No more typing reviews! Try our Samantha, our new voice AI agent.
Information Technology Consultant at a outsourcing company with 501-1,000 employees
Real User
May 9, 2023
Useful for containment and taking a triage image
Pros and Cons
  • "The most valuable feature of Trellix Endpoint Security is containment, which takes less than a minute."
  • "Currently, Trellix Endpoint Security can't find the running mutexes, while other open-source products can do it."

What is our primary use case?

We build our own use cases and those provided by the vendor for specific upcoming attack scenarios. Configuring the rule set using Trellix Endpoint Security is very much flexible based on the IOCs.

How has it helped my organization?

Trellix Endpoint Security is good for doing containment immediately. We can get visibility of processes or services running all over the enterprise, where the agent gets information on a particular end-user system. Since Trellix Endpoint Security keeps the data for three months, we can get a complete picture of the files downloaded from the end user mission. So Trellix Endpoint Security is very helpful when you do forensics. The only drawback is that we cannot change its format, and there is no workaround currently.

What is most valuable?

The most valuable feature of Trellix Endpoint Security is containment, which takes less than a minute. It also has a dual containment feature. Trellix Endpoint Security is also useful for taking the triage image, which takes roughly thirty minutes. So it's pretty fast, and we have multiple configuration sets. We can precisely take a triage image based on what you want, like endpoint logs, antivirus logs, or the RAM.

What needs improvement?

Currently, Trellix Endpoint Security can't find the running mutexes, while other open-source products can do it. Mutex is something like a malware user. Secondly, the solution should support multiple output formats for the triage image. Currently, the solution has only Mandiant format, where you can't use tools like volatility to analyze the memory image.

It would be good if Trellix Endpoint Security had a good visualization like other products, such as SentinelOne and Carbon Black.

Buyer's Guide
Trellix Endpoint Security Platform
August 2026
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Trellix Endpoint Security for one year and six months.

What do I think about the stability of the solution?

I rate Trellix Endpoint Security a seven out of ten for stability because it crashes frequently and requires a lot of maintenance.

What do I think about the scalability of the solution?

I rate Trellix Endpoint Security a nine out of ten for scalability. We have plans to increase the usage of the solution in the future.

How was the initial setup?

I rate Trellix Endpoint Security an eight out of ten for ease of initial setup.

What's my experience with pricing, setup cost, and licensing?

I rate Trellix Endpoint Security a nine out of ten for pricing.

What other advice do I have?

I am using the latest version of Trellix Endpoint Security. Using Trellix Endpoint Security depends upon the user's organizational needs. If their only concern is containing and taking the triage image, and if they are comfortable doing forensics with a deadline, then they can use Trellix Endpoint Security. But if some companies want to integrate their in-house or third-party tools, Trellix Endpoint Security is not a good option.

Overall, I rate Trellix Endpoint Security a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2176815 - PeerSpot reviewer
Executive Director of Infrastructure and Technology Asia Pacific at a manufacturing company with 10,001+ employees
Real User
May 8, 2023
Impacts performance of servers negatively but it does protect us against threats
Pros and Cons
  • "Provides protection against threats."
  • "Impacts performance of the servers quite negatively."

What is our primary use case?

This is an anti-virus and firewall solution. We have over 5,000 users and we are customers of Trellix. 

What is most valuable?

Provides endpoint security protection against malware and the like.

What needs improvement?

Trellix tends to get in the way and really impacts the performance of the servers quite negatively.

For how long have I used the solution?

We've been using this product for around 20 years.

How was the initial setup?

I wasn't involved in the initial setup. 

What other advice do I have?

I'd recommend that potential users of this solution look for something more modern, for a newer company providing innovative solutions. I rate this solution five out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Trellix Endpoint Security Platform
August 2026
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
Project Manager at LTIMINDTREE
Real User
Mar 15, 2023
We can deploy all our configurations through the cloud
Pros and Cons
  • "We have a cloud-based instance, so we can deploy all our configurations through the cloud. That's the beauty of FireEye."
  • "Upgrading to new versions isn't easy and it can take a long time. Also, other solutions' tamper protection features are better than FireEye's. Clients should have access to our local information, but they shouldn't change settings on the system itself."

What is our primary use case?

FireEye replaces our traditional antivirus solutions like Symantec and McAfee and covers multiple business use cases, including EDR. 

What is most valuable?

We have a cloud-based instance, so we can deploy all our configurations through the cloud. That's the beauty of FireEye.

What needs improvement?

Upgrading to new versions isn't easy and it can take a long time. Also, other solutions' tamper protection features are better than FireEye's. Clients should have access to our local information, but they shouldn't change settings on the system itself. 

For how long have I used the solution?

I I have used FireEye for 10 months.

What do I think about the stability of the solution?

I rate Endpoint Security seven out of 10. There is room for improvement and development. 

What do I think about the scalability of the solution?

FireEye is a cloud-based application, so it's easy to extend by purchasing more licenses. 

How are customer service and support?

FireEye responds promptly, and their support has been excellent so far.

How was the initial setup?

Deploying Endpoint Security is hassle-free. We uninstalled our legacy antivirus system and deployed FireEye. We created a package and deployed it across the servers manually. 

What other advice do I have?

I rate FireEye Endpoint Security eight out of 10. Explore the solution and see what benefits it can offer your organization. I recommend FireEye depending on the customer's needs and use cases. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
PeerSpot user
General Manager at a tech services company with 11-50 employees
Real User
Jan 4, 2023
The central management console is powerful.
Pros and Cons
  • "The central management console is powerful. You can manage endpoints, DLP, encryption, and all the other features from a single console."
  • "Trellix lacked email protection when it was a McAfee product. They added this feature during the merger with FireEye, but it hasn't been fully integrated. The core features will be integrated into the next release. FireEye has several solutions for EDR and sandboxing."

What is our primary use case?

We use Trellix to secure our customers' endpoint devices and the cloud. It was a McAfee solution before the Trellix acquisition. Trellix has a full portfolio for local and cloud protection. McAfee MVISION products are managed on the cloud, but some customers need an on-premise local management console.

What is most valuable?

The central management console is powerful. You can manage endpoints, DLP, encryption, and all the other features from a single console. 

What needs improvement?

Trellix lacked email protection when it was a McAfee product. They added this feature during the merger with FireEye, but it hasn't been fully integrated. The core features will be integrated into the next release. FireEye has several solutions for EDR and sandboxing. 

For how long have I used the solution?

I have used Endpoint Security for more than 10 years.

What do I think about the stability of the solution?

I rate Trellix nine out of 10 for stability. 

What do I think about the scalability of the solution?

I rate Trellix 10 out of 10 for scalability. 

How are customer service and support?

I rate Trellix support nine out of 10. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have always used McAfee, but I know a little about Symantec. I used it more than a year ago. 

How was the initial setup?

I rate Trellix seven out of 10 for ease of setup. It is a complex tool, but you can use many of the new features while you're installing it. The deployment time varies depending on the number of endpoint accounts and how the client is distributed. It typically takes less than a day for a large enterprise. If nothing goes wrong, you can finish in a few hours. One person is enough to deploy and maintain it. 

What's my experience with pricing, setup cost, and licensing?

I rate Trellix five out of 10 for affordability. It isn't cheap, but not expensive.

What other advice do I have?

I rate Trellix Endpoint Security nine out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
ShaneStutzman - PeerSpot reviewer
CyberSecurity Engineer at a government with 501-1,000 employees
Real User
Top 10
Nov 13, 2022
Scalable and quickly deployable, but they should try moving away from the signature-based model
Pros and Cons
  • "It can be deployed quickly, and it's scalable. Those are the two advantages of it."
  • "Trying to move away from the signature model for antivirus and malware blocking is something that would be nice. Instead of having to update every day, which is signature-based, moving to more of a kernel or architecture-based model would probably be beneficial."
  • "In terms of products in the market, it's probably not the best, but it's the one that is already paid for under the corporate buy."

What is our primary use case?

It covers the AV and malware security piece.

How has it helped my organization?

It's mainly for compliance. In terms of products in the market, it's probably not the best, but it's the one that is already paid for under the corporate buy. It basically checks the box that we're doing malware threat prevention and antivirus protection.

What is most valuable?

It can be deployed quickly, and it's scalable. Those are the two advantages of it.

What needs improvement?

Trying to move away from the signature model for antivirus and malware blocking is something that would be nice. Instead of having to update every day, which is signature-based, moving to more of a kernel or architecture-based model would probably be beneficial.

For how long have I used the solution?

It has probably been about a year since we rolled it out.

What do I think about the stability of the solution?

There are no issues. They continue to put out updates weekly or daily. The platform seems to be fairly mature.

What do I think about the scalability of the solution?

It's definitely scalable.

How are customer service and support?

Their tech support is average.

How was the initial setup?

It's pretty straightforward. It can be automated from the central ePolicy orchestrator server. So, the installation is fairly easy because you can automate it with the deployment of your virtual machines and things like that.

What's my experience with pricing, setup cost, and licensing?

I would rate it a three out of five in terms of cost.

What other advice do I have?

I would rate it a seven out of ten. That's mainly because it seems like there are additional security features that could be built into it, or from the signature-based model, it could move to a different model.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1973925 - PeerSpot reviewer
Owner / Consultant at a marketing services firm with 1-10 employees
Real User
Oct 8, 2022
A good solution that is stable and scalable with seamless deployment
Pros and Cons
  • "The seamless deployment is very valuable."
  • "At the same time, McAfee's deployment was seamless."
  • "The quality of the dashboard could be improved, and the central monitoring dashboard needs improvement."

What is our primary use case?

We deploy the solution on-premises but we have the roadmap to migrate it on cloud. Initially, everything was on-premises, but we are moving to the cloud, which will be our first cloud migration.

What is most valuable?

The seamless deployment is very valuable.

What needs improvement?

The quality of the dashboard could be improved, and the central monitoring dashboard needs improvement. At first, we thought we were getting multiple views. One was a wholly summarized view, and the other was a more detailed view of an endpoint device. Digging into one device's detail is sometimes difficult. Additionally, the granularity of reporting can be improved. The next release could also include an extended mobile connection for the solution.

For how long have I used the solution?

We have been using this solution for approximately four months.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable. Maybe in another six to eight months, we will scale to around 5,500 because we are recruiting more people, so the number may increase.

How are customer service and support?

I have not had any experience with customer service and support.

Which solution did I use previously and why did I switch?

We previously used Trend Micro. When we were deploying Trend Micro, we faced a lot of difficulties. When we acquired Trend Micro, we had no endpoint security so we had to remove an endpoint and deploy Trend Micro. As a result, deploying Trend Micro was very painful. There were frequent failures in the automatic script that Trend Micro had provided, and it took us about three and a half months to completely cover around 4,000 devices. At the same time, McAfee's deployment was seamless. There might have been an issue, but those issues never escalated. With Trend Micro, the issues escalated frequently.

We switched because of the distinction in scalability, Bluetooth and support. Additionally, one of the reasons we replaced Trend Micro was that we were raising a support ticket every month, which was embarrassing for us. We were losing five to seven tags. PSEs and the response to those PSEs were not satisfied every time.

What's my experience with pricing, setup cost, and licensing?

I rate pricing and licensing a seven out of ten.

What other advice do I have?

I rate this solution an eight out of ten. The solution is good, but the dashboard quality and granularity of reporting can be improved.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
ITOfficer at a educational organization with 201-500 employees
Real User
Top 20
Sep 13, 2022
An informative dashboard and immediate reporting and notifications
Pros and Cons
  • "We really like the dashboard from Trellix and we've found that it's pretty informative."
  • "What it does, it does really well, and you're able to experience possibly what's among the best products in the market."
  • "The solution consumes a lot of end user memory and CPU. Trellix doesn't really focus much on the anti-malware side."
  • "The solution consumes a lot of end user memory and CPU, so you need to have a computer that has a lot of resources for you to properly run Trellix."

What is our primary use case?

Our use case is pretty straightforward. We have the central ePO that's running, and clients connect to it. All the clients connect to the ePO for updates and the ePO is able to go out and get updates, so it's pretty much like a star topology where you have the ePO sitting at the middle and handling all the requests from the clients and the servers.

What is most valuable?

We really like the dashboard from Trellix and we've found that it's pretty informative. Also, the reporting is pretty much immediate, so if there's any activity on the network, you're able to get notifications immediately. That's something that we really like about this product.

What needs improvement?

The solution consumes a lot of end user memory and CPU, so you need to have a computer that has a lot of resources for you to properly run Trellix. The agent ends up using a lot of resources, either RAM or CPU, and at times that bogs down users. I don't know if it's possible to have a lighter version of the agent, but if the agent was lighter it wouldn't consume so many resources, which would be good.

It's a bit complex. It's very granular and you need to really, really know the ins and outs of configuration. If you are specifically configuring an XML against ransomware, some very special setup, it can end up being a bit technical. You wouldn't want to make any mistakes while doing your configuration. A single configuration can make you lose whatever you wanted to do.

The other thing is if the engine would also focus more on malware, sort of an anti-malware. Trellix doesn't really focus so much on the anti-malware side, but there are other better performing antivirus or endpoint products that have better engines or they have a higher detection rate compared to what Trellix is currently providing.

For how long have I used the solution?

I have been working with this solution for about three years.

What do I think about the stability of the solution?

If you've given the solution the resources that it needs, it's pretty much stable and it's able to continuously run uninterrupted. I've never seen any down times, so I'd say it's pretty much stable and it's built well.

What do I think about the scalability of the solution?

As far as scalability, I think the solution is able to handle quite a bit. We have around three admins who interact with the product. Then we have the rest of the organization who interface with it, which is around 300 to 500 employees.

How are customer service and support?

The tech support was pretty responsive and I believe all my questions were answered within the stated timeline. I can't remember what my questions were about, but I spoke with the technical team and got the help that I deserved. I would rate the support as a five out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

From a technical side, it's not so complicated. Of course, you need to set up your server correctly, and then deploying it to the agent is pretty simple. The setup on the server is the one that is a bit technical. You can't have a default deployment, so once you do your deployment you need to set up rules that work within your environment to be able to safeguard it against suspect files or potentially unwanted programs. You need to know exactly what to do, and that's the point that may not be very friendly to admin, because they might not know all of the threats that are out there. You can't really foresee a threat that you don't know about, or rather you don't know if you'd block it or not. The initial setup is pretty much straightforward if you're an IT person, but the configuration side has a learning curve. It takes quite some bit of time to really know exactly what you're doing.

What about the implementation team?

We handled implementation in-house because when we got the licensing, we also got training modules from Trellix. Trellix has KB articles, which are pretty much straightforward and really helped quite a bit. I'd say it took about four hours to deploy from the time we started with a clean machine to the time that we started pulling updates and deploying to client machines.

On a scale of one to five, I'd give the setup a four, because the product pretty much does what it says it does, but it's not perfect. If you're an IT person, you'll be able to deploy it, and sending the Agent file to clients is pretty much a no-brainer.

The maintenance bit is okay as well. There's not a high amount of maintenance because you can automate many activities. You just need to make sure that your server is able to pick up the updates that are necessary, and make sure the databases are running okay. It's nothing new if you're in the IT environment, just making sure everything is running properly. I've never landed on an update that broke the application.

What was our ROI?

I believe for organizations that are looking for what Trellix is offering right now, there is a definite return on investment.

What's my experience with pricing, setup cost, and licensing?

I think Trellix is more on the higher side of the market, just on a general scale, but I also think it depends on what particular package you choose. Different packages have different rates. I would give the pricing a three out of five. It depends on your usage because if the product works for you, then you might say the price is right. At one point it worked for us, but we have shifted our goals.

Which other solutions did I evaluate?

We currently considering switching from Trellix to Bitdefender mainly because Trellix isn't really focused on malware, and right now most threats are coming from within the organization as malware. Malware is something that can stop business continuity, so that's one of our main areas of focus, and Trellix is not doing really well within that perspective.

What other advice do I have?

I would recommend Trellix to someone as long as they know exactly what they're looking for within the organization. For instance, Trellix is very granular, so if you have a dedicated security department that can customize policies and XML documents at a very fine level and specifically work on this product, then I would say, go for it. The solution is going to serve them well, because what it does, it does really well. You're able to experience possibly what's among the best products in the market. I would recommend it as long as the people know exactly what they're getting into and they're ready to handle the challenge.

On a scale of one to ten, I would give Trellix an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Rahul Sawhney - PeerSpot reviewer
Group Manager at HCLSoftware
Real User
Jul 17, 2022
Works in an ecosystem, has a central console, and can enable blocking
Pros and Cons
  • "If the network has seen something, we can use that to put a block to all the endpoints."
  • "Centrally, from just one console, you can block malicious attacks across your environment."
  • "The solution can be expensive."

What is our primary use case?

We used it for a compromise assessment. That would be for our client. We deployed the agents. It was for endpoint security.

We had been using the solution previously for one of the clients. We were using it for six months, and we did a compromise assessment based on the FireEye Endpoints that were deployed across the group. At that point in time, there were a lot of ransomware attacks in the environment, and it was impossible to identify the source of the attack and where it came from. The tools didn't point to that visibility. We had to deploy these agents across the environment and also monitor the environment using the network security appliances provided by FireEye just to monitor.

We did monitor it for six months, so it was an assessment. In those six months, we did not have another ransomware attack. It was proven the environmental assessment was clean. That was the whole objective of the compromise assessment - to find out if there are any indicators or anything that has gained a foothold in the environment, trying to fend advanced persistent threats from that standpoint.

What is most valuable?

It is a great solution. The way it exchanges the information between the entire ecosystem, all the endpoints, as well as the network ATP, can trigger the blocking even if it is seen by some other device. If the network has seen something, we can use that to put a block to all the endpoints.

It works in an ecosystem. Centrally, from just one console, you can block malicious attacks across your environment. It provides you with the ability to respond to threats better.

What needs improvement?

The solution can be expensive.

If it could provide a little more in terms of automating things, for example, in response and automatic playbooks wherein you define whatever it is if you see this kind of a threat. You define the actions that need to be followed. If a playbook could be automated and run without even requiring manual involvement, that is the future we want, and they should look into how to make that happen. That is the kind of capability we want them to build.

In terms of reporting, also, if they could provide a little bit more information from where it started, how it progressed; a complete workflow, how that had progressed from where it was picked up; what was the target stage, what was the next stage, and what was the final stage, that would be very helpful. If they could pick up in a simple pictorial way of representing analysis just like the Cisco ASA Packet Analyzer used to do, that would be really helpful.

For how long have I used the solution?

We used the solution for six months.

What do I think about the stability of the solution?

The stability has been very good. There are no bugs or glitches and it doesn’t crash or freeze. It’s reliable.

What do I think about the scalability of the solution?

The product can scale. It’s not an issue at all. 20,000 users were using the solution with no problems.

How are customer service and support?

We have contacted tech support. Tech support was brilliant. They were very knowledgeable, very skillful, and very responsive, and they knew the subject matter. They knew what we were asking for.

How was the initial setup?

The agent installation was okay. It was just a package that was installed. It also provides options to customize and fine-tune based on the system's performance. It's not too heavy on the systems or the servers.

On the network side of things, I think there were challenges to getting that working. We had to do a couple of alterations in terms of making it work, mainly since the appliance's model was provided using a special-purpose SFP, and the compatible SFP was not available in the client environment at that one point. We had to procure it specifically for that assessment.

What's my experience with pricing, setup cost, and licensing?

It’s very costly.

What other advice do I have?

I’d recommend the solution to others.

I would rate the solution eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
RUBEN CARDENAS - PeerSpot reviewer
National Technical Support Manager at BancoSol S.A.
Real User
Jun 23, 2022
It's a good solution , not the best. Email protection could be better.
Pros and Cons
  • "MVISION offers decent protection."
  • "The email protection isn't efficient enough, and I'd like to see DLP features in the next release."
  • "I wouldn't recommend it to others because it's not secure enough."

What is most valuable?

MVISION offers decent protection.

What needs improvement?

The email protection isn't efficient enough, and I'd like to see DLP features in the next release. 

For how long have I used the solution?

I've been using MVISION for three years.

What do I think about the stability of the solution?

MVISION is stable.

What do I think about the scalability of the solution?

MVISION is scalable. 

How was the initial setup?

Setting up MVISION is easy.

What's my experience with pricing, setup cost, and licensing?

We have an annual license and pay extra for support.

What other advice do I have?

I rate McAfee MVISION Endpoint six out of 10. It's a good product, but not the best. I wouldn't recommend it to others because it's not secure enough. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Meleria Mangaring - PeerSpot reviewer
Meleria MangaringSystems Engineer at a consultancy with 1,001-5,000 employees
Top 20Real User

The GUI of ePO must be upgraded.

JamesYa - PeerSpot reviewer
Senior Solutions Architect at Cloud4C Services
Real User
Jun 4, 2022
Simple implementation, stable, but priced high
Pros and Cons
  • "McAfee MVISION Endpoint is stable."
  • "McAfee MVISION Endpoint is used for endpoint protection and protects the files and network against viruses and malware."
  • "The price of McAfee MVISION Endpoint could improve."

What is our primary use case?

McAfee MVISION Endpoint is used for endpoint protection. Protects the files and network against viruses and malware.

What needs improvement?

The price of McAfee MVISION Endpoint could improve.

For how long have I used the solution?

I have been using McAfee MVISION Endpoint for approximately one year.

What do I think about the stability of the solution?

McAfee MVISION Endpoint is stable.

Which solution did I use previously and why did I switch?

I have previously used Check Point and Microsoft Defender. I would recommend Microsoft Defender over the other solutions I have used.

How was the initial setup?

The installation of the McAfee MVISION Endpoint was simple. We are able to do it remotely from a central location.

What was our ROI?

I have had a return on investment by using McAfee MVISION Endpoint.

What's my experience with pricing, setup cost, and licensing?

We are on an annual subscription for McAfee MVISION Endpoint. The cost for the license could be less expensive.

What other advice do I have?

I rate McAfee MVISION Endpoint a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros sharing their opinions.