Listing Thumbnail

    Trellix Network Detection and Response

     Info
    Sold by: Trellix 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    Trellix NDR delivers unified, intelligence-driven visibility, detection, investigation, and response across your network using advanced analytics, machine learning, and GenAI. It analyzes traffic across data centers, multicloud, branch, and campus environments correlating signals, identifying anomalies, and accelerating response. Trellix Wise GenAI reduces alert fatigue, closes talent gaps, and automates deep investigations mapped to MITRE ATT&CK. Trellix NDR detects advanced threats across hybrid architectures, provides real-time visibility, and automates evidence gathering and response actions to reduce MTTR and prevent lateral movement.
    4.1

    Overview

    Disrupt Attackers at Every Stage

    Trellix NDR delivers extended visibility, multilayered threat detection and accelerated investigation and response into network traffic across each stage of the MITRE ATT&CK framework spanning data centers, hybrid cloud environments, branch offices, and corporate campuses.

    Product Options

    Trellix Network Security: Automatically spot suspicious network behavior and prevent attacks that elude traditional signature and policy based security. Combine multiple AI, machine learning, and correlation engines to detect and respond to advanced threats and lateral movements in minutes.

    Trellix Network Forensics: pairs the industrys fastest lossless data capture and retrieval solution with centralized analysis and visualization. Determine the scope and impact of threats and resecure your network faster.

    Trellix Intrusion Prevention System: Trellix IPS is a NDR ready, next generation IPS that detects and blocks sophisticated malware threats across the network. It uses advanced detection and emulation techniques, moving beyond traditional pattern matching to defend against stealthy attacks with a high degree of accuracy and performance.

    Please contact aws@trellix.com  before purchasing. Your account team will provide an AWS Private Offer with the correct product mix, quantities, and applicable discounts. Multiple product choices and deployment options are possible using part numbers not listed here.

    Highlights

    • Adapt to new threats automatically
    • Protect across your network to the cloud
    • Connect to Trellix Helix to enable GenAI insights

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Trellix Network Detection and Response

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    NDRT0-T
    Use Request Private Offer (To Be Removed - Do Not Use)
    $105,193.00
    NDRT1-T
    Use Request Private Offer (To Be Removed - Do Not Use)
    $142,010.55
    NDRT2-T
    Use Request Private Offer (To Be Removed - Do Not Use)
    $173,568.45
    DODE1E-AA
    To Be Removed - Do Not Use
    $9,999.00

    Vendor refund policy

    Please contact aws@trellix.com  for refund requests

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Standard support and customer success programs available support@trellix.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Generative AI
    Top
    10
    In Education & Research
    Top
    10
    In Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Advanced Threat Detection
    Combines multiple AI, machine learning, and correlation engines to detect advanced threats and lateral movements across network traffic
    Machine Learning-Based Anomaly Detection
    Analyzes traffic across data centers, multicloud, branch, and campus environments to correlate signals and identify anomalies
    Lossless Network Data Capture and Analysis
    Provides industry-fastest lossless data capture and retrieval solution with centralized analysis and visualization for threat scope determination
    Next-Generation Intrusion Prevention
    Detects and blocks sophisticated malware threats using advanced detection and emulation techniques beyond traditional pattern matching
    MITRE ATT&CK Framework Mapping
    Automates deep investigations and response actions mapped to MITRE ATT&CK framework stages across hybrid architectures
    Endpoint Detection and Response
    EDR capabilities enabling detection, investigation, and response to multi-stage threats across all key attack vectors
    Extended Detection and Response
    Unified XDR platform detecting and responding to threats across network, cloud, endpoint, identity, and email data sources
    Managed Detection and Response
    24/7 ransomware and breach prevention services with breach warranty and integration capabilities for existing security tools
    Threat Prevention Technology
    Prevention-first approach using sophisticated technologies to block a broad range of attacks
    Security Posture Assessment
    Deployment capabilities with drift identification in security posture and default-enabled strong protection
    Managed Extended Detection and Response
    Managed XDR capabilities for detecting and responding to threats across enterprise environments
    AI-Driven Threat Analytics
    Artificial intelligence-powered analytics for threat detection and analysis across workloads, identities, endpoints, and networks
    Unified Security Platform
    Centralized platform providing single source of truth for security operations and incident response across complex environments
    Deep Threat Intelligence Integration
    Integration of deep threat intelligence to enhance detection capabilities and reduce organizational risk
    Multi-Layer Protection Coverage
    Security protection spanning AI, cloud, networks, endpoints, and devices across enterprise infrastructure

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    87 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    53%
    37%
    4%
    5%
    1%
    3 AWS reviews
    |
    84 external reviews
    External reviews are from G2  and PeerSpot .
    Computer & Network Security

    Good Visibility and Useful Network Threat Detection

    Reviewed on Sep 20, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Trellix NDR is the visibility it gives into network activity. It makes it easier to spot unusual traffic, suspicious connections, and behavior that may otherwise be difficult to notice through traditional monitoring alone.

    I also find the investigation side useful. When an alert comes in, having the related network activity available in one place helps us understand what happened and whether it is actually something that needs attention. It is especially helpful as an additional layer of detection alongside other security tools.
    What do you dislike about the product?
    One thing I dislike is that the platform can feel a bit complex at first, especially when you are trying to understand why a particular alert was triggered. Some alerts need additional investigation and tuning before they become really useful, otherwise there can be unnecessary noise.
    What problems is the product solving and how is that benefiting you?
    Trellix NDR helps us identify suspicious network activity that may not always be visible through endpoint or firewall monitoring alone. It gives us better visibility into unusual connections, traffic patterns, and potential threats moving across the network.

    The main benefit is that it helps reduce the time spent investigating security events. Instead of checking multiple sources separately, we can use the network data to understand what happened and decide whether an alert needs further action. It has also improved our overall monitoring and incident investigation process.
    Wassim R.

    Proactive Defense with Global Visibility

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate the integration of Trellix Wise which ensures global visibility and risk prioritization. Additionally, the migration from McAfee to Trellix was completely smooth.
    What do you dislike about the product?
    Nothing to mention.
    What problems is the product solving and how is that benefiting you?
    Trellix NDR addresses issues of alert overload, analyst fatigue, blind spots in encrypted traffic, and improves visibility of unmanaged devices.
    ABUZAR K.

    Robust Threat Detection, Needs Setup Efficiency

    Reviewed on Aug 07, 2026
    Review provided by G2
    What do you like best about the product?
    I enjoy Trellix Network Detection and Response (NDR) for its real-time network visibility, precise threat detection, behavior analysis, and alerts. These features help our SOC team investigate cases more efficiently. The integration with other security systems enhances our operations. I appreciate the quick detection of suspicious network behavior through real-time visibility and the ability of behavioral analytics to detect threats that signature-based analytics might miss. The prioritized alerting ensures we can respond efficiently to any situation.
    What do you dislike about the product?
    I find the initial setup and policy configuration laborious, and I believe that further customizations to the dashboard, reports, and integrations would add value. Some alarms also require further tuning to reduce the number of false alarms.
    What problems is the product solving and how is that benefiting you?
    I use Trellix NDR for real-time monitoring, precise threat detection, and anomaly alerts, reducing investigation time and enabling faster response to incidents. It provides real-time network visibility and integrates with our security systems, enhancing our SOC team's efficiency.
    Mahesh Malve

    Daily threat monitoring has become faster and investigations gain deeper network context

    Reviewed on Jun 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My primary use case for Trellix Network Detection and Response is network threat monitoring and incident investigation. I use it to identify suspicious network activities, detect potential threats, and gain visibility into traffic patterns across the environment. On a day-to-day basis, I review alerts generated by the platform, investigate unusual communications, analyze indicators of compromise, and validate whether an alert represents a genuine security risk or a false positive.

    What is most valuable?

    Trellix Network Detection and Response definitely helps make investigations faster and more efficient. One of the biggest advantages is the visibility it provides into network activity, which allows me to quickly understand what happened and determine whether an alert requires immediate action. Instead of manually collecting data from multiple sources, I can use the platform to view relevant network communications, identify suspicious connections, and trace activity associated with a particular host or user. This significantly reduces the time needed for initial triage and investigations.

    Trellix Network Detection and Response has become a regular part of my daily security monitoring workflow, not just a tool I use when there is an incident. Beyond investigating alerts, I use it to maintain visibility into network activity, validate suspicious events identified by other security tools, and proactively look for unusual behavior that could indicate emerging threats. I also appreciate the context it provides during investigations. Having access to detailed network insights helps me make more informed decisions and collaborate more effectively with other teams when an issue needs to be escalated or remediated.

    The features I find most valuable in Trellix Network Detection and Response are the network visibility, threat detection capabilities, and the investigation tools that provide context around security events. One of the biggest strengths of Trellix Network Detection and Response is the ability to analyze network traffic and identify suspicious behavior that may not be obvious through traditional security monitoring. The alerting and detection capabilities help surface potential threats early, which allows us to investigate and respond more quickly. I also appreciate the level of detail available during investigations. Being able to view communication patterns, affected systems, and related activity in one place makes it much easier to understand the full scope of an incident. This saves time and reduces the effort required to manually correlate information from multiple sources.

    What needs improvement?

    I have had a positive experience with Trellix Network Detection and Response, but there are areas where it could be improved. One area would be further enhancement of alert prioritization and noise reduction. While the platform provides valuable detections, having even more intelligent correlation and risk-based prioritization could help analysts focus on the most critical threats more quickly.

    From an integration perspective, broader and more seamless integration with third-party security tools can always add value. Most organizations operate in multi-vendor environments, so simplifying data sharing and workflow automation across different security platforms would help improve operational efficiency. In terms of user experience, the interface is functional, but there is always room to make investigations more intuitive. Enhancements such as more customizable dashboards, streamlined navigation, and easier access to frequently used investigation data could help analysts work more efficiently, especially in fast-paced incident response situations.

    For how long have I used the solution?

    I have been using Trellix Network Detection and Response for approximately two years.

    What do I think about the stability of the solution?

    I would consider Trellix Network Detection and Response to be a stable and reliable platform. In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations. Enterprise security solutions can occasionally have minor issues related to updates, integrations, or environmental factors, but I have not experienced any significant reliability problems that have had a major impact on our security operations. The platform has generally performed as expected and has been available when needed for monitoring and incident investigations.

    What do I think about the scalability of the solution?

    Based on my experience, Trellix Network Detection and Response has scaled well within our environment. As the organization has grown and network activity has increased, the platform has continued to provide the visibility and detection capabilities needed to support security operations. From a day-to-day perspective, I have not noticed any significant issues related to growth or increased workload.

    Which solution did I use previously and why did I switch?

    We previously relied on a different solution for network monitoring and threat detection before Trellix Network Detection and Response. One of the reasons for moving to Trellix Network Detection and Response was the need for improved visibility, stronger investigation capabilities, and better integration with our overall security operations workflow. From my experience, Trellix Network Detection and Response provides valuable context around alerts and helps streamline investigations, which has improved efficiency for the security team.

    What was our ROI?

    I do not have official ROI metrics, but from what I have seen, the biggest return has been in time-saving and operational efficiency. Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources. I also think there is a value in detecting and understanding threats earlier. It is difficult to quantify exactly, but faster detection and response can help reduce the potential impact of incidents. While I cannot point to a specific dollar amount or reduction in staffing, the platform has helped the team work more efficiently and strengthen our overall security operation.

    Which other solutions did I evaluate?

    I was not directly involved in the formal evaluation and procurement process, so I cannot say with certainty which products were shortlisted or compared in detail before selecting Trellix Network Detection and Response. By the time I started working with the solution, Trellix Network Detection and Response had already been selected and deployed. From a user perspective, I have found it effective for network visibility, threat detection, and investigation support. While I am aware there are several strong solutions in the NDR market, I was not personally part of the product evaluation process.

    Saja Matar

    Unified network detection has strengthened visibility and supported compliance and incident response

    Reviewed on Jun 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Trellix Network Detection and Response is to give us network visibility and detect intrusions, which I use day-to-day.

    What is most valuable?

    Trellix Network Detection and Response offers excellent diversity and support for different capabilities because it is built and composed of different services. Trellix Network Detection and Response provides an all-in-one package with services such as Yara detection, Zeek detections, IPS, and IDS capabilities, all presented not as lazily implemented features but as standalone services that could be sold individually. The service that stands out the most for us is detecting and applying Riskwhere capabilities to see how our environment complies with standards, making it the full package for us. It supports compliance, security, and detection capabilities.

    Trellix Network Detection and Response allows for configuration of sandboxes, known as MVXes, which are separate standalone services that can be scaled up or down depending on your workload. For example, a smaller environment might only need one sandbox, while a larger one can set up a cluster of instances for sandboxing. It offers flexibility for inbound or outbound traffic by allowing you to set it inside the network to actively block or drop traffic, or simply mirror traffic for detection without prevention. The detection engine and services are powerful because they integrate different resources, enabling me to apply different integrations, such as Zeek integrations, for direct rule application.

    Trellix Network Detection and Response positively impacts my organization by providing an all-in-one package rather than requiring us to buy separate products from companies like FireEye or McAfee, which support different features. Multi-tenancy is critical for us as an MSSP, and Trellix Network Detection and Response's central management allows me to manage all appliances through a single UI, which is helpful despite some intricate configurations needing to be done on the appliance itself.

    What needs improvement?

    Trellix Network Detection and Response can be improved because it is still maturing, having been built by acquiring other companies and integrating their services. The goal seems to be unifying these services within a central management system, but current issues indicate that it is a work in progress. Its deployment is not straightforward and often requires vendor support to set it up effectively, making it difficult to manage without direct assistance. Trellix Network Detection and Response still needs more work for better unification of service management to clarify each service provided. The network detection component tends to have the most integrated services, featuring MVX, IPS, Malware Guard, and Smart Vision.

    I would suggest making central management more organized. Currently, features like IPS are shown as a large separate tab in central management, which seems counterintuitive since it is just a feature of NDR. Encapsulating every service in its appliance while standardizing central management would greatly enhance understanding of Trellix Network Detection and Response architecture for security engineers.

    Regarding Trellix Network Detection and Response's AI capabilities, they depend on setup for data safety and privacy. If Trellix Network Detection and Response allows local AI setup, it can provide security and privacy, but reliance on cloud-based AI would raise privacy concerns. I see more machine learning than true AI, as it requires turning on machine learning to understand the environment before it can fire alerts.

    The accuracy and reliability of Trellix Network Detection and Response output have drawbacks since it generates many false positives and is not one hundred percent accurate, necessitating further configurations, setup, and training.

    The main improvements needed, beyond what we have discussed, involve architectural concerns and API usage for running commands. Using Trellix Network Detection and Response's API for configuration benchmarks has not been smooth and has resulted in errors. Fixing the API to allow for easier automation of configurations would be beneficial.

    For how long have I used the solution?

    I have been using Trellix Network Detection and Response for approximately six months.

    What do I think about the stability of the solution?

    Trellix Network Detection and Response is stable for me as long as I provide the recommended specs. I encounter no issues with health or reliability when the recommended specifications are met.

    What do I think about the scalability of the solution?

    Trellix Network Detection and Response demonstrates excellent scalability, allowing both the addition of more interfaces and integration of additional appliances into the central management system. You can scale services within the appliance, such as sandboxing services, as needed.

    How are customer service and support?

    Trellix Network Detection and Response cannot be operated without customer support, especially during the first year and a half of use. Their support is helpful, providing necessary training and sessions to understand the system better.

    How was the initial setup?

    My advice to others looking into using Trellix Network Detection and Response is to prepare for an initial time-intensive setup, as it has many features that require time to configure properly. However, once past the setup phase, operations will run smoothly with patience.

    What was our ROI?

    I have not seen a return on investment in terms of reducing employees, since Trellix Network Detection and Response actually necessitates more team members to operate it. However, it saves time by consolidating what would have been multiple setups with different providers. The setup was complex and time-consuming, yet once operational, daily use becomes much easier, though overall cost savings remain unclear due to their pricing lack of transparency.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is confusing, given that each part requires separate management of licenses. Understanding the licensing necessitates vendor assistance, as documentation fails to clarify everything. The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.

    Which other solutions did I evaluate?

    I still run Corlight in parallel alongside Trellix Network Detection and Response. While Trellix Network Detection and Response limits access and navigation through alerts, making full investigations difficult, Corlight enables such investigations with customizable components including Suricata, Zeek, Yara, and smart Pcap features.

    We evaluated Corlight, which, while effective, necessitated extensive manual labor for setup, unlike Trellix Network Detection and Response.

    What other advice do I have?

    Something unique for our environment regarding how we use Trellix Network Detection and Response is how it is implemented and managed. Because we use two appliances for network detection, one for users for everyday use and another for servers, we ensure they have separate traffic and can control and apply different controls to each appliance.

    For the flexibility of sandbox configuration in Trellix Network Detection and Response, it has helped my team day-to-day by matching our exact workload. For example, in the data center environment where we have a lot of traffic needing processing, we can add three or four MVXes for sandboxing capabilities, without having to mirror those configurations for the disaster recovery center, allowing each appliance its own sandboxing configurations. For compliance, the compliance team checks network detection configurations, but there is no automation currently, though Trellix Network Detection and Response has a component called Riskwhere that performs risk assessments and covers configurations to benchmark our environment. However, it is important to note that Riskwhere still generates many false positives, requiring manual tuning to fit our environment.

    Regarding specific outcomes since using Trellix Network Detection and Response, the compliance scores have not improved yet since it requires manual configuration tailored to our needs. However, incidents have decreased because both solutions operate on a static basis, whereas Trellix Network Detection and Response utilizes sandboxes for dynamic analysis. It saves us a lot of time thanks to its central management, although some configurations sometimes conflict in application between central management and the appliances themselves. Trellix Network Detection and Response still needs more work for better unification of service management to clarify each service provided. The network detection component tends to have the most integrated services, featuring MVX, IPS, Malware Guard, and Smart Vision. I would rate this solution an eight overall.

    View all reviews