No more typing reviews! Try our Samantha, our new voice AI agent.
Trellix Endpoint Detection and Response (EDR) Logo

Trellix Endpoint Detection and Response (EDR) pros and cons

Vendor: Trellix
3.9 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Trellix Endpoint Detection and Response (EDR) offers comprehensive endpoint protection, enabling the automatic isolation of malicious behavior and generating alerts for enhanced security.
The integration of guided analytics and advanced investigative capabilities significantly improves detection and response times, ensuring thorough threat management.
Trellix Endpoint Detection and Response (EDR) excels in scalability and stability, allowing for effective management across a Wide Area Network and multiple sites.
Your organization can benefit from the reduction of business risks, expedited incident responses, and a strengthened security posture through Trellix Endpoint Detection and Response (EDR).
Trellix Endpoint Detection and Response (EDR) utilizes behavior-based detection and AI-guided investigations to deliver significant time savings and precise threat analysis, enhancing operational efficiency.

CONS

High CPU and memory consumption, particularly on servers, impacts performance negatively.
Technical support is inadequate, often slow, with insufficiently skilled engineers and OEM dependency.
Historical search capabilities and integration with external platforms require improvement.
The lack of alert mechanism and reporting capabilities leads companies to consider alternative options.
Agent resource optimization on high-load servers and improved API flexibility are needed.
 

Trellix Endpoint Detection and Response (EDR) Pros review quotes

Duncan  Kims - PeerSpot reviewer
Business Development Manager at a retailer with 10,001+ employees
Apr 14, 2026
Trellix Endpoint Detection and Response (EDR) has positively impacted my organization with threat exchange and intel, low false positive ratios, and very high uptime values for both inline and spam modes, along with advanced detection and mitigation capabilities ensuring the highest level of protection and proper detection for command and control and bot attacks.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 7, 2026
Trellix Endpoint Detection and Response (EDR) is valuable because we have a Wide Area Network with many sites, and the EDR is cross-site since it is installed and managed from the cloud.
Domit-Molina - PeerSpot reviewer
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
Jun 23, 2026
Trellix Endpoint Detection and Response (EDR) scores highly because of its sheer depth of endpoint visibility, the precision of its behavior-based detection, and the massive time savings we get from its AI-guided investigations.
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,344 professionals have used our research since 2012.
Abubakar Bello - PeerSpot reviewer
Security Administrator at a insurance company with 1,001-5,000 employees
Mar 19, 2026
Trellix Endpoint Detection and Response (EDR) does everything; it saves time, it saves money, and of course, it provides peace of mind.
Domit-Molina - PeerSpot reviewer
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
Jul 28, 2026
Trellix Endpoint Detection and Response (EDR) has positively impacted my organization by improving visibility into security events on endpoints and servers, enabling the early detection of suspicious activities, reducing investigation times, and strengthening our monitoring processes and operational efficiency through analysis, Threat Hunting, and remote response.
IM
Senior Information Security Specialist at a consultancy with 51-200 employees
Jun 13, 2026
My advice for others considering Trellix Endpoint Detection and Response (EDR) is to use it, or any other Trellix products, as I believe they are excellent.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 3, 2025
The product and the services we have are quite good.
RiaanDu Preez - PeerSpot reviewer
Senior Cyber Security Specialist Architect at a outsourcing company with 11-50 employees
Aug 15, 2024
The most useful features are behavior monitoring, DLP, and access control. The automation has gotten much better in the last two years than when it was McAfee. It works better now and integrates more smoothly.
RR
Head of Data Link at Telecom Egypt
Nov 30, 2023
The product's initial setup phase was very straightforward since you just need to install it, and it works.
Juan Muriel - PeerSpot reviewer
IT Management Specialist at a computer software company with 10,001+ employees
Feb 22, 2024
When Trellix detects some threats, the device is isolated in a quarantine zone for examination.
 

Trellix Endpoint Detection and Response (EDR) Cons review quotes

Duncan  Kims - PeerSpot reviewer
Business Development Manager at a retailer with 10,001+ employees
Apr 14, 2026
One area where Trellix Endpoint Detection and Response (EDR) can be improved is the lack of device or user mapping.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 7, 2026
The tools are not useful for that.
Domit-Molina - PeerSpot reviewer
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
Jun 23, 2026
From an operational standpoint, the first area of improvement would be agent resource optimization, especially for high-load servers, because Trellix Endpoint Detection and Response (EDR) captures an incredible depth of telemetry and real-time forensics.
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,344 professionals have used our research since 2012.
Abubakar Bello - PeerSpot reviewer
Security Administrator at a insurance company with 1,001-5,000 employees
Mar 19, 2026
Initially, I was using it on servers, but it consumes a lot of resources on servers.
Domit-Molina - PeerSpot reviewer
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
Jul 28, 2026
Although Trellix Endpoint Detection and Response (EDR) offers those detection, investigation and response capabilities, one area for improvement could be the expansion and increased flexibility of its APIs.
IM
Senior Information Security Specialist at a consultancy with 51-200 employees
Jun 13, 2026
I also think performance needs improvement, especially for servers, as the Trellix HX module uses high CPU, scans constantly, and negatively impacts the performance for our clients' users or our servers.
CESARCASTRO - PeerSpot reviewer
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Jan 3, 2025
I need some protection, possibly multi-factor authentication improvements.
RiaanDu Preez - PeerSpot reviewer
Senior Cyber Security Specialist Architect at a outsourcing company with 11-50 employees
Aug 15, 2024
I'd like the tool to become more like an XDR, with one management system and endpoint activation.
RR
Head of Data Link at Telecom Egypt
Nov 30, 2023
One of the issues about the product stems from the failure to work on its administrative scalability. The aforementioned area can be considered for improvement.
Juan Muriel - PeerSpot reviewer
IT Management Specialist at a computer software company with 10,001+ employees
Feb 22, 2024
The technical support must be improved.