No more typing reviews! Try our Samantha, our new voice AI agent.

ThreatLocker Zero Trust Platform vs Trellix Advanced Threat Defense comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 17, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ThreatLocker Zero Trust Pla...
Ranking in Advanced Threat Protection (ATP)
5th
Average Rating
9.2
Reviews Sentiment
7.0
Number of Reviews
86
Ranking in other categories
Network Access Control (NAC) (3rd), Endpoint Protection Platform (EPP) (5th), Application Control (1st), ZTNA as a Service (5th), ZTNA (6th), Ransomware Protection (1st)
Trellix Advanced Threat Def...
Ranking in Advanced Threat Protection (ATP)
22nd
Average Rating
7.8
Reviews Sentiment
5.6
Number of Reviews
9
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Advanced Threat Protection (ATP) category, the mindshare of ThreatLocker Zero Trust Platform is 2.8%, up from 2.4% compared to the previous year. The mindshare of Trellix Advanced Threat Defense is 2.1%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
ThreatLocker Zero Trust Platform2.8%
Trellix Advanced Threat Defense2.1%
Other95.1%
Advanced Threat Protection (ATP)
 

Featured Reviews

Santo Joy - PeerSpot reviewer
Head Of Cyber Security at a outsourcing company with 201-500 employees
Security controls have been strengthened with granular application, ringfencing, and access policies
The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most are the Ringfencing, elevation control, storage control, and application whitelisting functionality. For examples of how these features benefit my company, we were looking for a solution across various vendors to actually implement application whitelisting controls. ThreatLocker's agent, which is very lightweight and does not use much CPU or RAM, helped us achieve that solution. Ringfencing was an add-on that ticked off a lot of Australian framework security controls, which is the reason we chose it. My impression of the allowlisting feature in terms of managing which software, scripts, and libraries run on my devices is that ThreatLocker's community page has a lot of information around this, which is very helpful. Not only that, the Cyber Hero support that ThreatLocker provides gives us insights and best practices, helping us achieve that solution and guiding us to the right platform. The impact of Ringfencing on controlling the behavior of approved applications has been a big winner for us because it is something that many other platforms do not provide as a functionality. Having that allowed us to identify what applications talk to each other, which is something that many other platforms do not do. The network control feature impacts my ability to manage network traffic across my endpoints and servers. We have not used this widely across all our partners, but wherever required, we use it. It has been an easy solution for those customers to get that control implemented. The elevation feature's role in facilitating just-in-time administrative access for approved applications shows that elevation control helps in many use cases involving remote control platforms, door usage, and security system platforms that require local admins. There are many solutions that provide this functionality, but the licensing cost seems to be expensive, and it also adds another solution into the mix. Rather than doing that, we try to use ThreatLocker Zero Trust Endpoint Protection Platform to achieve that control. Regarding the storage control feature, I have used it. The primary function is USB blocking, which is very widely adopted, and also just locking down and allowing certain users to access certain file locations helps us there. When it comes to enforcing policy-driven access over various storage devices, it depends on the business risk adapted by the companies that we support, but generally the use case is USB and external storage devices where companies know that is a risk, but they do not have appropriate solutions. There are EDR platforms that claim to do this, but ThreatLocker Zero Trust Endpoint Protection Platform does it at an advanced level. My assessment of the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites leads me to think that Web Control is another functionality within ThreatLocker Zero Trust Endpoint Protection Platform that is an add-on on top of the current set. That is another solution that we use based on what is required for the company, but again, that is not widely adapted yet for our partners.
PP
RSSI at SDIS49
Ensuring long-term reliability while seeking internal email management enhancements
Prisma is a commercial name of the firewall now, but we don't work with the cloud product. Only our company is using it and we do not recommend it to customers. For us, it's transparent because it's a cloud product, so we don't really know the version as it's always updated. We have not had any problem, but it's difficult to report on what's going on because some days they can wash out perhaps 100 mails, and then it's difficult to say how many attacks you have reached. The right email has been washed out and then nobody has complained. We do not use the Threat Visualization feature; as we are in MX, the mail is washed out before it is in the mail inbox of the user, thus avoiding any problem requiring a reservation. In fact, there is no integration with existing security frameworks. The only problem we can have is that as we have no API interface, there is no inspection of internal mail. I rate Trellix Advanced Threat Defense a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have gotten a lot of use out of the feature of removing local admins from a lot of computers with ThreatLocker Zero Trust Endpoint Protection Platform."
"ThreatLocker Allowlisting has all of these features integrated into one console, making it effective."
"ThreatLocker Zero Trust Endpoint Protection Platform has helped my company and my clients' companies save on operational costs and expenses, and I would estimate we have saved at least thirty to forty percent."
"ThreatLocker Zero Trust Endpoint Protection Platform benefits our company because we can be secure while remaining relaxed, as we are only expecting normal behavior and nothing unusual."
"ThreatLocker Zero Trust Endpoint Protection Platform has helped us protect our environments and have more meaningful requests for access as well as meaningful logging for response."
"Being able to protect and trust nothing by default, known as zero trust, is the most important feature to me."
"My experience with pricing, setup cost, and licensing for ThreatLocker Zero Trust Endpoint Protection Platform is good because it has a nominal price, offers good value for money, saves money because it is not costly, and I would suggest it for other companies and definitely recommend it to new companies if I had the opportunity."
"Zero-Touch is the future, and ThreatLocker Zero Trust Endpoint Protection Platform is the easiest way to accomplish that."
"Provides good exfiltration, and is an all-in-one product."
"It was easy to set up initially."
"I recommend this solution because of its ease of use."
"The most valuable features are the administration console and its detection and response module."
"The fact that in 10 years, we have had no problem is the most valuable feature for us; it's really a washing machine, but the only problem we face is that it's difficult to report on this product."
"Its greatest strength is the DXL client which can rapidly disseminate attack information to all clients via the McAfee Agent instead of going through the ePO server."
"It is very scalable."
"I see ROI, as it stops in excess of twenty-five malware events per month, all of which could be critical to the business."
 

Cons

"I believe ThreatLocker Zero Trust Endpoint Protection Platform could be improved with a mobile version, as many clients work off their phones, downloading all kinds of things on their mobile devices."
"While ThreatLocker Zero Trust Platform is a strong zero trust platform, especially for application allowance and least privileges, areas for improvement include policy management, reporting dashboards, user experience, and notifications."
"Identifying areas of improvement is challenging, however, perhaps adding a few more built-ins could help."
"Sometimes it does block new things we try to run, but once we get them approved, it works perfectly and successfully blocks the things we want to be hindered."
"From my perspective, the initial setup and policy configuration of ThreatLocker Zero Trust Platform could be more intuitive, especially for new users."
"Adding applications to the allowlist can sometimes feel overwhelming."
"It is not easy to use. I am still learning."
"From my point of view, logging could be improved. Logging should be easier."
"Make the ATD system a part of the whole product and take the whole thing onto the cloud. While it is there already, it is not to the same level as the on-premise version."
"Make the ATD appliance a part of the whole product offering and take the whole thing onto the cloud."
"This solution needs to be made "cloud ready"."
"Some of our customers have mentioned the lack of a tool that would allow for remote capabilities without being attached to the internet."
"It was not complex, but there are things to look out for, because it's an intense product. It scans intensely and there are major obstacles to overcome if it scans while users are using a network, then it is not a good thing."
"Lacks remote capabilities not dependent on the internet."
"The support on their side is not readily available. It takes a while."
"The only problem we can have is that as we have no API interface, there is no inspection of internal mail."
 

Pricing and Cost Advice

"The pricing is fair and there is no hard sell."
"The pricing works fine for me. It's very reasonably priced."
"I do not know about the licensing and price as it comes bundled from our MSP. However, it seems fairly reasonable for us, which is why we chose it."
"We have not had any real issues with the pricing. As they have added more features, due to the way our contracts are structured with our customers, we have had to hold off on adopting the new features because they do add costs."
"The pricing is reasonable and normal. I do not have any problems with the cost."
"The price is very reasonable, and we have been able to integrate ThreatLocker with all of our clients."
"Considering what this product does, ThreatLocker is very well-priced, if not too nicely priced for the customer."
"The price of ThreatLocker Allowlisting is reasonable in the market, but it is not fantastic."
"The product is expensive, but it is better than the rest of them in the industry."
"Our licensing fees for this solution are approximately one million dollars per year."
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
11%
Financial Services Firm
11%
Computer Software Company
10%
Outsourcing Company
9%
Construction Company
15%
Outsourcing Company
15%
Comms Service Provider
11%
Financial Services Firm
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business61
Midsize Enterprise14
Large Enterprise18
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise4
Large Enterprise5
 

Questions from the Community

What is your experience regarding pricing and costs for ThreatLocker Allowlisting?
I am not sure about operational or cost expenses because we have not really experienced that.
What needs improvement with ThreatLocker Allowlisting?
When it comes to ThreatLocker Zero Trust Platform's policy making, it is very granular, but the moment you zoom out, you have a lot of information or a lot of alerts. However, the moment you zoom i...
What is your primary use case for ThreatLocker Allowlisting?
ThreatLocker Zero Trust Platform's main use case for us was data storage access control.We used ThreatLocker Zero Trust Platform for identifying the most critical and sensitive information of the o...
What needs improvement with McAfee Advanced Threat Defense?
I would like to see an API interface for internal email and control of outgoing email to make it closer to 10. It's necessary; today we have an MX interface, and it would be interesting to have an ...
What is your primary use case for McAfee Advanced Threat Defense?
We are working with Palo Alto products, specifically firewalls. We are only using Palo Alto Firewalls and not Cortex. With FireEye and Trellix, we only work with ETP now because the NDR function wh...
What advice do you have for others considering McAfee Advanced Threat Defense?
Prisma is a commercial name of the firewall now, but we don't work with the cloud product. Only our company is using it and we do not recommend it to customers. For us, it's transparent because it'...
 

Also Known As

Protect, Allowlisting, Network Control, Ringfencing
McAfee Advanced Threat Defense
 

Overview

 

Sample Customers

Information Not Available
The Radicati Group, Florida International University, MGM Resorts International, County Durham andDarlington NHS Foundation Trust
Find out what your peers are saying about ThreatLocker Zero Trust Platform vs. Trellix Advanced Threat Defense and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.