
Overview
Make your organization more resilient and confident with Trellix Security Operations. Filter out the noise and cut complexity to deliver faster, more effective SecOps. Effortlessly unify your security ecosystem by connecting native Trellix controls with 500+ third-party tools.
Product Options:
- Trellix Helix Connect
- Trellix ePO
- Trellix Enterprise Security Manager (ESM)
- Trellix Advanced Correlation Engine
- Trellix Global Threat Intelligence for ESM
Please contact aws@trellix.com before purchasing. These solutions may require additional add-on packs or specific licenses based on your organizational needs. Your account team will customize an AWS Private offer, reflecting appropriate quantities, SKUs, and qualified discounts.
Highlights
- Accelerate incident response
- Keep ahead of cyberthreats
- Unify your security tools
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
XDRECE-AA | Trellix XDR - Per User Pricing (1 yr) | $60.00 |
OX1ECE-AA | Trellix Open XDR for External Data Add-on - 50 GB | $20,925.00 |
EPOCDE-AA | Trellix ePolicy Orchestrator (ePO, On-Prem) - Per Node Pricing (1 yr) | $37.50 |
ELUVME-AA | Trellix Virtual Enterprise Security Manager SIEM - Per VM Pricing | $61,294.33 |
ELMVME-AA | Trellix Virtual Enterprise Log Manager VM - Per VM Pricing | $24,513.13 |
ELSVME-AA | Trellix Virtual Enterprise Log Search VM - Per VM Pricing | $24,513.13 |
EV2VME-AA | Trellix Event Receiver VM - Per VM Pricing | $15,317.83 |
ACVVME-AA | Trellix Virtual Advanced Correlation Engine VM - Per VM Pricing | $26,045.69 |
APMVME-AA | Trellix Application Data Monitor | $16,850.39 |
GTEELU12GIEAD | Trellix Global Threat Intelligence Module for ESM - Per ESM Appliance | $14,141.13 |
Vendor refund policy
Please contact aws@trellix.com for refund requests
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Standard support and customer success programs available support@trellix.comÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Reduces detection and response times through automation and alert correlation
What is our primary use case?
My main use case for Trellix Helix Connect is to provide an MDR service to our clients. We use Trellix Helix Connect to correlate the alerts and automate the response most often.
For example, we use Trellix Helix Connect for MDR services with our clients when we have XDRÂ for Trellix Helix Connect to analyze the alerts and set up the SOARÂ workflows. It depends on the client needs.
In our day-to-day operations, we have the main use case of Trellix Helix Connect which allows us to reduce MTTD and MTTR, and we have the KPIs to support this.
What is most valuable?
The best features that Trellix Helix Connect offers are SOARÂ , automation, hyperautomation, and the correlation of alerts and threat intelligence, for example, when the alerts cross through MITRE ATT&CK, which stand out most to me.
Out of those features, automation, alert correlation, and threat intelligence have made my work easier and more effective as we integrate many cybersecurity solutions into the XDRÂ and set up the use cases to reduce MTTD and MTTR from days to minutes.
I would add that the level of integration with other brands is something that surprises me about the features of Trellix Helix Connect.
Trellix Helix Connect has positively impacted my organization as it is the most important tool to provide MDR service to our clients, which has resulted in specific outcomes and improvements.
What needs improvement?
To improve Trellix Helix Connect, I think it is possible to enhance the dashboard to share more information about the incidents. For example, if I want to check a MITRE technique, maybe it is necessary to have a quick link to check this technique in the dashboard.
I think the usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements.
For how long have I used the solution?
I have been using Trellix Helix Connect for one year.
What do I think about the stability of the solution?
Trellix Helix Connect is very stable, and I have experienced almost no downtime or issues, as the downtime is mainly about maintenance time, confirming its reliability.
What do I think about the scalability of the solution?
Trellix Helix Connect's scalability is excellent as the solution has a library to make integrations with other brands, allowing it to handle growth easily via API.
How are customer service and support?
The customer support for Trellix Helix Connect is well in Latin America because there are many people in the region, which enhances the experience.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used legacy SIEMs before choosing Trellix Helix Connect.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that the licensing for XDR is good, though the hyperautomation feature is expensive.
What was our ROI?
We have seen a return on investment with Trellix Helix Connect, and we can share relevant metrics as we reduce the MTTD and MTTR and have KPIs indicating our ROI.
Which other solutions did I evaluate?
Before selecting Trellix Helix Connect, I evaluated other options including Palo Alto XDR, Cisco XDRÂ , and Rapid7 with the new generation SIEMÂ .
What other advice do I have?
The most important metrics are the reduced MTTD and MTTR because the clients' legacy solutions provide faster response when they use this tool, showing measurable benefits.
I advise anyone considering Trellix Helix Connect to review the different solutions of the XDR ecosystem, focusing on the capability to integrate with other brands without shadow cost and the capability to respond and reduce MTTD and MTTR. I would rate this product at a nine out of ten.
Experiencing frequent disconnections and support challenges but benefits from quick implementation and integration capabilities
What is our primary use case?
We use Trellix Helix Connect because it is a SaaS solution. I think it has its own infrastructure rather than AWS or another provider. We use the Helix SaaS and a component called Evidence Collector that gets the logs from on-premise infrastructure and sends them to SaaS. I believe everything about Trellix Helix Connect is SaaS-based.
We use Evidence Collector which can be installed with the on-premise infrastructure to collect components such as files and IPS. This product receives the logs from the infrastructure and sends the information to Helix.
What is most valuable?
The best feature of Trellix Helix Connect is its quick implementation.
The integration with Mandiant is another significant advantage. When investigating an incident, we have access to IOCs and can receive results from Mandiant about these IOCs, similar to what VirusTotal offers. We can search and utilize this integration effectively.
We utilize the artificial intelligence capabilities in Trellix Helix Connect. We can perform some customization by providing parameters in the YARA from Helix, which provides valuable analysis points.
The solution allows users to create reports more quickly with comprehensive information, which can be expanded within minutes. This demonstrates the effectiveness of Trellix Helix Connect's automation capabilities for reducing incident response times.
What needs improvement?
The timeout of the tenant is an area that needs improvement. When investigating and gathering information from the Helix tenant for extended periods, disconnections occur. This results in lost work and the need to restart investigations due to disconnected sessions.
It is problematic when progress is lost and investigations must be restarted, resulting in lost information and significant time wastage.
The capability to integrate with other TIPs or cybersecurity intelligence sources could be improved to determine whether IOCs are malicious, similar to Mandiant's functionality.
The capacity to reduce false positives needs improvement as we receive many alerts from Helix that turn out to be false positives upon investigation. Enhanced capability in this area would make the system more efficient and easier to use.
The dashboards could be improved as customers frequently request real-time SOC dashboard displays for Helix.
How are customer service and support?
The support for Trellix Helix Connect is not satisfactory. We experience difficulties accessing personnel with deep knowledge of Helix. We have numerous tickets to understand and resolve problems. It is not an easy product to support on a daily basis.
The support would rate a three out of ten. It can take one to four weeks to connect with someone who truly understands Helix and can provide solutions. This makes the product difficult to maintain.
How would you rate customer service and support?
Neutral
What other advice do I have?
The solution can be challenging for analysts with lower skill levels. The syntax for finding findings requires specific knowledge, making it more difficult for initial users.
Trellix Helix Connect is generally easy to use, but the Evidence Collector component presents more challenges.
This review rates Trellix Helix Connect as 6 out of 10.
AI capabilities streamline incident resolution and natural language search empowers security management
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Helps us detect some advanced malware and offers some automated collaborations enabled internally
What is our primary use case?
It helps prevent web security threats and other things.
We use Trellix ePO. We also use Trellix Endpoint Security and DLP encryption.
How has it helped my organization?
We are currently integrated with fewer security devices. It helps us understand deductions and analysis and provides collaborative input as a first priority.
What is most valuable?
We are able to block some advanced malware and other things. I think we use the appliance-based Helix.
It helps us detect some advanced malware. That's one of the major advantages. We also have some automated collaborations enabled internally. So, if there's a new attack or alert, we have visibility on it.
However, we are not experts in automation, but we do get some automation in the Trellix product. We want to test it further.
What needs improvement?
Trellix needs to address the price for the product to be more appealing to customers.
For how long have I used the solution?
It has been anywhere between six months to a year.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. The scalability is good.
How are customer service and support?
It's proper support. So no delays. They always respond on time and the responses are informative.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We chose Trellix among the variety of products on the market because other vendors support cloud-based threat intelligence, requiring us to interact with the cloud.
With Trellix Helix, we have on-premises offerings and we are able to collaborate on our logs within our premises. We don't want to send data outside our organization because we support banking customers. We can maintain everything internally.
How was the initial setup?
If you understand the concept of Trellix Helix, it's easy to deploy.
It took a couple of days. We haven't integrated it with any solutions yet. We just have some minimal solutions that need to be integrated. If we have any issues in the future, we'll let you know.pen_spark
What was our ROI?
There could be some financial benefits, but we are focused on security and threat prevention, not the financial aspect.
What's my experience with pricing, setup cost, and licensing?
It could be a bit expensive. I would give it an eight out of ten, with ten being expensive.
Which other solutions did I evaluate?
What other advice do I have?
I recommend Helix. I have a good experience with it. If I get a POC, I can easily give it to the customer and evaluate it.
The solution is stable and addresses advanced malware. It's also easy to access support in India.
Overall, I would rate it a nine out of ten.
Offers extensive platform visibility, event tracking, and integrations
What is our primary use case?
We work for a company that provides secret services related to XDR and NSS. We offer the Helix solution to many companies in Brazil. We manage the implementation and provide solutions to our customers. We are a Helix service provider for ten companies in Brazil.
How has it helped my organization?
We have started working with various customers, one of whom is particularly concerned about adjacency. We have identified several use cases where automation is possible. However, we face challenges with FSO tools, regarding integration versions. For example, our platform uses API V2, while Cisco uses V3 in some integrations. This has caused issues with professional services.
What is most valuable?
We are currently working with a provider where I need to send a lot of reports and queries to my customers. Instead, I create reports manually and provide customers with information about the solution.
What needs improvement?
We often rely on Martins to create logs and provide professional threat services rather than basic support. However, accessing these services can be inconsistent. Sometimes, responses are quick and valuable, but other times, they are delayed. For example, I've waited up to seven months for Martins to resolve an issue with Azure WAF in Helix. It can also be challenging to get timely responses from partners regarding updates and new features
How was the initial setup?
When we undertake projects to install Helix, initially, our company had all the logistical information needed from the installation guide. However, there are details not included in the manuals that we sometimes discover only through direct communication with Trelix experts. This process has become more manageable over time, but initially, we encountered significant challenges, such as issues with connectors, which handle different log formats. These discrepancies weren't clearly outlined in the manuals and caused delays.
For instance, it took about a month to deploy components like SSO and group collection for our customer's infrastructure. Each deployment involves specialized roles—one focusing on connections and another on development and automation with CFA. With these two roles, we can effectively implement Helix.
What's my experience with pricing, setup cost, and licensing?
When the merge of the companies start to use some about the price of the issue. We are using the FSO and security administrator.
I have some case of sources with some customer that returned with some a big security and and can resolve with some attacks.
What other advice do I have?
I have numerous advantages with ten client customers who use our services. We have a dedicated team working directly with the Helix system at PeerSpot within our company, providing maintenance and generating reports for our customers.
The solution offers extensive platform visibility, event tracking, and integrations. While we explore other integration possibilities like CNA, we haven't found a comparable solution yet. Integrating with other vendors and multi-platform environments presents challenges, especially in ensuring API compatibility and staying current with integrations.
I strongly recommend Helix to our new customers for its capabilities and reliability.
Overall, I rate the solution a nine out of ten.