In Trellix Endpoint Security, I use all modules, including firewall and web control, except for encryption.
IT Security Specialist at asystel italia
A stable solution that offers good technical support and can be implemented without much difficulties
Pros and Cons
- "It is a stable solution...The solution's technical support is good."
- "There are certain shortcomings in the features concerning DLP in Trellix, where certain additions must be made in the future."
What is our primary use case?
What needs improvement?
There are certain shortcomings in the features concerning DLP in Trellix, where certain additions must be made in the future.
For how long have I used the solution?
I have been using Trellix Endpoint Security for five years. My company is a customer of the solution.
What do I think about the stability of the solution?
It is a stable solution. If I consider using Trellix Endpoint Security right now, I won't find it a problem since it is a good product to use.
Buyer's Guide
Trellix Endpoint Security Platform
July 2026
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.
What do I think about the scalability of the solution?
There are around 800 users of the solution in my company.
How are customer service and support?
The solution's technical support is good. Whenever I open or raise a ticket with Trellix's support team, I get a response from their end.
I rate the technical support a nine out of ten.
How was the initial setup?
The implementation part of the product is not difficult. From an implementation perspective, I find the product to be good enough.
For me, the product's deployment in all endpoints takes an hour, and it is a simple process. I don't know if the deployment process is still simple or not and whether improvements have been made to the solution.
What other advice do I have?
I find Trellix Endpoint Security to be a good product. In Trellix Endpoint Security, it is not simple to understand the policies and rules, but it is good as an antivirus product. Trellix Endpoint Security is not easy to use, especially since the mechanism of communication is not very good.
I rate the overall product an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
A good endpoint security software in the market that needs to offer more customization capabilities
Pros and Cons
- "The most valuable feature of the solution is its dashboard."
- "The customization capabilities of the solution are an area where it lacks, so it would be great if our company could customize the solution to meet the demands of our customers."
What is our primary use case?
Trellix Endpoint Security (ENS) is useful as an endpoint security software.
What is most valuable?
The most valuable feature of the solution is its dashboard.
What needs improvement?
The dashboard provided by the solution needs to be improved. The customization capabilities of the solution are an area where it lacks, so it would be great if our company could customize the solution to meet the demands of our customers.
In the future, I would like technical support for the solution and its UI to be more efficient.
For how long have I used the solution?
I have been using Trellix Endpoint Security (ENS) for two years. I usually deal with a product's latest version. My company has a partnership with Trellix.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten. The solution is mostly stable, but sometimes, there is a need to do some troubleshooting.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a seven out of ten.
How are customer service and support?
I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Currently, I work with CrowdStrike since my company has a partnership with it. CrowdStrike is better than Trellix Endpoint Security (ENS). CrowdStrike offers functionalities like machine learning and DLP.
How was the initial setup?
I have used the solution on the cloud and on-premises. Currently, the solution is deployed on the cloud services offered by Trellix, which I feel is a public cloud.
What's my experience with pricing, setup cost, and licensing?
I don't think there are any extra expenses besides its licensing costs.
What other advice do I have?
Maintenance of the solution is required, including some troubleshooting parts managed by five to six engineers in our company.
I recommend the solution to those planning to use it.
Not all solutions in the market are good, though I found Trellix Endpoint Security (ENS) to be a good product.
I rate the overall solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Trellix Endpoint Security Platform
July 2026
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.
Information Technology Consultant at a outsourcing company with 501-1,000 employees
Useful for containment and taking a triage image
Pros and Cons
- "The most valuable feature of Trellix Endpoint Security is containment, which takes less than a minute."
- "Currently, Trellix Endpoint Security can't find the running mutexes, while other open-source products can do it."
What is our primary use case?
We build our own use cases and those provided by the vendor for specific upcoming attack scenarios. Configuring the rule set using Trellix Endpoint Security is very much flexible based on the IOCs.
How has it helped my organization?
Trellix Endpoint Security is good for doing containment immediately. We can get visibility of processes or services running all over the enterprise, where the agent gets information on a particular end-user system. Since Trellix Endpoint Security keeps the data for three months, we can get a complete picture of the files downloaded from the end user mission. So Trellix Endpoint Security is very helpful when you do forensics. The only drawback is that we cannot change its format, and there is no workaround currently.
What is most valuable?
The most valuable feature of Trellix Endpoint Security is containment, which takes less than a minute. It also has a dual containment feature. Trellix Endpoint Security is also useful for taking the triage image, which takes roughly thirty minutes. So it's pretty fast, and we have multiple configuration sets. We can precisely take a triage image based on what you want, like endpoint logs, antivirus logs, or the RAM.
What needs improvement?
Currently, Trellix Endpoint Security can't find the running mutexes, while other open-source products can do it. Mutex is something like a malware user. Secondly, the solution should support multiple output formats for the triage image. Currently, the solution has only Mandiant format, where you can't use tools like volatility to analyze the memory image.
It would be good if Trellix Endpoint Security had a good visualization like other products, such as SentinelOne and Carbon Black.
For how long have I used the solution?
I have been using Trellix Endpoint Security for one year and six months.
What do I think about the stability of the solution?
I rate Trellix Endpoint Security a seven out of ten for stability because it crashes frequently and requires a lot of maintenance.
What do I think about the scalability of the solution?
I rate Trellix Endpoint Security a nine out of ten for scalability. We have plans to increase the usage of the solution in the future.
How was the initial setup?
I rate Trellix Endpoint Security an eight out of ten for ease of initial setup.
What's my experience with pricing, setup cost, and licensing?
I rate Trellix Endpoint Security a nine out of ten for pricing.
What other advice do I have?
I am using the latest version of Trellix Endpoint Security. Using Trellix Endpoint Security depends upon the user's organizational needs. If their only concern is containing and taking the triage image, and if they are comfortable doing forensics with a deadline, then they can use Trellix Endpoint Security. But if some companies want to integrate their in-house or third-party tools, Trellix Endpoint Security is not a good option.
Overall, I rate Trellix Endpoint Security a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Executive Director of Infrastructure and Technology Asia Pacific at a manufacturing company with 10,001+ employees
Impacts performance of servers negatively but it does protect us against threats
Pros and Cons
- "Provides protection against threats."
- "Impacts performance of the servers quite negatively."
What is our primary use case?
This is an anti-virus and firewall solution. We have over 5,000 users and we are customers of Trellix.
What is most valuable?
Provides endpoint security protection against malware and the like.
What needs improvement?
Trellix tends to get in the way and really impacts the performance of the servers quite negatively.
For how long have I used the solution?
We've been using this product for around 20 years.
How was the initial setup?
I wasn't involved in the initial setup.
What other advice do I have?
I'd recommend that potential users of this solution look for something more modern, for a newer company providing innovative solutions. I rate this solution five out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Manager at LTIMINDTREE
We can deploy all our configurations through the cloud
Pros and Cons
- "We have a cloud-based instance, so we can deploy all our configurations through the cloud. That's the beauty of FireEye."
- "Upgrading to new versions isn't easy and it can take a long time. Also, other solutions' tamper protection features are better than FireEye's. Clients should have access to our local information, but they shouldn't change settings on the system itself."
What is our primary use case?
FireEye replaces our traditional antivirus solutions like Symantec and McAfee and covers multiple business use cases, including EDR.
What is most valuable?
We have a cloud-based instance, so we can deploy all our configurations through the cloud. That's the beauty of FireEye.
What needs improvement?
Upgrading to new versions isn't easy and it can take a long time. Also, other solutions' tamper protection features are better than FireEye's. Clients should have access to our local information, but they shouldn't change settings on the system itself.
For how long have I used the solution?
I I have used FireEye for 10 months.
What do I think about the stability of the solution?
I rate Endpoint Security seven out of 10. There is room for improvement and development.
What do I think about the scalability of the solution?
FireEye is a cloud-based application, so it's easy to extend by purchasing more licenses.
How are customer service and support?
FireEye responds promptly, and their support has been excellent so far.
How was the initial setup?
Deploying Endpoint Security is hassle-free. We uninstalled our legacy antivirus system and deployed FireEye. We created a package and deployed it across the servers manually.
What other advice do I have?
I rate FireEye Endpoint Security eight out of 10. Explore the solution and see what benefits it can offer your organization. I recommend FireEye depending on the customer's needs and use cases.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
General Manager at a tech services company with 11-50 employees
The central management console is powerful.
Pros and Cons
- "The central management console is powerful. You can manage endpoints, DLP, encryption, and all the other features from a single console."
- "Trellix lacked email protection when it was a McAfee product. They added this feature during the merger with FireEye, but it hasn't been fully integrated. The core features will be integrated into the next release. FireEye has several solutions for EDR and sandboxing."
What is our primary use case?
We use Trellix to secure our customers' endpoint devices and the cloud. It was a McAfee solution before the Trellix acquisition. Trellix has a full portfolio for local and cloud protection. McAfee MVISION products are managed on the cloud, but some customers need an on-premise local management console.
What is most valuable?
The central management console is powerful. You can manage endpoints, DLP, encryption, and all the other features from a single console.
What needs improvement?
Trellix lacked email protection when it was a McAfee product. They added this feature during the merger with FireEye, but it hasn't been fully integrated. The core features will be integrated into the next release. FireEye has several solutions for EDR and sandboxing.
For how long have I used the solution?
I have used Endpoint Security for more than 10 years.
What do I think about the stability of the solution?
I rate Trellix nine out of 10 for stability.
What do I think about the scalability of the solution?
I rate Trellix 10 out of 10 for scalability.
How are customer service and support?
I rate Trellix support nine out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have always used McAfee, but I know a little about Symantec. I used it more than a year ago.
How was the initial setup?
I rate Trellix seven out of 10 for ease of setup. It is a complex tool, but you can use many of the new features while you're installing it. The deployment time varies depending on the number of endpoint accounts and how the client is distributed. It typically takes less than a day for a large enterprise. If nothing goes wrong, you can finish in a few hours. One person is enough to deploy and maintain it.
What's my experience with pricing, setup cost, and licensing?
I rate Trellix five out of 10 for affordability. It isn't cheap, but not expensive.
What other advice do I have?
I rate Trellix Endpoint Security nine out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
CyberSecurity Engineer at a government with 501-1,000 employees
Scalable and quickly deployable, but they should try moving away from the signature-based model
Pros and Cons
- "It can be deployed quickly, and it's scalable. Those are the two advantages of it."
- "Trying to move away from the signature model for antivirus and malware blocking is something that would be nice. Instead of having to update every day, which is signature-based, moving to more of a kernel or architecture-based model would probably be beneficial."
- "In terms of products in the market, it's probably not the best, but it's the one that is already paid for under the corporate buy."
What is our primary use case?
It covers the AV and malware security piece.
How has it helped my organization?
It's mainly for compliance. In terms of products in the market, it's probably not the best, but it's the one that is already paid for under the corporate buy. It basically checks the box that we're doing malware threat prevention and antivirus protection.
What is most valuable?
It can be deployed quickly, and it's scalable. Those are the two advantages of it.
What needs improvement?
Trying to move away from the signature model for antivirus and malware blocking is something that would be nice. Instead of having to update every day, which is signature-based, moving to more of a kernel or architecture-based model would probably be beneficial.
For how long have I used the solution?
It has probably been about a year since we rolled it out.
What do I think about the stability of the solution?
There are no issues. They continue to put out updates weekly or daily. The platform seems to be fairly mature.
What do I think about the scalability of the solution?
It's definitely scalable.
How are customer service and support?
Their tech support is average.
How was the initial setup?
It's pretty straightforward. It can be automated from the central ePolicy orchestrator server. So, the installation is fairly easy because you can automate it with the deployment of your virtual machines and things like that.
What's my experience with pricing, setup cost, and licensing?
I would rate it a three out of five in terms of cost.
What other advice do I have?
I would rate it a seven out of ten. That's mainly because it seems like there are additional security features that could be built into it, or from the signature-based model, it could move to a different model.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner / Consultant at a marketing services firm with 1-10 employees
A good solution that is stable and scalable with seamless deployment
Pros and Cons
- "The seamless deployment is very valuable."
- "At the same time, McAfee's deployment was seamless."
- "The quality of the dashboard could be improved, and the central monitoring dashboard needs improvement."
What is our primary use case?
We deploy the solution on-premises but we have the roadmap to migrate it on cloud. Initially, everything was on-premises, but we are moving to the cloud, which will be our first cloud migration.
What is most valuable?
The seamless deployment is very valuable.
What needs improvement?
The quality of the dashboard could be improved, and the central monitoring dashboard needs improvement. At first, we thought we were getting multiple views. One was a wholly summarized view, and the other was a more detailed view of an endpoint device. Digging into one device's detail is sometimes difficult. Additionally, the granularity of reporting can be improved. The next release could also include an extended mobile connection for the solution.
For how long have I used the solution?
We have been using this solution for approximately four months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. Maybe in another six to eight months, we will scale to around 5,500 because we are recruiting more people, so the number may increase.
How are customer service and support?
I have not had any experience with customer service and support.
Which solution did I use previously and why did I switch?
We previously used Trend Micro. When we were deploying Trend Micro, we faced a lot of difficulties. When we acquired Trend Micro, we had no endpoint security so we had to remove an endpoint and deploy Trend Micro. As a result, deploying Trend Micro was very painful. There were frequent failures in the automatic script that Trend Micro had provided, and it took us about three and a half months to completely cover around 4,000 devices. At the same time, McAfee's deployment was seamless. There might have been an issue, but those issues never escalated. With Trend Micro, the issues escalated frequently.
We switched because of the distinction in scalability, Bluetooth and support. Additionally, one of the reasons we replaced Trend Micro was that we were raising a support ticket every month, which was embarrassing for us. We were losing five to seven tags. PSEs and the response to those PSEs were not satisfied every time.
What's my experience with pricing, setup cost, and licensing?
I rate pricing and licensing a seven out of ten.
What other advice do I have?
I rate this solution an eight out of ten. The solution is good, but the dashboard quality and granularity of reporting can be improved.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager Pre-Sales (ICT) at CNS Engineering
Provides good mobile device protection and it works on all platforms
Pros and Cons
- "The solution provides good mobile device protection and it's great that it's on the cloud."
- "The solution lacks device control."
- "The solution currently lacks mobile device management."
What is our primary use case?
We primarily use this solution as cover for mobile devices. I'm the manager of pre-sales and we are resellers and users of this solution. We are low-level partners of McAfee.
What is most valuable?
The solution provides good mobile device protection and it's great that it's on the cloud. The product is compatible and works for all platforms.
What needs improvement?
I'd like McAfee to include device control on MVISION. The solution currently lacks mobile device management. The cost of the solution is comparatively high and I'd like to see that reduced.
For how long have I used the solution?
I've been using MVISION for one year and working with McAfee solutions for the past 10 years.
What do I think about the stability of the solution?
The solution is stable for threat protection.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support is very good. They are very knowledgeable and also happy to help out.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy and very straightforward.
What's my experience with pricing, setup cost, and licensing?
There's a USD$1,500 supported annual subscription fee that includes maintenance for anywhere between 51 and 100 users. It's USD$30 per users which I think is quite expensive.
What other advice do I have?
It's important to be clear about your use case and environment before purchasing this solution.
I rate this solution eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller / Partner
Group Manager at HCLSoftware
Works in an ecosystem, has a central console, and can enable blocking
Pros and Cons
- "If the network has seen something, we can use that to put a block to all the endpoints."
- "Centrally, from just one console, you can block malicious attacks across your environment."
- "The solution can be expensive."
What is our primary use case?
We used it for a compromise assessment. That would be for our client. We deployed the agents. It was for endpoint security.
We had been using the solution previously for one of the clients. We were using it for six months, and we did a compromise assessment based on the FireEye Endpoints that were deployed across the group. At that point in time, there were a lot of ransomware attacks in the environment, and it was impossible to identify the source of the attack and where it came from. The tools didn't point to that visibility. We had to deploy these agents across the environment and also monitor the environment using the network security appliances provided by FireEye just to monitor.
We did monitor it for six months, so it was an assessment. In those six months, we did not have another ransomware attack. It was proven the environmental assessment was clean. That was the whole objective of the compromise assessment - to find out if there are any indicators or anything that has gained a foothold in the environment, trying to fend advanced persistent threats from that standpoint.
What is most valuable?
It is a great solution. The way it exchanges the information between the entire ecosystem, all the endpoints, as well as the network ATP, can trigger the blocking even if it is seen by some other device. If the network has seen something, we can use that to put a block to all the endpoints.
It works in an ecosystem. Centrally, from just one console, you can block malicious attacks across your environment. It provides you with the ability to respond to threats better.
What needs improvement?
The solution can be expensive.
If it could provide a little more in terms of automating things, for example, in response and automatic playbooks wherein you define whatever it is if you see this kind of a threat. You define the actions that need to be followed. If a playbook could be automated and run without even requiring manual involvement, that is the future we want, and they should look into how to make that happen. That is the kind of capability we want them to build.
In terms of reporting, also, if they could provide a little bit more information from where it started, how it progressed; a complete workflow, how that had progressed from where it was picked up; what was the target stage, what was the next stage, and what was the final stage, that would be very helpful. If they could pick up in a simple pictorial way of representing analysis just like the Cisco ASA Packet Analyzer used to do, that would be really helpful.
For how long have I used the solution?
We used the solution for six months.
What do I think about the stability of the solution?
The stability has been very good. There are no bugs or glitches and it doesn’t crash or freeze. It’s reliable.
What do I think about the scalability of the solution?
The product can scale. It’s not an issue at all. 20,000 users were using the solution with no problems.
How are customer service and support?
We have contacted tech support. Tech support was brilliant. They were very knowledgeable, very skillful, and very responsive, and they knew the subject matter. They knew what we were asking for.
How was the initial setup?
The agent installation was okay. It was just a package that was installed. It also provides options to customize and fine-tune based on the system's performance. It's not too heavy on the systems or the servers.
On the network side of things, I think there were challenges to getting that working. We had to do a couple of alterations in terms of making it work, mainly since the appliance's model was provided using a special-purpose SFP, and the compatible SFP was not available in the client environment at that one point. We had to procure it specifically for that assessment.
What's my experience with pricing, setup cost, and licensing?
It’s very costly.
What other advice do I have?
I’d recommend the solution to others.
I would rate the solution eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
IBM Security QRadar
Elastic Security
Huntress Managed EDR
TrendAI Vision One
WatchGuard Firebox
TrendAI Vision One – Cloud Security
HP Wolf Security
Microsoft Defender XDR
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Symantec Endpoint vs. McAfee Complete Endpoint Protection: Technical Comparison Between Data Loss Protection Solutions
- How does McAfee Endpoint Security compare with MVISION?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?
- Where can I get a fully paid for training course for McAfee MVISION Endpoint?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?


















