No more typing reviews! Try our Samantha, our new voice AI agent.
Trellix Endpoint Detection and Response (EDR) Logo

Trellix Endpoint Detection and Response (EDR) pros and cons

Vendor: Trellix
3.8 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Trellix Endpoint Detection and Response (EDR) provides significant time and cost savings while ensuring a stable security environment.
The guided analytics feature with real-time investigation capabilities enhances detection and response efficiency.
The integration of EDR and antivirus strengthens threat prevention and overall endpoint security.
The ease of setup and one-click file recovery simplify system management and user experience.
Advanced detection and mitigation capabilities offer high protection levels against threats like ransomware and command and control attacks.

CONS

There is high resource consumption, including CPU and RAM usage.
Customer support is slow and lacks sufficient engineers.
Historical search functionality is limited.
Trellix and McAfee MVISION Endpoint are not integrated into a single system.
Lack of integration with external platforms and inability to handle unknown fileless attacks effectively.
 

Trellix Endpoint Detection and Response (EDR) Pros review quotes

Duncan  Kims - PeerSpot reviewer
Business Development Manager at a retailer with 10,001+ employees
Apr 14, 2026
Trellix Endpoint Detection and Response (EDR) has positively impacted my organization with threat exchange and intel, low false positive ratios, and very high uptime values for both inline and spam modes, along with advanced detection and mitigation capabilities ensuring the highest level of protection and proper detection for command and control and bot attacks.
Domit-Molina - PeerSpot reviewer
Especialista Sr Seguridad Endpoint at Total Cyber Sec
Jun 23, 2026
Trellix Endpoint Detection and Response (EDR) scores highly because of its sheer depth of endpoint visibility, the precision of its behavior-based detection, and the massive time savings we get from its AI-guided investigations.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 7, 2026
Trellix Endpoint Detection and Response (EDR) is valuable because we have a Wide Area Network with many sites, and the EDR is cross-site since it is installed and managed from the cloud.
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
Abubakar Bello - PeerSpot reviewer
Security Administrator at a insurance company with 1,001-5,000 employees
Mar 19, 2026
Trellix Endpoint Detection and Response (EDR) does everything; it saves time, it saves money, and of course, it provides peace of mind.
IM
Senior Information Security Specialist at a consultancy with 51-200 employees
Jun 13, 2026
My advice for others considering Trellix Endpoint Detection and Response (EDR) is to use it, or any other Trellix products, as I believe they are excellent.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 3, 2025
The product and the services we have are quite good.
RiaanDu Preez - PeerSpot reviewer
Senior Cyber Security Specialist Architect at a outsourcing company with 11-50 employees
Aug 15, 2024
The most useful features are behavior monitoring, DLP, and access control. The automation has gotten much better in the last two years than when it was McAfee. It works better now and integrates more smoothly.
ObaseunAwoyinfa - PeerSpot reviewer
Security Consultant at Trinexia
Jun 5, 2024
It relies on external systems for detection and then asks the endpoint to handle blocking. However, the most crucial feature is its investigative capabilities. With real-time search and other functionalities, it enables comprehensive detection and response.
RR
Head of Data Link at Telecom Egypt
Nov 30, 2023
The product's initial setup phase was very straightforward since you just need to install it, and it works.
Juan Muriel - PeerSpot reviewer
IT Management Specialist at a computer software company with 10,001+ employees
Feb 22, 2024
When Trellix detects some threats, the device is isolated in a quarantine zone for examination.
 

Trellix Endpoint Detection and Response (EDR) Cons review quotes

Duncan  Kims - PeerSpot reviewer
Business Development Manager at a retailer with 10,001+ employees
Apr 14, 2026
One area where Trellix Endpoint Detection and Response (EDR) can be improved is the lack of device or user mapping.
Domit-Molina - PeerSpot reviewer
Especialista Sr Seguridad Endpoint at Total Cyber Sec
Jun 23, 2026
From an operational standpoint, the first area of improvement would be agent resource optimization, especially for high-load servers, because Trellix Endpoint Detection and Response (EDR) captures an incredible depth of telemetry and real-time forensics.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 7, 2026
The tools are not useful for that.
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
Abubakar Bello - PeerSpot reviewer
Security Administrator at a insurance company with 1,001-5,000 employees
Mar 19, 2026
Initially, I was using it on servers, but it consumes a lot of resources on servers.
IM
Senior Information Security Specialist at a consultancy with 51-200 employees
Jun 13, 2026
I also think performance needs improvement, especially for servers, as the Trellix HX module uses high CPU, scans constantly, and negatively impacts the performance for our clients' users or our servers.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 3, 2025
I need some protection, possibly multi-factor authentication improvements.
RiaanDu Preez - PeerSpot reviewer
Senior Cyber Security Specialist Architect at a outsourcing company with 11-50 employees
Aug 15, 2024
I'd like the tool to become more like an XDR, with one management system and endpoint activation.
ObaseunAwoyinfa - PeerSpot reviewer
Security Consultant at Trinexia
Jun 5, 2024
Trellix needs to focus on gaining traction with partners and building trust among users.
RR
Head of Data Link at Telecom Egypt
Nov 30, 2023
One of the issues about the product stems from the failure to work on its administrative scalability. The aforementioned area can be considered for improvement.
Juan Muriel - PeerSpot reviewer
IT Management Specialist at a computer software company with 10,001+ employees
Feb 22, 2024
The technical support must be improved.