

Trellix Network Detection and Response and ExtraHop Reveal(x) are competitors in the network security and monitoring space. ExtraHop Reveal(x) has the upper hand due to its strong network visibility and SSL decryption capabilities, which enhance real-time monitoring and integration options.
Features: Trellix Network Detection and Response provides zero-day attack detection, APT identification, and application filtering. It offers a reliable MVX engine, effective incident response, and a straightforward alert dashboard. ExtraHop Reveal(x) stands out with its network visibility, machine learning capabilities, and integration with various solutions. It provides customizable dashboards and can decrypt SSL traffic for anomaly detection.
Room for Improvement: Trellix Network Detection and Response needs enhancement in analytics, false positive reduction, and improved integration with other vendor tools and cloud support. ExtraHop Reveal(x) could improve with a longer look-back period, enhanced nesting in collections, and additional user training resources. Both products could benefit from improved support protocols and optimized pricing strategies.
Ease of Deployment and Customer Service: Trellix Network Detection and Response offers on-premises deployment with highly responsive customer service, known for its robust classic support system. ExtraHop Reveal(x) provides deployment options across hybrid, on-premises, and public cloud environments, with customer service also rated highly. Both could improve support and usability.
Pricing and ROI: Trellix Network Detection and Response is considered costly but delivers significant ROI by effectively preventing threats. ExtraHop Reveal(x) is also seen as expensive, requiring strategic planning for setup, yet provides good value by reducing breaches and enhancing productivity, affirming its ROI.
I would rate their technical support nine out of ten.
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
The customer support for Trellix Network Detection and Response is great.
Currently, we have to check manually as we do not receive any notifications about new patches, maintenance, or firmware releases.
I would like to see improvements in areas where events are getting dropped; we're not able to view complete insights.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
When I need urgent support from Trellix, there is a response after four hours or three hours.
I would like to see in Trellix Network Detection and Response more explanation about some details of the threat.
The price for Trellix Network Detection and Response is reasonable.
If I want to know a specific IP and which server it has been connected to, it's easy to gather those kinds of trees from the NDR.
The solution offers a friendly GUI for security features.
What makes Trellix Network Detection and Response stand out for me compared to other tools is the way you can detect threats. It is very easy and comfortable to use, and the detection shows clearly on the screen, which is very easy to understand.
Trellix NDR provides an essential defense by automatically responding to network incidents that firewalls may not catch.
| Product | Mindshare (%) |
|---|---|
| ExtraHop Reveal(x) | 6.1% |
| Trellix Network Detection and Response | 2.9% |
| Other | 91.0% |


| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 4 |
| Large Enterprise | 9 |
| Company Size | Count |
|---|---|
| Small Business | 21 |
| Midsize Enterprise | 8 |
| Large Enterprise | 19 |
ExtraHop Reveal(x) offers advanced network visibility and threat detection through seamless integration with CrowdStrike. It enhances security with machine learning-driven behavioral analysis and customizable dashboards.
ExtraHop Reveal(x) excels in network detection and response by decrypting SSL traffic and providing real-time packet inspection. Users benefit from its dynamic triggers and historical data tracing. The platform is valued for its depth of information, powerful analytics, and cloud-based administration. It allows effective monitoring of attack chains and integrates with other solutions to boost security. However, there is room for improvement in pricing flexibility, licensing models, and integration capabilities, particularly with Microsoft Sentinel.
What are ExtraHop Reveal(x)'s Key Features?ExtraHop Reveal(x) is employed across industries for network traffic monitoring, malware detection, and real-time analysis. Analysts use it for server-to-server networking insights and application troubleshooting. Companies leverage its capabilities for behavioral analytics and compliance monitoring without deploying sensors on individual devices.
Trellix Network Detection and Response provides robust threat protection with advanced detection of zero-day attacks and APTs. Its user-friendly dashboard and real-time response capabilities enhance security and visibility across networks.
Trellix Network Detection and Response stands out with its MVX engine, leveraging virtual machines for comprehensive behavioral analysis. The solution supports detection of advanced cyber threats through features like sandboxing and application filtering, offering real-time response and packet capture for detailed contextual insights. Companies benefit from seamless integration with other platforms, enhancing usability and overall protection. User-friendly interfaces improve network visibility, while stability and ease of configuration safeguard against both signature-based and signature-less threats.
What key features does Trellix offer?Companies in sectors like finance, healthcare, and enterprise security utilize Trellix Network Detection and Response for tasks such as network intrusion detection, endpoint protection, and securing data transmission paths. It aids in threat investigations, pre-sales demos, and network forensics, reducing risks by protecting against cyber threats like phishing.
We monitor all Network Detection and Response (NDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.