a really great solution for threat protections and detections.

    What is most valuable?

    The best features Trellix Endpoint Detection and Response (EDR) offers primarily include advanced threat detection, which utilizes AI-driven analytics and capabilities to identify and respond to threats. It continuously collects data from different sources to perform a comprehensive analysis to identify endpoints. Another key feature is its forensic capability, which captures critical data, files, memory, and processes running on the host, allowing it to quickly take action in terms of containment, investigations, and automated responses, including integration with MITRE ATT&CK framework.

    Out of the features I mentioned, I find myself relying on advanced threat detection the most because it quickly identifies emerging threats across the business and takes action in terms of detection as well as the response, also identifying the containment of devices, isolating devices, and taking IOCs blocking to the global organization level, which is enhanced by great forensic capabilities as well.

    Trellix Endpoint Detection and Response (EDR) has positively impacted our organization by improving overall efficiency, overall detection and response capabilities, and the capability to improve threat detections as well as the overall efficiency, time utilized, resource management, and analytic use cases review, significantly enhancing the business functionality.

    What needs improvement?

    Regarding improvements needed for Trellix Endpoint Detection and Response (EDR), there are many ways the EDR solution can improve, but I do not see any specific area where improvement is necessary.

    I think Trellix Endpoint Detection and Response (EDR) is a really good solution with no major improvements needed, though if Trellix support can be improved, that would make it even better, especially given its good integration with the cloud for updates and feature deployment.

    For how long have I used the solution?

    I have been using Trellix Endpoint Detection and Response (EDR) for more than four years.

    What do I think about the stability of the solution?

    Trellix Endpoint Detection and Response (EDR) is very stable.

    What do I think about the scalability of the solution?

    Trellix Endpoint Detection and Response (EDR) is really scalable, allowing easy deployment with its agent across all devices and servers within the organization.

    How are customer service and support?

    The customer support for Trellix Endpoint Detection and Response (EDR) is excellent.

    Which solution did I use previously and why did I switch?

    We previously used Cisco AMP EDR solution, but we prefer Trellix Endpoint Detection and Response (EDR) as it is more effective in detecting emerging threats.

    How was the initial setup?

    We purchased Trellix Endpoint Detection and Response (EDR) through the AWS Marketplace .

    What was our ROI?

    I have seen a return on investment with Trellix Endpoint Detection and Response (EDR); a lot of time is saved as it minimizes the efforts of manual work, requiring very few analysts to process all those alerts, thus improving operational efficiency and overall.

    What's my experience with pricing, setup cost, and licensing?

    Regarding pricing, setup cost, and licensing, our leadership or management generally discusses these aspects, and the vendor is very supportive in terms of deployment and setup costs. For the license requirement, we worked with the vendor to secure the minimum price for Trellix endpoint solutions, with no additional costs charged by the vendor.

    Which other solutions did I evaluate?

    Before choosing Trellix Endpoint Detection and Response (EDR), we evaluated other options including Cisco Antimalware protections and Symantec Endpoint Protection, but Trellix Endpoint Detection and Response (EDR) turned out to be a much better solution.

    What other advice do I have?

    This EDR solution stands out through its automated threat response, forensic investigation capabilities, and integration with the MITRE ATT&CK framework. Compared to other solutions, such as Cisco Antimalware protections and Symantec Endpoint protections, Trellix Endpoint Detection and Response (EDR) is not just behavior-based analysis but also supports signature-based analysis.

    My advice for others looking into using Trellix Endpoint Detection and Response (EDR) is that they should work with the vendor on deployment and integrations with the EDR agent, ensuring complete discussions with the vendor for better results.

    I think Trellix Endpoint Detection and Response (EDR) is a really good solution, with no performance glitches, performance behavior gaps, or discontinuities. I would rate this solution a 10 on a scale of one to ten because it not only serves as an EDR solution but also excels in detecting and responding to behaviors based on data, quickly identifying processes running on the host and correlating the data, taking action very quickly, making it a very good solution without any gaps that I see.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Duncan Kims

    Advanced detection has reduced targeted attacks and builds daily confidence in our defenses

    Reviewed on Apr 14, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Trellix Endpoint Detection and Response (EDR)  is my organization's main solution for threat detection and mitigation of zero-day and advanced persistent threats in the network, and it is being used throughout the company.

    It is highly effective and scalable in terms of detection and prevention, and our usage within Trellix Endpoint Detection and Response (EDR)  enhances the value. The SOC team is constantly monitoring Trellix Endpoint Detection and Response (EDR) alerts, in addition to SIEM-generated incidents.

    Inline mitigation capabilities work particularly well, and different deployment models cater to specific needs, along with frequent updates, low false positive rates, and advanced detection of targeted attacks.

    Trellix Endpoint Detection and Response (EDR) is deployed in my organization using a hybrid cloud.

    I purchased Trellix Endpoint Detection and Response (EDR) through the AWS Marketplace .

    Advanced detection of targeted attacks has reduced the attacks, and I have seen low false positive rates as relevant metrics that show the return on investment.

    What is most valuable?

    Trellix Endpoint Detection and Response (EDR) has a very low false positive rate compared to other products, thus increasing the SOC efficiency in how my team relies on the solution day-to-day.

    With the best features Trellix Endpoint Detection and Response (EDR) offers, ease of SOAR  integration helps to automate the IOC distribution, and our security team and management trust the product. Advanced detection capabilities ensure that targeted attacks will be detected and blocked before they arrive at our network.

    SOAR  integration has assisted our security team and management in trusting the product.

    What needs improvement?

    One area where Trellix Endpoint Detection and Response (EDR) can be improved is the lack of device or user mapping.

    I cannot make manual submissions to NX, which I would like to add about the needed improvements to make my experience better.

    Performance optimization for busy networks is cumbersome.

    For how long have I used the solution?

    I have been working in my current field for seven years.

    What was our ROI?

    Trellix Endpoint Detection and Response (EDR) has positively impacted my organization with threat exchange and intel, low false positive ratios, and very high uptime values for both inline and spam modes, along with advanced detection and mitigation capabilities ensuring the highest level of protection and proper detection for command and control and bot attacks.

    I have noticed a decrease in attacks as a specific outcome that shows the positive impact of Trellix Endpoint Detection and Response (EDR).

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is very cost-effective, but for small organizations working under a tight budget, the price may be challenging to manage.

    What other advice do I have?

    I would rate this product a 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Abubakar Bello

    Centralized endpoint protection has improved reporting and now needs smarter automation

    Reviewed on Mar 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We use routing and switches, IP phones, routers, switches, and a core switch. We also have Identity Services Engine, but it is end of life or end of support now, so we are working on replacing it.

    Our solutions cut across various security products from Sophos and Trellix. We started with McAfee for 15 years and have now transitioned to Trellix, which acquired McAfee.

    Basically, we use this to protect our endpoints.

    How has it helped my organization?

    Trellix Endpoint Detection and Response (EDR)  does everything. It saves time, it saves money, and of course, it provides peace of mind. Anytime management wants any report, we can generate it automatically and push it. This is quite effective.

    What is most valuable?

    First, it is user-friendly. Second, it works with a lot of products and many different versions of Windows. Third, the reporting module is very good. Because if you are using Endpoint Protection with ePO, it has a central console that is quite easy to manage all endpoints at a single dashboard. It has very good threat intelligence.

    In addition to the threat intelligence, it is easy to manage and granular. We can easily manage products up to the client level, and we know what is happening, then we do a lot of threat analysis. There are many resources that we can use. They also have very good support.

    Trellix Endpoint Detection and Response (EDR)  has very good threat hunting capability. We can use the logs to see when a process starts and what it hits, and the other processes or services it has affected. This is quite encouraging.

    What needs improvement?

    They can enhance Trellix Endpoint Detection and Response (EDR) using AI now to do more enhanced reporting and more enhanced threat analysis. There are some client task assignments and policies that should be automatically automated with AI with a click of a button. They should introduce AI and do a lot of things.

    For how long have I used the solution?

    We have used this for 16 years. All this information, how can we protect it? Are we covered by the GDPR regulation?

    What do I think about the stability of the solution?

    Initially, I was using it on servers, but it consumes a lot of resources on servers. So I have to use Sophos XDR  on servers because Sophos XDR  does not consume resources. That is the difference.

    How are customer service and support?

    We do a lot of research. Our only problem with Trellix is that it is resource intensive and takes a lot of resources. However, we found out that it works on our systems and on our desktops. But on our servers, we do not want it to touch our resources, so we deployed Sophos XDR on the server.

    How was the initial setup?

    It is straightforward. The only little challenge is that you have to get all the necessary updates for it to connect to the database.

    I am using on-premises with the ePolicy Orchestrator  and then we apply the license. After the product is already installed, we do the necessary upgrade, restart the system, and then push the agents to the endpoints. Then we receive updates and manage our clients.

    What about the implementation team?

    We have partners that provide Trellix Endpoint Detection and Response (EDR), so we work with them to deploy.

    What's my experience with pricing, setup cost, and licensing?

    It is quite reasonable.

    Which other solutions did I evaluate?

    For network troubleshooting, I moved to security now and I am not in network, but I think they are using Cisco product too for that.

    View all reviews