While Trellix XDR is a strong platform overall, there are a few areas where it could be improved. The initial setup and configuration can be complex, especially for organizations with diverse environments. Some additional advanced features also have a learning curve and may require extra training for security teams to fully utilize them. Moreover, reporting and dashboard customization could be more flexible, allowing users to create highly customized views and reports more easily. There are also areas that could optimize detection surveys. Addressing these areas would further enhance the overall experience and operational effectiveness. One additional improvement would be deeper integration with a wider range of third-party security tools and cloud platforms. While Trellix XDR integrates with many solutions, simplifying the integration management would help organizations with complex security ecosystems. I would like to see more out-of-the-box reports and executive-level dashboards that make it easier to communicate security metrics to leadership. Finally, continuous enhancement to automation and AI-driven threat prioritization would further reduce analysts' workflow and improve response effectiveness. Overall, these are areas that need refinement rather than being major concerns, as the platform still delivers strong security and operational value.
System Administrator at a consultancy with 11-50 employees
Real User
Top 20
Jun 6, 2026
I would say Trellix XDR can be improved if they develop, for example, DLP and ePO policy orchestration on a Linux system. For example, ePO also uses Microsoft SQL Server, which has a free version, but when your organization grows, you need a bigger database to maintain all this data. So I would suggest that Trellix should develop, for example, installations on Windows and free databases such as Postgres, maybe some MariaDB, or any other databases. I chose eight out of ten because they have some downsides. As I mentioned, regarding how Trellix can improve, this step that I told you about developing the ePolicy Orchestration on Linux and another database not based on Microsoft SQL Server is important. Another reason is that their support sometimes is poor. For example, I had experience when my ticket was opened for a few months, and I pinged them every week, and they haven't responded to me. It's sometimes inconsistent; sometimes they're fast, but sometimes they have not-so-good support.
I believe Trellix XDR could improve better visualization of attack paths and threat relationships. Having used Microsoft Defender for Endpoint and Microsoft XDR, I found better mapping in visualization there. Thus, I think this area could be improved in Trellix XDR to help detect threats more actively.
The main area regarding Trellix XDR improvement is that setup and tuning can be complex because it requires a skilled analyst based on utilization. Another concern is cost. If an organization has multiple security products, the cost will be higher. Integration with third-party tools is easy, but when a new or fresh analyst works on Trellix XDR, it might be more complex and they require support from a senior analyst. In some cases, when compared to CrowdStrike or Microsoft Defender, it is less preferred.
Solutions Architect at Mideast Communication Systems-MCS
Reseller
Top 5
Apr 27, 2026
Trellix XDR should get involved in AI security itself. They use AI, but they do not secure AI. They need to move in the direction that Trend Micro, F5, and Palo Alto have taken. Trellix XDR is not involved in this field, and their licensing prices are fairly expensive as well. It is not the biggest difference, and they are a good player, but they should get involved in this field. The trend these days is moving toward AI security, and Trellix XDR should align with this direction.
The CPU utilization is very high with Trellix XDR. We are getting multiple types of CPU utilization from the EPP solution, with the EPP agent reaching as high as 80 percent CPU utilization. This creates big challenges for us. The support experience is also concerning. When we require support from Trellix immediately with high priority, we receive multiple emails requesting logs of various types. After that, we have to escalate to Trellix higher management, and then their agent will come in for a remote session to resolve any issues. I would give them eight out of ten points because of the high CPU utilization and the delayed support we experience.
The EdgeGear solution is an area that requires attention, specifically regarding AI solutions and intelligence features. We are still investigating how XDR performs and will identify areas for improvement as we deploy it further.
The platform should enhance compatibility with all other SIEM solutions. Customers should not feel constrained to using only Trellix products due to integration challenges, as this limits their options. Future updates should prioritize enhanced integration features with third-party SIEMs and broader threat intelligence capabilities to improve the platform's adaptability in diverse environments.
Trellix XDR provides a comprehensive approach to threat detection and response, enhancing security by integrating data from multiple sources into a single pane of glass for more effective incident management.Leveraging robust analytics, Trellix XDR enables organizations to improve threat visibility and response capabilities. The platform streamlines security operations by centralizing data from networks, endpoints, and cloud resources. This integration helps security teams quickly identify,...
I believe Trellix XDR can be improved with more automation. I would like more improvements in terms of response.
While Trellix XDR is a strong platform overall, there are a few areas where it could be improved. The initial setup and configuration can be complex, especially for organizations with diverse environments. Some additional advanced features also have a learning curve and may require extra training for security teams to fully utilize them. Moreover, reporting and dashboard customization could be more flexible, allowing users to create highly customized views and reports more easily. There are also areas that could optimize detection surveys. Addressing these areas would further enhance the overall experience and operational effectiveness. One additional improvement would be deeper integration with a wider range of third-party security tools and cloud platforms. While Trellix XDR integrates with many solutions, simplifying the integration management would help organizations with complex security ecosystems. I would like to see more out-of-the-box reports and executive-level dashboards that make it easier to communicate security metrics to leadership. Finally, continuous enhancement to automation and AI-driven threat prioritization would further reduce analysts' workflow and improve response effectiveness. Overall, these are areas that need refinement rather than being major concerns, as the platform still delivers strong security and operational value.
I would say Trellix XDR can be improved if they develop, for example, DLP and ePO policy orchestration on a Linux system. For example, ePO also uses Microsoft SQL Server, which has a free version, but when your organization grows, you need a bigger database to maintain all this data. So I would suggest that Trellix should develop, for example, installations on Windows and free databases such as Postgres, maybe some MariaDB, or any other databases. I chose eight out of ten because they have some downsides. As I mentioned, regarding how Trellix can improve, this step that I told you about developing the ePolicy Orchestration on Linux and another database not based on Microsoft SQL Server is important. Another reason is that their support sometimes is poor. For example, I had experience when my ticket was opened for a few months, and I pinged them every week, and they haven't responded to me. It's sometimes inconsistent; sometimes they're fast, but sometimes they have not-so-good support.
I believe Trellix XDR could improve better visualization of attack paths and threat relationships. Having used Microsoft Defender for Endpoint and Microsoft XDR, I found better mapping in visualization there. Thus, I think this area could be improved in Trellix XDR to help detect threats more actively.
The main area regarding Trellix XDR improvement is that setup and tuning can be complex because it requires a skilled analyst based on utilization. Another concern is cost. If an organization has multiple security products, the cost will be higher. Integration with third-party tools is easy, but when a new or fresh analyst works on Trellix XDR, it might be more complex and they require support from a senior analyst. In some cases, when compared to CrowdStrike or Microsoft Defender, it is less preferred.
Trellix XDR should get involved in AI security itself. They use AI, but they do not secure AI. They need to move in the direction that Trend Micro, F5, and Palo Alto have taken. Trellix XDR is not involved in this field, and their licensing prices are fairly expensive as well. It is not the biggest difference, and they are a good player, but they should get involved in this field. The trend these days is moving toward AI security, and Trellix XDR should align with this direction.
The CPU utilization is very high with Trellix XDR. We are getting multiple types of CPU utilization from the EPP solution, with the EPP agent reaching as high as 80 percent CPU utilization. This creates big challenges for us. The support experience is also concerning. When we require support from Trellix immediately with high priority, we receive multiple emails requesting logs of various types. After that, we have to escalate to Trellix higher management, and then their agent will come in for a remote session to resolve any issues. I would give them eight out of ten points because of the high CPU utilization and the delayed support we experience.
The EdgeGear solution is an area that requires attention, specifically regarding AI solutions and intelligence features. We are still investigating how XDR performs and will identify areas for improvement as we deploy it further.
The platform should enhance compatibility with all other SIEM solutions. Customers should not feel constrained to using only Trellix products due to integration challenges, as this limits their options. Future updates should prioritize enhanced integration features with third-party SIEMs and broader threat intelligence capabilities to improve the platform's adaptability in diverse environments.