
Overview
Make your organization more resilient and confident with Trellix Security Operations. Filter out the noise and cut complexity to deliver faster, more effective SecOps. Effortlessly unify your security ecosystem by connecting native Trellix controls with 500+ third-party tools.
Product Options:
- Trellix Helix
- Trellix ePO
- Trellix Enterprise Security Manager (ESM)
- Trellix Advanced Correlation Engine
- Trellix Global Threat Intelligence for ESM
Please contact aws@trellix.com before purchasing. These solutions may require additional add-on packs or specific licenses based on your organizational needs. Your account team will customize an AWS Private offer, reflecting appropriate quantities, SKUs, and qualified discounts.
Highlights
- Accelerate incident response
- Keep ahead of cyberthreats
- Unify your security tools
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
XDRECE-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $9,999.00 |
OX1ECE-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $20,925.00 |
EPOCDE-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $9,999.00 |
ELUVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $61,294.33 |
ELMVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $24,513.13 |
ELSVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $24,513.13 |
EV2VME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $15,317.83 |
ACVVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $26,045.69 |
APMVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $16,850.39 |
GTEELU12GIEAD | Use Request Private Offer (To Be Removed - Do Not Use) | $14,141.13 |
Vendor refund policy
Please contact aws@trellix.com for refund requests
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Standard support and customer success programs available support@trellix.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Advanced integrations have improved threat detection and now provide comprehensive attack visibility
What is our primary use case?
Trellix Helix Connect is typically used for monitoring hidden events, such as malware events that a normal team might not detect, including phishing attacks. This is the most powerful case of an XDR , enabling easy detection of phishing scams and malware events.
How has it helped my organization?
I assess the effectiveness of Trellix Helix Connect 's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike. It provides detailed visibility reports and granular reporting.
The orchestrated workflows of Trellix Helix Connect enhance threat response by providing detailed reporting, integration dashboards, and detailed feature reporting through Trellix ePolicy Orchestrator .
Metrics about the efficiency improvements Trellix Helix Connect has brought to our security operations demonstrate that its settings are the best when compared with other solutions in effectiveness.
What is most valuable?
The main advantage of Trellix Helix Connect is the vast integration with over 4,000 applications. This extensive support for integration is a major advantage of this product.
Trellix Helix Connect easily integrates with Office 365 and also integrates well with FortiGate, Palo Alto, and Barracuda, especially within AWS environments.
What needs improvement?
The weak point of Trellix Helix Connect is the data storage capacity; more storage must be purchased as the data grows, which is a disadvantage because the cost increases when more space is needed on the cloud.
It is quite costly, especially if the events are increasing daily. The overall solution is fine but requires purchasing more space on the cloud, which can be expensive.
For how long have I used the solution?
I have been working with Trellix Helix Connect for around four to seven years. Before Trellix Helix Connect, it was known as McAfee, and I worked with McAfee for around 18 to 20 years.
What do I think about the stability of the solution?
Earlier, the technical support from Trellix was not good, but currently, there has been very significant improvement in technical cases, and the responses are strong and very helpful.
How are customer service and support?
Earlier, the technical support from Trellix was not good, but currently, there has been very significant improvement in technical cases, and the responses are strong and very helpful.
I assess the effectiveness of Trellix Helix Connect's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike. It provides detailed visibility reports and granular reporting.
How was the initial setup?
The initial deployment of Trellix Helix Connect is neither easy nor complex; I would rate it as medium because if you are a technical person familiar with antivirus and security products, you can handle it.
What about the implementation team?
More people are needed for deployment; at least two or three people are necessary to cover all aspects and security postures in one solution, as it is not possible for one person to deploy everything.
Deployment for Trellix Helix Connect may take about two to three weeks if you are managing around 100 to 300 users.
Which other solutions did I evaluate?
I am currently also working with Microsoft, Kaspersky, and Symantec, along with Trellix Helix Connect.
I also work with Kaspersky and Symantec because they are cheaper solutions, but Trellix Helix Connect is the overall complete cybersecurity solution, covering all aspects in one package. That is why I prefer Trellix Helix Connect for cybersecurity.
What other advice do I have?
The orchestrated workflows of Trellix Helix Connect enhance threat response by providing detailed reporting, integration dashboards, and detailed feature reporting through Trellix ePolicy Orchestrator .
I rate the technical support from Trellix an eight out of ten.
I rate Trellix Helix Connect a nine out of ten as a product in general.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Reduces detection and response times through automation and alert correlation
What is our primary use case?
My main use case for Trellix Helix Connect is to provide an MDR service to our clients. We use Trellix Helix Connect to correlate the alerts and automate the response most often.
For example, we use Trellix Helix Connect for MDR services with our clients when we have XDR for Trellix Helix Connect to analyze the alerts and set up the SOAR workflows. It depends on the client needs.
In our day-to-day operations, we have the main use case of Trellix Helix Connect which allows us to reduce MTTD and MTTR, and we have the KPIs to support this.
What is most valuable?
The best features that Trellix Helix Connect offers are SOAR , automation, hyperautomation, and the correlation of alerts and threat intelligence, for example, when the alerts cross through MITRE ATT&CK, which stand out most to me.
Out of those features, automation, alert correlation, and threat intelligence have made my work easier and more effective as we integrate many cybersecurity solutions into the XDR and set up the use cases to reduce MTTD and MTTR from days to minutes.
I would add that the level of integration with other brands is something that surprises me about the features of Trellix Helix Connect.
Trellix Helix Connect has positively impacted my organization as it is the most important tool to provide MDR service to our clients, which has resulted in specific outcomes and improvements.
What needs improvement?
To improve Trellix Helix Connect, I think it is possible to enhance the dashboard to share more information about the incidents. For example, if I want to check a MITRE technique, maybe it is necessary to have a quick link to check this technique in the dashboard.
I think the usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements.
For how long have I used the solution?
I have been using Trellix Helix Connect for one year.
What do I think about the stability of the solution?
Trellix Helix Connect is very stable, and I have experienced almost no downtime or issues, as the downtime is mainly about maintenance time, confirming its reliability.
What do I think about the scalability of the solution?
Trellix Helix Connect's scalability is excellent as the solution has a library to make integrations with other brands, allowing it to handle growth easily via API.
How are customer service and support?
The customer support for Trellix Helix Connect is well in Latin America because there are many people in the region, which enhances the experience.
Which solution did I use previously and why did I switch?
I previously used legacy SIEMs before choosing Trellix Helix Connect.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that the licensing for XDR is good, though the hyperautomation feature is expensive.
What was our ROI?
We have seen a return on investment with Trellix Helix Connect, and we can share relevant metrics as we reduce the MTTD and MTTR and have KPIs indicating our ROI.
Which other solutions did I evaluate?
What other advice do I have?
The most important metrics are the reduced MTTD and MTTR because the clients' legacy solutions provide faster response when they use this tool, showing measurable benefits.
I advise anyone considering Trellix Helix Connect to review the different solutions of the XDR ecosystem, focusing on the capability to integrate with other brands without shadow cost and the capability to respond and reduce MTTD and MTTR. I would rate this product at a nine out of ten.
Experiencing frequent disconnections and support challenges but benefits from quick implementation and integration capabilities
What is our primary use case?
We use Trellix Helix Connect because it is a SaaS solution. I think it has its own infrastructure rather than AWS or another provider. We use the Helix SaaS and a component called Evidence Collector that gets the logs from on-premise infrastructure and sends them to SaaS. I believe everything about Trellix Helix Connect is SaaS-based.
We use Evidence Collector which can be installed with the on-premise infrastructure to collect components such as files and IPS. This product receives the logs from the infrastructure and sends the information to Helix.
What is most valuable?
The best feature of Trellix Helix Connect is its quick implementation.
The integration with Mandiant is another significant advantage. When investigating an incident, we have access to IOCs and can receive results from Mandiant about these IOCs, similar to what VirusTotal offers. We can search and utilize this integration effectively.
We utilize the artificial intelligence capabilities in Trellix Helix Connect. We can perform some customization by providing parameters in the YARA from Helix, which provides valuable analysis points.
The solution allows users to create reports more quickly with comprehensive information, which can be expanded within minutes. This demonstrates the effectiveness of Trellix Helix Connect's automation capabilities for reducing incident response times.
What needs improvement?
The timeout of the tenant is an area that needs improvement. When investigating and gathering information from the Helix tenant for extended periods, disconnections occur. This results in lost work and the need to restart investigations due to disconnected sessions.
It is problematic when progress is lost and investigations must be restarted, resulting in lost information and significant time wastage.
The capability to integrate with other TIPs or cybersecurity intelligence sources could be improved to determine whether IOCs are malicious, similar to Mandiant's functionality.
The capacity to reduce false positives needs improvement as we receive many alerts from Helix that turn out to be false positives upon investigation. Enhanced capability in this area would make the system more efficient and easier to use.
The dashboards could be improved as customers frequently request real-time SOC dashboard displays for Helix.
How are customer service and support?
The support for Trellix Helix Connect is not satisfactory. We experience difficulties accessing personnel with deep knowledge of Helix. We have numerous tickets to understand and resolve problems. It is not an easy product to support on a daily basis.
The support would rate a three out of ten. It can take one to four weeks to connect with someone who truly understands Helix and can provide solutions. This makes the product difficult to maintain.
What other advice do I have?
The solution can be challenging for analysts with lower skill levels. The syntax for finding findings requires specific knowledge, making it more difficult for initial users.
Trellix Helix Connect is generally easy to use, but the Evidence Collector component presents more challenges.
This review rates Trellix Helix Connect as 6 out of 10.
AI capabilities streamline incident resolution and natural language search empowers security management
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Helps us detect some advanced malware and offers some automated collaborations enabled internally
What is our primary use case?
It helps prevent web security threats and other things.
We use Trellix ePO. We also use Trellix Endpoint Security and DLP encryption.
How has it helped my organization?
We are currently integrated with fewer security devices. It helps us understand deductions and analysis and provides collaborative input as a first priority.
What is most valuable?
We are able to block some advanced malware and other things. I think we use the appliance-based Helix.
It helps us detect some advanced malware. That's one of the major advantages. We also have some automated collaborations enabled internally. So, if there's a new attack or alert, we have visibility on it.
However, we are not experts in automation, but we do get some automation in the Trellix product. We want to test it further.
What needs improvement?
Trellix needs to address the price for the product to be more appealing to customers.
For how long have I used the solution?
It has been anywhere between six months to a year.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. The scalability is good.
How are customer service and support?
It's proper support. So no delays. They always respond on time and the responses are informative.
Which solution did I use previously and why did I switch?
We chose Trellix among the variety of products on the market because other vendors support cloud-based threat intelligence, requiring us to interact with the cloud.
With Trellix Helix, we have on-premises offerings and we are able to collaborate on our logs within our premises. We don't want to send data outside our organization because we support banking customers. We can maintain everything internally.
How was the initial setup?
If you understand the concept of Trellix Helix, it's easy to deploy.
It took a couple of days. We haven't integrated it with any solutions yet. We just have some minimal solutions that need to be integrated. If we have any issues in the future, we'll let you know.pen_spark
What was our ROI?
There could be some financial benefits, but we are focused on security and threat prevention, not the financial aspect.
What's my experience with pricing, setup cost, and licensing?
It could be a bit expensive. I would give it an eight out of ten, with ten being expensive.
Which other solutions did I evaluate?
What other advice do I have?
I recommend Helix. I have a good experience with it. If I get a POC, I can easily give it to the customer and evaluate it.
The solution is stable and addresses advanced malware. It's also easy to access support in India.
Overall, I would rate it a nine out of ten.