

Darktrace and Trellix Email Security are competitive in the cybersecurity solutions category, focusing on different aspects of security. Darktrace has an advantage in AI-driven threat detection and network traffic analysis, while Trellix stands out in email security with its phishing detection and integration capabilities.
Features: Darktrace boasts strong AI-driven behavior analytics, providing comprehensive network visibility and autonomous responses, enhanced by its integration with Antigena for real-time threat management. Trellix Email Security features exceptional detection accuracy for phishing and malware, employing advanced sandboxing and URL rewriting for thorough email protection.
Room for Improvement: Darktrace could improve reporting accuracy to reduce false positives and enhance endpoint integration and pricing clarity. Trellix Email Security could refine its whitelisting processes, reduce false positives, and improve management interfaces to make them more user-friendly.
Ease of Deployment and Customer Service: Darktrace is easy to deploy across on-premises and hybrid cloud architectures, although experiences with customer support are mixed. Trellix Email Security is noted for its intuitive setup, particularly in cloud environments, with reliable and effective technical support.
Pricing and ROI: Darktrace is seen as expensive, often negotiated yet justifiable for large organizations looking for significant ROI through security enhancement. Trellix Email Security offers competitive, user-focused pricing, deemed cost-effective with a good ROI, especially appreciated for its affordability against other vendors.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
It reduces costs by almost 40% or 45% compared to other security solutions.
The question is what would happen if an organization did not have this security measure in place and got hit by ransomware.
One of the main positive impacts of Trellix Email Security is its ability to detect and respond to phishing and suspicious email activity much faster.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
Solutions take three to four weeks maximum if you want something fixed.
Trellix should have a dedicated center for the African market due to the unique dynamics and challenges within this region.
We raise a case on the customer portal, and our engineer will be aligned with us, and the engineer resolves the issue.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
The scalability rates at nine out of ten.
I would rate scalability between eight and nine because Trellix Email Security can be deployed in the cloud or on-premises, and in terms of scale, it can handle any size.
The scalability of Trellix Email Security is excellent.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
For stability, I would rate Darktrace an eight out of ten.
In terms of product stability, I would rate Trellix Email Security between eight and nine because the solution is quite stable.
Trellix Email Security is very stable, with no downtime noticed.
Whenever we deploy the product from the ePO console to that particular machine, it shows that the product is inactive.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
If they provide better customization options, it would be easier to understand everything in a single dashboard instead of navigating through dropdown menus to see reports.
I think there is a high number of false positives that also need attention.
They want to get the actual report on that, why they are sending and which way they are sending these emails.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
I am satisfied with the secure licensing cost because compared to other solutions, Trellix Email Security is cheaper and provides most features.
In my case, it is somewhat cost-effective and affordable.
The licensing is per user.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
If users try to open links that have converted to phishing after some time, those need to be blocked.
My experience with the malware analysis and quarantine features is that they are easy to manage and they have been very effective because we have been able to quarantine any suspicious emails or prevent any attempt before it affects our systems.
Monitoring and threat tracking in Trellix Email Security have the potential to reduce significantly the threats because I am able to review and analyze in real-time any potential threats to my environment and tackle them immediately.
| Product | Mindshare (%) |
|---|---|
| Darktrace | 1.8% |
| Trellix Email Security | 0.4% |
| Other | 97.8% |


| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 20 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 4 |
| Large Enterprise | 7 |
Darktrace revolutionizes network security with AI-driven alerts, anomaly detection, and robust visibility across networks. It autonomously detects threats, minimizing the need for human oversight, and offers efficient IP identification with minimal false positives.
Darktrace uses advanced AI analytics to enhance network protection. Its powerful real-time threat response capabilities and self-learning enable thorough monitoring and insightful analysis of network activities. While providing scalable and reliable security, users seek improvements in false positive reduction, user-friendly interfaces, and pricing. Enhanced third-party integration, more effective dashboards, and centralized automation features remain top priorities. Users benefit greatly from its Antigena feature, offering automated responses like blocking suspicious connections for robust network defense.
What Are Darktrace's Key Features?In industries employing Darktrace, it is pivotal in securing LAN networks, analyzing behavioral patterns, and detecting internal and external threats. Adoption alongside platforms like F5 and SAP enhances incident response, traffic analysis, and threat identification, utilizing Antigena for proactive security measures.
Trellix Email Security boosts email safety with advanced attachment sandboxing and URL reputation analysis, minimizing phishing and ransomware risks while effectively blocking malicious URLs post-delivery.
Trellix Email Security offers robust email protection through efficient malware analysis and mail filtering. Its user-friendly interface and straightforward policy rules enhance usability. The dashboard aids in threat assessment and reporting, though users advocate for more intuitive and customizable interfaces. Reporting and logging improvements are desired. The platform integrates well with threat management systems, providing clear insights into email flow and supporting advanced phishing defenses.
What are the key features?Industries incorporate Trellix Email Security for its capability to filter and trace email threats at the gateway level. Its features are valued in sectors requiring advanced spam and attachment detection, employing URL rewrite settings to block threats. While effective, some settings may require complex management.
We monitor all Email Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.