Try our new research platform with insights from 80,000+ expert users
Trellix Endpoint Detection and Response (EDR) Logo

Trellix Endpoint Detection and Response (EDR) pros and cons

Vendor: Trellix
3.7 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Trellix Endpoint Detection and Response (EDR) offers stable and scalable endpoint protection capable of isolating and quarantining devices as well as blocking ransomware and other threats.
The guided analytics and EDR investigation feature is highly valuable for threat detection and response.
Automation, real-time search, and behavior monitoring have improved, integrating seamlessly with other systems for a comprehensive threat response.
Trellix EDR provides a straightforward setup and offers one-click recovery of encrypted files, enhancing user efficiency.
The tool autonomously detects malicious behavior, isolates threats, and supports cross-site management from the cloud.

CONS

McAfee MVISION Endpoint Detection and Response consumes significant CPU and RAM resources, impacting performance during scans.
The historical search capabilities and integration with external platforms are lacking, limiting effectiveness.
Alerts require manual portal login instead of automated notifications, necessitating improvements for timely threat awareness.
The ability to detect unknown fileless attacks is insufficient, requiring enhancement for comprehensive protection.
Issues with administrative scalability and technical support hinder effective management and user trust.
 

Trellix Endpoint Detection and Response (EDR) Pros review quotes

PN
Chief Information Security Officer at Romsons
Oct 20, 2020
This is a stable product.
SK
Solution architect at CSP
Apr 27, 2022
The most valuable feature I found in McAfee MVISION Endpoint Detection and Response is the guided analytics or guided EDR investigation.
RH
Senior Security and Risk Management Analyst at National Commercial Bank Jamaica Limited (NCB)
May 19, 2022
The most valuable features of the solution are the ability to isolate or quarantine devices and block or detect Ransomware and other well-known tools that are used to exploit vulnerabilities on devices.
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,036 professionals have used our research since 2012.
Moizuddin Sayed - PeerSpot reviewer
Senior IT Systems Administrator at IndusInd Bank ltd
Jul 3, 2022
It is a scalable solution and very easy to use.
AM
IT Security Specialist at Commercial Bank of Ethiopia
Jul 29, 2022
What we're using the most and what we found valuable in McAfee MVISION Endpoint Detection and Response are Web Control, Advanced Threat Protection, and Threat Prevention features.
Alex Lapinski - PeerSpot reviewer
Cyber Security & ICT Director at Polish Security Experts Association
Apr 11, 2023
It is a stable solution. Stability-wise, I rate the solution a nine out of ten...I rate the solution's technical support team a nine and a half or ten out of ten.
Christian Guillén - PeerSpot reviewer
Sales Manager at Last call
May 8, 2023
Blocking browser navigation is a feature of the solution with which we have experienced success.
Shashank-Gahoi - PeerSpot reviewer
Security Architect at a tech services company with 1,001-5,000 employees
Jul 18, 2023
If there is any malicious behavior in the workstation or server, the tool stops or isolates it automatically and generates alerts.
Hung-LE - PeerSpot reviewer
Group IT Manager at Discova
Nov 9, 2023
Trellix Endpoint Detection and Response (EDR) offers endpoint protection and helps collect information while also allowing users to investigate malicious files in an IT environment...It is a stable solution...It is a scalable solution.
RR
Head of Data Link at Telecom Egypt
Nov 30, 2023
The product's initial setup phase was very straightforward since you just need to install it, and it works.
 

Trellix Endpoint Detection and Response (EDR) Cons review quotes

PN
Chief Information Security Officer at Romsons
Oct 20, 2020
The main drawbacks are resources and processing time, as it consumes a lot of CPU and RAM.
SK
Solution architect at CSP
Apr 27, 2022
An area for improvement in McAfee MVISION Endpoint Detection and Response is the historical search. For example: when you have information on the artifact and a precedent, you want to do a search, and that is a bit lacking in the tool.
RH
Senior Security and Risk Management Analyst at National Commercial Bank Jamaica Limited (NCB)
May 19, 2022
The dashboard and reporting features are not so user-friendly or intuitive, so they need some work.
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,036 professionals have used our research since 2012.
Moizuddin Sayed - PeerSpot reviewer
Senior IT Systems Administrator at IndusInd Bank ltd
Jul 3, 2022
The endpoints and utilization are too high, which impacts the production activity.
AM
IT Security Specialist at Commercial Bank of Ethiopia
Jul 29, 2022
The alert feature of McAfee MVISION Endpoint Detection and Response needs improvement because for you to get the alerts, you have to log on to the portal. What my company needs is a tool that sends you alerts. For example, if it detects a threat on your machine, it should send you an alert. My company gets the alerts instead from the antivirus software rather than the EDR. If you want to see the alerts on McAfee MVISION Endpoint Detection and Response, you have to connect to the system manually. Another area for improvement in the tool is the reporting. My company needs weekly and monthly reports about the alerts, but you can't extract reports from McAfee MVISION Endpoint Detection and Response, so a decision was made to move to another EDR solution, particularly Microsoft Defender for Endpoint, next month. My company tested Microsoft Defender for Endpoint via a POC for one to three months. The resource usage of McAfee MVISION Endpoint Detection and Response is also an area for improvement because it consumes a lot of memory. For example, during the on-demand scan, you can't work because of the high CPU usage. You need to schedule the scans. McAfee MVISION Endpoint Detection and Response has a lot of modules, but my company doesn't use all modules.
Alex Lapinski - PeerSpot reviewer
Cyber Security & ICT Director at Polish Security Experts Association
Apr 11, 2023
The solution lacks the ability to integrate with external platforms. In future releases of the solution, I would like to see the solution increase its integration capabilities with external platforms.
Christian Guillén - PeerSpot reviewer
Sales Manager at Last call
May 8, 2023
For Spanish users, it is necessary to have a knowledge base specifically designed for them, which is currently not available.
Shashank-Gahoi - PeerSpot reviewer
Security Architect at a tech services company with 1,001-5,000 employees
Jul 18, 2023
The console has a lot of bugs, and it creates many issues.
Hung-LE - PeerSpot reviewer
Group IT Manager at Discova
Nov 9, 2023
The solution's downside stems from the fact that Trellix Endpoint Detection and Response (EDR) and McAfee MVISION Endpoint are not combined into a single solution, so from an improvement perspective, they need to be combined into a single solution.
RR
Head of Data Link at Telecom Egypt
Nov 30, 2023
One of the issues about the product stems from the failure to work on its administrative scalability. The aforementioned area can be considered for improvement.