No more typing reviews! Try our Samantha, our new voice AI agent.

DeepArmor vs Trellix Endpoint Security Platform comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
DeepArmor
Ranking in Endpoint Protection Platform (EPP)
58th
Average Rating
2.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Trellix Endpoint Security P...
Ranking in Endpoint Protection Platform (EPP)
7th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
167
Ranking in other categories
Endpoint Detection and Response (EDR) (8th), Extended Detection and Response (XDR) (7th)
 

Mindshare comparison

As of September 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, up from 3.8% compared to the previous year. The mindshare of DeepArmor is 0.4%, up from 0.1% compared to the previous year. The mindshare of Trellix Endpoint Security Platform is 3.3%, down from 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.8%
Trellix Endpoint Security Platform3.3%
DeepArmor0.4%
Other92.5%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Muhammad Fahad - PeerSpot reviewer
Manager Tech. & Support (Information Technology) at Texitech
Security needs improvement and email scanning features are not included
The email scanning feature is not available in DeepArmor. We cannot use this for email scanning. There are many options that are not available in DeepArmor. We cannot use separate applications for different internet applications or for different internet scanning. This is why we cannot use it. I would like to see additional features such as email scanning, which should be included, or malware detections, and other cybersecurity features should be included. It could also be more secure.
AmitKumar22 - PeerSpot reviewer
Product Manager at Frontier Business systems
Strong endpoint protection has simplified compliance and reduced effort for large user environments
One of the best features of Trellix Endpoint Security Platform is its endpoint security, and I have been using it for the last four and a half to five years, so I can say this is one of the best EDR endpoint security solutions I have ever seen. The features that make Trellix Endpoint Security Platform stand out for me are ease of use and analytics, which I really appreciate the most. Trellix Endpoint Security Platform positively impacts my organization, ensuring we are compliant with SOC 2, HIPAA, and all other compliance requirements, so there are no issues with that.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
"The initial setup is pretty easy."
"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"Palo Alto is the best security solution in the market."
"It is an easy-to-use tool."
"It's very stable. I've never experienced downtime for the ASM console or ASM core."
"Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
"Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard."
"It is easy to install."
"The most valuable feature of this solution is its simplicity."
"The detection is great and the solution is constantly improving."
"From the McAfee side, I really like the ePolicy Orchestrator software that allows us to manage all of our endpoints."
"It has a very simple like multi-tenancy option and scalability is outstanding."
"Dynamic Application Containment."
"The most valuable feature of Trellix Endpoint Security is its extensive customization capability, which allows me to create and deploy policies autonomously, suiting my individual needs."
"The solution is broken down into different components from the portals. Web filtering, which is an added feature has been great for us."
"I can say that all the features of this product are most valuable for me, but I believe that Antivirus, McAfee Data Loss Prevention Endpoint, McAfee Device Control, Drive Encryption and Deep Command are the basic features that any business needs (Enterprise, Small or Medium)."
 

Cons

"The downside to the solution is that there are a large number of false positives."
"Additionally, I think the price is very high, and if it can be adjusted, I believe it will be a very good solution."
"Managing the product should be easier."
"In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement."
"I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."
"Traps doesn't work with McAfee. You need to remove McAfee to install Traps. This is very common, and its nothing that should be an issue. Some antivirus engines recognize Traps as an threat component, so maybe they need to shake hands somewhere."
"Cortex XDR by Palo Alto Networks is not only pricey; it is extremely expensive."
"It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
"The email scanning feature is not available in DeepArmor. We cannot use this for email scanning."
"The software download features could stand improvement."
"We have reports by users of machines being slow when the on-demand scan starts."
"The Linux support is very poor. I use base detection. Currently, they are providing malware protection and logon track features in Windows and Mac. These features aren't available in Linux. It will be helpful to extend these capabilities to Linux. We would also like assets grouping and device lock protection features, which are included in their roadmap."
"One of the drawbacks to the solution is that it is not 100% secure."
"It didn't work well for some of the use cases. We have different use cases for each entity. Their support is also not good and needs improvement."
"The reports need more development. They need more details on the reports and more details taking the executive view into consideration."
"If you have another endpoint product running on the same machine, you have to fine tune functions from FireEye to avoid performance and user experience issues."
"The product is not bad, but there may be somethings that need to be modified."
 

Pricing and Cost Advice

"It is "expensive" and flexible."
"I don't recall what the cost was, but it wasn't really that expensive."
"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"The pricing is a little bit on the expensive side."
"It has reasonable pricing for the use cases it provides to the company."
"Cortex XDR’s pricing is very reasonable."
"Cortex XDR's pricing is ok."
"I don't like that they have different types of licenses."
"There are licensing fees."
"It is not that expensive. There is no additional cost. We got the entire bundle together."
"Trellix Endpoint Security is an inexpensive platform."
"It is not so cheap in comparison to Sophos and other solutions."
"We pay for the license on an annual basis."
"Licensing fees are billed on a yearly basis."
"Trellix Endpoint Security (ENS) has a reasonable price."
"Trellix may cost around $46 to $47 for a single license without an EDR."
"They should reduce the cost or make it free, open-source software."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
No data available
Outsourcing Company
14%
Financial Services Firm
9%
Manufacturing Company
9%
Construction Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
No data available
By reviewers
Company SizeCount
Small Business68
Midsize Enterprise39
Large Enterprise67
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
How does McAfee Endpoint Security compare with MVISION?
The flexible manageability of McAfee Endpoint Security is one of our favorite aspects of this solution. You can deplo...
How does Crowdstrike Falcon compare with FireEye Endpoint Security?
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effec...
What is your experience regarding pricing and costs for McAfee Endpoint Security?
I don't have visibility on pricing because it is negotiated by a different team, as I look after the technical side.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
McAfee Endpoint Security, McAfee Endpoint Protection, Intel Security Total Protection for Endpoint, McAfee Complete Endpoint Protection, Trellix Endpoint Security (ENS)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
AV-Comparatives
inHouseIT, Seagate Technology
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
913,683 professionals have used our research since 2012.