Listing Thumbnail

    Trellix Network Detection and Response

     Info
    Sold by: Trellix 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    Trellix NDR delivers unified, intelligence-driven visibility, detection, investigation, and response across your network using advanced analytics, machine learning, and GenAI. It analyzes traffic across data centers, multicloud, branch, and campus environments correlating signals, identifying anomalies, and accelerating response. Trellix Wise GenAI reduces alert fatigue, closes talent gaps, and automates deep investigations mapped to MITRE ATT&CK. Trellix NDR detects advanced threats across hybrid architectures, provides real-time visibility, and automates evidence gathering and response actions to reduce MTTR and prevent lateral movement.
    4.1

    Overview

    Disrupt Attackers at Every Stage

    Trellix NDR delivers extended visibility, multilayered threat detection and accelerated investigation and response into network traffic across each stage of the MITRE ATT&CK framework spanning data centers, hybrid cloud environments, branch offices, and corporate campuses.

    Product Options

    Trellix Network Security: Automatically spot suspicious network behavior and prevent attacks that elude traditional signature and policy based security. Combine multiple AI, machine learning, and correlation engines to detect and respond to advanced threats and lateral movements in minutes.

    Trellix Network Forensics: pairs the industrys fastest lossless data capture and retrieval solution with centralized analysis and visualization. Determine the scope and impact of threats and resecure your network faster.

    Trellix Intrusion Prevention System: Trellix IPS is a NDR ready, next generation IPS that detects and blocks sophisticated malware threats across the network. It uses advanced detection and emulation techniques, moving beyond traditional pattern matching to defend against stealthy attacks with a high degree of accuracy and performance.

    Please contact aws@trellix.com  before purchasing. Your account team will provide an AWS Private Offer with the correct product mix, quantities, and applicable discounts. Multiple product choices and deployment options are possible using part numbers not listed here.

    Highlights

    • Adapt to new threats automatically
    • Protect across your network to the cloud
    • Connect to Trellix Helix to enable GenAI insights

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Trellix Network Detection and Response

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    NDRT0-T
    Use Request Private Offer (To Be Removed - Do Not Use)
    $105,193.00
    NDRT1-T
    Use Request Private Offer (To Be Removed - Do Not Use)
    $142,010.55
    NDRT2-T
    Use Request Private Offer (To Be Removed - Do Not Use)
    $173,568.45
    DODE1E-AA
    To Be Removed - Do Not Use
    $9,999.00

    Vendor refund policy

    Please contact aws@trellix.com  for refund requests

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Standard support and customer success programs available support@trellix.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Generative AI
    Top
    10
    In Education & Research
    Top
    10
    In Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Advanced Threat Detection
    Combines multiple AI, machine learning, and correlation engines to detect advanced threats and lateral movements across network traffic
    Machine Learning-Based Anomaly Detection
    Analyzes traffic across data centers, multicloud, branch, and campus environments to correlate signals and identify anomalies
    Lossless Network Data Capture and Analysis
    Provides industry-fastest lossless data capture and retrieval solution with centralized analysis and visualization for threat scope determination
    Next-Generation Intrusion Prevention
    Detects and blocks sophisticated malware threats using advanced detection and emulation techniques beyond traditional pattern matching
    MITRE ATT&CK Framework Mapping
    Automates deep investigations and response actions mapped to MITRE ATT&CK framework stages across hybrid architectures
    Endpoint Detection and Response
    EDR capabilities enabling detection, investigation, and response to multi-stage threats across all key attack vectors
    Extended Detection and Response
    Unified XDR platform detecting and responding to threats across network, cloud, endpoint, identity, and email data sources
    Managed Detection and Response
    24/7 ransomware and breach prevention services with breach warranty and integration capabilities for existing security tools
    Threat Prevention Technology
    Prevention-first approach using sophisticated technologies to block a broad range of attacks
    Security Posture Assessment
    Deployment capabilities with drift identification in security posture and default-enabled strong protection
    Managed Extended Detection and Response
    Managed XDR capabilities for detecting and responding to threats across enterprise environments
    AI-Driven Threat Analytics
    Artificial intelligence-powered analytics for threat detection and analysis across workloads, identities, endpoints, and networks
    Unified Security Platform
    Centralized platform providing single source of truth for security operations and incident response across complex environments
    Deep Threat Intelligence Integration
    Integration of deep threat intelligence to enhance detection capabilities and reduce organizational risk
    Multi-Layer Protection Coverage
    Security protection spanning AI, cloud, networks, endpoints, and devices across enterprise infrastructure

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    89 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    52%
    38%
    4%
    5%
    1%
    3 AWS reviews
    |
    86 external reviews
    External reviews are from G2  and PeerSpot .
    Esmeraldo N.

    Excellent Visibility, Interface Could Improve

    Reviewed on Sep 25, 2026
    Review provided by G2
    What do you like best about the product?
    I like the capability of Trellix Network Detection and Response (NDR) to provide good network visibility and quickly identify bad behaviors or potential threats. It allows me to have a clearer view of what's happening in the network environment, enabling the detection of communication patterns and abnormal behaviors, as well as verifying threats more quickly. This helps in having a quick and informed response.
    What do you dislike about the product?
    The interface could be simpler and more intuitive, especially to facilitate quick alert analysis and investigation. Improving alert prioritization and contextualization would reduce false positives and highlight more critical incidents more clearly. Additionally, better integration with other security tools and existing systems, along with more customized reports and dashboards, could facilitate the daily work of the team and improve decision-making.
    What problems is the product solving and how is that benefiting you?
    I use Trellix NDR to monitor and analyze network traffic, detect threats and suspicious activities in real-time, improving network visibility, which allows me a quick and informed response.
    Anonymous

    Solid Detection Capabilities, Needs Better Blocking

    Reviewed on Sep 22, 2026
    Review provided by G2
    What do you like best about the product?
    I like the dashboard showing IPS and malicious traffic detected, as it provides clear visibility. Additionally, I appreciate the multitude of detections possible. The initial setup of Trellix Network Detection and Response (NDR) was straightforward.
    What do you dislike about the product?
    I don't like that the IPS engines leave some critical events unblocked. This requires us to create our own rules to block these, which feels cumbersome. I believe that critical or high-marked events should be blocked by default, and we should receive alerts to review and open them if necessary, not the other way around.
    What problems is the product solving and how is that benefiting you?
    Trellix Network Detection and Response (NDR) gives me visibility into traffic entering hosts and checks EDR functionality, while also showing detected malicious traffic on the dashboard. It supports detecting a multitude of threats, though I need to set custom rules for some critical events left unblocked.
    Computer & Network Security

    Good Visibility and Useful Network Threat Detection

    Reviewed on Sep 20, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Trellix NDR is the visibility it gives into network activity. It makes it easier to spot unusual traffic, suspicious connections, and behavior that may otherwise be difficult to notice through traditional monitoring alone.

    I also find the investigation side useful. When an alert comes in, having the related network activity available in one place helps us understand what happened and whether it is actually something that needs attention. It is especially helpful as an additional layer of detection alongside other security tools.
    What do you dislike about the product?
    One thing I dislike is that the platform can feel a bit complex at first, especially when you are trying to understand why a particular alert was triggered. Some alerts need additional investigation and tuning before they become really useful, otherwise there can be unnecessary noise.
    What problems is the product solving and how is that benefiting you?
    Trellix NDR helps us identify suspicious network activity that may not always be visible through endpoint or firewall monitoring alone. It gives us better visibility into unusual connections, traffic patterns, and potential threats moving across the network.

    The main benefit is that it helps reduce the time spent investigating security events. Instead of checking multiple sources separately, we can use the network data to understand what happened and decide whether an alert needs further action. It has also improved our overall monitoring and incident investigation process.
    Wassim R.

    Proactive Defense with Global Visibility

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate the integration of Trellix Wise which ensures global visibility and risk prioritization. Additionally, the migration from McAfee to Trellix was completely smooth.
    What do you dislike about the product?
    Nothing to mention.
    What problems is the product solving and how is that benefiting you?
    Trellix NDR addresses issues of alert overload, analyst fatigue, blind spots in encrypted traffic, and improves visibility of unmanaged devices.
    ABUZAR K.

    Robust Threat Detection, Needs Setup Efficiency

    Reviewed on Aug 07, 2026
    Review provided by G2
    What do you like best about the product?
    I enjoy Trellix Network Detection and Response (NDR) for its real-time network visibility, precise threat detection, behavior analysis, and alerts. These features help our SOC team investigate cases more efficiently. The integration with other security systems enhances our operations. I appreciate the quick detection of suspicious network behavior through real-time visibility and the ability of behavioral analytics to detect threats that signature-based analytics might miss. The prioritized alerting ensures we can respond efficiently to any situation.
    What do you dislike about the product?
    I find the initial setup and policy configuration laborious, and I believe that further customizations to the dashboard, reports, and integrations would add value. Some alarms also require further tuning to reduce the number of false alarms.
    What problems is the product solving and how is that benefiting you?
    I use Trellix NDR for real-time monitoring, precise threat detection, and anomaly alerts, reducing investigation time and enabling faster response to incidents. It provides real-time network visibility and integrates with our security systems, enhancing our SOC team's efficiency.
    View all reviews