![Microsoft Defender Threat Intelligence [EOL] Logo](https://images.peerspot.com/image/upload/c_scale,dpr_3.0,f_auto,q_100,w_64/GqfBeX9zWxZG3rC5hyrUo9Aq.jpeg?_a=BACAGSGT)

Trellix Network Detection and Response and Microsoft Defender Threat Intelligence compete in the cybersecurity category. Trellix appears to have the upper hand with its superior threat detection capabilities compared to the strong integration offered by Microsoft Defender.
Features: Trellix Network Detection and Response is noted for its ability to detect zero-day attacks with features like deep malware analysis, an intuitive alert dashboard, and a powerful MVX engine that uses virtual execution to block malicious files. Its application filtering is also highly valued. Microsoft Defender Threat Intelligence stands out due to its native integration within Microsoft's ecosystem, offering seamless use alongside other Microsoft products. It features global threat intelligence and effective user data management within the tenant.
Room for Improvement: Trellix Network Detection and Response can improve by addressing false positive issues, expanding integration with other vendors, and enhancing its customization options and documentation. Pricing is seen as a concern for smaller enterprises. Microsoft Defender Threat Intelligence needs to reduce false positives, enhance AI capabilities, and improve third-party integration. Stability issues and pricing concerns, particularly in non-Microsoft environments, are also areas to address.
Ease of Deployment and Customer Service: Trellix Network Detection and Response is often deployed on-premises, with customer service providing various contact options, though some delays in support responses are noted during critical incidents. Microsoft Defender Threat Intelligence, part of the Microsoft 365 suite, is available on public and hybrid clouds, simplifying deployment within the Microsoft ecosystem, although SMEs find pricing complex. Both solutions offer support but need improved responsiveness and technical expertise, especially during high-severity scenarios.
Pricing and ROI: Trellix Network Detection and Response is expensive, yet users find it offers high ROI due to its effective threat detection. Its pricing can be a barrier for smaller organizations. Microsoft Defender Threat Intelligence is bundled within E5 licenses, offering value to enterprises utilizing Microsoft products but posing challenges with licensing for SMEs. Despite the costs, both products deliver positive ROI by reducing breach incidents and response times, though Trellix's standalone cost may concern price-sensitive users.
It's a value-for-money product.
Level two support is knowledgeable and knows how the product works, which is very good.
I would give Microsoft an eight for their technical support.
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
The customer support for Trellix Network Detection and Response is great.
If there were some customizations available, I would rate its scalability as nine out of ten.
It provides a high level of security and avoids phishing and scam emails.
Providing code customization would help keep pace with new vulnerabilities and threats.
If Microsoft could direct critical messages regarding updates or vulnerabilities affecting users' environments, it would help users understand the importance of security updates.
From the telemetry data standpoint, I would prefer Defender data to be more open in future updates.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
I would like to see in Trellix Network Detection and Response more explanation about some details of the threat.
If it wasn't for that real-time threat detection on the vulnerability, I think we would not have survived the attack.
Our threat detection is enhanced due to the AI agents in Microsoft Defender Threat Intelligence, which helps in detecting automatically.
One of the best features is that it provides a certain level of customization, allowing us to set our spam confidence levels.
Trellix NDR provides an essential defense by automatically responding to network incidents that firewalls may not catch.
What makes Trellix Network Detection and Response stand out for me compared to other tools is the way you can detect threats. It is very easy and comfortable to use, and the detection shows clearly on the screen, which is very easy to understand.

| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 2 |
| Large Enterprise | 15 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 8 |
| Large Enterprise | 19 |
Microsoft Defender Threat Intelligence [EOL] offers comprehensive security by integrating with Microsoft platforms, retaining data within tenants, and providing real-time threat detection and collaboration. It's designed for both enterprise and SMB environments.
Microsoft Defender Threat Intelligence enhances cybersecurity operations by integrating with Azure Sentinel and Microsoft products like Intune and Azure. Its capabilities in endpoint, email, and cloud security ensure robust protection against a wide range of threats. With global threat data, anti-spam features, and customization options, it addresses threat prevention and vulnerability management. Seamless scaling and proactive incident prevention make it a reliable choice for enterprises looking for collaborative, efficient security management.
What are the key features of Microsoft Defender Threat Intelligence?Microsoft Defender Threat Intelligence is crucial for industries that value data retention and comprehensive threat analyses in safeguarding their operations. Financial institutions, healthcare providers, and technology firms implement this solution to secure their environments by updating security protocols and ensuring compliance with various industry standards. The focus on integration and customization helps these organizations adapt to evolving cybersecurity threats effectively.
Detect the undetectable and stop evasive attacks. Trellix Network Detection and Response (NDR) helps your team focus on real attacks, contain intrusions with speed and intelligence, and eliminate your cybersecurity weak points.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.