No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2843139 - PeerSpot reviewer
Presales Manager
Real User
Top 20
May 20, 2026
Advanced detection has provided full network visibility and supports proactive threat response
Pros and Cons
  • "The best features that Trellix Network Detection and Response offers are visibility, threat detection, and immediate response, which allows us to take action almost instantly while keeping proof through proper data capture and maintaining logs for future analysis to prevent attacks and ensure that we have the right policies and controls."
  • "Trellix Network Detection and Response is stable but occasionally encounters performance issues, which we can fix quickly."

What is our primary use case?

My main use case for Trellix Network Detection and Response is to detect anomalies within the network to ensure that the NDR functionality is delivering what is expected, so primarily the NDR functionality.

A specific example of how I have used Trellix Network Detection and Response in a project is that it provides visibility for clients, allowing them to see all the traffic within their network infrastructure, detect any security triggers that need to be investigated, and take action to protect the network, ensuring there is no unusual or unwanted behavior or traffic.

What is most valuable?

The main aspect of Trellix Network Detection and Response regarding visibility is that visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response. Based on what we can see or the events we can observe and how the traffic flows, we can take the next action, investigate incidents, have a proper workflow, and assign the right person or agent to take action and prevent threats before jeopardizing the network or data. Visibility is the top feature that needs to be addressed when it comes to detection and response.

The best features that Trellix Network Detection and Response offers are visibility, threat detection, and immediate response, which allows us to take action almost instantly while keeping proof through proper data capture and maintaining logs for future analysis to prevent attacks and ensure that we have the right policies and controls. Having historical data and integrating with other security stack tools also helps; therefore, proper integration with other security tools is also essential.

Trellix Network Detection and Response positively impacts my organization by enhancing our security posture and helping us cover several controls for compliance, as we need to fulfill various security frameworks to maintain our business operations. The presence of Trellix Network Detection and Response assists us in meeting compliance expectations, which is crucial.

Regarding specific outcomes after using Trellix Network Detection and Response, compliance is vital; having Trellix Network Detection and Response implemented is mandatory for several security frameworks, including local and industry-specific ones, making it a crucial component of our cybersecurity strategy.

What needs improvement?

Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest; this is a significant point to address.

To improve Trellix Network Detection and Response, adapting more AI use cases is essential, such as creating automated incidents for anomalies in traffic that assign themselves to security agents. Automation is vital, and I envision the potential for ready out-of-the-box playbooks for known scenarios to be executed without complex configurations, enhancing automation of known incidents.

For how long have I used the solution?

I have been managing several projects that include Trellix Network Detection and Response for the last five years, with the most recent project being in the last quarter of 2025.

Buyer's Guide
Trellix Network Detection and Response
July 2026
Learn what your peers think about Trellix Network Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,834 professionals have used our research since 2012.

What do I think about the stability of the solution?

Trellix Network Detection and Response is stable but occasionally encounters performance issues, which we can fix quickly.

What do I think about the scalability of the solution?

I find Trellix Network Detection and Response to be quite scalable; it depends on the number of users, and we have accounted for that ahead of deployment, which leads me to believe scalability will not be an issue.

How are customer service and support?

Customer support for Trellix Network Detection and Response is excellent, with almost immediate responses to our inquiries.

Which solution did I use previously and why did I switch?

I have not previously used a different solution, as no system was deployed before.

How was the initial setup?

My experience with pricing, setup costs, and licensing has been satisfactory, although I believe the pricing could be better.

What about the implementation team?

My company does not have any business relationship with this vendor beyond being a customer.

What was our ROI?

While the return on investment from Trellix Network Detection and Response is not immediately tangible, I feel the benefits concerning an enhanced security posture create a sense of confidence in our security; however, I do not see immediate savings linked to the system.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing has been satisfactory, although I believe the pricing could be better.

Which other solutions did I evaluate?

Before choosing Trellix Network Detection and Response, I evaluated other options, specifically exploring Get Watcher.

What other advice do I have?

I would give Trellix Network Detection and Response a rating of ten out of ten.

I give it a ten because it delivers what it promises by providing network detection and response, maintaining logs, offering detailed analytics, and enhancing the system's learning capabilities over time, particularly with the introduction of AI in current and future releases, leading to an ideal NDR deployment expected by customers.

I advise others looking into using Trellix Network Detection and Response to proceed with implementation immediately, as it is one of the best and most trusted brands that deliver on its promises; Trellix Network Detection and Response has been in the market for a long time and is well-known for its customer support and technical capabilities, and those without an NDR should definitely aim for implementation as soon as possible. I would recommend this product with a rating of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 20, 2026
Flag as inappropriate
PeerSpot user
Dhanaji Mali - PeerSpot reviewer
Technical Specialist at VDA Infosolutions Pvt. Ltd.
Real User
Top 5Leaderboard
Jun 9, 2026
Continuous monitoring has strengthened our threat detection and improved response to network risks
Pros and Cons
  • "Trellix Network Detection and Response has positively impacted our organization by making our security team more confident and responsible, knowing that the network is being watched all the time, allowing us to respond to threats much faster than we used to."

    What is our primary use case?

    Our main use case for Trellix Network Detection and Response is to maintain oversight of our network traffic and catch any threats or unusual activity as early as possible.

    Trellix Network Detection and Response runs in the background monitoring all network traffic, and whenever something unusual comes up, it sends us an alert and we look into it straight away without any delay.

    What is most valuable?

    The best features Trellix Network Detection and Response offers are real-time threat detection, traffic analysis, and the way it breaks down alerts in a clear and simple way.

    The feature we rely on the most day-to-day is real-time threat detection because catching a threat early makes a huge difference, and this product does that very well.

    Trellix Network Detection and Response has positively impacted our organization by making our security team more confident and responsible, knowing that the network is being watched all the time, allowing us to respond to threats much faster than we used to.

    Our team now responds to network threats much quicker than before, and we have managed to stop a few suspicious activities early that could have caused bigger problems.

    What needs improvement?

    Based on my experience with the solution, I do not see any improvements needed for Trellix Network Detection and Response at present; it might be required in the future, but there is no space to improve it currently.

    If I had to imagine an area where Trellix Network Detection and Response could be enhanced in the future, I would say that more AI-based alerting could be improved so that more customized and advanced reporting could be generated.

    For how long have I used the solution?

    I have been using Trellix Network Detection and Response for three years.

    What do I think about the stability of the solution?

    Trellix Network Detection and Response is quite stable and performs well overall.

    What do I think about the scalability of the solution?

    Trellix Network Detection and Response's scalability has been really good; it has handled our growing network well, and as we have added more systems, it has kept up without any issue.

    How are customer service and support?

    Customer support for Trellix Network Detection and Response is very excellent, as they provide thorough troubleshooting steps to overcome any technical issues.

    Which solution did I use previously and why did I switch?

    We are using this type of solution for the first time, so we have not switched from other solutions.

    How was the initial setup?

    My advice for others looking into using Trellix Network Detection and Response is to take some time to set it up properly, fine-tune the alerts to suit your environment, and once that is done, it runs very smoothly and gives your security team a much stronger grip on what is happening across the network.

    Which other solutions did I evaluate?

    We did not evaluate other options before selecting Trellix Network Detection and Response; we chose it based on its advanced threat detection capabilities and integration with our existing security ecosystem.

    What other advice do I have?

    Regarding Trellix Network Detection and Response's AI capabilities, I think the governance side is well thought out, keeping everything in check and ensuring that detection is handled in a controlled and secure manner.

    As for Trellix Network Detection and Response's accuracy and reliability of output, it has been quite accurate in the detection of real threats, and we have not seen any false alarms, so the alerts have been mostly relevant and actionable.

    I would rate this product overall as a 9.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: Jun 9, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Trellix Network Detection and Response
    July 2026
    Learn what your peers think about Trellix Network Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
    908,834 professionals have used our research since 2012.
    Hitesh Singh Thakur - PeerSpot reviewer
    Mentor Operations at eClinicalWorks
    Real User
    Top 5
    Jun 8, 2026
    Advanced threat visibility has transformed how we detect unusual behavior and respond faster
    Pros and Cons
    • "Overall, security operations are approximately 30 to 40 percent more efficient, and we can save time because everything automatically analyzes, resulting in approximately 40 to 50 percent time savings."
    • "Trellix Network Detection and Response is a powerful tool with areas that need improvement, such as dashboard customization options and reporting flexibility."

    What is our primary use case?

    Trellix Network Detection and Response is used for monitoring network traffic, detecting advanced threats, identifying suspicious behavior, and improving incident response capability across the organization.

    What is most valuable?

    Trellix Network Detection and Response offers network visibility and behavior analysis combined with real-time threat detection as its most valuable capabilities. Traditional security tools are very effective at detecting known threats, but Trellix Network Detection and Response stands out because it can identify unusual network behavior and potential threats that do not match known signatures. In our environment, this has helped us detect suspicious activity much earlier and prioritize investigation more effectively.

    Other features such as network visibility and threat detection are also beneficial.

    Trellix Network Detection and Response has positively impacted our organization by improving threat visibility, accelerating investigation, and strengthening our ability to detect advanced threats across the network.

    What needs improvement?

    Trellix Network Detection and Response is a powerful tool with areas that need improvement, such as dashboard customization options and reporting flexibility. Additionally, I find that third-party integrations are somewhat complex and need to be more user-friendly. Everything else is reliable and meets our security requirements well.

    For how long have I used the solution?

    I have been using Trellix Network Detection and Response for more than two years.

    What do I think about the stability of the solution?

    Trellix Network Detection and Response is stable in our environment, with no downtime issues.

    What do I think about the scalability of the solution?

    Trellix Network Detection and Response has excellent scalability, as the platform has scaled well as our environment has grown and continues to provide consistent visibility and performance.

    How are customer service and support?

    Customer support for Trellix Network Detection and Response is knowledgeable, responsive, and helpful during troubleshooting and recommendations.

    Which solution did I use previously and why did I switch?

    Before Trellix Network Detection and Response, we were using traditional network monitoring security tools.

    What was our ROI?

    I have seen a return on investment with Trellix Network Detection and Response through improvements in operational efficiency, faster threat investigation, and reduced manual monitoring effort. Overall, security operations are approximately 30 to 40 percent more efficient, and we can save time because everything automatically analyzes, resulting in approximately 40 to 50 percent time savings.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is positive, as the setup process was straightforward, licensing was flexible, and the value delivered by the platform justified the investment.

    Which other solutions did I evaluate?

    Before choosing Trellix Network Detection and Response, I evaluated other options as alternatives.

    What other advice do I have?

    A specific example of how Trellix Network Detection and Response helped me detect and respond to a real threat was when it detected an unusual communication pattern from an internal device to an unknown external destination. Traditional security controls did not flag the activity, but Trellix Network Detection and Response behavior analysis identified it as suspicious, allowing me to investigate and mitigate the risk quickly.

    Threat investigation and incident response activities are approximately 30 to 40 percent faster than before due to centralized visibility and automated analysis, which demonstrates how much investigation time has improved.

    I advise others looking into Trellix Network Detection and Response to integrate it with existing security ecosystems and establish clear incident response workflows, as organizations that improve their visibility capability will gain significant value from the platform. I would rate this product a 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jun 8, 2026
    Flag as inappropriate
    PeerSpot user
    Jose Vargas - PeerSpot reviewer
    Agente De Servicios Técnicos at a computer software company with 11-50 employees
    Real User
    Top 5
    Nov 6, 2025
    Has improved threat detection workflows and supports seamless customer monitoring
    Pros and Cons
    • "Trellix Network Detection and Response is a great tool that integrates with a lot of security tools such as Palo Alto, which is a good firewall, and if you have these types of tools, your organization would benefit greatly."
    • "I would like to see in Trellix Network Detection and Response more explanation about some details of the threat, and I wish it had more actions that you can take to contain the host or move it somewhere else."

    What is our primary use case?

    My main use case for Trellix Network Detection and Response is providing support for our customers, and one of our customers has Trellix, so we had to provide monitoring or specific XDR tools for that customer, including Trellix, Crowdstrike, and many others.

    A typical task or incident I have handled using Trellix Network Detection and Response demonstrates that it is a very good tool for XDR, very comfortable to use, and extremely easy to use, making it one of the best XDR tools.

    What is most valuable?

    The best features Trellix Network Detection and Response offers include very good threat detection, and I believe that it is one of the best XDR tools. For example, ePO and XDR components are very comfortable and similar to many other tools for this type of monitoring, and I have received very good feedback for this tool.

    What makes Trellix Network Detection and Response stand out for me compared to other tools is the way you can detect threats. It is very easy and comfortable to use, and the detection shows clearly on the screen, which is very easy to understand.

    Regarding the features, I think that the integration with other platforms is very comfortable with the customer because we can integrate it with any switch or firewall, and it is comfortable to add this tool.

    Trellix Network Detection and Response has positively impacted my organization as I have improved my knowledge about detection and response. I have already used some other tools such as CrowdStrike and Umbrella, but Trellix is one of the best that I have tested.

    I believe that for my organization, Trellix has helped a lot with detection and supported our customers effectively.

    Trellix Network Detection and Response is a great tool that integrates with a lot of security tools such as Palo Alto, which is a good firewall. If you have these types of tools, your organization would benefit greatly.

    What needs improvement?

    I would like to see in Trellix Network Detection and Response more explanation about some details of the threat, and I wish it had more actions that you can take to contain the host or move it somewhere else.

    For how long have I used the solution?

    I have been using Trellix Network Detection and Response for a couple of months, possibly around six months, and I believe that it is a good tool and a very good XDR tool.

    What do I think about the stability of the solution?

    Trellix Network Detection and Response is stable in my experience.

    What do I think about the scalability of the solution?

    The scalability of Trellix Network Detection and Response is very great.

    How are customer service and support?

    The customer support for Trellix Network Detection and Response is great.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I previously used another solution, but Trellix was my first XDR tool. Then, I used CrowdStrike and Umbrella.

    What was our ROI?

    I think my comments about the return on investment are the same that the customers think.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is very great.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Trellix Network Detection and Response.

    What other advice do I have?

    My advice for others looking into using Trellix Network Detection and Response is to remember the actions that can be added for the SOC team. I would rate this review as a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    BiswabhanuPanda - PeerSpot reviewer
    Senior technical consultant at Hitachi Systems Micro Clinic
    Real User
    Apr 28, 2024
    Offers in-depth investigation capabilities, integrates well and smoothly transitioned from a lower-capacity appliance to a higher one
    Pros and Cons
    • "We wanted to cross-reference that activity with the network traffic just to be sure there was no lateral movement. With Trellix, we easily confirmed that there was no lateral network involvement and that nothing else was infected. It helped us correlate the events and feel confident in our containment."
    • "The analytics could be better. It seems heavily influenced by the McAfee and FireEye integration, and that integration still isn't seamless."

    What is our primary use case?

    The solution has been in place for quite some time – three or four years. We've renewed it several times, and we upgraded from Gen 3 to Gen 4 hardware at one point as well.

    Currently, it's integrated with our firewall and McAfee IPS. We also have network-based sandboxing deployed. It uses static and dynamic analysis engines, so we get alerts if malicious traffic is detected or harmful objects are downloaded.

    We've been using their PX solution for packet capture, which is the core of their NDR functionality. But we haven't fully adopted the combined product – NX and PX  – yet because they are still separate. 

    The storage requirements for raw packet capture, especially with our traffic levels, make it quite expensive.  And that's true for many security products. I feel like NDR is pretty expensive. 

    However, this is especially true about raw packet capture for network telemetry – the storage requirements with RAID 0 become quite expensive, regardless of the solution.

    How has it helped my organization?

    We had a serious incident where an attacker attempted a web shell attack on one of our web servers [DevOps server]. We were able to identify that the hackers used a malicious script and tried to target specific files. The hacker also tried to make a copy of some files. 

    We wanted to cross-reference that activity with the network traffic just to be sure there was no lateral movement. With Trellix, we easily confirmed that there was no lateral network involvement and that nothing else was infected. It helped us correlate the events and feel confident in our containment.

    Trellix NDR was effective in that situation.

    Morevoer, we've integrated this solution with our SIEM. There's a degree of integration provided by Trellix with their solution, and we're satisfied with that. However, without the SIEM, that's the extent of our integrations at the moment.

    We're exploring further options due to organizational shifts towards the cloud, potentially moving away from a hybrid environment. We're assessing SaaS-based SIEM solutions. Trellix has its own offering, Helix, which we've evaluated and even purchased in the past. Ultimately, we discontinued its use. To summarize, our primary integration right now is with our SIEM.

    The SIEM integrates well with our threat intelligence sources. We also have some secondary integrations in place. Overall, things are running smoothly.

    What is most valuable?

    The in-depth investigation capabilities are a major advantage. When the system flags something as malicious, it provides a packet capture of that activity within the environment. 

    That helps my team quickly identify additional context that most other tools wouldn't offer – like source IP or base64 encoded data. We can also see DNS requests and other details that aren't readily available in solutions like Check Point or others that we've tried.

    The detection itself is solid, and their sandboxing is powerful. 

    There's a learning curve – you need a strong grasp of OS-level changes, process forking, registry changes, and the potential impact of those. But with that knowledge, the level of information Trellix provides is far greater than what we've seen elsewhere.

    The real-time response capability of Trellix has been quite effective, although it's not very fast.  The key is this solution's concept of 'preference zero.' They don't immediately act on a zero-day. For example, the solution has seen a piece of malware for the first time. It'll let it in, then do sandboxing. Maybe after four or five minutes, it identifies that specific file's DNX Secure Store as malicious. At that point, they update the static analysis engine, and it gets detected if anything else tries to download the same file.

    There is that initial 'preference zero' concept, like with Panda. You may not hold traffic in the network. That's standard in the industry; we don't do much about it. To address that, we also have endpoint solutions. We use SentinelOne in our environment, which helps us identify threats like Western Bureaus and others.

    What needs improvement?

    The analytics could be better. It seems heavily influenced by the McAfee and FireEye integration, and that integration still isn't seamless. 

    STG needs to... I'm not sure what their roadmap is; they've mentioned full integration, but it hasn't materialized yet. Both the McAfee and FireEye engineering teams need to accelerate the process, as it would definitely benefit customers. The integration between Nextiva and Trellix could also use some work.

    For how long have I used the solution?

    I have been using it for seven years. I have been involved since the FireEye days. That's when I started working with it.

    We're on version 9.1.5.

    What do I think about the stability of the solution?

    I would rate the stability an eight out of ten. It's quite stable.

    What do I think about the scalability of the solution?

    We've upgraded without any major hiccups – I'd rate scalability a nine out of ten. We've smoothly transitioned from a lower-capacity appliance to a higher one. The current appliance supports 2.5 Gbps of traffic, and we're currently handling around 300-500 Mbps without issue. Scalability is definitely there, we've never faced any problems in that regard.

    We have approximately 500+ users. However, we also have applications hosted here, along with multiple IPC tunnels. We're using Netskope's Zero Trust Web DNA as well. So, 500+ users, but typical traffic averages around 300 to 400 Mbps.

    How are customer service and support?

    The customer service and support are really good. Trellix offer multiple contact options – you can call and get immediate assistance from someone in Israel, Singapore, Japan, or even India. Plus, they offer chat support through Teams or Webex. 

    Trellix's documentation portal is also good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We've used Forcepoint, NetFlow, SentinelOne, Trellix, Arista…some Splunk, and some Elastic as well. It's a mix of tools across different security domains.

    These are all security-focused products. Security is my primary focus.

    How was the initial setup?

    The initial setup was really straightforward. It took maybe a day to complete the upgrade. 

    We spent some time getting the prerequisites ready, which took a bit longer, but the actual deployment was very fast.

    So you just identify the network where you want to connect it and just plug it in. It only took half a day. 

    Therefore, the preparation took some time, but the deployment itself was quick.

    Handling upgrades:

    We have a practice where network device upgrades take priority - starting with the App Firewall and working our way through Web Proxy and so on. We avoid parallel endpoint upgrades as we've had challenges with those.

    Trellix releases sandbox system updates yearly, which are fine. Those don't require downtime. However, operating system upgrades are a factor. 

    We review KBR details thoroughly. Three or four months ago, we went from 9.1.4 to 9.1.5, and we're evaluating a possible upgrade to version 10, perhaps next month.

    Generally, we follow the n-1 version strategy. But if there are significant new features in a release, we might upgrade sooner. Overall, it's manageable – we upgrade frequently, and this particular solution hasn't caused downtime issues. Plus, we use DNS-based global [settings/configuration?], so downtime isn't a major concern.

    What about the implementation team?

    For the deployment process, we needed two or three engineers. The physical appliance mounting and setup require multiple people. Trellix's appliances are very heavy.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is fair, a little expensive, but fair. We've evaluated other products, and they're similarly priced. It's a bit on the expensive side, but we don't want to compromise with cheap, less reliable solutions. 

    We want quality. It's like... you might not opt for the top-of-the-line Apple product, but Samsung is a good choice. We wouldn't go for an Oppo, VIVO or ASUS type of device.

    Overall, I would rate the pricing an eight out of ten, with one being expensive and ten being very cheap. 

    What other advice do I have?

    Overall, I would rate the solution a nine out of ten.

    Potential customers should definitely evaluate their specific use cases, budget, and commercial considerations. The product itself is good, there's no doubt. But it's essential to understand your use cases – then I'd definitely recommend it.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Abdullah Al Hadi - PeerSpot reviewer
    Information Security Engineer at Nhq Distribution Ltd
    Real User
    Top 5Leaderboard
    Feb 18, 2025
    Network defense becomes effective with automatic responses to incidents
    Pros and Cons
    • "Trellix NDR provides an essential defense by automatically responding to network incidents that firewalls may not catch."
    • "The Trellix solution could be improved by enhancing the Central Management Console for faster visibility, which would help in network detection response."
    • "Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents."

    What is our primary use case?

    The primary use case for Trellix Network Detection and Response is network intrusion detection, which is crucial for protecting environments. It helps secure networks and defend against phishing and other attacks created by the networking sector. We use the solution for detection and forensics investigation, reporting incidents such as the source and network path of attacks.

    What is most valuable?

    Trellix NDR provides an essential defense by automatically responding to network incidents that firewalls may not catch. When users break firewall rules, the solution identifies affected areas for immediate action, helping determine the actual reason for attacks. Its ability to report incidents like network paths makes it invaluable in securing the environment. With eight years of experience, I can attest that Trellix NDR is effective in detecting and protecting networks.

    What needs improvement?

    The Trellix solution could be improved by enhancing the Central Management Console for faster visibility, which would help in network detection response. Networking often involves complexity that could be simplified. More visibility in the dashboard would help in quickly identifying and responding to incidents. Additionally, there should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.

    For how long have I used the solution?

    I have been using Trellix NDR for approximately eight and a half years.

    How are customer service and support?

    Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents. There is a need for technical expertise, specifically in device control and DLP issues.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of Trellix NDR has some complexities, particularly when dealing with big organizations' network design and path.

    What's my experience with pricing, setup cost, and licensing?

    While I do not handle pricing directly, it is known that there is a variety of customers with different licensing needs, which depends on the organization's size and policy.

    What other advice do I have?

    Currently, I would rate Trellix NDR as an eight out of ten. There are various opportunities for improving its response capabilities and dashboard visibility to quickly address incidents, which could improve the overall effectiveness of the solution.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Information Security Senior Advisor at Eskom Ltd
    Real User
    Top 20
    Mar 11, 2024
    Blocks traffic and DDoS attacks
    Pros and Cons
    • "Over the thirteen years of using the product, we have not experienced a single compromise in our environment. During the COVID period, we faced numerous DDoS attacks, and the tool proved highly effective in mitigating these threats."
    • "Certain features in Trellix Network Detection and Response, such as using AL-type commands, may initially pose a challenge for those unfamiliar with such commands. However, once users become accustomed to the system, it becomes easier to use."

    What is our primary use case?

    We use the solution in our servers and workstations for Endpoint Detection and Response. 

    What is most valuable?

    Over the thirteen years of using the product, we have not experienced a single compromise in our environment. During the COVID period, we faced numerous DDoS attacks, and the tool proved highly effective in mitigating these threats. The IP devices played a crucial role in blocking and reducing the amount of malicious traffic entering our company. Its endpoint security, EDR, and insights are valuable. The automation functionality, particularly the ability to automatically handle and mitigate detected threats, has proven to be immensely beneficial for our security operations.

    What needs improvement?

    Certain features in Trellix Network Detection and Response, such as using AL-type commands, may initially pose a challenge for those unfamiliar with such commands. However, once users become accustomed to the system, it becomes easier to use.

    For how long have I used the solution?

    I have been using the product for 13 years. 

    What do I think about the stability of the solution?

    I rate the product’s stability a nine out of ten. 

    What do I think about the scalability of the solution?

    We are using Trellix Network Detection and Response on approximately 3,500 servers and 33,000 workstations. I rate its scalability a ten out of ten. 

    How are customer service and support?

    We handle the first-line support for Trellix Network Detection and Response on our own, performing troubleshooting and maintenance. For more advanced issues, we rely on Trellix Network Detection and Response's classic support as the third-line support.

    How was the initial setup?

    The tool's integration with our existing security infrastructure was not difficult. Following the provided processes made the integration relatively straightforward. Its deployment was not difficult for us. We received support from Trellix professional services, which made the process smoother. The process took two months to complete. 

    What other advice do I have?

    I rate the tool a nine out of ten. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    YaserAljohani - PeerSpot reviewer
    OT/ICS Information Security Specialist at SANS
    Real User
    Feb 16, 2024
    A user-friendly product that needs to improve its integration capabilities
    Pros and Cons
    • "The installation phase was easy."
    • "The product's integration capabilities are an area of concern where improvements are required."

    What is our primary use case?

    In my company, the solution is used for our endpoints.

    What needs improvement?

    The product's integration capabilities are an area of concern where improvements are required.

    For how long have I used the solution?

    I have been using Trellix Network Detection and Response for two to three years. I use the solution's latest version.

    What do I think about the stability of the solution?

    Stability-wise, I rate the solution an eight out of ten.

    What do I think about the scalability of the solution?

    Around 1,000 people in my company use the product.

    Which solution did I use previously and why did I switch?

    I have not worked with other solutions before Trellix Network Detection and Response.

    How was the initial setup?

    The installation phase was easy.

    The solution is deployed on an on-premises model.

    The solution can be deployed in a couple of days.

    There are around 15 engineers in my company to take care of the product's deployment and maintenance areas.

    What other advice do I have?

    Trellix Network Detection and Response has enhanced our organization's in-house capability in the area of threat detection.

    Trellix Network Detection and Response worked very well in a scenario where it was used to help my company respond to a network incident efficiently.

    The network detection and response capabilities of the product are the most valuable for our company's security operations.

    The operation of the dashboards is not problematic in the product.

    The network analytics feature of the product helps me in my daily tasks.

    The product is user-friendly.

    The product did improve my company's time to detect and respond to threats.

    My company takes care of the maintenance of the product.

    I rate the overall tool a seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Senior Manager at a financial services firm with 10,001+ employees
    Real User
    Dec 13, 2022
    Excellent support, easy to set up, and offers good NTAP features
    Pros and Cons
    • "Support is very helpful and responsive."
    • "We'd like the potential for better scaling."

    What is our primary use case?

    It is mostly an NTAP tool. It is just blocking the CNC domains. That is the primary use case.

    What is most valuable?

    The NTAP features are the most valuable aspects of the product. Other features, like ITS, are there, however, the primary value is in the NTAP protocols.

    It is an easy product to set up.

    The product has been quite stable. 

    Support is very helpful and responsive. 

    What needs improvement?

    It is not supporting multiple SSLs. If we've got four or five servers and all the traffic has to pass through Fire Eye, and the servers are using their own SSL certificate, FireEye is not supporting this. 

    We'd like the potential for better scaling. 

    Generally, this particular product has a lot of room for improvement.

    For how long have I used the solution?

    I've used the solution for a few years. 

    What do I think about the stability of the solution?

    It's stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. 

    What do I think about the scalability of the solution?

    This is a standalone solution. It doesn't scale per se. 

    How are customer service and support?

    The technical support is really very good. We are quite satisfied with the level of services we get. 

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution. 

    How was the initial setup?

    The product is plug-and-play so there is no complication regarding the setup of the solution. It's very simple and straightforward. I wouldn't describe the process as complex. 

    In terms of maintenance, only some support is required occasionally. You do not need a dedicated staff member constantly on the product to maintain everything. 

    What's my experience with pricing, setup cost, and licensing?

    I have never really gotten into the licensing aspect of the solution. I can't speak to the exact costs. 

    Which other solutions did I evaluate?

    We are currently evaluating Check Point SandBlast Network.

    What other advice do I have?

    I'm an end-user. 

    I'd rate the solution seven out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    AmgadYousry - PeerSpot reviewer
    Head of Infrastructure at a tech services company with 11-50 employees
    Real User
    Leaderboard
    Sep 12, 2022
    Great sandboxing, good reliability, and helpful support
    Pros and Cons
    • "The solution can scale."
    • "There are sandbox capabilities; you can submit malicious files and get great feedback, including if there is malware and what it is doing, and it can give you simulations in different operating systems and applications to provide real insights from the perspective of a real environment."
    • "It is an expensive solution."
    • "The product is pricey. We'd like it to cost less. Not all customers can afford it."

    What is most valuable?

    There are sandbox capabilities. You can submit malicious files and great feedback, including if there is malware, what it is doing, et cetera.

    The way it works is better than others thanks to the sandbox. It can give you simulations in different operating systems and applications and give your real insights from the perspective of a real environment.  You gain insights into evasion techniques. 

    It's not just running in the background on an endpoint. You can do tests and learn. You can do behavior analysis. That's the main feature. 

    The solution can scale. 

    What needs improvement?

    There isn't something missing - even with HX. HX was in the box and was working EDR and antivirus. They just need to keep the updates running and the features stable, and that's it. No new thing is required.

    The initial setup is not exactly easy. 

    It is an expensive solution.

    For how long have I used the solution?

    We've been using the solution for six to eight years, since 2014. 

    What do I think about the stability of the solution?

    The stability is okay. It's something they always need to improve and manage. Yet it's quite good overall, so long as it stays updated. I'd rate it nine out of ten. 

    What do I think about the scalability of the solution?

    The solution can scale well. It's not a problem.

    We have one client with around 5,000 users, however, the user base varies from customer to customer. 

    How are customer service and support?

    We've dealt with technical support. 

    They take some time to answer, however, they solve the issue.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I compared this product with something like MD, for example, Forcepoint.

    It's about how you are using the solution. If you don't have a Forcepoint Next Generation Firewall proxy you shouldn't go for MD. You should go for FireEye.If you need to use MD, you need to have the other solution as well. It's not working as a standalone. It feeds from other solutions.

    How was the initial setup?

    The initial setup is a bit complex. It's not simple. For example, in the box, the imaging is very complex.

    What about the implementation team?

    We implement the solution for our clients.

    What's my experience with pricing, setup cost, and licensing?

    The product is pricey. We'd like it to cost less. Not all customers can afford it.

    What other advice do I have?

    I am a deployment engineer. We are not using FireEye for ourselves. We are deploying it to our customers.

    We are usually using the latest version since the database will be updated, and the images of the box itself will be updated regularly. It's always better in this kind of solution to have the latest update.

    You can get it as a service provided by your cloud provider. With the on-premise, you will get the box, and each type of box has its deployment methodology or deployment technique. For example, if you are going to deploy the NX, you can make it online, and your networking can give it a motherboard from your switch.

    I'd rate the solution nine out of ten. It's just a bit complex to set up.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Buyer's Guide
    Download our free Trellix Network Detection and Response Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Trellix Network Detection and Response Report and get advice and tips from experienced pros sharing their opinions.