

Trellix Network Detection and Response and IRONSCALES are competitors in the cybersecurity category, focusing on network security and email security, respectively. Trellix seems to have an edge in threat detection, particularly with advanced threats, while IRONSCALES excels in email phishing protection due to its community-driven intelligence.
Features: Trellix Network Detection and Response offers advanced threat detection, particularly against zero-day threats and APTs, with features such as the MVX Engine for intensive analysis, capable sandboxing, and threat intelligence sharing. IRONSCALES, in contrast, provides exceptional email security, utilizing AI-driven automated detection, community threat intelligence, and a proactive phishing protection system that automates threat management.
Room for Improvement: Trellix Network Detection and Response could benefit from enhanced integration options, greater customization capabilities, and a more user-friendly sandboxing and VM control interface. Meanwhile, IRONSCALES may improve by expanding its training awareness resources, refining its user interface, and enhancing phishing awareness campaigns for better user engagement.
Ease of Deployment and Customer Service: Trellix Network Detection and Response typically sees on-premises deployment, with customer service rated from adequate to responsive and support seen as competent. IRONSCALES, often used in public cloud environments, receives praise for its strong customer service and satisfaction with support, indicating ease of deployment and operation within various cloud settings.
Pricing and ROI: Trellix Network Detection and Response is on the pricier side but justifies this with effective threat detection and significant ROI achieved through reduced incident response times. IRONSCALES, though also meeting ROI expectations by improving security and reducing manual threat management, is regarded as more affordable compared to peers due to its cost-effective email threat prevention capabilities.
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
The time was reduced because of the automated detections.
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
Customer support for IRONSCALES is outstanding.
I would rate their technical support as very good, as they respond promptly when my team opens a ticket.
The support team was responsive and knowledgeable.
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
I encounter no issues with health or reliability when the recommended specifications are met.
If there were clickable drill downs on specific users or specific correspondence to relate them to certain types of mails, that would be beneficial.
Having a more user-friendly UI would make it easier to identify features and options when using the tool.
Though this isn't problematic for our users, the content could be updated more frequently.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
While I don't specifically oversee the pricing details, I understand that IRONSCALES is in the range of similar solutions while offering better results.
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
IRONSCALES has positively impacted my organization by making email security simple in terms of controlling mails, understanding where the threats are, and protecting the organization itself.
The best features of IRONSCALES are that most alerts are validated through AI, which reduces the fatigue of alerts that need to be worked on by the team handling the alerts investigation part.
IRONSCALES excels at analyzing the intention, not just the content itself, but the sender's attempt to gain user attention.
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
| Product | Mindshare (%) |
|---|---|
| Trellix Network Detection and Response | 4.1% |
| IRONSCALES | 2.8% |
| Other | 93.1% |

| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 4 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 35 |
| Midsize Enterprise | 11 |
| Large Enterprise | 23 |
IRONSCALES delivers cutting-edge AI-driven email phishing detection and prevention, seamlessly integrating with Microsoft 365 for enhanced security.
IRONSCALES, with its advanced AI capabilities, focuses on email security by detecting phishing threats, mitigating business email compromises, and preventing impersonation. Its integration with Microsoft 365 strengthens spam filters, automatically responding to suspicious emails. The platform is used globally for threat inspection, quarantine, and end-user incident reporting. Staff training is enhanced through simulated phishing campaigns, offering an extra layer of protection beyond Microsoft's spam filters. Areas for improvement include better Google Suite integration, pricing adjustments, and enhanced reporting features.
What features make IRONSCALES stand out?In finance, IRONSCALES plays an essential role in safeguarding sensitive data from phishing attacks, ensuring compliance with industry standards. Educational institutions use IRONSCALES for training faculty and students on recognizing phishing attempts, thereby enhancing overall cybersecurity awareness. IT sectors leverage its capabilities for managing complex threat landscapes.
Trellix Network Detection and Response provides robust threat protection with advanced detection of zero-day attacks and APTs. Its user-friendly dashboard and real-time response capabilities enhance security and visibility across networks.
Trellix Network Detection and Response stands out with its MVX engine, leveraging virtual machines for comprehensive behavioral analysis. The solution supports detection of advanced cyber threats through features like sandboxing and application filtering, offering real-time response and packet capture for detailed contextual insights. Companies benefit from seamless integration with other platforms, enhancing usability and overall protection. User-friendly interfaces improve network visibility, while stability and ease of configuration safeguard against both signature-based and signature-less threats.
What key features does Trellix offer?Companies in sectors like finance, healthcare, and enterprise security utilize Trellix Network Detection and Response for tasks such as network intrusion detection, endpoint protection, and securing data transmission paths. It aids in threat investigations, pre-sales demos, and network forensics, reducing risks by protecting against cyber threats like phishing.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.