No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1581882 - PeerSpot reviewer
Sr Manager - Information Security & Researcher at a tech services company with 1,001-5,000 employees
Real User
May 29, 2021
Enables us to do IOC-based search across the enterprise and isolate compromised devices
Pros and Cons
  • "It is easy to use, flexible, and stable. Because it is a cloud-based solution and it integrates all endpoints of the cloud, we can do an IOC-based search. It can search the entire enterprise and tell us the endpoints that are possibly compromised."
  • "It has a feature called Isolation. If a device is compromised, we can connect it to our SOC, and no one would be able to access it. This way we can limit the damage to the network while we are investigating."
  • "It is easy to use, flexible, and stable."
  • "Malware detection can be better. It doesn't have support and detection for the recent malware, but it has a compensatory control where it can do the behavior-based assessment and alert you when there is something malicious or unexpected. For example, when a certain user is executing the privilege command, which is not normal. These dynamic detections are good, and they compensate for malware detection."
  • "It has very good integrations. However, its integration with Palo Alto was not good, and they seem to be working on it at the backend. It is not very resource-hungry, but it can be even better in terms of resource utilization. It could be improved in terms of efficiency, memory sizing, and disk consumption by agents."
  • "They have something called Managed Detection and Response. They get intel from their customers, and that intel is shared with the rest of FireEye's customers. I want to subscribe to their intel, but that is not available to us."

What is our primary use case?

It can be used for ransomware detection and data exfiltration. It is also able to detect Remote Access Trojan (RAT).

What is most valuable?

It is easy to use, flexible, and stable. Because it is a cloud-based solution and it integrates all endpoints of the cloud, we can do an IOC-based search. It can search the entire enterprise and tell us the endpoints that are possibly compromised.

It has a feature called Isolation. If a device is compromised, we can connect it to our SOC, and no one would be able to access it. This way we can limit the damage to the network while we are investigating.

What needs improvement?

Malware detection can be better. It doesn't have support and detection for the recent malware, but it has a compensatory control where it can do the behavior-based assessment and alert you when there is something malicious or unexpected. For example, when a certain user is executing the privilege command, which is not normal. These dynamic detections are good, and they compensate for malware detection.

It has very good integrations. However, its integration with Palo Alto was not good, and they seem to be working on it at the backend. It is not very resource-hungry, but it can be even better in terms of resource utilization. It could be improved in terms of efficiency, memory sizing, and disk consumption by agents.

They have something called Managed Detection and Response. They get intel from their customers, and that intel is shared with the rest of FireEye's customers. I want to subscribe to their intel, but that is not available to us.

For how long have I used the solution?

I have been using this solution for two years.

Buyer's Guide
Trellix Endpoint Security Platform
August 2026
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is stable. The FireEye team monitors it, and in case it goes down, we get an alert saying that the device is down. We either get their help or troubleshoot it ourselves to get it up and running.

What do I think about the scalability of the solution?

It is quite scalable. We have scaled it according to their sizing recommendations. They have devices for different bandwidths, models, and offices.

We have about 4,000 people who are using this product. In terms of our plans to increase its usage, we are currently studying two options. One of them will basically scale up to about 40,000 instances.

How are customer service and support?

Their technical support is good. For each region, they seem to have got local support that takes care of all problems. They have support teams in Singapore, India, and North America.

How was the initial setup?

Its initial setup was straightforward. I have done one installation that took about 90 minutes. Virtual installations are straightforward. Physical installations have got some networking interfaces, and one needs to go through the documentation to do it. If you have got the right configuration, it is straightforward.

What about the implementation team?

We have about five people within SOC. We manage the engineering and deployment aspects of it. It is not very resource-hungry.

For its deployment, we just needed about four people. We deployed about 14 appliances and one cloud-based instance. We have automated the deployment. We deployed it via Puppet, so the installation was fast.

Which other solutions did I evaluate?

We also use CrowdStrike Falcon, which is also endpoint security. At that time, we chose the best option based on our study. Both Falcon and FireEye were doing good in the market, so we basically went ahead with what was the best at that time. We buy the licenses for both of these and then do the deployment.

We also use Sophos, but it is signature-based. We have licenses for the normal management control software of Sophos and the agents. We have not used Sophos Intercept X. My understanding is that it is an EDR, and we look forward to doing a study on it.

What other advice do I have?

Based on my two years of experience with this solution, I would comfortably recommend this solution.

I would rate FireEye Endpoint Security an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Security Specialist at Commercial Bank of Ethiopia
Real User
Apr 11, 2021
Stable with good technical support and very good threat prevention capabilities
Pros and Cons
  • "The product is quite user-friendly."
  • "The solution is pretty good for threat prevention, web protection, adaptive threat protection, and other tasks."
  • "Users can just install software into their computers. We need some sort of application control system that, if there are any pieces of software that are not whitelisted, then the solution could flag it or maybe alert the administers. That would be very helpful."
  • "We have disabled it due to the fact that a lot of stuff was being blocked, it was blocking a lot of internal stuff, which meant it needed some fine-tuning."

What is our primary use case?

We basically use the solution for threat detection. It's for security purposes.

What is most valuable?

The solution is pretty good for threat prevention, web protection, adaptive threat protection, and other tasks.

The solution is very stable.

We have had a good experience dealing with technical support.

The product is quite user-friendly.

What needs improvement?

Currently, we have the threat prevention as well as the web protection, and the McAfee firewall, which we were using before, however, we have not installed it on any of our machines. We have disabled it due to the fact that a lot of stuff was being blocked, it was blocking a lot of internal stuff, which meant it needed some fine-tuning. We were supposed to fine-tune it so that we can recognize our items, however, we're still working on that.

We wanted an EDR solution, and our first option was McAfee as the EDR would go hand in hand with the Endpoint integration. We'd like McAfee to offer stronger security. It's not that it isn't strong right now, however, it needs to continue to improve as attacks are always evolving. We are concerned some attacks may be able to find a way to bypass McAfee. If the solution offered something that could detect better, it would be ideal. It would add more value to what is already in place.

I know that they have application control and all the like. The one feature that maybe is lacking is a different module for the antivirus, however, we have a lot of applications that are running in our environment that were not authorized. 

Users can just install software into their computers. We need some sort of application control system that, if there are any pieces of software that are not whitelisted, then the solution could flag it or maybe alert the administers. That would be very helpful.

For how long have I used the solution?

I joined the organization a little while back in 2016 and when I got here they were already using McAfee product. Therefore, I've been using the solution for a few years now.

What do I think about the stability of the solution?

We've found the solution to be quite stable. It doesn't crash or freeze. There are no bugs or glitches. It's quite reliable.

What do I think about the scalability of the solution?

We haven't tried scaling it to as normally the license that we buy, we buy for 650 Rand and at this point, we haven't even tried adding more to try and scale it to that.

How are customer service and technical support?

The tech support has been superb. You log a call. Sometimes we are in a different time zone when we log a service request. However, they are very responsive. I was on the line with them a few hours ago and they were helping me with an issue I was having. We are currently in the process of consolidating our SQL servers. We want them to be running from a centralized server instead of having different SQL servers scattered all over the place. Technical support is really great at helping us with the process.

How was the initial setup?

While I wasn't at the company for the original implementation, looking at it, it's not that complex of a process. When I got here, we were using the lower version and then we've just upgraded it and used a higher version level. The process wasn't difficult. We upgraded to 10.5, 10.6, now we are on 10.7.

What's my experience with pricing, setup cost, and licensing?

We pay 650 Rand for a license. It is a perpetual license which we normally run for two years. It will be expiring sometime in July and our renewal is normally for two years.

When we are looking at the pricing, nobody will ever say the pricing is bad. Normally what we do is we'll take quotes from different local partners, as McAfee doesn't allow us to buy direct from them. Therefore, we typically deal with resellers.

What other advice do I have?

We are customers and end-users. We don't have a business relationship with McAfee.

We are a central bank and one of the things that we haven't really experienced or gone into is putting our solutions into the cloud - even though everything is moving in that direction. We are moving slowly in that direction as well. We'll get there one day.

I have found this solution easy to use. When you need support, you get it. Even in terms of protection, it's fine. I would recommend it to other users.

I'd rate the solution at an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Trellix Endpoint Security Platform
August 2026
Learn what your peers think about Trellix Endpoint Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
reviewer1383249 - PeerSpot reviewer
IT Infrastructure Manager at a financial services firm with 51-200 employees
Real User
Feb 19, 2021
Protect your business against a wide variety of threats
Pros and Cons
  • "It's quite easy to install agents."
  • "From the McAfee side, I really like the ePolicy Orchestrator software that allows us to manage all of our endpoints."
  • "With McAfee, if there is a zero-day vulnerability, you have to download the patch for it from the McAfee website, then apply it to your endpoint."
  • "The main reason that we moved from McAfee to Cylance is that McAfee is still a signature-based product."

What is our primary use case?

We currently have around 50 servers. We aren't really a big company but we have 50 servers which we manage. We use McAfee for the web filtering portion of it. For example, if a user is doing a search on Google, there's a risk-rating web content filter built into McAfee. This alerts us if there are any threats present. 

We have licensed McAfee ENS on a per-server basis. As of now, from memory, I think we have 56 endpoints running McAfee — 56 servers in total.

What is most valuable?

From the McAfee side, I really like the ePolicy Orchestrator software that allows us to manage all of our endpoints. You can create the deployment policies and whenever there is a new update — a new version of the ENS Agent, or threat protection — we could test it out in the evaluation branch, and even test it on some of our servers.

It's quite easy to manage. Quite intuitive. I would say the dashboard of ePolicy Orchestrator software is quite intuitive and quite easy to understand and manage. 

For how long have I used the solution?

I have been using this solution for 15 to 20 years.

What do I think about the stability of the solution?

We have had some issues from the performance side of things, especially when we were deploying new types of software. Sometimes the consumption of resources from McAfee was a bit high. Afterward, these problems were resolved gradually in future versions of McAfee. From what I've read from the release notes, in regard to the handling of memory, McAfee has been doing a better job, which wasn't really the case in the early years. 

What do I think about the scalability of the solution?

It's easily scalable. If I need to deploy the Agent over 800 endpoints, I just have to script it and run a group policy to deploy it to all of our computers on the network — it's quite easy. 

How are customer service and technical support?

For day-to-day management and ongoing queries, if ever I didn't have the solution to queries, I would just raise the case to the case management section of the McAfee website. Then the McAfee support team would help me out.

I was definitely satisfied with the support team. I really can't complain. They always sent me the correct knowledge-based article and they provided really insightful information to help me find a resolution to the issue. 

Which solution did I use previously and why did I switch?

At the previous company that I worked for, we used Symantec Endpoint Protection. Now, we are working with CylancePROTECT and OPTICS.

The main reason that we moved from McAfee to Cylance is that McAfee is still a signature-based product. We moved to Cylance, a signatureless-based product, where everything is updated. What I was doing, from an ENS product point stance, I had set reminders to myself and my team to update the Agent and look into the software repository to see if there were any updates every month.

Indeed, every month we had software updates and fixing restrictions. It wasn't good but I now have less of a hard time looking into this from a Cylance perspective as the Cylance library doesn't push one-minute software updates per year. I would say at most, two or three software updates a year, which is very, very small from a software update perspective in comparison to McAfee.

They're both good products. I'm not saying McAfee is a bad product. It's a very, very good product. It's mainly for these reasons that we moved to Cylance.

The ePolicy Orchestrator console is good, but from my side, I would say Cylance has a better artificial intelligence module — the OPTICS module which I would say is the way to go. I haven't really seen the trend in terms of what other companies other than McAfee or Symantec are doing, but Cylance is doing a really good job with this artificial intelligence module. It's great when it comes to notifying the team when it detects something malicious.

With McAfee, if there is a zero-day vulnerability, you have to download the patch for it from the McAfee website, then apply it to your endpoint. With Cylance, it's not like that. Each agent does it by itself — it's like a self-healing application. This is something that signature-based antivirus solutions like McAfee and Symantec didn't have until now, unfortunately. That's why we moved towards Cylance.

How was the initial setup?

It's quite easy to install agents. Deployment and product updates are quite easy, as well. It goes without saying that it comes with some, I would say, low-level training and upscaling but these are easily retrievable from the knowledge base of McAfee.

We manually downloaded their AMCore versions to keep all our endpoints up to date. This way, whenever we troubleshoot the root cause of an issue, we still keep our endpoints as updated as possible and keep our environment safe.

When we installed the Agent — let's say I am building a new VM and new server. When you run the frame package, it's really intense. I would say it takes roughly two minutes to install, then afterward, to install the ENS modules, like the threat protection and web filtering packages, you've got to go through the ePolicy Orchestrator management console. I would say, all in all, it takes roughly 10 minutes.

To get it up to date, to download everything, all the packages, the software updates, and all of the AMCore DAT files as well as the virus definitions, it's quite easy. It doesn't take much time at all.  

What about the implementation team?

For deployment, I worked with one external consultant.

Initially, when I came to the company, I didn't really have a background or any experience managing McAfee. I came from more of a Symantec background but I gained some knowledge from one of our external consultants who really had a deep understanding of McAfee products and their deployment. We had some training sessions and then I could manage the McAfee forum on my own. After a week's worth of training, I could manage McAfee on my own.

What's my experience with pricing, setup cost, and licensing?

We had McAfee on a year renewal. We purchased it initially and then we renewed it on a yearly basis. I think the only reason we are renewing the license is for support reasons. 

What other advice do I have?

I would definitely recommend this solution to others. McAfee is a good product. I worked with Symantec, but personally, I think McAfee is better.

However, in my opinion, now having worked with CylancePROTECT and OPTICS, I think  CylancePROTECT and OPTICS are on another level. Still, we have been working with McAfee for nearly 10 years and I feel it's a very good product. 

Overall, on a scale from one to ten, I would give McAfee a rating of eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1442769 - PeerSpot reviewer
System Engineer at a comms service provider with 10,001+ employees
Real User
Nov 5, 2020
Good reporting, and we are happy with technical support and the price
Pros and Cons
  • "The most valuable features are reporting from the ePO console and the advanced threat protection (ATP)."
  • "The support that we get from McAfee is excellent."
  • "We know that McAfee isn't the best antivirus and it can't protect us 100%, although we are okay with the level of protection that it gives us."

What is our primary use case?

We use this product for our endpoint security.

What is most valuable?

The most valuable features are:  

- reporting facility using the ePO console for conformity and threat identification  

- using the advanced threat protection (ATP) 

- MNE module for customising and securing Windows Bitlocker.

What needs improvement?

We know that McAfee isn't the best antivirus and it can't protect us 100%, although we are okay with the level of protection that it gives us. I don't think that the problem lies in the antivirus, but rather, it's the user. Users are not happy with the antivirus and they try to solve the issue on their own, and that causes very big problems.

The is an incompatibility problem between Mcafee and Linux subsystem for Windows, another that has to do with Outlook and scripts. McAfee knows that, but the problem can't be solved at this time so we try to minimize the effect.

For how long have I used the solution?

We have been using McAfee Endpoint Security for ten years.

What do I think about the stability of the solution?

In terms of stability, we haven't had many problems.

What do I think about the scalability of the solution?

We use that solution for more that 10k station and servers, and we have space to grow...

How are customer service and technical support?

The support that we get from McAfee is excellent.

Which solution did I use previously and why did I switch?

We tried Bitdefender, F-Secure, and many other products before settling on McAfee. When our central agency switched to McAfee, we all adopted it.

What's my experience with pricing, setup cost, and licensing?

The price of this product is good.

Which other solutions did I evaluate?

One of our subsidiaries has tried to switch products, although I don't know the reason why. Ultimately, the project was aborted.

What other advice do I have?

My advice for anybody who is looking at McAfee Endpoint Security is simply to use it.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Long-Tran - PeerSpot reviewer
Cloud Expert at GalaxyOne
Real User
Aug 10, 2024
Has valuable AI capabilities and good technical support services
Pros and Cons
  • "The platform's most valuable features are AI capabilities and its quick updates."
  • "They could provide better integration capabilities for the product with other services."

What is our primary use case?

We use the platform for managing and securing endpoints in our organization.

How has it helped my organization?

The solution's technical support services have a quick response time. It has been beneficial for our organization. 

What is most valuable?

The platform's most valuable features are AI capabilities and its quick updates. 

What needs improvement?

They could provide better integration capabilities for the product with other services.

For how long have I used the solution?

We have been using Trellix Endpoint Security (ENS) for two to three years. We are using the latest version and regularly update it.

What do I think about the stability of the solution?

I rate the product's stability a seven out of ten. 

What do I think about the scalability of the solution?

Our corporation has approximately 13,000 Trellix Endpoint Security (ENS) users. It is a scalable product.

What was our ROI?

The solution helps manage users easier and reduces the workload for the IT team.

What's my experience with pricing, setup cost, and licensing?

The product pricing is high. 

Which other solutions did I evaluate?

We are evaluating Trellix Endpoint Security (ENS) features compared to others. 

What other advice do I have?

I advise others to consider the specific requirements of users, such as personal devices that may not be supported before making a purchase decision.

I rate it an eight out of ten. 

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Talent Acquisition Specialist at Nine A Business Connect
Real User
Sep 24, 2023
Easy to deploy, use and stable solution
Pros and Cons
  • "It's good that it periodically scans all my drives. I can stay up to date with the status of my drivers and update them if needed."
  • "One suggestion is they should reduce the constant notifications. Whenever I open my laptop, there are too many notifications from McAfee, and it gets annoying."

What is our primary use case?

McAfee is used to secure my laptop against online threats and malware. It detects and removes any potential issues from the laptop.

What is most valuable?

It's good that it periodically scans all my drives. I can stay up to date with the status of my drivers and update them if needed.

What needs improvement?

One suggestion is they should reduce the constant notifications. Whenever I open my laptop, there are too many notifications from McAfee, and it gets annoying.

I would like to see less notifications.

For how long have I used the solution?

I have been using this solution for about four to five months because I've just purchased my new laptop. It came with the latest version when I got the laptop.

What do I think about the stability of the solution?

The stability is good. I receive updates regularly, which is quite good.

How was the initial setup?

It's quite straightforward. You have the dashboard to access all the data protection features, so it's easy to use.

The deployment hardly takes two to three minutes.

What about the implementation team?

For the McAfee process, I didn't need to contact anybody. I just needed to switch on my laptop, and it started on its own.

What's my experience with pricing, setup cost, and licensing?

You need to subscribe to McAfee. There's a subscription on a yearly basis. It's not that expensive; it's quite affordable.

What other advice do I have?

I would suggest giving it a try. Overall, I would rate the solution a nine out of ten. Due to the notifications, I would deduct one point. But overall, it's a nine. It's good.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Maytee Malabanan - PeerSpot reviewer
Solutions Consultant at Ask4key Sdn Bhd
Consultant
Sep 3, 2023
Efficient background scanning but performance could be improved
Pros and Cons
  • "The setup is not that complex. It takes five to ten minutes to set up."
  • "The performance could be better. I noticed that it slows down a bit."

What is our primary use case?

We just run it in the background and potentially scan any wireless or malicious file. It must be the same setup.

What needs improvement?

Maybe the performance could be better. I noticed that it slows down a bit when I start it up in the morning.

For how long have I used the solution?

We have had this solution for over three years now. It's enterprise security. We use the latest version. 

What do I think about the stability of the solution?

It's stable. It's just that I don't have to use it very often. I can go weeks without having to deal with any issues. If something does pop up, it's usually pretty easy to fix. I just let the people who know what they're doing handle it.

What do I think about the scalability of the solution?

It's scalable enough for our needs. I don't see any problems right now. There are about 55 users in two branches of our company.

How are customer service and support?

We haven't needed to use tech support. We are an IT company, so we usually take care of our own devices.

How was the initial setup?

The setup is not that complex. It takes five to ten minutes to set up. It's mostly this is our old devices.

What about the implementation team?

It's a self-deployable solution, so we don't need any technical staff for deployment.

What's my experience with pricing, setup cost, and licensing?

We do need to pay for a license.

What other advice do I have?

Overall, I would rate the solution a six out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Abu Imran - PeerSpot reviewer
Information Security Engineer at Nhq Distribution Ltd
Real User
Aug 31, 2023
A good endpoint security software in the market that needs to offer more customization capabilities
Pros and Cons
  • "The most valuable feature of the solution is its dashboard."
  • "The customization capabilities of the solution are an area where it lacks, so it would be great if our company could customize the solution to meet the demands of our customers."

What is our primary use case?

Trellix Endpoint Security (ENS) is useful as an endpoint security software.

What is most valuable?

The most valuable feature of the solution is its dashboard.

What needs improvement?

The dashboard provided by the solution needs to be improved. The customization capabilities of the solution are an area where it lacks, so it would be great if our company could customize the solution to meet the demands of our customers.

In the future, I would like technical support for the solution and its UI to be more efficient.

For how long have I used the solution?

I have been using Trellix Endpoint Security (ENS) for two years. I usually deal with a product's latest version. My company has a partnership with Trellix.

What do I think about the stability of the solution?

Stability-wise, I rate the solution an eight out of ten. The solution is mostly stable, but sometimes, there is a need to do some troubleshooting.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a seven out of ten.

How are customer service and support?

I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Currently, I work with CrowdStrike since my company has a partnership with it. CrowdStrike is better than Trellix Endpoint Security (ENS). CrowdStrike offers functionalities like machine learning and DLP.

How was the initial setup?

I have used the solution on the cloud and on-premises. Currently, the solution is deployed on the cloud services offered by Trellix, which I feel is a public cloud.

What's my experience with pricing, setup cost, and licensing?

I don't think there are any extra expenses besides its licensing costs.

What other advice do I have?

Maintenance of the solution is required, including some troubleshooting parts managed by five to six engineers in our company.

I recommend the solution to those planning to use it.

Not all solutions in the market are good, though I found Trellix Endpoint Security (ENS) to be a good product.

I rate the overall solution a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Solution Architect at PentechSolution Sdn Bhd
Reseller
Aug 25, 2023
Easy-to-manage platform with good stability
Pros and Cons
  • "The technical support services are good."
  • "The product’s on-premise version is costly in terms of extra charges for SQL database and Windows server licenses."

What is most valuable?

Trellix Endpoint Security (ENS) is an easy-to-manage platform.

What needs improvement?

The product’s on-premise version is costly in terms of extra charges for SQL database and Windows server licenses. It would be easier to deploy if included in the package as a virtual appliance.

For how long have I used the solution?

We have been using Trellix Endpoint Security (ENS) for two and a half years.

What do I think about the stability of the solution?

It is a stable platform.

How are customer service and support?

The technical support services are good. However, its response time could be better.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is straightforward. The deployment time depends on the number of devices. It ranges from a few days to a couple of weeks. It is suitable for small as well as enterprise businesses.

What's my experience with pricing, setup cost, and licensing?

Trellix Endpoint Security (ENS) has a reasonable price.

Which other solutions did I evaluate?

We evaluated vSphere and CrowdStrike. In comparison, Trellix is an inexpensive product. 

What other advice do I have?

Trellix Endpoint Security (ENS)’s cloud version is superior to the on-premise version. It should support other operating systems like Linux. I rate it a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Systems Engineer at First Datacorp
Real User
Aug 9, 2023
A solution with a flexible dashboard that can be used for setting up data storage via ELM
Pros and Cons
  • "Trellix Endpoint Security's dashboard is very flexible, and I can create my own user-specific dashboard depending on user privilege or preference."
  • "It would be a lot easier if I could add multiple user accounts within a single device."

What is our primary use case?

Some of the solution's primary use cases include successfully adding devices through ESM GUI and setting up data storage via ELM.

What is most valuable?

Trellix Endpoint Security's dashboard is very flexible, and I can create my own user-specific dashboard depending on user privilege or preference.

What needs improvement?

With Trellix Endpoint Security, adding a device as a data source can be done one by one. Whenever I try to add a device like a firewall or a server, the accounts are enrolled one by one per added data source. It would be a lot easier if I could add multiple user accounts within a single device.

For how long have I used the solution?

I have been testing Trellix Endpoint Security for around three months.

How are customer service and support?

I have tried to contact the solution's technical support team. Whenever I tried to ask for partner support, the Trellix website would ask for my company email details. Then an email would come to my inbox saying that Trellix would get back to me shortly, but unfortunately, they did not. So I couldn't contact Trellix Endpoint Security's technical support.

Which solution did I use previously and why did I switch?

I have worked with other security tools, such as CrowdStrike. The flexibility of the dashboard and filtering are useful features in Trellix Endpoint Security. Also, adding different elements to the SIEM infrastructure is not that complicated with Trellix Endpoint Security.

How was the initial setup?

There's no need for any additional configuration settings to install Trellix Endpoint Security. You just access the web UI, and that's it.

What about the implementation team?

It took me two months to implement Trellix Endpoint Security because of our company's hardware limitations.

My implementation strategy for Trellix Endpoint Security was to build a demonstration based on what the company would like me to do. So I built a SIEM infrastructure and got the images of the different tools first. Then from there, I tried to connect the different devices before I connected the data sources.

What other advice do I have?

My advice is that users should have a fair background in MQL, which really helps a lot in investigating.

Overall, I rate Trellix Endpoint Security an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Trellix Endpoint Security Platform Report and get advice and tips from experienced pros sharing their opinions.