

Trellix Network Detection and Response and Check Point SandBlast Network are competing solutions in the network detection and response category. Trellix has an edge due to advanced threat detection features and strong incident response capabilities, while Check Point is noted for its versatile threat handling and AI/ML integration.
Features: Trellix NDR offers advanced malware detection, zero-day threat capabilities, MVX for virtualized execution, and sandboxing technologies. Incident response and deep threat insights are notable. Check Point SandBlast excels in handling various file types, combining signature-based and zero-day threat prevention with robust Threat Extraction and Emulation features.
Room for Improvement: Trellix could improve integration, reporting options, and reduce false positives. Enhanced user customization and cloud integration are needed. Check Point SandBlast requires better support responsiveness, pricing clarity, and more intuitive configuration. Both products need adaptation to changing cyber environments and improved interoperability.
Ease of Deployment and Customer Service: Trellix NDR is primarily on-premises with high customer service ratings for responsiveness. Check Point SandBlast offers hybrid and cloud options with slightly lower service ratings due to support delays and deployment complexity.
Pricing and ROI: Trellix NDR is seen as expensive but justifies cost with effective breach prevention and substantial ROI. Check Point SandBlast, also with a higher cost for advanced features, is competitively priced, offering favorable ROI through comprehensive threat management.
Protecting around 2,000 users from cyber threats, including ransomware, has positively impacted the organization's growth by reducing disruptions and business loss.
We have seen a good return on investment since implementing Check Point SandBlast Network, as we are spending less time on forensics and it is also preventing us from potential breaches, which itself justifies the cost.
I have seen a return on investment since using Check Point SandBlast Network, as it has improved the efficiency of incident handling and saved costs.
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
The time was reduced because of the automated detections.
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
The customer support for Check Point SandBlast Network is great, as the security team has extensive knowledge and provides proper solutions.
I did get the best from Check Point SandBlast Network's support team; they were very helpful while troubleshooting any kind of issues we faced.
The customer support on chat is pretty much available and relevant to solve the problems.
The support team was responsive and knowledgeable.
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
The scalability of Check Point SandBlast Network meets our organization's needs as we grow.
The scalability of Check Point SandBlast Network is very nice.
It is scalable but requires growing the box itself because it is a resource-intensive solution.
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
When configured correctly with adequate resources, it functions properly.
In my experience, Check Point SandBlast Network is stable and I have not encountered any downtime or reliability issues.
Check Point SandBlast Network is stable in my experience, providing proper security to our organization.
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
I encounter no issues with health or reliability when the recommended specifications are met.
Simplification of granular tuning for false positive reduction and bypassing benign files would benefit non-expert users.
The customer support for Check Point SandBlast Network could be improved as they are sometimes late with their responses.
Check Point SandBlast Network can be improved by adding more integration capabilities, such as integration with third-party firewalls, third-party EDR solutions, and SIEM.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
My experience with pricing and setup cost is that pricing was a bit high.
Pricing is a bit costly, but considering the features and security offered by Check Point SandBlast Network, it is reasonable.
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
The key features of Check Point SandBlast Network include its ability to detect zero-day attacks, provide sandboxing capabilities, and offer real-time protection with threat extraction.
Check Point SandBlast Network has positively impacted my organization as it's very accurate and gives almost no false positives, providing excellent threat prevention and protecting against server zero-day attacks.
It detects zero-day exploits in suspicious and normal files, and includes forensic and reporting features that provide detailed incident analysis, malware behavior reports, and indicators of compromise.
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
| Product | Mindshare (%) |
|---|---|
| Check Point SandBlast Network | 3.4% |
| Trellix Network Detection and Response | 4.1% |
| Other | 92.5% |


| Company Size | Count |
|---|---|
| Small Business | 30 |
| Midsize Enterprise | 8 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 35 |
| Midsize Enterprise | 11 |
| Large Enterprise | 23 |
Check Point SandBlast Network is trusted for advanced threat prevention, employing real-time threat detection and AI-powered analysis to secure corporate environments from zero-day attacks and file-based exploits.
Focused on comprehensive security, SandBlast Network integrates seamlessly with smart security tools to deliver proactive threat prevention. The network leverages sandboxing for zero-day threats, sanitizes email attachments, and frequently updates threat signatures. Threat Emulation and Extraction are key, preventing malicious file downloads and minimizing disruptions while retaining originals for in-depth analysis. Effective at securing emails and web downloads, it offers robust protection against phishing and ransomware.
What are Check Point SandBlast Network's standout features?Check Point SandBlast Network is widely implemented in industries needing advanced threat prevention, such as financial, healthcare, and governmental sectors. These industries utilize its robust features to safeguard sensitive data, protect against sophisticated cyber threats, and ensure a secure digital environment for their operations.
Trellix Network Detection and Response provides robust threat protection with advanced detection of zero-day attacks and APTs. Its user-friendly dashboard and real-time response capabilities enhance security and visibility across networks.
Trellix Network Detection and Response stands out with its MVX engine, leveraging virtual machines for comprehensive behavioral analysis. The solution supports detection of advanced cyber threats through features like sandboxing and application filtering, offering real-time response and packet capture for detailed contextual insights. Companies benefit from seamless integration with other platforms, enhancing usability and overall protection. User-friendly interfaces improve network visibility, while stability and ease of configuration safeguard against both signature-based and signature-less threats.
What key features does Trellix offer?Companies in sectors like finance, healthcare, and enterprise security utilize Trellix Network Detection and Response for tasks such as network intrusion detection, endpoint protection, and securing data transmission paths. It aids in threat investigations, pre-sales demos, and network forensics, reducing risks by protecting against cyber threats like phishing.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.