No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Defender Threat Intelligence [EOL] vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 16, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.2
Microsoft Defender Threat Intelligence enhances security, saves on budgets, and improves detection, offering significant ROI and value.
Sentiment score
7.0
Trellix Network Detection boosts security efficiency, reducing response times by 30-40% and enhancing threat prevention without extra staff.
It's a value-for-money product.
Mobility & IT Project Manager at Voicevine Pty Ltd
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
Security Engineer at Digitaltrack
 

Customer Service

Sentiment score
7.5
Microsoft Defender support is rated very good, with knowledgeable level two assistance, competent partners, and a helpful community platform.
Sentiment score
7.2
Trellix Network Detection and Response's support is praised for responsiveness, though some users experience delays but remain generally satisfied.
Level two support is knowledgeable and knows how the product works, which is very good.
Cloud Solution architect at a tech services company with 51-200 employees
I would give Microsoft an eight for their technical support.
Mobility & IT Project Manager at Voicevine Pty Ltd
The support team was responsive and knowledgeable.
Business development executive at Digitaltrack solution Pvt Ltd
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Scalability Issues

Sentiment score
7.4
Microsoft Defender Threat Intelligence is highly scalable, adaptable for businesses of all sizes, and supports thousands of endpoints efficiently.
Sentiment score
8.0
Trellix Network Detection and Response offers scalable, adaptable solutions, integrating well despite minor legacy connection issues, maintaining performance.
If there were some customizations available, I would rate its scalability as nine out of ten.
Cloud Solution architect at a tech services company with 51-200 employees
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Cyber Security Engineer at a retailer with 51-200 employees
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
Business development executive at Digitaltrack solution Pvt Ltd
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
8.0
Microsoft Defender Threat Intelligence is seen as stable and secure, with high reliability and effective phishing prevention despite occasional outages.
Sentiment score
8.0
Trellix Network Detection and Response is reliable and robust, ensuring stability with minimal disruptions and quick issue resolution.
It provides a high level of security and avoids phishing and scam emails.
Cloud Solution architect at a tech services company with 51-200 employees
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
Senior Business Development Associate at DigitalTrack Solutions ind pvt ltd
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
Business development executive at Digitaltrack solution Pvt Ltd
I encounter no issues with health or reliability when the recommended specifications are met.
CyberSecurity Architect at a comms service provider with 51-200 employees
 

Room For Improvement

Microsoft Defender needs price adjustments, improved integration, better accuracy, enhanced AI, and smoother user experience for evolving cybersecurity.
Trellix needs better reporting, integrations, UI, user support, and alert management to enhance threat detection and response.
Providing code customization would help keep pace with new vulnerabilities and threats.
Cloud Solution architect at a tech services company with 51-200 employees
The main area of improvement for Microsoft Defender Threat Intelligence is related to how information is conveyed.
Mobility & IT Project Manager at Voicevine Pty Ltd
From the telemetry data standpoint, I would prefer Defender data to be more open in future updates.
Consultant at Dell Technologies
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Network & Security Lead at Net-International
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Presales Manager
 

Setup Cost

Microsoft Defender Threat Intelligence is cost-effective in bundles, but SMEs face challenges with standalone pricing and evolving licensing.
Trellix Network Detection pricing is high but justified; straightforward licensing, pricey maintenance, and competitive with Cisco or Palo Alto.
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
Business development executive at Digitaltrack solution Pvt Ltd
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
CyberSecurity Architect at a comms service provider with 51-200 employees
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
Network & Security Lead at Net-International
 

Valuable Features

Microsoft Defender Threat Intelligence excels in integration, threat detection, user interface, data retention, real-time protection, and analytics.
Trellix Network Detection and Response enhances security with real-time threat detection, swift incident response, and seamless tool integration.
If it wasn't for that real-time threat detection on the vulnerability, I think we would not have survived the attack.
Mobility & IT Project Manager at Voicevine Pty Ltd
One of the best features is that it provides a certain level of customization, allowing us to set our spam confidence levels.
Cloud Solution architect at a tech services company with 51-200 employees
Our threat detection is enhanced due to the AI agents in Microsoft Defender Threat Intelligence, which helps in detecting automatically.
Consultant at Dell Technologies
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Network & Security Lead at Net-International
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
Presales Manager
 

Categories and Ranking

Microsoft Defender Threat I...
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
32
Ranking in other categories
No ranking in other categories
Trellix Network Detection a...
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
54
Ranking in other categories
Advanced Threat Protection (ATP) (10th), Network Detection and Response (NDR) (7th)
 

Featured Reviews

Charles Mokoena - PeerSpot reviewer
Mobility & IT Project Manager at Voicevine Pty Ltd
Has strengthened our ability to detect threats in real time and improved internal security decision-making
The features that I find most valuable in Microsoft Defender Threat Intelligence include the Sentinel part of it. There are several features we've looked at, including Sentinel as well as extended Defender, which is XDR. I've used those two, and that's what I've found quite useful for us, especially in the hardening and analysis part of the whole threat analysis. We use the real-time threat detection features in Microsoft Defender Threat Intelligence. If it wasn't for that real-time threat detection on the vulnerability, I think we would not have survived the attack. The integration capabilities of Microsoft Defender Threat Intelligence with other Microsoft security tools have benefited our organization's threat management process by initially being quite a challenge, especially coming from other security tools such as Fortinet and Check Point. However, once you've gotten used to it, it's quite easy and user-friendly. The dashboard, especially the threat analysis dashboard, is quite detailed in terms of providing a view of which areas in our environment need attention, making it quite useful.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Continuous network insight has improved early threat detection and streamlined investigations
Overall, we have a positive experience with Trellix Network Detection and Response, but like any enterprise security solution, there are areas where it can continue to improve. One area would be user interface and dashboard customization. While the platform provides a lot of valuable information, new users can sometimes face a learning curve when navigating and investigating and creating customized views. More intuitive dashboards would simplify workflows and help analysts access critical information even faster. Another area for improvement is reporting and analytics. The existing reporting capabilities are useful, but more flexibility and customizable reporting options would make it easier to generate executive-level summaries, compliance reports, and operational metrics for different audiences.
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Manufacturing Company
9%
Computer Software Company
8%
Marketing Services Firm
7%
Manufacturing Company
16%
Financial Services Firm
13%
Comms Service Provider
9%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise2
Large Enterprise15
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise14
Large Enterprise23
 

Questions from the Community

What needs improvement with Microsoft Defender Threat Intelligence?
From the telemetry data standpoint, I would prefer Defender data to be more open in future updates.
What is your primary use case for Microsoft Defender Threat Intelligence?
We have tried Microsoft Defender Threat Intelligence. I have expertise with Microsoft Defender products. I am not familiar with Microsoft Defender for IoT because we did not use that in our environ...
What advice do you have for others considering Microsoft Defender Threat Intelligence?
I will recommend Microsoft Defender Threat Intelligence because it is a complete automation solution for threat production detection and an end-to-end solution for client security. Unfortunately, s...
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is positive, as the setup process was straightforward, licensing was flexible, and the value deliver...
What needs improvement with FireEye Network Security?
Based on my experience with the solution, I do not see any improvements needed for Trellix Network Detection and Response at present; it might be required in the future, but there is no space to im...
What is your primary use case for FireEye Network Security?
Our main use case for Trellix Network Detection and Response is to maintain oversight of our network traffic and catch any threats or unusual activity as early as possible. Trellix Network Detectio...
 

Also Known As

No data available
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Information Not Available
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Palo Alto Networks, Microsoft, Proofpoint and others in Advanced Threat Protection (ATP). Updated: June 2026.
902,417 professionals have used our research since 2012.