This is more of a cloud-based clientless type solution, for file-based security.
Sr. Sales Engineer at a tech services company with 11-50 employees
Scalable with a good strategy when everything is in place
What is our primary use case?
What is most valuable?
The solution is scalable and the product has a good strategy when everything is in place.
What needs improvement?
One of their issues is that they were very much based on agents, whereas most of the other solutions are clientless. There were a lot of legacy issues and they needed to evolve to more of the current operating systems of Microsoft for endpoint systems and PCs. If you're clientless, your cloud-based applications sit on top of the operating system and are not built into it.
What do I think about the stability of the solution?
It's reasonably stable. They made some changes to the architecture and that always creates issues.
Buyer's Guide
Trellix Endpoint Detection and Response (EDR)
May 2025

Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
They had pretty good tech support. I think a lot of what happened to McAfee, from my perspective, was everything went offshore to India and for US customers, there is a language barrier that created problems.
How was the initial setup?
The initial setup was relatively complicated and used a lot of resources - CPU resources, memory, disk.
What other advice do I have?
There are a lot of companies in this space now and they are all pretty close to each other in terms of what they offer. I think those that are more user-friendly, and have the agentless client have the advantage over the legacy companies with older architecture.
They lost a lot of product managers and engineering managers in the breakup. That said, I think this is a good product with a good strategy, they just haven't quite reached maturity yet.
I rate this solution eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Solution architect at CSP
Scalable and stable tool for threat hunting and threat response, with guided investigation and analysis features
Pros and Cons
- "The most valuable feature I found in McAfee MVISION Endpoint Detection and Response is the guided analytics or guided EDR investigation."
- "An area for improvement in McAfee MVISION Endpoint Detection and Response is the historical search. For example: when you have information on the artifact and a precedent, you want to do a search, and that is a bit lacking in the tool."
What is our primary use case?
I'm a consultant. One of my clients was experiencing attacks on one of his endpoints, so we installed McAfee MVISION Endpoint Detection and Response, and we used it to check if the other endpoints were also being attacked. This is one of the uses cases of the solution: threat hunting.
Another use case is that McAfee MVISION Endpoint Detection and Response consolidates all the information back to the MVISION Insights, so that's threat intelligence information, and we match whatever IOC we have, together with the current attack campaign data in the McAfee databases.
What is most valuable?
The most valuable feature I found in McAfee MVISION Endpoint Detection and Response is the guided analytics or guided EDR investigation. Normally, when you use an EDR solution, you need to have an analyst to understand all the artifacts, then you come up with the question and come up with the answers. With the guided investigation feature in McAfee MVISION Endpoint Detection and Response, DoD is easier, because the tool does the analysis itself, based on the artifact, then it maps back into the MITRE Framework and gives us all the answers.
What needs improvement?
An area for improvement in McAfee MVISION Endpoint Detection and Response is the historical search. For example: when you have information on the artifact and a precedent, you want to do a search, and that is a bit lacking in the tool.
Another area for improvement is in the automation feature of McAfee MVISION Endpoint Detection and Response, because it still needs some work in terms of integration.
What I'd like in the next release of McAfee MVISION Endpoint Detection and Response is the ability to use it with a newer security platform. This means that the information you get from network parameters such as IPS and firewalls can be pumped back to the tool, so we can match all the information to do better threat hunting. Threat hunting is only on the endpoints, so if McAfee MVISION Endpoint Detection and Response could cover everything, that would be good.
For how long have I used the solution?
We've been using McAfee MVISION Endpoint Detection and Response for a year, and we're using its latest version.
What do I think about the stability of the solution?
The stability and performance of McAfee MVISION Endpoint Detection and Response are quite good, especially because it's still using the same agent. It doesn't require hardware, as long as there's good internet connectivity, for example: the bandwidth of the customer in the office is quite good, so the tool seems okay. I don't see anything lacking in terms of its performance. It's quite a good tool.
What do I think about the scalability of the solution?
Because McAfee MVISION Endpoint Detection and Response is deployed on cloud, scalability is not an issue. You have to look at scalability in terms of the endpoint agent. If the endpoint control panel is good enough or is large enough, scalability is good enough, so it won't be much of an issue.
How are customer service and support?
McAfee technical support has been not that great in the past two months, and it could be because they just merged with another company. Their level of support was high previously, but now it's not so good, and it's not on par with what I expect. On a scale of one to five, I would rate their support a three.
How was the initial setup?
We already have the baseline for the current endpoint, so deploying McAfee MVISION Endpoint Detection and Response was simpler.
What about the implementation team?
I was the one who did the deployment for a customer, and it was quite straightforward. Because we already have the baseline and we used the same engine and the same integration, deployment of McAfee MVISION Endpoint Detection and Response took less than two days.
What's my experience with pricing, setup cost, and licensing?
Pricing for McAfee MVISION Endpoint Detection and Response is not that expensive, but it's not something that a startup could buy. Pricing for it is for midsized businesses.
There's an additional payment if you want data retention for more than thirty days. They gave us data retention for thirty days. Then if you want longer data retention, they have the paid option for a three-month data retention period and for a one-year data retention period.
What other advice do I have?
We don't use any backup protection, but previously, we used Commvault for backups.
In terms of maintaining the tool, you don't have to do a lot of fine tuning, because the fine tuning will happen on the endpoint protection, in particular, the tool will do all the hunting. What we just need to do is to monitor the data location and the database.
My rating for McAfee MVISION Endpoint Detection and Response is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Trellix Endpoint Detection and Response (EDR)
May 2025

Learn what your peers think about Trellix Endpoint Detection and Response (EDR). Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
Detect different threats but difficult to manage
Pros and Cons
- "Trellix has a user-friendly interface."
- "Trellix does not support Linux and Mac."
What is our primary use case?
We use the solution to detect different threats.
What is most valuable?
Trellix has a user-friendly interface.
What needs improvement?
Everything is normal, but it's not up to the mark compared to other solutions. It isn't easy to manage. The detection rate is also not reasonable. Trellix does not support Linux and Mac.
For how long have I used the solution?
I have used Trellix Endpoint Detection and Response (EDR) for 1 year.
What do I think about the stability of the solution?
I rate the solution’s stability a six out of ten.
What do I think about the scalability of the solution?
Earlier, 10,000 users were using this solution.
I rate the solution’s scalability a six out of ten.
How are customer service and support?
Support is good. They provide a swift response.
Which solution did I use previously and why did I switch?
I have used Symantec. It is a user-friendly solution with good performance and easy deployment. Support is also good.
How was the initial setup?
The initial setup is easy. We use email deployment. Sometimes, we use third-party tools like SSCM to deploy.
What's my experience with pricing, setup cost, and licensing?
The product has agent-based costs.
What other advice do I have?
We need to get special training for maintenance. Maintenance is very easy, but it requires engineers.
Overall, I rate the solution a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security and Risk Management Analyst at National Commercial Bank Jamaica Limited (NCB)
Quarantines devices and blocks ransomware, but dashboard and reporting features are not user-friendly
Pros and Cons
- "The most valuable features of the solution are the ability to isolate or quarantine devices and block or detect Ransomware and other well-known tools that are used to exploit vulnerabilities on devices."
- "The dashboard and reporting features are not so user-friendly or intuitive, so they need some work."
What is our primary use case?
We use this solution to protect our endpoints, meaning our workstation laptops.
What is most valuable?
The most valuable features of the solution are the ability to isolate or quarantine devices and block or detect Ransomware and other well-known tools that are used to exploit vulnerabilities on devices.
What needs improvement?
The dashboard and reporting features are not so user-friendly or intuitive, so they need some work.
In terms of being able to detect new threats, it would be good if the solution was not so dependent on a signature base, but instead offered a more rapid release for being able to detect zero-days.
For how long have I used the solution?
My company has been using McAfee MVISION Endpoint Detection and Response for about seven months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is easily scalable.
How are customer service and support?
Their technical support is better than some of the competitors in the space. To make a direct comparison, it's definitely better than Symantec Broadcom.
How was the initial setup?
The initial setup takes a bit of work, but it can be done. It's not easy. It's not hard. It's in between.
What other advice do I have?
I would rate this solution as a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Security Officer at Romsons
Resource-heavy, slow processing time, and bad technical support
Pros and Cons
- "This is a stable product."
- "The main drawbacks are resources and processing time, as it consumes a lot of CPU and RAM."
What is our primary use case?
I have upgraded to EDR for endpoint protection.
What is most valuable?
Feature-wise, this product is similar to other EDRs.
What needs improvement?
The main drawbacks are resources and processing time, as it consumes a lot of CPU and RAM.
The alert system should be improved.
Technical support is in need of improvement.
The dashboard should be improved because it needs a fresh look.
Improvement in the centralized policy enforcement is needed.
For how long have I used the solution?
I have been using this product for three years.
What do I think about the stability of the solution?
This is a stable product.
What do I think about the scalability of the solution?
The scalability is okay, although not much more than that.
How are customer service and technical support?
This is the worst technical support. Without OEM support, you can't handle this product. OEM support is mandatory, yet sometimes, they are not capable of installing and implementing the product properly.
Which solution did I use previously and why did I switch?
I was using McAfee DLP for Endpoint protection, but it is not very strong. This is why I have upgraded to the EDR solution.
How was the initial setup?
We did not have any issues with configuration. However, in terms of implementation, we had a lot of issues. There is complexity in policy aggregation. When you upgrade the client, there is a challenge in policy enforcement.
Initially, it will take about one month to deploy.
What's my experience with pricing, setup cost, and licensing?
The cost is okay, compared to other products.
Which other solutions did I evaluate?
We have been looking at replacing McAfee with Trend Micro, but to change our setup is a big task. It is very complex and we need a plan, so are just upgrading instead of changing at this time.
What other advice do I have?
My advice for anybody looking into implementing this product is to first look into who will be providing the support. If they do not have good capabilities and the support is not very strong, then do not choose this option.
I would rate this solution a three out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Support Engineer at Mu Sigma Inc.
User-friendly, reasonably priced, helps with real-time monitoring, and improves security posture
Pros and Cons
- "The product is user-friendly."
- "The graphical view for nodes must be increased."
What is our primary use case?
The solution is used for threat hunting and incident response.
What is most valuable?
Trellix is a good solution. It helps with real-time monitoring and alerts. We are pretty satisfied with it. The product is user-friendly. It improves our security posture.
What needs improvement?
The graphical view for nodes must be increased.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
The tool’s stability is good.
What do I think about the scalability of the solution?
The tool is scalable.
How was the initial setup?
We need three to four months to learn the tool. We were given training. It is not difficult if we read the documents properly.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable.
What other advice do I have?
We were looking for other solutions. Whoever is interested in the product can learn to use it. Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Its scalability is valuable for my use cases, but it should be more compatible with macOS
What is our primary use case?
Please share how Trellix Endpoint Detection and Response has improved your organization. If it didn't, please explain why.
What needs improvement?
The solution should be more compatible with macOS.
What do I think about the stability of the solution?
The solution is stable. I rate it a nine out of ten.
What do I think about the scalability of the solution?
The solution is scalable. Since we are from the banking industry, we have 10,000 users for the solution.
What about the implementation team?
We have two architects, five engineers and two technical support personnel for deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing for Trellix Endpoint Detection and Response (EDR) is good.
What other advice do I have?
I rate Trellix Endpoint Detection and Response a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Trellix Endpoint Detection and Response (EDR) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Endpoint Detection and Response (EDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
IBM Security QRadar
Trellix Endpoint Security Platform
Trend Vision One Endpoint Security
Cisco Secure Endpoint
VMware Carbon Black Endpoint
Kaspersky Endpoint Detection and Response
Sangfor Endpoint Secure
Trellix Active Response
Buyer's Guide
Download our free Trellix Endpoint Detection and Response (EDR) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?
- What is the best EDR or XDR product for a company with 9000 employees?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Do we need to use both EDR and Antivirus (AV) solutions for better protection of IT assets?
- How does EternalBlue work?
- What are the best on-premise Endpoint Security solutions for a Tech Services company with 10,000 employees?
- Which is better for Endpoint Security: EDR or XDR solutions?