What is our primary use case?
We use Helix in a very restrictive environment that doesn't allow solutions to be connected to the cloud. Some solutions, like CrowdStrike and some XDR solutions, need to be connected to an external cloud. The same goes for Trellix, but with Helix, we have one option.
If we need DDI feeds or IOC feeds from vendors or customers, Helix will provide these IOCs via DDI push from Trellix to our side, even if we haven't faced any incidents.
How has it helped my organization?
It's very easy to integrate Helix into IT workflows in general, especially if you have the original system. If you have the full portfolio from Trellix or solutions that integrate easily, like XSOAR or some buckets of vendor flow or vendors like Kaspersky, then we won't be facing many problems.
I have worked on implementations with Huawei and IBM QRadar. Now, when it's a Helix operation. Sometimes, I remember that IBM told me to open a request for enhancement from both sides, Huawei and IBM, which, until now, hasn't happened. These tickets have been open for about three years. That caused the customer to replace Huawei with a Cisco engine to make the integration very easy.
I am aware that Helix is investing in the development to enhance its solutions. I already attended multiple webinars regarding cybersecurity solutions from Trellix's cybersecurity solutions.
However, I’m not sure if it can integrate with other vendors like IBM’s EDR or cloud-based solutions. But as far as its core functionality goes, it’s spot-on.
What is most valuable?
Enrichments. It's all about enrichments. Helix is a robust solution.
Helix, it's a good solution. Since management, I've been working with the team; I like the Helix ecosystem.
What needs improvement?
There is room for improvement in the integration capabilities of third-party tools.
It has no problem connecting all solutions to Helix. Right now, we only connect one of Trellix's appliances to the Helix solution, the EDR solution. That's it.
We faced many problems regarding integrating some with Helix or integrating the ITSM with Helix; the system refused that.
So, it depends on the customer's environment and regulations.
For how long have I used the solution?
I have been using it for one and a half years.
What do I think about the stability of the solution?
In terms of stability, I’d rate it a strong nine out of ten, where ten is the most stable. Very reliable overall.
What do I think about the scalability of the solution?
Since I haven’t worked with Helix extensively, I can’t give it a perfect ten, but I’d rate the scalability of this solution an eight out of ten.
For small businesses, they might not initially opt for Helix. Instead, they often choose solutions like Kaspersky antivirus or EDR SIP.
However, for medium and large enterprises, Helix is a solid choice. I’ve also heard that big customers tend to prefer CrowdStrike and Fidelis.
How are customer service and support?
The customer service and support are very fast. Trellix’s vendor support is excellent. They have responsive experts who can assist us without delay. We don’t need to go through lengthy processes; our local support team handles Helix cases efficiently. For critical issues, they usually respond within thirty minutes to an hour. Overall, their professionalism stands out.
Which solution did I use previously and why did I switch?
I worked with a customer that had a McAfee EDR from Kaspersky and another vendor's NDR. They faced many issues, and eventually, they paid much money for little value.
The main competitors are CrowdStrike and Fidelis. In terms of customers, they don't have a problem with cloud connection. We will put CrowdStrike as the first competitor because of customers' worries about the cloud connection. Most of the POCs I saw were Fidelis and Trellix, or Cortex, against Linux. I see these two at customers all the time.
How was the initial setup?
The initial setup is very simple. Before we bought Trellix, we had some other competitors like Kaspersky and Fidelis. During the proof of concept (POC), we found it very hard to integrate in that situation.
And capability-wise, Fidelis is also big for enterprises, but the main issue was integration and management, especially that the appliance management of services is not that good.
On the other hand, Trellix has the SIEM appliance, which can create custom rules and make your EDR and NDR talk to each other and provide more enrichments and more insights into incidents, whether it is a true positive or false positive. But it's good to have, especially when we talk about EDR and NDR, it is very recommended to have both solutions from the same vendor to avoid any integration and configuration issues.
We primarily manage Helix software for API cloud. The appliances are physical and managed in the data centre.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable compared to its competitors.
What other advice do I have?
Overall, I would rate the product a nine out of ten. I would recommend it to other users.