Try our new research platform with insights from 80,000+ expert users

Trellix Endpoint Detection and Response (EDR) vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.2
Trellix EDR enhances visibility, resolves issues rapidly, prevents breaches, and boosts credibility, despite varied perceptions on cost-effectiveness.
Sentiment score
6.8
USM Anywhere enhances security, saves time and resources, reduces staffing needs, and meets compliance, offering financial and time benefits.
Customers see ROI as they save on staff and other resources.
Co-Founder/Director at Bangkok MSP Company Limited
 

Customer Service

Sentiment score
7.3
Trellix EDR receives mixed reviews for support, citing helpful staff but issues with response times and communication barriers.
Sentiment score
8.0
USM Anywhere's customer service is generally praised for responsiveness but experiences occasional delays and inconsistent support information.
I have contracted support and also have an operating control so I can get various types of support.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
 

Scalability Issues

Sentiment score
7.3
Trellix EDR is scalable for various enterprises, offering centralized management but may experience occasional slowdowns and support needs.
Sentiment score
7.5
USM Anywhere is scalable for small to medium businesses, but enterprise-scale deployments face data volume and speed challenges.
USM Anywhere faces scalability issues because of a 60 TB limit.
Co-Founder/Director at Bangkok MSP Company Limited
 

Stability Issues

Sentiment score
7.9
Trellix EDR is stable and reliable, with performance improvements and resolved issues in recent updates, facing minimal deployment challenges.
Sentiment score
7.2
USM Anywhere receives mixed stability reviews, with some users praising its reliability and others reporting issues during updates or large data handling.
 

Room For Improvement

Trellix EDR struggles with high resource use, slow speed, poor integration, UI issues, and limited features and compatibility.
USM Anywhere needs improved performance, user interface, integration, and support, with better updates and less disruptive software changes.
I am seeing, for workflows, some sort of ethical hacking to test our environment.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Trellix Endpoint Detection and Response (EDR) is interesting and is a very good entry point that has been evolving through the last years.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks.
Co-Founder/Director at Bangkok MSP Company Limited
 

Setup Cost

Trellix EDR is priced reasonably, but advanced features and international factors can make it expensive for enterprise buyers.
USM Anywhere offers scalable, affordable SIEM solutions ideal for SMBs, recommended for budget-conscious enterprises over costly competitors.
 

Valuable Features

Trellix EDR provides advanced threat protection, real-time monitoring, and user-friendly management with integration of EDR and antivirus.
USM Anywhere offers event correlation, vulnerability scanning, and centralized logging with customizable, user-friendly security monitoring for small teams.
All the tree of data that we have, which may be a lot of information to argue whether it is going to be a threat or not, can be analyzed.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
I have spent efforts on training our managers and others - what can software do if the knowledge base is low?
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
The 365-day block query is a major feature.
Co-Founder/Director at Bangkok MSP Company Limited
 

Categories and Ranking

Trellix Endpoint Detection ...
Ranking in Endpoint Detection and Response (EDR)
22nd
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
24
Ranking in other categories
No ranking in other categories
USM Anywhere
Ranking in Endpoint Detection and Response (EDR)
45th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Log Management (37th), Security Information and Event Management (SIEM) (30th), Compliance Management (13th)
 

Mindshare comparison

As of February 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Trellix Endpoint Detection and Response (EDR) is 1.1%, up from 0.8% compared to the previous year. The mindshare of USM Anywhere is 0.6%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Market Share Distribution
ProductMarket Share (%)
Trellix Endpoint Detection and Response (EDR)1.1%
USM Anywhere0.6%
Other98.3%
Endpoint Detection and Response (EDR)
 

Featured Reviews

CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Cross-site threat hunting has improved visibility and supports proactive incident response
I believe this is a product in evolution. I do not think it is a final tool to conduct forensics or information forensics of the incidents or information incidents that could arise in our network infrastructure. Trellix Endpoint Detection and Response (EDR) is interesting and is a very good entry point that has been evolving through the last years. In the next two months, I have a new contract, and we are pointing out to have an XDR solution with NDR and EDR together. I do not have enough time to do it because I am the manager. However, my coworkers do not understand it yet. I have a contract with a third-party company that is making reports around that, but also they do not have enough experience or enough utility of this. It would be interesting if I have a notification system from EDR. For example, if I am the manager, it would be interesting to have a warning, alarm, or something around that which could call me to get into the system and the dashboard to see what is happening. For example, if it is a high-level threat. However, most of them are just advisory or warnings. I do not enter the tool frequently. I guess I access it once every three months.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
881,757 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Government
10%
Computer Software Company
9%
Manufacturing Company
8%
Computer Software Company
13%
Comms Service Provider
10%
Performing Arts
7%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise3
Large Enterprise10
By reviewers
Company SizeCount
Small Business64
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

What is your experience regarding pricing and costs for McAfee MVISION Endpoint Detection and Response?
I pay for what we get. But the service level from my partner company is not enough to overcome a complex case.
What needs improvement with McAfee MVISION Endpoint Detection and Response?
I believe this is a product in evolution. I do not think it is a final tool to conduct forensics or information forensics of the incidents or information incidents that could arise in our network i...
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
 

Also Known As

McAfee MVISION EDR, MVISION EDR, MVISION Endpoint Detection and Response
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Overview

 

Sample Customers

Sutherland Global Services
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about Trellix Endpoint Detection and Response (EDR) vs. USM Anywhere and other solutions. Updated: December 2025.
881,757 professionals have used our research since 2012.