Try our new research platform with insights from 80,000+ expert users
reviewer2099124 - PeerSpot reviewer
Assistant Vice President at a financial services firm with 10,001+ employees
Real User
A good combination of features for both signature and signature-less detection
Pros and Cons
  • "The solution includes a good combination of features for both signature and signature-less."
  • "The solution could provide open XDR in addition to EDR."

What is our primary use case?

Our company just started evaluating the solution for endpoint protection. We have tested it in a POC environment but have not deployed it to the production environment. 

What is most valuable?

The solution includes a good combination of features for both signature and signature-less detection. Based on types of threats, we can opt to use either or a combination of both. 

What needs improvement?

Good progress has been made with integrations for McAfee and FireEye but more work has to be completed because the feature is still pending. Down the line with these integrations, the solution will be very good product. 

The solution could provide open XDR in addition to EDR.

Adding MDR makes sense instead of just being on the EDR and DXDR fronts. 

For how long have I used the solution?

I have been using the solution for a couple of weeks. 

Buyer's Guide
Trellix Endpoint Security Platform
July 2025
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,164 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is SaaS so should be fully scalable but we have not yet tested scalability. 

How are customer service and support?

Technical support could be improved. Our team worked with the product reps to coordinate requirements and deploy.

How was the initial setup?

The setup is quite easy and only takes a few minutes because it is a SaaS solution. 

What about the implementation team?

We implemented the solution in-house for our POC environment. 

Which other solutions did I evaluate?

We use several products simultaneously and are using the solution in a test case. It might take two or three months to confirm if we plan to deploy to our production environment. 

What other advice do I have?

The solution meets customer expectations and is a good product. I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2519793 - PeerSpot reviewer
Technical consultant at a construction company with 51-200 employees
Consultant
Top 20
Protects server files deployed in the web tier but have poor support
Pros and Cons
  • "HIPS protects server files from being modified or deleted by unauthorized users. It's primarily deployed in the web tier."
  • "It is a bit technical. The user interface has some significant limitations, mainly when using HIPS on the server side, to protect files from being changed or deleted by hackers, users, or administrators."

What is our primary use case?

I'm working on a project for the Hong Kong library system under the Hong Kong government. They provide workstations in the library for citizens to access the Internet. The ENS needs to be installed on all the PCs in the library. Another part involves the CSWA for the server farm. They are upgrading the entire library system, including the rental system, book search, eBooks, multimedia, and other services. The CSWA modules are primarily for the backend servers, including Linux and Windows.

How has it helped my organization?

Detection and response functionality meet our requirements, but the support is poor.

What is most valuable?

HIPS protects server files from being modified or deleted by unauthorized users. It's primarily deployed in the web tier.

What needs improvement?

It is a bit technical. The user interface has some significant limitations, mainly when using HIPS on the server side, to protect files from being changed or deleted by hackers, users, or administrators. The UI only allows for the inclusion of files using wildcards. 

For example, it can protect an entire directory or a subdirectory, but it doesn't let you select specific files within a directory.

For how long have I used the solution?

I have been using Trellix Endpoint Security (ENS) as an implementor for two years.

What do I think about the stability of the solution?

We haven't had any system crashes or problems in most cases. SolidCore is not compatible with some kernels, which is causing problems. Endpoint, HIPS, and anti-theft are working fine so far. 

I rate the solution’s stability as seven out of ten.

What do I think about the scalability of the solution?

We use one ePO server to manage around four thousand endpoints, including servers. This single server effectively handles this load.

It is suitable for medium and large enterprises.

I rate the solution’s scalability as seven out of ten.

How are customer service and support?

Support is poor. A module called Solidcore needs to match with the OS kernel in one area. The support for this module has been slow because it doesn't match the latest OS. As a result, we haven't been able to upgrade our OS because McAfee does not support the latest version. We've also encountered issues where the product can't be upgraded or installed successfully. We're managing over 300 servers and 3,000 workstations. Upgrading has been a nightmare with this setup.

It provides a slow response. Sometimes, getting feedback takes a few days, and that is also not to the point.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is easy and straightforward. Determining specific modules and functions often involves a lot of trial and error. Deployment takes only a couple of days.

What other advice do I have?

Overall, I rate the solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
Buyer's Guide
Trellix Endpoint Security Platform
July 2025
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,164 professionals have used our research since 2012.
Peter Antoni - PeerSpot reviewer
Product and Service Architect at Radar Cyber Security
Real User
Top 10
Offers endpoint protection and generates alarms for events
Pros and Cons
  • "The tool has contributed to improving our security posture. While it's just one part of our overall solution, it plays a crucial role. As we continue to evolve, we anticipate it becoming even more important alongside other aspects like network behavior and additional metrics."
  • "The product is consolidating its portfolio into one product. It is difficult at the moment."

What is our primary use case?

The tool is primarily used for endpoint detection. When an event occurs on an endpoint, alarms are generated. Colleagues from my company then investigate these alarms based on a playbook. Depending on the playbook and the specific customer contract, actions may be taken, such as informing the customer or implementing endpoint containment measures.

What is most valuable?

The tool has contributed to improving our security posture. While it's just one part of our overall solution, it plays a crucial role. As we continue to evolve, we anticipate it becoming even more important alongside other aspects like network behavior and additional metrics.

The tool's most valuable feature is containment. Last year, a German company faced an external attack. We installed the product on every machine, totaling hundreds of endpoints. The Trellix agent collected information, allowing us to check the entire IT infrastructure. 

What needs improvement?

The product is consolidating its portfolio into one product. It is difficult at the moment. 

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the scalability of the solution?

The solution's scalability is easy. If you have Trellix Endpoint Security on-premises, you need to define how many agents you will support and consider future scaling. Different appliances are available for various scenarios. If you plan to have hundreds or thousands of agents in the future, hardware considerations become important. However, if it is deployed in the cloud, scaling up or down is easily manageable.

How are customer service and support?

My experience with the product's tech support is good. 

How would you rate customer service and support?

Positive

How was the initial setup?

Trellix Endpoint Security (ENS)'s deployment is not difficult. There are different options available, such as using an on-prem hardware box or a virtual machine in the cloud. Setting up the virtual machine in the cloud is easy, requiring only a connection to the customer's system. 

If you plan to install the solution on-premises, you bring the box to the customer and connect it to their system. This involves some configuration, such as opening a port on the firewalls. Deploying agents on the endpoints is straightforward and can be done from a central management point. The entire process takes around a day to configure, and then you are up and running.

What's my experience with pricing, setup cost, and licensing?

Microsoft Defender is not cheap and from a cost perspective, Trellix Endpoint Security (ENS) is a better option. 

What other advice do I have?

We integrate the product into our system using API. The information, in the form of messages or alarms, is received in our system. We further process this information and incorporate it into our complete solution. 

I rate the product an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Joseck Wekesa - PeerSpot reviewer
Partner Account Manager at Trinexia
Real User
It integrates well with other solutions, but the vendor needs more of a local presence and faster response
Pros and Cons
  • "Trellix integrates well with most SIEM and data classification solutions."
  • "You do not have access to all the features when you use the Trellix web interface. For example, you cannot do device or drive encryption from the web interface. Also, when we're working with customers, it's sometimes challenging to get sales support. Delays mean we might lose an opportunity. Lastly, Trellix lacks some documentation about custom features."

What is our primary use case?

We primarily use Trellix for drive encryption and malware prevention, but we also use some advanced features, such as centralized control and policy management. 

How has it helped my organization?

Trellix enables us to customize and centrally manage policies. We can set on-prem policies and synchronize them with the cloud. 

What is most valuable?

Trellix integrates well with most SIEM and data classification solutions.

What needs improvement?

You do not have access to all the features when you use the Trellix web interface. For example, you cannot do device or drive encryption from the web interface. Also, when we're working with customers, it's sometimes challenging to get sales support.  Delays mean we might lose an opportunity. Lastly, Trellix lacks some documentation about custom features. 

I would like to see Trellix add database activity monitoring. They don't have a plan for this, and there isn't a significant roadmap around it. They have an enterprise service manager, which is sort of like a SIEM, but there is no roadmap. I want to see a clearer roadmap for integrating specific critical solutions like PAM and other things, too.

For how long have I used the solution?

I have used Trellix ENS for two to three years.

What do I think about the stability of the solution?

Trellix ENS is stable. 

What do I think about the scalability of the solution?

Trellix is scalable with some limitations. I recommend it for small or medium-sized businesses.  The integration needs to be simplified for it to work in an enterprise with a large, complex environment.

How are customer service and support?

I rate Trellix support six out of 10. They need more local presence in South Africa and a faster response. Other distributors work through a partner system. There are also some challenges due to the merger of McAfee and FireEye to form Trellix and some legacy issues around a lack of innovation. 

Standard support is included with the subscription, and there are layers of escalation when you open a ticket. You can pay extra to get premium support, which is priced separately. 

How would you rate customer service and support?

Neutral

How was the initial setup?

Trellix is easy to deploy if you have enough skills. Some customers think they can do it alone without professional services, but the deployment doesn't go smoothly. They have misconfigurations, which become a problem. They have issues when they are renewing the license because they didn't scale sufficiently in the beginning. The deployment time can range from five days to three months, depending on the size and complexity of your environment. 

What's my experience with pricing, setup cost, and licensing?

Trellix is reasonably priced, but the cost goes up by about 7 to 10 percent annually, so some of our customers complain at renewal time. The license is based on the number of devices. There are discounts as you add more devices, so you may pay $15 per device or up to $50 per device. 

Standard support is included with the subscription for the first year, but you'll pay for the deployment costs. In the next year, you'll pay only for the license and support.

Which other solutions did I evaluate?

Trellix is one of the best legacy endpoint protection solutions, but we're also looking at Crowdstrike. Other solutions have advantages over Trellix in brand awareness and local presence. 

The company needs to do more to build its presence in this country. I've never seen an account manager or sales rep show up to an in-person event in South Africa. Other companies like Trend Micro have offices here. 

What other advice do I have?

I rate Trellix Endpoint Security six out of 10. I would give it a seven or an eight if not for the vendor's shortcomings in terms of support and local presence. The scale and speed of response make a difference. It's an excellent product that may not be perceived as such because of how it's supported and the awareness of potential customers. 

Before implementing Trellix, you should take time to understand the core use cases you want to achieve and match them to specific features. You should also do a limited proof of concept with the vendor or a distributor.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Venugopal Potumudi - PeerSpot reviewer
Senior Consultant at Tata Consultancy
Real User
Reliable with good independent modules and a straightforward setup
Pros and Cons
  • "The independent modules are very good."
  • "The complexity of advanced modules can be improved."

What is our primary use case?

For some of our engagements, we have used MVISION, including data protection, threat intelligence, and DPP also.

We use McAfee MVISION primarily for endpoint protection, antivirus, and understanding the threat intel for end users. 

What is most valuable?

It is very stable.  

The independent modules are very good. 

For the most part, the setup and deployment are simple.

What needs improvement?

The only challenge we found is the integration with its product modules. It has a DPP. That integration, we felt, is slightly complex. The complexity of advanced modules can be improved. They could do some improvements so that it is easier to deploy the advanced modules.

We would like more in their advanced modules or ATP.

For how long have I used the solution?

I've used the solution for a could of years.

What do I think about the stability of the solution?

The solution has been quite stable. It is reliable. There are no bugs or glitches. It doesn't crash or freeze.

What do I think about the scalability of the solution?

I cannot comment on the scalability. I've never tried to scale the solution. 

How are customer service and support?

For desktop support, they are pretty good. 

Which solution did I use previously and why did I switch?

There are certain engagements where our customers are still using it. Now, however, we do see a common trend of people moving towards Defender service rather than using McAfee.

We also use Trend Micro. We would prefer Trend Micro and would rate Trend Micro top and then make McAfee next.

How was the initial setup?

The basic modules are straightforward to set up. We don't see many challenges there. However, when we talk about going into advanced ATP modules, et cetera, we do see certain amounts of complexity.

I did not work on the implementation and cannot say how long exactly it took to deploy. Likely, it would take between three and six months.

What's my experience with pricing, setup cost, and licensing?

We generally deal with annual licensing. 

What other advice do I have?

I'd rate the solution seven out of ten. Having used Trend Micro as well, I would rate Trend Micro higher. However, I would still choose this product as a second option.

When we recommend a product, we would recommend something based on the fit of the product and customer requirements. We worked with Defender, we worked with Trend Micro, and we worked with McAfee. All of them almost overlap in multiple use cases. That said, we do see the customer IT strategy and where they're going, and they are adopting Azure more. We know there are certain limitations in their landscape where there may be some old legacy systems, and in that case, then we would either switch back to McAfee or Trend Micro instead of Defender.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1810833 - PeerSpot reviewer
CEO at a tech services company with 1-10 employees
Real User
Top 5Leaderboard
Central management that enhances endpoint protection with helpful support
Pros and Cons
  • "The EPO, the ePolicy Orchestrator, is the best endpoint protection central management system."
  • "The detection and response capabilities need to be improved."

What is our primary use case?

We use Trellix Endpoint Security for endpoint protection, including virus protection for desktops, laptops, and servers. The solution includes special dedicated modules, such as those for Microsoft SharePoint security.

How has it helped my organization?

Trellix Endpoint Security helps us support and secure a large number of endpoints efficiently. We have a lot of installations, supporting up to twenty thousand endpoints. With the central management system EPO, it has significantly improved our ability to manage security across these devices.

What is most valuable?

The EPO, the ePolicy Orchestrator, is the best endpoint protection central management system. 

Trellix Endpoint Security has a lot of special small modules that I like very much, such as access protection, adaptive threat prevention, exclusion capabilities, and logging capabilities. Together with disk encryption or file encryption, it provides a comprehensive solution.

What needs improvement?

The detection and response capabilities need to be improved. The product is not sharp enough in catching viruses, and we often have to use additional components alongside the pure endpoint security. Symantec, for example, might be better in this area.

For how long have I used the solution?

We have been working with Trellix Endpoint Security for about 20 years.

What do I think about the stability of the solution?

The stability of the solution is very high, I'd rate it around eight or nine out of ten.

What do I think about the scalability of the solution?

Scalability is high; I'd rate it 20 out of ten if possible.

How are customer service and support?

Technical support is correct and absolutely helpful. We had some issues during the migration from McAfee to Trellix, particularly with account migrations, but generally, support has been good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used Fortinet Endpoint Management, Symantec, Kaspersky, Check Point, and others. Among these, I find that the EPO system of Trellix is the best.

How was the initial setup?

I like the initial setup very much because Trellix Endpoint Security has a lot of special small modules and configurations. It's flexible and allows for detailed customizations.

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution is correct and justified for the value it provides.

What other advice do I have?

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Large account Manager at Softcell Technologies Limited
Real User
Top 5Leaderboard
Offers good malware protection features but needs to improve its scalability
Pros and Cons
  • "The product's initial setup phase was straightforward."
  • "Sometimes, one might face issues with the scalability of the product. The aforementioned area can be considered for improvement."

What is our primary use case?

The solution is used, especially by those who want an antivirus product. It is also useful for those looking for tools that offer endpoint detection and response features. The product offers multiple features, one of which is endpoint security.

What needs improvement?

Sometimes, one might face issues with the scalability of the product. The aforementioned area can be considered for improvement.

For how long have I used the solution?

I have been using Trellix Endpoint Security (ENS) for five years. I operate as a system integrator of the product in my company.

What do I think about the stability of the solution?

Stability-wise, I rate the solution an eight out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a seven out of ten.

My company caters to the needs of small, medium, and large-sized businesses.

How are customer service and support?

I rate the technical support a ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The product's initial setup phase was straightforward.

The solution is deployed on the cloud and on an on-premises model.

The time required for the deployment of the product can vary, and it also depends on whether the company has been actively using the product.

What's my experience with pricing, setup cost, and licensing?

The price of the product is similar to the ones in the market that offer the same features.

What other advice do I have?

The product has improved its malware protection features since it provides a couple of features that no other solution does. The tool is helpful for multiple companies.

The tool streamlines the incident response process.

The most effective part of the product for threat prevention is related to the tool's rollback feature.

Trellix Endpoint Security (ENS) is like an antivirus tool, but it doesn't alone provide the rollback feature since it is something that is possible with Trellix Endpoint Detection and Response (EDR).

The tool does provide adaptive threat protection features.

I recommend the product to those who plan to use it.

I rate the tool a seven to eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Harsh Bhardwaj - PeerSpot reviewer
Presales Engineer at Rah Infotech Pvt Ltd
Real User
Top 5
A stable anti-malware solution that provides DLP (data loss prevention) and DAC (Dynamic Access Control)
Pros and Cons
  • "The most valuable features of the solution include DLP (data loss prevention), CASB (cloud access security broker) functionality, endpoint encryption, and cloud workload security."
  • "The solution's documentation is not streamlined and is in bits and pieces, which should be in a single format."

What is our primary use case?

Customers use Trellix Endpoint Security as an anti-malware or antivirus solution that provides AI and machine learning features. The solution provides DAC (Dynamic Access Control) and HIPS (host intrusion prevention system) functionality in its firewall module. It also has a web control functionality, wherein we can allow, deny, or choose the category part and work it out.

What is most valuable?

Trellix Endpoint Security provides a single umbrella kind of architecture. A lot of different solutions come under a single umbrella and a single console. The most valuable features of the solution include DLP (data loss prevention), CASB (cloud access security broker) functionality, endpoint encryption, and cloud workload security. The solution also has features like application control, device control, and cloud DLP.

What needs improvement?

The solution's documentation is not streamlined and is in bits and pieces, which should be in a single format.

Trellix Endpoint Security should include the virtual patching feature in the next release.

For how long have I used the solution?

I have been working with Trellix Endpoint Security for one year.

What do I think about the stability of the solution?

I rate Trellix Endpoint Security a nine out of ten for stability.

What do I think about the scalability of the solution?

Trellix Endpoint Security has good scalability. Our customers for the solution are most enterprise businesses and government entities.

I rate the solution a nine out of ten for scalability.

How was the initial setup?

The solution’s initial setup is easy.

I rate Trellix Endpoint Security ten out of ten for the ease of its initial setup.

What about the implementation team?

The solution's deployment on the cloud is very fast because we give the requirement and get the solution. On-premises, the basic initial setup of the server takes about half an hour or one hour.

What's my experience with pricing, setup cost, and licensing?

Trellix Endpoint Security is neither a cheap nor an expensive solution.

On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a four out of ten.

What other advice do I have?

I am working with the latest version of Trellix Endpoint Security. We provide our customers with on-premises, on-cloud, and hybrid cloud deployment models for Trellix Endpoint Security.

Overall, I rate Trellix Endpoint Security an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Distributor
PeerSpot user
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros sharing their opinions.