Try our new research platform with insights from 80,000+ expert users
Senior Vice President IT at AS IT Consulting Pvt. Ltd.
Real User
Top 5Leaderboard
A scalable solution that provides a one-click recovery of encrypted files and excellent threat-hunting features
Pros and Cons
  • "The product provides a one-click recovery of encrypted files."
  • "The CPU utilization of the product is quite high compared to its competitors."

What is most valuable?

The product provides a one-click recovery of encrypted files. Threat hunting is marvelous.

What needs improvement?

The product must improve the ability to work with different operating systems like Windows and macOS. The CPU utilization of the product is quite high compared to its competitors. The agent file size is higher. The number of services that run on a system is quite high. Other EDR solutions have only a single service running on it.

For how long have I used the solution?

I have been working with the product from the day of inception. I am using the latest version of the solution.

What do I think about the stability of the solution?

The stability is good. I rate the stability a nine and a half out of ten.

Buyer's Guide
Trellix Endpoint Detection and Response (EDR)
July 2025
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,155 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I rate the tool’s scalability a ten out of ten. The solution is suitable for small, medium, and large enterprises.

How are customer service and support?

The support is great.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is simple. It can be done in a couple of days. The solution is cloud-based.

What's my experience with pricing, setup cost, and licensing?

The product’s aggressiveness in competing with the competitor's pricing is almost nil. The pricing is always high. I rate the pricing a three and a half out of ten.

Which other solutions did I evaluate?

We can compare the tool with SentinelOne and CrowdStrike. Kaspersky and Trend Micro cannot compete against the solution.

What other advice do I have?

People must always evaluate the product first. They must see the difference in manageability and flexibility of the licenses. They must also consider the manageability and flexibility of the software before making a decision. Overall, I rate the solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Moizuddin Sayed - PeerSpot reviewer
Senior IT Systems Administrator at IndusInd Bank ltd
Real User
A multiple feature solution that is stable, scalable and straightforward to implement
Pros and Cons
  • "It is a scalable solution and very easy to use."
  • "The endpoints and utilization are too high, which impacts the production activity."

What is our primary use case?

It has been helpful in terms of identifying unknown threats. The file is available on the endpoint, and the information is retrieved to identify any unknown or malicious file and then converted to a known file.

What needs improvement?

The endpoints and utilization are too high, which impacts the production activity. 

There are no additional features I would add. The McAfee MVISION Endpoint Detection and Response already has multiple features required for an IT solution.

For how long have I used the solution?

We have been using this solution for two years, and it is deployed on-premises.

What do I think about the stability of the solution?

From a solution point of view, it is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution and very easy to use in terms of hardware or sizing.

In terms of the number of users, because we are a banking environment, the IT department, bankers and people on the business side use this solution. Therefore, a minimum of five people is required to manage the environment. We currently use it to its full extent but plan to replace it.

How are customer service and support?

The technical support is very good, and we have never had problems with them.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We used a different solution for more than 15 years before we migrated to McAfee MVISION Endpoint Detection and Response.

How was the initial setup?

The initial setup was very straightforward. I rate the initial setup experience an eight out of ten. We used a third-party tool, and the deployment took a couple of months. 

What was our ROI?

Regarding ROI, I do not have precise numbers, but I rate it a four out of ten. 

What's my experience with pricing, setup cost, and licensing?

We have a perpetual license that is renewed annually. I do not know the specific price in terms of costs, but I rate the cost a six out of ten. We also get the whole package for this solution in a bundle.

Which other solutions did I evaluate?

Before we chose McAfee MVISION Endpoint Detection and Response, there were other options available like Carbon Black, Cisco and Trend Micro.

What other advice do I have?

If I were to advise on this solution, it would be that irrespective of the endpoint a company uses, it should have a good endpoint configuration. I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Trellix Endpoint Detection and Response (EDR)
July 2025
Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,155 professionals have used our research since 2012.
RiaanDu Preez - PeerSpot reviewer
Senior Cyber Security Specialist Architect at a tech consulting company with 11-50 employees
Real User
Top 5Leaderboard
Has behavior monitoring, DLP, and access control
Pros and Cons
  • "The most useful features are behavior monitoring, DLP, and access control. The automation has gotten much better in the last two years than when it was McAfee. It works better now and integrates more smoothly."
  • "I'd like the tool to become more like an XDR, with one management system and endpoint activation."

What is our primary use case?

I've used Trellix EDR to improve endpoints and servers' security and feed into MDR solutions.

What is most valuable?

The most useful features are behavior monitoring, DLP, and access control. The automation has gotten much better in the last two years than when it was McAfee. It works better now and integrates more smoothly.

What needs improvement?

I'd like the tool to become more like an XDR, with one management system and endpoint activation.

For how long have I used the solution?

I have been using the solution for seven years. 

What do I think about the stability of the solution?

Sometimes, stability issues come from incorrect partner deployments, not Trellix EDR itself.

What do I think about the scalability of the solution?

I rate the tool a seven out of ten. To improve it, I'd like a cloud-based management system where I only need to put a correlator at the client's site, as CyberArk does. The best setup would be cloud management, a manager in a VM, and super agents on endpoints.

How are customer service and support?

My opinion about technical support might be biased because I have direct access to top-level senior staff. I know some people struggle with support if they go through normal channels.

How would you rate customer service and support?

Positive

How was the initial setup?

Setting up the solution is easy for me because I've been in cybersecurity for almost 30 years, but new users might find it hard. Depending on the client's needs, it can be set up on-premises, in a private or hybrid cloud, or fully in the cloud. Setting it up can take a few days for small environments or months for big companies with thousands of endpoints.

What's my experience with pricing, setup cost, and licensing?

Pricing is a problem in South Africa. It could be cheaper here. The rand-to-dollar exchange rate makes it expensive for us. A 25 dollar endpoint cost becomes quite significant when converted to rand.

What other advice do I have?

Our clients are usually medium-sized and enterprise businesses. Overall, I would recommend Trellix EDR to others. I'd rate it eight and a half out of ten. No EDR or XDR solution gets a nine from me right now because they all have room for improvement. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Bernard Van Den Heuvel - PeerSpot reviewer
Professional Services Manager at Concanon LLC
Real User
Top 10
A user-friendly and integrated solution that includes EDR and antivirus
Pros and Cons
  • "The biggest strength of the solution is that it's an integrated product that includes EDR and antivirus."
  • "Some modules that are doing machine learning and artificial intelligence are blocking our processes."

What is our primary use case?

We're looking at the logs, and the customer defines the solution's use cases.

What is most valuable?

Trellix Endpoint Detection and Response is a user-friendly solution. The biggest strength of the solution is that it's an integrated product that includes EDR and antivirus. It's not like you have different technologies for different solutions.

What needs improvement?

Some modules that are doing machine learning and artificial intelligence are blocking our processes.

For how long have I used the solution?

I have been using Trellix Endpoint Detection and Response for one year.

What other advice do I have?

Overall, I rate Trellix Endpoint Detection and Response an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Christian Guillén - PeerSpot reviewer
Sales Manager at Last call
Reseller
Efficiently blocks traffic and browser navigation while offering ease of setup to its users
Pros and Cons
  • "Blocking browser navigation is a feature of the solution with which we have experienced success."
  • "For Spanish users, it is necessary to have a knowledge base specifically designed for them, which is currently not available."

What is our primary use case?

As a user, I didn't have any concerns about technical aspects where I was working previously. Working together. So, we sell licenses of McAfee. We had a promotional activity in which when you buy a cell phone, you get a McAfee subscription for mobile, and we used to offer a license of McAfee with an internet connection.

How has it helped my organization?

Blocking browser navigation is a feature of the solution with which we have experienced success.

What is most valuable?

The fact that it is easy to manage by consumers, families, small businesses, or parents while blocking traffic is a valuable feature of the solution.

What needs improvement?

For Spanish users, it is necessary to have a knowledge base specifically designed for them, which is currently not available.

Blocking other browsers should be a feature introduced in the solution. At this time, you can control Safari and Microsoft Edge. But I don't know about the other browsers.

For how long have I used the solution?

I have been using McAfee MVISION Endpoint Detection and Response for five years. We use the solution on mobile and in the cloud. Also, my company is a reseller.

What do I think about the stability of the solution?

There are issues with the solution on the other browsers. So, I don't know if any feature is enabled in the solution to resolve the issues.

What do I think about the scalability of the solution?

We have been providing a lot of licenses, and we never had a problem. So, it is a scalable product. For personal use in my family, I may have plans to use it.

How are customer service and support?

I rate the technical support a ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution's initial setup process was simple.

What was our ROI?

There has been a return on investment since it is a good business. Hence, we embedded the solution in our services. So, I know that this is a good investment.

What other advice do I have?

My company does provide the solution at a good price for our customers. The solution needs to support their Spanish customers. Overall, I rate the solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Shashank-Gahoi - PeerSpot reviewer
Security Architect at a tech services company with 1,001-5,000 employees
Real User
A scalable and easy-to-implement solution that provides timely alerts on malicious behavior in the server
Pros and Cons
  • "If there is any malicious behavior in the workstation or server, the tool stops or isolates it automatically and generates alerts."
  • "The console has a lot of bugs, and it creates many issues."

What is our primary use case?

The product works as a preventive tool. It checks for signatures as well as behaviors.

What is most valuable?

If there is any malicious behavior in the workstation or server, the tool stops or isolates it automatically and generates alerts. It creates reports on the incidents and provides the details to us. The product is very easy to scale and implement.

What needs improvement?

The product must focus on improving the appliances. The console has a lot of bugs, and it creates many issues. It is very tedious to troubleshoot the issues sometimes. The support team does not help. We solve our problems by testing things we find on Google and other forums where people give suggestions about the product. The product has very limited options for creating policies. The product could provide more options for creating policies. The options must be customizable according to the user’s requirements.

For how long have I used the solution?

I have been using the solution for more than two years.

What do I think about the stability of the solution?

I rate the tool’s stability an eight out of ten.

What do I think about the scalability of the solution?

The tool is scalable. We have implemented it across the organization. I would recommend the tool for both small and large companies.

How are customer service and support?

The support team is the worst. The support team must improve its knowledge.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

We used an anti-malware solution before we started using Trellix.

How was the initial setup?

The solution is deployed on the cloud. The initial setup was simple.

What about the implementation team?

The deployment took nearly a month. Trellix’s team helped us deploy the product. They were helpful during the purchasing and implementation process. Four or five people in the organization manage and maintain the solution.

What's my experience with pricing, setup cost, and licensing?

The product’s pricing is reasonable. However, we have to have a minimum contract of three years. The licensing model is not so good. Advanced threat intelligence features are very expensive.

What other advice do I have?

We are planning to change the vendor. We have one more year of contract on the product. Companies must use EDR, but they must research before choosing vendors. Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Alex Lapinski - PeerSpot reviewer
Cyber Security & ICT Director at Polish Security Experts Association
Real User
Top 5
A solution that efficiently detects the early stages of cyberattacks and offers a sound technical support to its users
Pros and Cons
  • "It is a stable solution. Stability-wise, I rate the solution a nine out of ten...I rate the solution's technical support team a nine and a half or ten out of ten."
  • "The solution lacks the ability to integrate with external platforms. In future releases of the solution, I would like to see the solution increase its integration capabilities with external platforms."

What is our primary use case?

My company's clients use the solution to detect the early stages of attacks and to react to the strange things that happen on the endpoints.

What is most valuable?

Visualization of cyberattacks is one of the most valuable features of the solution.

What needs improvement?

It is tough to comment on what needs improvement in the solution. At the moment, it is difficult to recall and comment on what needs to improve in the solution.

The solution lacks the ability to integrate with external platforms. In future releases of the solution, I would like to see the solution increase its integration capabilities with external platforms. At this moment, I want the solution to integrate with more XDR tools. The solution should provide its users an ease of administration in future releases.

My company has spoken to McAfee about their solution being on the pricier side. So, McAfee is aware that there is room for improvement in its pricing strategy.

For how long have I used the solution?

I have been using McAfee MVISION Endpoint Detection and Response for over two years. So, my company has a partnership with McAfee. Though I don't remember the version of the solution I am working on, it is the latest one since it is a common security practice to use the updated version of the tool.

What do I think about the stability of the solution?

It is a stable solution. Stability-wise, I rate the solution a nine out of ten.

What do I think about the scalability of the solution?

I won't be able to comment on the solution's scalability since, at the moment, we do not need to consider scalability or expansion. However, it is probably easy to scale up since the solution is deployed on AWS. My company has clients who run small, medium, and enterprise-sized businesses. The number of uses using the solution depends upon the company or business size. So, there have been times when a client using the solution has over 1000 users using the tool.

How are customer service and support?

I rate the solution's technical support team a nine and a half or ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution's initial setup process was easy and straightforward. On a scale of one to ten, where one is difficult and ten is very easy, I rate the solution's initial setup a ten out of ten. The solution is usually deployed on the cloud platform.

The solution is usually deployed on the cloud platform. Though unsure, I feel the solution is deployed using AWS since I am referring to the users in Europe. The deployment process took place over a few days. The deployment process is covered by the client and distribution services team. The deployment process involves fire and forget, wherein the agent is sent to the user. All the settings are within the agents, and only the installation needs to be done for the deployment process to be completed.

What's my experience with pricing, setup cost, and licensing?

On a scale of one to ten, where one is low and ten is high, I rate the solution's pricing an eight out of ten. McAfee MVISION Endpoint Detection and Response is pricey compared to other solutions in the market.

Though I cannot remember the approximate licensing cost of the solution, it would definitely depend upon the customer, the overall pricing of the solution, and the additional features.

One needs to incur retention costs in addition to the standard licensing fees paid for the solution.

What other advice do I have?

I would tell those planning to use the solution in the future that if they already have McAfee products, then they should go for it since the solution integrates well with other McAfee tools and with some endpoint protection platforms or DLP that are deployed on-premises.

The software will have bugs in them at some point, and bug-related issues are to be taken care of by technical support. Our company reports such issues, and the technical support team tries to resolve them. Presently, this process works well for us. Overall, I rate the product an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Solution architect at CSP
Real User
Scalable and stable tool for threat hunting and threat response, with guided investigation and analysis features
Pros and Cons
  • "The most valuable feature I found in McAfee MVISION Endpoint Detection and Response is the guided analytics or guided EDR investigation."
  • "An area for improvement in McAfee MVISION Endpoint Detection and Response is the historical search. For example: when you have information on the artifact and a precedent, you want to do a search, and that is a bit lacking in the tool."

What is our primary use case?

I'm a consultant. One of my clients was experiencing attacks on one of his endpoints, so we installed McAfee MVISION Endpoint Detection and Response, and we used it to check if the other endpoints were also being attacked. This is one of the uses cases of the solution: threat hunting.

Another use case is that McAfee MVISION Endpoint Detection and Response consolidates all the information back to the MVISION Insights, so that's threat intelligence information, and we match whatever IOC we have, together with the current attack campaign data in the McAfee databases.

What is most valuable?

The most valuable feature I found in McAfee MVISION Endpoint Detection and Response is the guided analytics or guided EDR investigation. Normally, when you use an EDR solution, you need to have an analyst to understand all the artifacts, then you come up with the question and come up with the answers. With the guided investigation feature in McAfee MVISION Endpoint Detection and Response, DoD is easier, because the tool does the analysis itself, based on the artifact, then it maps back into the MITRE Framework and gives us all the answers.

What needs improvement?

An area for improvement in McAfee MVISION Endpoint Detection and Response is the historical search. For example: when you have information on the artifact and a precedent, you want to do a search, and that is a bit lacking in the tool.

Another area for improvement is in the automation feature of McAfee MVISION Endpoint Detection and Response, because it still needs some work in terms of integration.

What I'd like in the next release of McAfee MVISION Endpoint Detection and Response is the ability to use it with a newer security platform. This means that the information you get from network parameters such as IPS and firewalls can be pumped back to the tool, so we can match all the information to do better threat hunting. Threat hunting is only on the endpoints, so if McAfee MVISION Endpoint Detection and Response could cover everything, that would be good.

For how long have I used the solution?

We've been using McAfee MVISION Endpoint Detection and Response for a year, and we're using its latest version.

What do I think about the stability of the solution?

The stability and performance of McAfee MVISION Endpoint Detection and Response are quite good, especially because it's still using the same agent. It doesn't require hardware, as long as there's good internet connectivity, for example: the bandwidth of the customer in the office is quite good, so the tool seems okay. I don't see anything lacking in terms of its performance. It's quite a good tool.

What do I think about the scalability of the solution?

Because McAfee MVISION Endpoint Detection and Response is deployed on cloud, scalability is not an issue. You have to look at scalability in terms of the endpoint agent. If the endpoint control panel is good enough or is large enough, scalability is good enough, so it won't be much of an issue.

How are customer service and support?

McAfee technical support has been not that great in the past two months, and it could be because they just merged with another company. Their level of support was high previously, but now it's not so good, and it's not on par with what I expect. On a scale of one to five, I would rate their support a three.

How was the initial setup?

We already have the baseline for the current endpoint, so deploying McAfee MVISION Endpoint Detection and Response was simpler.

What about the implementation team?

I was the one who did the deployment for a customer, and it was quite straightforward. Because we already have the baseline and we used the same engine and the same integration, deployment of McAfee MVISION Endpoint Detection and Response took less than two days.

What's my experience with pricing, setup cost, and licensing?

Pricing for McAfee MVISION Endpoint Detection and Response is not that expensive, but it's not something that a startup could buy. Pricing for it is for midsized businesses.

There's an additional payment if you want data retention for more than thirty days. They gave us data retention for thirty days. Then if you want longer data retention, they have the paid option for a three-month data retention period and for a one-year data retention period.

What other advice do I have?

We don't use any backup protection, but previously, we used Commvault for backups.

In terms of maintaining the tool, you don't have to do a lot of fine tuning, because the fine tuning will happen on the endpoint protection, in particular, the tool will do all the hunting. What we just need to do is to monitor the data location and the database.

My rating for McAfee MVISION Endpoint Detection and Response is eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Download our free Trellix Endpoint Detection and Response (EDR) Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free Trellix Endpoint Detection and Response (EDR) Report and get advice and tips from experienced pros sharing their opinions.