
Overview
Disrupt Attackers at Every Stage
Trellix NDR delivers extended visibility, multilayered threat detection and accelerated investigation and response into network traffic across each stage of the MITRE ATT&CK framework spanning data centers, hybrid cloud environments, branch offices, and corporate campuses.
Product Options
Trellix Network Security: Automatically spot suspicious network behavior and prevent attacks that elude traditional signature and policy based security. Combine multiple AI, machine learning, and correlation engines to detect and respond to advanced threats and lateral movements in minutes.
Trellix Network Forensics: pairs the industrys fastest lossless data capture and retrieval solution with centralized analysis and visualization. Determine the scope and impact of threats and resecure your network faster.
Trellix Intrusion Prevention System: Trellix IPS is a NDR ready, next generation IPS that detects and blocks sophisticated malware threats across the network. It uses advanced detection and emulation techniques, moving beyond traditional pattern matching to defend against stealthy attacks with a high degree of accuracy and performance.
Please contact aws@trellix.com before purchasing. Your account team will provide an AWS Private Offer with the correct product mix, quantities, and applicable discounts. Multiple product choices and deployment options are possible using part numbers not listed here.
Highlights
- Adapt to new threats automatically
- Protect across your network to the cloud
- Connect to Trellix Helix to enable GenAI insights
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
NDRT0-T | Use Request Private Offer (To Be Removed - Do Not Use) | $105,193.00 |
NDRT1-T | Use Request Private Offer (To Be Removed - Do Not Use) | $142,010.55 |
NDRT2-T | Use Request Private Offer (To Be Removed - Do Not Use) | $173,568.45 |
DODE1E-AA | To Be Removed - Do Not Use | $9,999.00 |
Vendor refund policy
Please contact aws@trellix.com for refund requests
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Standard support and customer success programs available support@trellix.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Good Visibility and Useful Network Threat Detection
I also find the investigation side useful. When an alert comes in, having the related network activity available in one place helps us understand what happened and whether it is actually something that needs attention. It is especially helpful as an additional layer of detection alongside other security tools.
The main benefit is that it helps reduce the time spent investigating security events. Instead of checking multiple sources separately, we can use the network data to understand what happened and decide whether an alert needs further action. It has also improved our overall monitoring and incident investigation process.
Proactive Defense with Global Visibility
Robust Threat Detection, Needs Setup Efficiency
Daily threat monitoring has become faster and investigations gain deeper network context
What is our primary use case?
My primary use case for Trellix Network Detection and Response is network threat monitoring and incident investigation. I use it to identify suspicious network activities, detect potential threats, and gain visibility into traffic patterns across the environment. On a day-to-day basis, I review alerts generated by the platform, investigate unusual communications, analyze indicators of compromise, and validate whether an alert represents a genuine security risk or a false positive.
What is most valuable?
Trellix Network Detection and Response definitely helps make investigations faster and more efficient. One of the biggest advantages is the visibility it provides into network activity, which allows me to quickly understand what happened and determine whether an alert requires immediate action. Instead of manually collecting data from multiple sources, I can use the platform to view relevant network communications, identify suspicious connections, and trace activity associated with a particular host or user. This significantly reduces the time needed for initial triage and investigations.
Trellix Network Detection and Response has become a regular part of my daily security monitoring workflow, not just a tool I use when there is an incident. Beyond investigating alerts, I use it to maintain visibility into network activity, validate suspicious events identified by other security tools, and proactively look for unusual behavior that could indicate emerging threats. I also appreciate the context it provides during investigations. Having access to detailed network insights helps me make more informed decisions and collaborate more effectively with other teams when an issue needs to be escalated or remediated.
The features I find most valuable in Trellix Network Detection and Response are the network visibility, threat detection capabilities, and the investigation tools that provide context around security events. One of the biggest strengths of Trellix Network Detection and Response is the ability to analyze network traffic and identify suspicious behavior that may not be obvious through traditional security monitoring. The alerting and detection capabilities help surface potential threats early, which allows us to investigate and respond more quickly. I also appreciate the level of detail available during investigations. Being able to view communication patterns, affected systems, and related activity in one place makes it much easier to understand the full scope of an incident. This saves time and reduces the effort required to manually correlate information from multiple sources.
What needs improvement?
I have had a positive experience with Trellix Network Detection and Response, but there are areas where it could be improved. One area would be further enhancement of alert prioritization and noise reduction. While the platform provides valuable detections, having even more intelligent correlation and risk-based prioritization could help analysts focus on the most critical threats more quickly.
From an integration perspective, broader and more seamless integration with third-party security tools can always add value. Most organizations operate in multi-vendor environments, so simplifying data sharing and workflow automation across different security platforms would help improve operational efficiency. In terms of user experience, the interface is functional, but there is always room to make investigations more intuitive. Enhancements such as more customizable dashboards, streamlined navigation, and easier access to frequently used investigation data could help analysts work more efficiently, especially in fast-paced incident response situations.
For how long have I used the solution?
I have been using Trellix Network Detection and Response for approximately two years.
What do I think about the stability of the solution?
I would consider Trellix Network Detection and Response to be a stable and reliable platform. In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations. Enterprise security solutions can occasionally have minor issues related to updates, integrations, or environmental factors, but I have not experienced any significant reliability problems that have had a major impact on our security operations. The platform has generally performed as expected and has been available when needed for monitoring and incident investigations.
What do I think about the scalability of the solution?
Based on my experience, Trellix Network Detection and Response has scaled well within our environment. As the organization has grown and network activity has increased, the platform has continued to provide the visibility and detection capabilities needed to support security operations. From a day-to-day perspective, I have not noticed any significant issues related to growth or increased workload.
Which solution did I use previously and why did I switch?
We previously relied on a different solution for network monitoring and threat detection before Trellix Network Detection and Response. One of the reasons for moving to Trellix Network Detection and Response was the need for improved visibility, stronger investigation capabilities, and better integration with our overall security operations workflow. From my experience, Trellix Network Detection and Response provides valuable context around alerts and helps streamline investigations, which has improved efficiency for the security team.
What was our ROI?
I do not have official ROI metrics, but from what I have seen, the biggest return has been in time-saving and operational efficiency. Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources. I also think there is a value in detecting and understanding threats earlier. It is difficult to quantify exactly, but faster detection and response can help reduce the potential impact of incidents. While I cannot point to a specific dollar amount or reduction in staffing, the platform has helped the team work more efficiently and strengthen our overall security operation.
Which other solutions did I evaluate?
I was not directly involved in the formal evaluation and procurement process, so I cannot say with certainty which products were shortlisted or compared in detail before selecting Trellix Network Detection and Response. By the time I started working with the solution, Trellix Network Detection and Response had already been selected and deployed. From a user perspective, I have found it effective for network visibility, threat detection, and investigation support. While I am aware there are several strong solutions in the NDR market, I was not personally part of the product evaluation process.
Unified network detection has strengthened visibility and supported compliance and incident response
What is our primary use case?
My main use case for Trellix Network Detection and Response is to give us network visibility and detect intrusions, which I use day-to-day.
What is most valuable?
Trellix Network Detection and Response offers excellent diversity and support for different capabilities because it is built and composed of different services. Trellix Network Detection and Response provides an all-in-one package with services such as Yara detection, Zeek detections, IPS, and IDS capabilities, all presented not as lazily implemented features but as standalone services that could be sold individually. The service that stands out the most for us is detecting and applying Riskwhere capabilities to see how our environment complies with standards, making it the full package for us. It supports compliance, security, and detection capabilities.
Trellix Network Detection and Response allows for configuration of sandboxes, known as MVXes, which are separate standalone services that can be scaled up or down depending on your workload. For example, a smaller environment might only need one sandbox, while a larger one can set up a cluster of instances for sandboxing. It offers flexibility for inbound or outbound traffic by allowing you to set it inside the network to actively block or drop traffic, or simply mirror traffic for detection without prevention. The detection engine and services are powerful because they integrate different resources, enabling me to apply different integrations, such as Zeek integrations, for direct rule application.
Trellix Network Detection and Response positively impacts my organization by providing an all-in-one package rather than requiring us to buy separate products from companies like FireEye or McAfee, which support different features. Multi-tenancy is critical for us as an MSSP, and Trellix Network Detection and Response's central management allows me to manage all appliances through a single UI, which is helpful despite some intricate configurations needing to be done on the appliance itself.
What needs improvement?
Trellix Network Detection and Response can be improved because it is still maturing, having been built by acquiring other companies and integrating their services. The goal seems to be unifying these services within a central management system, but current issues indicate that it is a work in progress. Its deployment is not straightforward and often requires vendor support to set it up effectively, making it difficult to manage without direct assistance. Trellix Network Detection and Response still needs more work for better unification of service management to clarify each service provided. The network detection component tends to have the most integrated services, featuring MVX, IPS, Malware Guard, and Smart Vision.
I would suggest making central management more organized. Currently, features like IPS are shown as a large separate tab in central management, which seems counterintuitive since it is just a feature of NDR. Encapsulating every service in its appliance while standardizing central management would greatly enhance understanding of Trellix Network Detection and Response architecture for security engineers.
Regarding Trellix Network Detection and Response's AI capabilities, they depend on setup for data safety and privacy. If Trellix Network Detection and Response allows local AI setup, it can provide security and privacy, but reliance on cloud-based AI would raise privacy concerns. I see more machine learning than true AI, as it requires turning on machine learning to understand the environment before it can fire alerts.
The accuracy and reliability of Trellix Network Detection and Response output have drawbacks since it generates many false positives and is not one hundred percent accurate, necessitating further configurations, setup, and training.
The main improvements needed, beyond what we have discussed, involve architectural concerns and API usage for running commands. Using Trellix Network Detection and Response's API for configuration benchmarks has not been smooth and has resulted in errors. Fixing the API to allow for easier automation of configurations would be beneficial.
For how long have I used the solution?
I have been using Trellix Network Detection and Response for approximately six months.
What do I think about the stability of the solution?
Trellix Network Detection and Response is stable for me as long as I provide the recommended specs. I encounter no issues with health or reliability when the recommended specifications are met.
What do I think about the scalability of the solution?
Trellix Network Detection and Response demonstrates excellent scalability, allowing both the addition of more interfaces and integration of additional appliances into the central management system. You can scale services within the appliance, such as sandboxing services, as needed.
How are customer service and support?
Trellix Network Detection and Response cannot be operated without customer support, especially during the first year and a half of use. Their support is helpful, providing necessary training and sessions to understand the system better.
How was the initial setup?
My advice to others looking into using Trellix Network Detection and Response is to prepare for an initial time-intensive setup, as it has many features that require time to configure properly. However, once past the setup phase, operations will run smoothly with patience.
What was our ROI?
I have not seen a return on investment in terms of reducing employees, since Trellix Network Detection and Response actually necessitates more team members to operate it. However, it saves time by consolidating what would have been multiple setups with different providers. The setup was complex and time-consuming, yet once operational, daily use becomes much easier, though overall cost savings remain unclear due to their pricing lack of transparency.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is confusing, given that each part requires separate management of licenses. Understanding the licensing necessitates vendor assistance, as documentation fails to clarify everything. The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
Which other solutions did I evaluate?
I still run Corlight in parallel alongside Trellix Network Detection and Response. While Trellix Network Detection and Response limits access and navigation through alerts, making full investigations difficult, Corlight enables such investigations with customizable components including Suricata, Zeek, Yara, and smart Pcap features.
We evaluated Corlight, which, while effective, necessitated extensive manual labor for setup, unlike Trellix Network Detection and Response.
What other advice do I have?
Something unique for our environment regarding how we use Trellix Network Detection and Response is how it is implemented and managed. Because we use two appliances for network detection, one for users for everyday use and another for servers, we ensure they have separate traffic and can control and apply different controls to each appliance.
For the flexibility of sandbox configuration in Trellix Network Detection and Response, it has helped my team day-to-day by matching our exact workload. For example, in the data center environment where we have a lot of traffic needing processing, we can add three or four MVXes for sandboxing capabilities, without having to mirror those configurations for the disaster recovery center, allowing each appliance its own sandboxing configurations. For compliance, the compliance team checks network detection configurations, but there is no automation currently, though Trellix Network Detection and Response has a component called Riskwhere that performs risk assessments and covers configurations to benchmark our environment. However, it is important to note that Riskwhere still generates many false positives, requiring manual tuning to fit our environment.
Regarding specific outcomes since using Trellix Network Detection and Response, the compliance scores have not improved yet since it requires manual configuration tailored to our needs. However, incidents have decreased because both solutions operate on a static basis, whereas Trellix Network Detection and Response utilizes sandboxes for dynamic analysis. It saves us a lot of time thanks to its central management, although some configurations sometimes conflict in application between central management and the appliances themselves. Trellix Network Detection and Response still needs more work for better unification of service management to clarify each service provided. The network detection component tends to have the most integrated services, featuring MVX, IPS, Malware Guard, and Smart Vision. I would rate this solution an eight overall.