No more typing reviews! Try our Samantha, our new voice AI agent.

ThreatLocker Zero Trust Platform vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 17, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.5
ThreatLocker boosts ROI by enhancing security, reducing costs, improving IT efficiency, and minimizing cyber threat risks for businesses.
Sentiment score
6.9
Trellix Network Detection and Response improves ROI by enhancing security, accelerating threat investigations, and reducing costs with automation.
If something were to happen without ThreatLocker, the cost would be huge, and thus, having it is definitely worth it.
Tier 1 IT Engineer at a retailer with 11-50 employees
Based on what we use ThreatLocker Zero Trust Endpoint Protection Platform for with the same functionalities and packaging, it was around 13 or 14 hours.
Head Of Cyber Security at a outsourcing company with 201-500 employees
We have the MDR package as well, and just knowing someone is watching those endpoints at 3:00 a.m. is a lifesaver that you cannot put a dollar figure on.
System Administrator at Gwynedd Mercy University
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
Security Engineer at Digitaltrack
We have seen a positive return on investment with Trellix Network Detection and Response through the improved investigation efficiency, reduced manual effort, and faster threat identification.
Assistant General Manager at Sunteck Realty Pvt Ltd
 

Customer Service

Sentiment score
7.8
ThreatLocker Zero Trust Platform provides outstanding support with immediate expert assistance and high user satisfaction despite minor connection complexities.
Sentiment score
7.5
Trellix support is often praised for responsiveness and knowledge but receives mixed reviews on expertise and incident handling.
They have been very responsive, helpful, and knowledgeable.
Systems Security Analyst & Deputy Security Officer at a financial services firm with 201-500 employees
I would rate their customer support a ten out of ten.
Director, Managed Services at a consultancy with 11-50 employees
Their support is world-class.
Supervisor, Client Security at a consultancy with 11-50 employees
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
They help and support us promptly, allowing us to resolve issues immediately.
Network & Security Lead at Net-International
 

Scalability Issues

Sentiment score
7.7
ThreatLocker Zero Trust Platform offers seamless scalability and adaptability, catering to various organizational sizes and requirements effortlessly.
Sentiment score
7.8
Trellix Network Detection and Response excels in scalability, flexibility, and performance, adapting to growing environments and diverse user needs.
I started off with just the servers, and within a month and a half, I set up the entire company with ThreatLocker.
Technical Engineer at Cloud 1 Solutions
It seems to primarily operate on the endpoints rather than at a central location pushing out policies.
Systems Security Analyst & Deputy Security Officer at a financial services firm with 201-500 employees
ThreatLocker Zero Trust Endpoint Protection Platform scales very smoothly with our growing needs.
CEO at Mostro
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Cyber Security Engineer at a retailer with 51-200 employees
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response is scalable.
Network & Security Lead at Net-International
 

Stability Issues

Sentiment score
7.8
ThreatLocker Zero Trust Platform is generally stable with minor policy update issues, quickly addressed by responsive developers, ensuring reliability.
Sentiment score
7.9
Trellix Network Detection and Response is praised for stability and reliability, with swift issue resolution and vendor support.
For five years, we have not had a problem.
Supervisor, Client Security at a consultancy with 11-50 employees
Once deployed, it downloads the policies locally, so even if the computer doesn't have internet, it doesn't matter.
Information Cybersecurity Technology Specialist at Freez.it
It has been very stable, reliable, and accessible.
COO at Panda Technology
Trellix Network Detection and Response is somewhat stable but there is a bit of downtime sometimes during the off-hours.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Room For Improvement

Enhance training, transparency, reporting, and integration in ThreatLocker, improve mobile compatibility, and control bulk actions for better functionality.
Trellix requires improved integration, AI capabilities, customizable dashboards, better workflows, reduced noise, enhanced support, and stronger network security.
Controlling the cloud environment, not just endpoints, is crucial.
COO at Panda Technology
ThreatLocker Zero Trust Endpoint Protection Platform could improve by being a little more hands-off, perhaps by having a team inside ThreatLocker that does all the vetting of patches; having one person hired by ThreatLocker to check out patches means that a million other industries using ThreatLocker Zero Trust Endpoint Protection Platform do not have to vet the same patch, ultimately saving time and money around the world.
Technical Support Engineer at CMIT Solutions of Central Orlando
This feedback would help us understand what is learned in real-time, especially during a one-hour learning mode setup, ensuring we remain aware of potentially unnecessary learned items.
Server Administrator at Clay County Sheriff's Office
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Network & Security Lead at Net-International
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Presales Manager
 

Setup Cost

ThreatLocker Zero Trust Platform offers competitive, flexible pricing with customizable deals, comprehensive features, and cost-effective enterprise security solutions.
Trellix offers strong security features with mixed reviews on cost and setup, valuable despite its premium pricing.
After conversations with other partners, it became clear we underpriced it initially, which caused most of our issues.
Director, Managed Services at a consultancy with 11-50 employees
We are moving towards the Unified solution, where they basically bundle everything together, providing us better stability with the ability to bring in new product offerings without having to go back to the customer and say, 'This is going to cost you.'
Supervisor, Client Security at a consultancy with 11-50 employees
Money is saved because it is not costly, and I would suggest it for other companies.
Helpdesk Engineer at Computer Network Infrastructure (CNI) Consultants
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
Network & Security Lead at Net-International
I wanted something that was not too price-heavy like SentinelOne but also not much cheaper like Kaspersky.
Cyber Security Engineer at a retailer with 51-200 employees
The price for Trellix Network Detection and Response is reasonable.
IT Manager at Gigabit Technologies Pvt Ltd
 

Valuable Features

ThreatLocker Zero Trust Platform enhances security via application controls, intuitive interface, cost reduction, and seamless tool integration.
Trellix Network Detection and Response offers advanced threat detection, automation, and integration to enhance security and expedite resolution.
ThreatLocker Zero Trust Endpoint Protection Platform's ability to block access to unauthorized applications has been excellent.
Cyber Security Specialist at Bremmar Consulting
It protects our customers.
CTO at Zettabytes
The major benefit is fewer breaches overall, as nothing can be run without prior approval. This helps my company protect its data and secure itself effectively.
Tier 1 IT Engineer at a retailer with 11-50 employees
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Network & Security Lead at Net-International
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
Presales Manager
 

Categories and Ranking

ThreatLocker Zero Trust Pla...
Ranking in Advanced Threat Protection (ATP)
4th
Average Rating
9.2
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
Network Access Control (NAC) (4th), Endpoint Protection Platform (EPP) (6th), Application Control (1st), ZTNA as a Service (4th), ZTNA (5th), Ransomware Protection (1st)
Trellix Network Detection a...
Ranking in Advanced Threat Protection (ATP)
10th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
51
Ranking in other categories
Network Detection and Response (NDR) (7th)
 

Mindshare comparison

As of June 2026, in the Advanced Threat Protection (ATP) category, the mindshare of ThreatLocker Zero Trust Platform is 2.7%, up from 2.1% compared to the previous year. The mindshare of Trellix Network Detection and Response is 4.1%, up from 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
ThreatLocker Zero Trust Platform2.7%
Trellix Network Detection and Response4.1%
Other93.2%
Advanced Threat Protection (ATP)
 

Featured Reviews

Santo Joy - PeerSpot reviewer
Head Of Cyber Security at a outsourcing company with 201-500 employees
Security controls have been strengthened with granular application, ringfencing, and access policies
The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most are the Ringfencing, elevation control, storage control, and application whitelisting functionality. For examples of how these features benefit my company, we were looking for a solution across various vendors to actually implement application whitelisting controls. ThreatLocker's agent, which is very lightweight and does not use much CPU or RAM, helped us achieve that solution. Ringfencing was an add-on that ticked off a lot of Australian framework security controls, which is the reason we chose it. My impression of the allowlisting feature in terms of managing which software, scripts, and libraries run on my devices is that ThreatLocker's community page has a lot of information around this, which is very helpful. Not only that, the Cyber Hero support that ThreatLocker provides gives us insights and best practices, helping us achieve that solution and guiding us to the right platform. The impact of Ringfencing on controlling the behavior of approved applications has been a big winner for us because it is something that many other platforms do not provide as a functionality. Having that allowed us to identify what applications talk to each other, which is something that many other platforms do not do. The network control feature impacts my ability to manage network traffic across my endpoints and servers. We have not used this widely across all our partners, but wherever required, we use it. It has been an easy solution for those customers to get that control implemented. The elevation feature's role in facilitating just-in-time administrative access for approved applications shows that elevation control helps in many use cases involving remote control platforms, door usage, and security system platforms that require local admins. There are many solutions that provide this functionality, but the licensing cost seems to be expensive, and it also adds another solution into the mix. Rather than doing that, we try to use ThreatLocker Zero Trust Endpoint Protection Platform to achieve that control. Regarding the storage control feature, I have used it. The primary function is USB blocking, which is very widely adopted, and also just locking down and allowing certain users to access certain file locations helps us there. When it comes to enforcing policy-driven access over various storage devices, it depends on the business risk adapted by the companies that we support, but generally the use case is USB and external storage devices where companies know that is a risk, but they do not have appropriate solutions. There are EDR platforms that claim to do this, but ThreatLocker Zero Trust Endpoint Protection Platform does it at an advanced level. My assessment of the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites leads me to think that Web Control is another functionality within ThreatLocker Zero Trust Endpoint Protection Platform that is an add-on on top of the current set. That is another solution that we use based on what is required for the company, but again, that is not widely adapted yet for our partners.
Hassan Sheikh - PeerSpot reviewer
Network & Security Lead at Net-International
Integrated sensors have improved traffic inspection and now provide resilient east-west threat control
I believe Trellix Network Detection and Response can be improved by integrating machine learning into its detection response capabilities. Additionally, incorporating failover kits integrated into the sensors could be beneficial. It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features. While Trellix Network Detection and Response sensors are highly capable, I think it would be advantageous to include features such as Layer 7 profiles, application profile filters, web filters, IDx, IP feature sets, signature detection features, and routing and switching capabilities all in one device. While the user interface of Trellix Network Detection and Response is very good, I suggest implementing a customizable dashboard. Additionally, there should be report generation for critical attacks and high alert severities, displayed graphically on the dashboard, and providing options to extract files in Excel format for better visibility.
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
899,645 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
7%
Manufacturing Company
17%
Financial Services Firm
13%
Comms Service Provider
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business52
Midsize Enterprise13
Large Enterprise11
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise10
Large Enterprise23
 

Questions from the Community

What is your experience regarding pricing and costs for ThreatLocker Allowlisting?
My experience with pricing, setup cost, and licensing for ThreatLocker Zero Trust Endpoint Protection Platform is good because it has a nominal price.I would say ThreatLocker Zero Trust Endpoint Pr...
What needs improvement with ThreatLocker Allowlisting?
My experience with ThreatLocker Zero Trust Platform has been fairly good with not a lot of complaints. If I have to say what they can improve, one area would be making policy tuning and onboarding ...
What is your primary use case for ThreatLocker Allowlisting?
I currently work in the Enterprise GitLab platform for Scania where we have a lot of users using our GitLab platform for code pull and push, and our main use case for ThreatLocker Zero Trust Platfo...
What is your experience regarding pricing and costs for FireEye Network Security?
The price for Trellix Network Detection and Response is reasonable. The pricing is reasonable, and I do not need to bargain with Trellix or customers.
What needs improvement with FireEye Network Security?
The negative aspect is support. When I need urgent support from Trellix, there is a response after four hours or three hours, which is my main concern regarding the negative point of Trellix Networ...
What is your primary use case for FireEye Network Security?
I am working with Trellix Network Detection and Response as part of my overall experience with these products today. Trellix Network Detection and Response is used for threat and response use cases...
 

Also Known As

Protect, Allowlisting, Network Control, Ringfencing
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Information Not Available
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about ThreatLocker Zero Trust Platform vs. Trellix Network Detection and Response and other solutions. Updated: June 2026.
899,645 professionals have used our research since 2012.