No more typing reviews! Try our Samantha, our new voice AI agent.

Trellix Advanced Threat Defense vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Trellix Advanced Threat Def...
Ranking in Advanced Threat Protection (ATP)
23rd
Average Rating
7.8
Reviews Sentiment
5.6
Number of Reviews
9
Ranking in other categories
No ranking in other categories
Trellix Network Detection a...
Ranking in Advanced Threat Protection (ATP)
17th
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
42
Ranking in other categories
Network Detection and Response (NDR) (13th)
 

Mindshare comparison

As of May 2026, in the Advanced Threat Protection (ATP) category, the mindshare of Trellix Advanced Threat Defense is 2.1%, up from 1.3% compared to the previous year. The mindshare of Trellix Network Detection and Response is 4.1%, up from 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Trellix Network Detection and Response4.1%
Trellix Advanced Threat Defense2.1%
Other93.8%
Advanced Threat Protection (ATP)
 

Featured Reviews

PP
RSSI at SDIS49
Ensuring long-term reliability while seeking internal email management enhancements
Prisma is a commercial name of the firewall now, but we don't work with the cloud product. Only our company is using it and we do not recommend it to customers. For us, it's transparent because it's a cloud product, so we don't really know the version as it's always updated. We have not had any problem, but it's difficult to report on what's going on because some days they can wash out perhaps 100 mails, and then it's difficult to say how many attacks you have reached. The right email has been washed out and then nobody has complained. We do not use the Threat Visualization feature; as we are in MX, the mail is washed out before it is in the mail inbox of the user, thus avoiding any problem requiring a reservation. In fact, there is no integration with existing security frameworks. The only problem we can have is that as we have no API interface, there is no inspection of internal mail. I rate Trellix Advanced Threat Defense a nine out of ten.
reviewer2840397 - PeerSpot reviewer
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Threat detection has improved for zero‑day attacks but alert noise and support still need work
There are many ways Trellix Network Detection and Response can be improved. Trellix Network Detection and Response needs to reduce the alert noise because even after a lot of filtering, there is still a lot of noise which needs to be tuned by the industry vertical. Trellix Network Detection and Response needs to deepen the cloud-native support with parity between on-premises and cloud deployments. Trellix Network Detection and Response needs to improve threat intelligence depth as Trellix Network Detection and Response is not known to have the best signatures or the AI-supported intelligence that competitors may have. Trellix Network Detection and Response also needs revamped documentation because we had a lot of issues trying to find the syntaxes for all the rule-making. We had to search a lot and Trellix Network Detection and Response does not really help with their documentation, as it only covers basic information. The customer service is not that good. Trellix Network Detection and Response needs accelerated customer support to reach out to the top-level heads. Most of the time we are just stuck at the ground level talking to their customer support team, and they are not able to help us because we usually need to connect with the engineering team to help us out with the specifics.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It was easy to set up initially."
"If a system admin can put in the patience to read and constantly update the ePO system in terms of rules, enforcing them at regular intervals, you can safely go to sleep every night."
"Provides good exfiltration, and is an all-in-one product."
"The most valuable features are the administration console and its detection and response module."
"The features I find most valuable are: the management, the ability for automatic remediation of threats and it can successfully detect a threat, and to act upon it."
"The product is expensive, but it is better than the rest of them in the industry."
"It stops in excess of twenty-five malware events per month, all of which could be critical to the business."
"The fact that in 10 years, we have had no problem is the most valuable feature for us; it's really a washing machine, but the only problem we face is that it's difficult to report on this product."
"Very functional and good for detecting malicious traffic."
"It allows us to be more hands off in checking on emails and networking traffic, as we can set up a bunch of different alerts and have it alert us, giving us a better view of our network and our email environment."
"The most valuable feature is MVX, which tests all of the files that have been received in an email."
"FireEye has created an ecosystem of products integrated with their own SIEM, which is cloud-based and integrates with network security, email security, host security and the like."
"The most valuable feature is the network security module."
"Over the thirteen years of using the product, we have not experienced a single compromise in our environment. During the COVID period, we faced numerous DDoS attacks, and the tool proved highly effective in mitigating these threats."
"Application categorization is the most valuable feature for us."
"We see ROI in the sense that we don't have to react because it stops anything from hurting the network."
 

Cons

"The only problem we can have is that as we have no API interface, there is no inspection of internal mail."
"This solution needs to be made "cloud ready"."
"Lacks remote capabilities not dependent on the internet."
"There could be a tool that automatically updates all-new Microsoft IPs, which are available for free to connect to the client."
"Make the ATD appliance a part of the whole product offering and take the whole thing onto the cloud."
"We'd like them to be better at dealing with script threats."
"I would like to see future versions of the solution incorporate artificial intelligence technology."
"Make the ATD system a part of the whole product and take the whole thing onto the cloud. While it is there already, it is not to the same level as the on-premise version."
"The negative aspect is support."
"The world is currently shifting to AI, but FIreEye is not following suit."
"The problem with FireEye is that they don't allow VM or sandbox customization. The user doesn't have control of the VMs that are inside the box. It comes from the vendor as-is. Some users like to have control of it. Like what type of Windows and what type of applications and they have zero control over this."
"The product's integration capabilities are an area of concern where improvements are required."
"It would be very helpful if there were better integration with other solutions from other vendors, such as Fortinet and Palo Alto."
"A lot of false positives."
"The support from FireEye Network Security is not very good."
"FireEye’s main feature is its sandboxing or threat emulation capabilities to detect malware with extra add-ons such as signature-based IPS or endpoint protection, but these features are lacking compared to most IPS or endpoint vendors."
 

Pricing and Cost Advice

"Our licensing fees for this solution are approximately one million dollars per year."
"The product is expensive, but it is better than the rest of them in the industry."
"The tool is a bit pricey."
"FireEye is comparable to other products, such as HX, but seems expensive. It may cause us to look at other products in the market."
"Pricing and licensing are reasonable compared to competitors."
"The pricing is a little high."
"We're partners with Cisco so we get a reasonable price. It's cheaper than Palo Alto in terms of licensing."
"When you purchase FireEye Network Security NX, will need to purchase a megabit per second package. You must know your needs from day one."
"The pricing is fair, a little expensive, but fair. We've evaluated other products, and they're similarly priced."
"Its price is a bit high. A small customer cannot buy it. Its licensing is on a yearly basis."
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
894,668 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
16%
Comms Service Provider
12%
Outsourcing Company
11%
Financial Services Firm
9%
Financial Services Firm
14%
Comms Service Provider
12%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise4
Large Enterprise5
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise8
Large Enterprise20
 

Questions from the Community

What needs improvement with McAfee Advanced Threat Defense?
I would like to see an API interface for internal email and control of outgoing email to make it closer to 10. It's necessary; today we have an MX interface, and it would be interesting to have an ...
What is your primary use case for McAfee Advanced Threat Defense?
We are working with Palo Alto products, specifically firewalls. We are only using Palo Alto Firewalls and not Cortex. With FireEye and Trellix, we only work with ETP now because the NDR function wh...
What advice do you have for others considering McAfee Advanced Threat Defense?
Prisma is a commercial name of the firewall now, but we don't work with the cloud product. Only our company is using it and we do not recommend it to customers. For us, it's transparent because it'...
What do you like most about FireEye Network Security?
We wanted to cross-reference that activity with the network traffic just to be sure there was no lateral movement. With Trellix, we easily confirmed that there was no lateral network involvement an...
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is very great.
What needs improvement with FireEye Network Security?
I would like to see in Trellix Network Detection and Response more explanation about some details of the threat, and I wish it had more actions that you can take to contain the host or move it some...
 

Also Known As

McAfee Advanced Threat Defense
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

The Radicati Group, Florida International University, MGM Resorts International, County Durham andDarlington NHS Foundation Trust
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Trellix Advanced Threat Defense vs. Trellix Network Detection and Response and other solutions. Updated: April 2026.
894,668 professionals have used our research since 2012.