

VMware Carbon Black Endpoint and Trellix Helix Connect operate within the advanced security solutions market. VMware Carbon Black Endpoint has an upper hand in customer satisfaction due to its pricing and support. Meanwhile, Trellix Helix Connect stands out for its comprehensive features, justifying its higher cost.
Features: VMware Carbon Black Endpoint is known for its resource efficiency, behavioral monitoring, and dynamic grouping. It excels in timeline capabilities and offers robust threat-hunting abilities. Trellix Helix Connect provides cloud-native automation, advanced threat intelligence, and extensive integration with platforms like Mandiant. It enhances customization and enrichment capabilities, offering significant depth in feature offerings.
Room for Improvement: VMware Carbon Black Endpoint could improve in integration capabilities, on-premise infrastructure, and UI simplification. There's a need for better response to issues and enhanced mobile device support. Trellix Helix Connect could enhance its cloud connectors, integration with third-party tools, and information presentation in dashboards. Both could benefit from more intuitive management features.
Ease of Deployment and Customer Service: VMware Carbon Black Endpoint shows flexibility by offering deployment options in public, private, and hybrid cloud setups as well as on-premises. Trellix Helix Connect is typically deployed in public cloud environments, with limited private cloud support. Customer service for Carbon Black is generally reliable but sometimes delayed in engineering responses. Trellix Helix offers high-level support but may be slow in resolving specific issues.
Pricing and ROI: VMware Carbon Black Endpoint is considered high-priced but offers flexible MSI pricing options that provide good value and substantial ROI, especially in long-term cost savings. Trellix Helix Connect is also seen as competitively priced, though expensive for smaller businesses. However, it offers a reasonable return on investment due to its efficient pricing structure, particularly advantageous for FireEye cloud customers.
Before Trellix Helix Connect, we were doing everything manually, but after that, it has become automatic, allowing us to save about 40 to 45% time and reduce operational inefficiencies.
We have seen a return on investment with Trellix Helix Connect, and we can share relevant metrics as we reduce the MTTD and MTTR and have KPIs indicating our ROI.
From an analyst's perspective, it has required fewer L2 operators since we already have a broader view of what is happening with the endpoint machines.
I assess the effectiveness of Trellix Helix Connect's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike.
My experience with the support team was very good; they were cooperative and demonstrated good knowledge of how things worked.
We often wait for weeks to get a response from the engineering team due to a long relay process from customer representatives to the engineering team and then back to us.
Regarding the technical support of Broadcom, they are responsive and helpful.
We support the largest companies in the world and can cater to large environments.
Trellix Helix Connect's scalability is excellent as the solution has a library to make integrations with other brands.
The platform has scaled well as our environment and log volume have grown.
The solution's scalability has had a medium impact on the IT environment.
The availability is high, which is critical for our customers who rely on a single panel of glass to operate.
Trellix Helix Connect is very stable, and I have experienced almost no downtime or issues.
Trellix Helix Connect has stability issues as it experienced downtimes during off-hours that affected our night shifts and late hours.
VMware Carbon Black Endpoint is slow for the stability rating.
The GUI and dashboard feel very old-school and legacy, needing improvement, as all competitors have far superior GUIs and UI/UX interfaces.
We have just released the solutions to the market recently, making it a revolution in the cybersecurity sector.
The usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements.
I think VMware Carbon Black Endpoint should improve in every area, because currently the NetGen AV, even from Microsoft and even from CrowdStrike, is better than VMware Carbon Black Endpoint.
We mainly chose this solution because of the pricing factor alone; many other options were more lucrative feature-wise, but for pricing, it was quite competitive at the time.
It is not the cheapest, but also not the most expensive solution.
We do not face much performance issues; for pricing, it was close to other competitors.
My rating for the pricing of VMware Carbon Black Endpoint is that it is not cheap, but it is also not as inexpensive as I would prefer.
Trellix Helix, as an AI XDR platform, helps our organization by offering an extensive number of connectors for integration, enabling us to consolidate all information in a single dashboard.
Trellix Helix Connect easily integrates with Office 365 and also integrates well with FortiGate, Palo Alto, and Barracuda, especially within AWS environments.
The features that I find most valuable in Trellix Helix Connect are the incident response capabilities, which include EDR and XDR, along with the SoC capabilities added in the new advanced Trellix AI intelligence.
I assess VMware Carbon Black Endpoint's machine learning capabilities in detecting unknown threats as fantastic.
VMware Carbon Black Endpoint does facilitate endpoint protection and incident response, and it is an EDR.
| Product | Mindshare (%) |
|---|---|
| Trellix Helix Connect | 5.8% |
| VMware Carbon Black Endpoint | 6.0% |
| Other | 88.2% |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 1 |
| Large Enterprise | 12 |
| Company Size | Count |
|---|---|
| Small Business | 31 |
| Midsize Enterprise | 9 |
| Large Enterprise | 33 |
Trellix Helix Connect leverages automation with playbooks and AI, enhancing incident management, data correlation, and reducing response times while easing integration and improving threat visibility.
Trellix Helix Connect transforms cyber operations with automated workflows, cutting response times and decreasing analyst fatigue. Its ability to integrate seamlessly with existing infrastructures improves incident handling through advanced AI and data correlation techniques. Quick to implement, it enhances threat visibility, enabling faster incident triage, alert correlation, and threat intelligence integration. While the platform excels in these areas, users have noted areas for enhancement, such as integration with third-party tools, better dashboard functionalities, and reduced false positives. Despite concerns over licensing costs and connectivity issues, Trellix Helix Connect remains a valuable asset for centralized security event management and response automation.
What are the key features of Trellix Helix Connect?Organizations rely on Trellix Helix Connect for centralized correlation and security event management, integrating it with existing tools for streamlined alert management and enhanced cybersecurity measures. It supports tasks like phishing detection, data protection, and endpoint security, essential in industries facing persistent network threats, including managing logs, detecting malware, and automating responses, reducing investigation times and improving notification efficiency.
VMware Carbon Black Endpoint enhances endpoint security with its robust EDR, threat detection, and live response features. The cloud-based architecture supports remote management and easy setup while behavioral monitoring and dynamic grouping minimize security risks.
VMware Carbon Black Endpoint is designed for those seeking comprehensive endpoint protection. With its cloud-based deployment, organizations experience streamlined remote control and simplified rollout processes. Its behavioral monitoring, incident response capabilities, and firewall integration deliver advanced security measures. Although it addresses many security challenges, areas like manual alert management, on-demand scanning, and integration with systems like AlienVault USM require refinement. Improved UI, EDR components, and flexible pricing models would enhance user satisfaction. On-premise deployment infrastructure and compatibility issues with some operating systems need attention. Enhanced reporting, container security, and multi-tenancy support are also essential for fulfilling industry needs. AI-driven analysis and threat isolation empower companies by fostering proactive management.
What are the key features of VMware Carbon Black Endpoint?
What benefits should users look for when evaluating VMware Carbon Black Endpoint?
VMware Carbon Black Endpoint finds extensive application in industries focused on stringent security requirements. Managed security service providers leverage its capabilities to deliver comprehensive protection to multiple clients worldwide. Organizations use it primarily for antivirus protection and incident management, integrating it with their existing security frameworks to strengthen endpoint visibility and real-time threat prevention. Its advanced detection and application control features make it a preferred choice in industries that prioritize robust security measures. However, it requires improvements in terms of system compatibility and customization flexibility to better serve diverse industry environments.
We monitor all Security Incident Response reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.