No more typing reviews! Try our Samantha, our new voice AI agent.

Fortinet FortiSandbox vs Palo Alto Networks WildFire vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.8
Fortinet FortiSandbox ensures high ROI by preventing cyber threats, saving costs, and securing data, rated nine out of ten.
Sentiment score
6.1
Organizations report quick ROI from WildFire, enhancing security, reducing false positives, and lowering costs by 25-30%.
Sentiment score
7.8
Trellix NDR boosts productivity and ROI, reduces threat response time, and is valued for preventing attacks and breaches.
The service generates a low rate of false positives, reducing the overhead of managing false positive events.
Presale Engineer at Westcon-Comstor
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Customer Service

Sentiment score
7.2
Fortinet FortiSandbox generally offers friendly, informed support, but users face delays and need better handling of complex issues.
Sentiment score
6.7
Customer service is mixed, with large companies excelling, slow response times for some, and premium tiers offering better support.
Sentiment score
6.6
Trellix Network Detection and Response support is mostly effective, with some users noting communication delays and areas for improvement.
Sometimes the technical engineer is very good and helpful, and sometimes we go through many processes until it gets escalated to a higher level or to another advanced technical engineer.
Security Manager at a computer software company with 11-50 employees
There is a lack of SLA adherence, and third-party partners do not provide prompt responses.
Technical Superintendent at Indian Institute Of Technology, Patna
We have had some open tickets for months, maybe half a year, and there is no real answer.
IT Security Specialist at a tech services company with 11-50 employees
The service response times are aligned with standards, responding within a few hours based on the problem's criticality.
Presale Engineer at Westcon-Comstor
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
The customer support for Trellix Network Detection and Response is great.
Agente De Servicios Técnicos at a computer software company with 11-50 employees
 

Scalability Issues

Sentiment score
7.4
Fortinet FortiSandbox is scalable and adaptable, though experiences vary with cloud licenses and hardware requirements.
Sentiment score
8.0
Palo Alto Networks WildFire offers scalable, adaptable integration for various networks, seamlessly accommodating growth, though on-premises scaling may incur costs.
Sentiment score
7.1
Trellix Network Detection and Response effectively scales in cloud environments, smoothly handling diverse user bases and existing configurations.
Wildfire is highly scalable.
Technical Superintendent at Indian Institute Of Technology, Patna
Palo Alto Networks WildFire is scalable, and I give it a nine for scalability.
Content Specialist at PeerSpot
The on-premises version is expensive to scale as it might need an additional device to be installed in the setup.
IT Security Specialist at a tech services company with 11-50 employees
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
7.6
Fortinet FortiSandbox is generally rated as stable and reliable, with users giving stability ratings between eight and nine.
Sentiment score
8.5
Palo Alto Networks WildFire is highly reliable, scalable, and integrates seamlessly, offering robust malware filtering and network compatibility.
Sentiment score
7.8
Trellix Network Detection is praised for stability and reliability, though some face downtime and memory or CPU issues.
Fortinet FortiSandbox works fine, is easy to manage, and functions well.
Security Manager at a computer software company with 11-50 employees
It performs filtering, malware blocking, and scanning.
Engineer at Taalumgroup
The solution is scalable and stable.
Technical Manager at PSR
Trellix Network Detection and Response is somewhat stable but there is a bit of downtime sometimes during the off-hours.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Room For Improvement

Fortinet FortiSandbox needs better vendor integration, enhanced features, improved usability, and faster, more automated security analysis capabilities.
Users seek improvements in functionality, user interface, support, pricing, deployment complexity, automation, integration, and advanced capabilities.
Trellix Network Detection and Response needs enhancements in customization, integration, support, threat intelligence, and AI capabilities to reduce false positives.
I think Fortinet FortiSandbox could introduce more automation tools and AI tools.
Security Manager at a computer software company with 11-50 employees
It should be easier to establish the Palo Alto Networks WildFire cluster between the devices.
IT Security Specialist at a tech services company with 11-50 employees
The dashboard should provide better visibility, especially in showing how many files are sent to Wildfire and their findings.
Technical Superintendent at Indian Institute Of Technology, Patna
It is a very good product.
Engineer at Taalumgroup
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
When I need urgent support from Trellix, there is a response after four hours or three hours.
IT Manager at Gigabit Technologies Pvt Ltd
Trellix Network Detection and Response needs to deepen the cloud-native support with parity between on-premises and cloud deployments.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Setup Cost

Fortinet FortiSandbox is priced mid-range, with options for cloud and on-prem, plus potential support license costs.
Palo Alto Networks WildFire is an enterprise-focused, costly solution with robust threat prevention, offering various pricing tiers and a free trial.
Trellix Network Detection and Response is costly, yet valued for quality threat detection, appealing to larger enterprises over smaller clients.
The cost is in the mid-range.
Security Manager at a computer software company with 11-50 employees
I would rate it an eight out of ten in terms of affordability.
Presale Engineer at Westcon-Comstor
The price for Trellix Network Detection and Response is reasonable.
IT Manager at Gigabit Technologies Pvt Ltd
I am sure the ROI was definitely fine for this because we were using this tool for three years.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Valuable Features

Fortinet FortiSandbox delivers excellent threat detection, seamless integration, fast performance, ease of use, and robust customization options.
Palo Alto Networks WildFire offers advanced malware detection, effective sandboxing, and robust integration with next-gen firewalls for threat protection.
Trellix NDR excels in zero-day detection, integrates with security platforms, reduces alert fatigue, and offers user-friendly threat analysis.
The smooth integrations between Fortinet FortiSandbox and other Fortinet solutions such as FortiWeb and FortiFirewall and with other Fortinet environments are what I really appreciate.
Security Manager at a computer software company with 11-50 employees
Integrating Palo Alto Networks WildFire with various security protocols similar to a firewall has significantly improved the overall threat detection capabilities in our organization.
Content Specialist at PeerSpot
The most valuable feature of Wildfire is its sandboxing capability for examining suspicious files or locations.
Technical Superintendent at Indian Institute Of Technology, Patna
The integration and working with third-party solutions was very seamless and smooth.
IT Security Specialist at a tech services company with 11-50 employees
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix NDR provides an essential defense by automatically responding to network incidents that firewalls may not catch.
Information Security Engineer at Nhq Distribution Ltd
What makes Trellix Network Detection and Response stand out for me compared to other tools is the way you can detect threats. It is very easy and comfortable to use, and the detection shows clearly on the screen, which is very easy to understand.
Agente De Servicios Técnicos at a computer software company with 11-50 employees
 

Mindshare comparison

As of May 2026, in the Advanced Threat Protection (ATP) category, the mindshare of Fortinet FortiSandbox is 4.8%, down from 7.9% compared to the previous year. The mindshare of Palo Alto Networks WildFire is 7.4%, down from 11.5% compared to the previous year. The mindshare of Trellix Network Detection and Response is 4.1%, up from 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks WildFire7.4%
Fortinet FortiSandbox4.8%
Trellix Network Detection and Response4.1%
Other83.7%
Advanced Threat Protection (ATP)
 

Featured Reviews

AN
Security Manager at a computer software company with 11-50 employees
Advanced sandboxing has protected users from zero-day threats and has simplified secure file scanning
The smooth integrations between Fortinet FortiSandbox and other Fortinet solutions such as FortiWeb and FortiFirewall and with other Fortinet environments are what I really appreciate. We have minimum false positives during threat detection. Our clients have not given negative feedback from detection. As you know, it still needs some tuning after implementation. However, we never receive negative feedback for many false positives during implementation.
RK
Engineer at Taalumgroup
Achieve effective threat prevention and seamless integration with powerful technical support
Integration with third-party products is possible. For example, connecting a mail gateway with Palo Alto Networks WildFire allows them to handle prevention. Palo Alto Networks WildFire is a cloud-based sandboxing solution. The firewall is connected to WildFire, and XDR performs sandboxing from the cloud. WildFire conducts malware scanning and emulation, then informs the firewall to block threats based on the response. It also generates reports regarding malware and other issues. The sandboxing process involves sending sample files to the cloud for scanning, checking file authenticity, certificates, and detecting malicious code. WildFire performs multiple checks and informs the XDR agent about file status. This automatic process occurs within minutes or seconds. For unknown or suspicious files, immediate blocking occurs while samples are sent to WildFire for identification. I rate Palo Alto Networks WildFire a 9 out of 10.
reviewer2840397 - PeerSpot reviewer
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Threat detection has improved for zero‑day attacks but alert noise and support still need work
There are many ways Trellix Network Detection and Response can be improved. Trellix Network Detection and Response needs to reduce the alert noise because even after a lot of filtering, there is still a lot of noise which needs to be tuned by the industry vertical. Trellix Network Detection and Response needs to deepen the cloud-native support with parity between on-premises and cloud deployments. Trellix Network Detection and Response needs to improve threat intelligence depth as Trellix Network Detection and Response is not known to have the best signatures or the AI-supported intelligence that competitors may have. Trellix Network Detection and Response also needs revamped documentation because we had a lot of issues trying to find the syntaxes for all the rule-making. We had to search a lot and Trellix Network Detection and Response does not really help with their documentation, as it only covers basic information. The customer service is not that good. Trellix Network Detection and Response needs accelerated customer support to reach out to the top-level heads. Most of the time we are just stuck at the ground level talking to their customer support team, and they are not able to help us because we usually need to connect with the engineering team to help us out with the specifics.
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
894,998 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Security Consultant at Webernetz.net - Network Security Consulting
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Financial Services Firm
10%
Government
8%
Computer Software Company
7%
Computer Software Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Manufacturing Company
8%
Financial Services Firm
14%
Comms Service Provider
12%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise13
Large Enterprise9
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise15
Large Enterprise29
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise8
Large Enterprise20
 

Questions from the Community

What is your experience regarding pricing and costs for Fortinet FortiSandbox?
The cost is in the mid-range. It is not low and it is not high.
What needs improvement with Fortinet FortiSandbox?
I think Fortinet FortiSandbox could introduce more automation tools and AI tools.
What is your primary use case for Fortinet FortiSandbox?
Clients primarily ask us to integrate Fortinet FortiSandbox either with FortiMail or with firewalls to scan downloada...
How does Cisco Firepower NGFW Firewall compare with Palo Alto Networks Wildfire?
The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one conside...
Which is better - Wildfire or FortiGate?
FortiGate has a lot going for it and I consider it to be the best, most user-friendly firewall out there. What I like...
How does Cisco ASA Firewall compare with Palo Alto's WildFire?
When looking to change our ASA Firewall, we looked into Palo Alto’s WildFire. It works especially in preventing advan...
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is very great.
What needs improvement with FireEye Network Security?
I would like to see in Trellix Network Detection and Response more explanation about some details of the threat, and ...
What is your primary use case for FireEye Network Security?
My main use case for Trellix Network Detection and Response is providing support for our customers, and one of our cu...
 

Also Known As

FortiSandbox
No data available
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Novamedia, Nexon Asia Pacific, Lenovo, Samsonite, IOOF, Sinogrid, SanDisk Corporation
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Palo Alto Networks, Microsoft, Proofpoint and others in Advanced Threat Protection (ATP). Updated: May 2026.
894,998 professionals have used our research since 2012.