
Overview
Make your organization more resilient and confident with Trellix Security Operations. Filter out the noise and cut complexity to deliver faster, more effective SecOps. Effortlessly unify your security ecosystem by connecting native Trellix controls with 500+ third-party tools.
Product Options:
- Trellix Helix
- Trellix ePO
- Trellix Enterprise Security Manager (ESM)
- Trellix Advanced Correlation Engine
- Trellix Global Threat Intelligence for ESM
Please contact aws@trellix.com before purchasing. These solutions may require additional add-on packs or specific licenses based on your organizational needs. Your account team will customize an AWS Private offer, reflecting appropriate quantities, SKUs, and qualified discounts.
Highlights
- Accelerate incident response
- Keep ahead of cyberthreats
- Unify your security tools
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
XDRECE-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $9,999.00 |
OX1ECE-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $20,925.00 |
EPOCDE-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $9,999.00 |
ELUVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $61,294.33 |
ELMVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $24,513.13 |
ELSVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $24,513.13 |
EV2VME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $15,317.83 |
ACVVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $26,045.69 |
APMVME-AA | Use Request Private Offer (To Be Removed - Do Not Use) | $16,850.39 |
GTEELU12GIEAD | Use Request Private Offer (To Be Removed - Do Not Use) | $14,141.13 |
Vendor refund policy
Please contact aws@trellix.com for refund requests
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Standard support and customer success programs available support@trellix.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Centralized threat triage has improved endpoint control but still needs better cloud insights
What is our primary use case?
I have been using Trellix Helix Connect for about 1.5 years now.
The main use case for Trellix Helix Connect is to see the detections and the endpoint results of the endpoints involved in those detections. For example, if a user generates an alert by doing something suspicious, we get the alert on Trellix EDR, and then we get a link to Helix Connect through which we can check the details about the user and their machine.
Checking those details in Helix Connect helps me in my day-to-day work because, for example, if someone downloaded something that they were not supposed to download and we get a flag on the EDR, we see that person is the user on the EDR system and we go to Helix Connect to search out the username or maybe the hostname. We get the full device details, and from the device, we can contain the device, restrict the device, or delete that file from the device. We can also quarantine or un-quarantine the particular file based on the business needs of the company. This is how it makes it easier for us to mitigate things.
What is most valuable?
The best features Trellix Helix Connect offers are that it provides readily available connection and the speed of deployment. It comes with a set of pre-built rules, integrations, and analytics which eliminate months of hard work and research that we have to do on the rule-making part. Trellix Helix Connect is also easy to implement and integrate as both come from the same parent company. With the existing data sources, we can connect it, and it also has many connectors and over 490 third-party connectors which help us get prioritized AI-guided responses. The GenAI triage, which used to be called Trellix Wise before, is now accessible to both current and new customers. This GenAI-powered alert triage helps us in the automation of triaging the detections.
The pre-built rules and analytics save us a lot of time and have positively impacted my team's workflow because whenever we migrate to a new tool, we basically have to sit for months to form the rules and alerts. Trellix Helix Connect provided a very ready-to-go data source with connectors, which made it easy for us to implement the things from the start. It did not take a long time for us to set it up and launch into operations practically.
Trellix Helix Connect has positively impacted our organization by helping us quarantine and un-quarantine files and manage our full asset inventory. We can watch every host and what is happening with them, whether the host is being deleted, onboarded, or off-boarded. It has also helped with our monthly reviews and the reports through which we can observe the types of malware affecting us, the malware that is not impacting us anymore, and the trends in malware activity.
What needs improvement?
Trellix Helix Connect can definitely be improved, especially regarding cloud and SaaS telemetry gaps. It could enhance its native cloud and SaaS telemetry integration. Additionally, sometimes when we open the details of a file, it lacks meta fields altogether, and we must manually ask the user for the meta fields, such as when the file was created, last opened, last updated, and its hash value. Helix does not perform as expected in this regard. There are also many false positives flagged that should not be, and there is no on-premises option for FireEye Helix. Lastly, the GUI and dashboard feel very old-school and legacy, needing improvement, as all competitors have far superior GUIs and UI/UX interfaces.
I would add that we have experienced specific problems with session timeouts where we randomly log out from the system after some time and face issues in logging back in. This required us to contact customer service frequently, which is also not very reliable or prompt.
For how long have I used the solution?
I have been using Trellix Helix Connect for about 1.5 years now.
What do I think about the stability of the solution?
Trellix Helix Connect has stability issues as it experienced downtimes during off-hours that affected our night shifts and late hours; however, the outages were only about 30 minutes to one hour long. Sometimes, this caused a mismatch in detections, but it is still manageable and not significant enough to cause major disruptions.
What do I think about the scalability of the solution?
The scalability of Trellix Helix Connect is good as it has over 400 ready-to-go connectors, which is a strong feature.
How are customer service and support?
The customer support is not very good, not that responsive, and not that fast either. We often wait for weeks to get a response from the engineering team due to a long relay process from customer representatives to the engineering team and then back to us.
Which solution did I use previously and why did I switch?
We previously used Defender, and we switched to Trellix Helix Connect because the client wanted a more affordable solution.
What was our ROI?
I have not seen explicit ROI metrics since that part was handled by the sales representatives of our company and the client's company. However, from an analyst's perspective, it has required fewer L2 operators since we already have a broader view of what is happening with the endpoint machines, which helps us form a verdict quickly and results in fewer employees needed.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Trellix Helix Connect showed that the pricing was definitely competitive. We mainly chose this solution because of the pricing factor alone; many other options were more lucrative feature-wise, but for pricing, it was quite competitive at the time.
Which other solutions did I evaluate?
Before choosing Trellix Helix Connect, we evaluated other options, including CrowdStrike and Palo Alto.
What other advice do I have?
My advice to others considering Trellix Helix Connect is to proceed only if you are getting competitive pricing; otherwise, it is nothing special and simply offers what many other connectors, such as CrowdStrike, Palo Alto, and Defender, already offer. Those options are far superior in terms of GUI and UI/UX standards. If you find competitive pricing that seems worthwhile, then proceed; otherwise, I would not recommend it. I gave this product a rating of 7 out of 10.
Alarm correlation has improved incident investigations and streamlines multi-vendor security operations
What is our primary use case?
Correlating the alarms is the priority for us, and Trellix Helix Connect was capable of doing that, and we were happy for this feature because we connect some third-party resources as well. We are not only using Trellix products but also other third-party firewalls and other security tools.
It helped streamline our incident management by reducing our investigation time; not extremely, but it helped.
What is most valuable?
Correlating the alarms is the priority for us, and Trellix Helix Connect was capable of doing that, and we were happy for this feature because we connect some third-party resources as well. We are not only using Trellix products but also other third-party firewalls and other security tools.
It helped streamline our incident management by reducing our investigation time; not extremely, but it helped.
What needs improvement?
There is room for improvement for Trellix Helix Connect; I see some direction that they still could improve.
The most problematic part was the integration part because in their catalog, they have so many third-party vendors, but some of them were not fully supported, so we requested some development and feature requests. Sometimes we saw that some documentation was not enough to integrate the third-party vendor's product. However, they improved their documentation, so it was a good experience.
Everyone expected that we could use an XDR solution as on-premises; they could make some improvement on this point, which is a priority for some institutions.
I am not sure what additional functionalities I would like to see in the future for Trellix Helix Connect; they could add some AI features, basically machine learning capabilities, and also improvements in the chatbot feature, but it was at the first stage an average.
For how long have I used the solution?
I am not sure how long we were using it in our company; maybe two years or three years.
What do I think about the stability of the solution?
SLA times were okay for us; I cannot complain about anything for support. However, sometimes we can face some level one support engineers, at which point we had some problems.
We do not face much performance issues.
How are customer service and support?
I would rate the technical support an eight from one to ten.
SLA times were okay for us; I cannot complain about anything for support. However, sometimes we can face some level one support engineers, at which point we had some problems.
Which solution did I use previously and why did I switch?
Because of the budget, we are not using any XDR right now.
We stopped using FireEye Helix six or seven months ago.
I only used Trellix XDR , Helix Connect before Trellix Helix Connect.
How was the initial setup?
The initial setup for Trellix Helix Connect was straightforward.
What's my experience with pricing, setup cost, and licensing?
It is not the pricing of the product; basically, it was related to our own budget.
We had some issues, but it took some time, and we handled the problems.
We do not face much performance issues; for pricing, it was close to other competitors, but again, as I mentioned, it was directly related to our own budget.
Which other solutions did I evaluate?
The architecture has changed a little bit; there are new competitors according to me. So we may need to make POCs again and evaluate again.
What other advice do I have?
I can say that I was working with Trellix Helix Connect overall, and the product was great; on the other hand, the concept has changed a little bit. We do not have any issue with the product. I was okay.
I used the integration feature of Trellix Helix Connect.
We also use NX, network security, and email security appliances and solutions as well, so with the ecosystem, it was excellent.
I leveraged some reports, and I can say that is all.
In general, I can say that Trellix Helix Connect impacted my organization positively.
I tried to integrate with Check Point and also Symantec mail security product, Secure Mail Gateway, which were the most problematic vendors.
Long-term use has improved incident response and supports adaptable security workflows
What is our primary use case?
The orchestrated workflows in Trellix Helix Connect have helped enhance my threat response. In the orchestration, we are getting the reporting site and an investigation report. If you are using DLP or XDR , we get the DLP report on the orchestrated platform. For SaaS-based EPO that is already in the cloud, customers have no hassle because all upgradations and products are upgraded automatically on the cloud side. However, for on-premises platforms, customers want different types of reporting. For example, if any incident happens, it instantly shows in the dashboard, and from this, we can get detailed reporting on that attack surface and incident report. I think if these types of things are added to the platform, it would be helpful for customers and for us.
What is most valuable?
Additionally, DLP is also very essential for our organization, as they are already using it. We are trying to introduce the Trellix layer security, but we still need some time to introduce all aspects to our own customers. We are working at our level best to achieve that.
The customizable alerts and reports in Trellix Helix Connect assist my team in adapting security strategies. When using cloud sites with products such as EDR and XDR, you are not left with vulnerabilities, but when you are using third-party tools, you can analyze that your site is totally secured. This is something customers sometimes require. For example, with this type of report submitted to CrowdStrike, that product shows their reporting and sends the email to that customer particularly, and they are very happy about that. In Trellix, we need these types of reports where you are giving information for analyzing or reporting, and scanning shows that your site is very secure and you are using a high-level, advanced-level threat protection detection product. This type of report could sometimes be sent to the customer, stating that you are using it and you are totally secure. This would be helpful for us.
What needs improvement?
Trellix Helix Connect can be improved in various ways. There are some issues such as high CPU utilization that we have experienced in the past whenever we were using Trellix Endpoint Security in the cloud system, which prevented anyone from working properly. I think they are reducing this with the upgradation of the Endpoint Security product and other products, but the main concern is sometimes the client cannot work properly when using Endpoint Security because it takes high CPU utilization. We also sometimes face issues with encryption. We are worried about this because sometimes some systems are taking the encryption as inactive. The encryption is happening, but it is not active and is showing as inactive. However, for reporting purposes in the EPO, it is showing that it is active when it is not actually active. These types of mismatches between the customer and Trellix platform side need to be improved.
For how long have I used the solution?
How are customer service and support?
What other advice do I have?
I can share that the efficiency improvement Trellix Helix Connect brought to my customer's security operations varies because for different customers, their expectations, design, and requirements are different. For example, banks have different requirements than customers on the medical side, such as pharmaceuticals. In some banking sectors, they want proper visualization, reporting, and a customized dashboard that can help them submit their report to higher authorities. On the other hand, if you consider the pharmaceutical sector, they want total security where nobody can access and nobody can get any internal report or internal information. They want to secure their site. This is the difference between companies using it, as their requirements are totally different. Some use Application Control for ATM security for banks, but on the other hand, if you consider pharmaceuticals, they do not need any ATM security level of protection. They need high-level data protection as that is a high concern for them. Overall, the different products and their working capabilities are different, and customers want to get their organization secure in that way. I think penetration testing and other things could be added which would be helpful for customers for future reporting purposes, protection purposes, or detection purposes. My overall rating for Trellix Helix Connect is eight out of ten.
Advanced integrations have improved threat detection and now provide comprehensive attack visibility
What is our primary use case?
Trellix Helix Connect is typically used for monitoring hidden events, such as malware events that a normal team might not detect, including phishing attacks. This is the most powerful case of an XDR , enabling easy detection of phishing scams and malware events.
How has it helped my organization?
I assess the effectiveness of Trellix Helix Connect 's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike. It provides detailed visibility reports and granular reporting.
The orchestrated workflows of Trellix Helix Connect enhance threat response by providing detailed reporting, integration dashboards, and detailed feature reporting through Trellix ePolicy Orchestrator .
Metrics about the efficiency improvements Trellix Helix Connect has brought to our security operations demonstrate that its settings are the best when compared with other solutions in effectiveness.
What is most valuable?
The main advantage of Trellix Helix Connect is the vast integration with over 4,000 applications. This extensive support for integration is a major advantage of this product.
Trellix Helix Connect easily integrates with Office 365 and also integrates well with FortiGate, Palo Alto, and Barracuda, especially within AWS environments.
What needs improvement?
The weak point of Trellix Helix Connect is the data storage capacity; more storage must be purchased as the data grows, which is a disadvantage because the cost increases when more space is needed on the cloud.
It is quite costly, especially if the events are increasing daily. The overall solution is fine but requires purchasing more space on the cloud, which can be expensive.
For how long have I used the solution?
I have been working with Trellix Helix Connect for around four to seven years. Before Trellix Helix Connect, it was known as McAfee, and I worked with McAfee for around 18 to 20 years.
What do I think about the stability of the solution?
Earlier, the technical support from Trellix was not good, but currently, there has been very significant improvement in technical cases, and the responses are strong and very helpful.
How are customer service and support?
Earlier, the technical support from Trellix was not good, but currently, there has been very significant improvement in technical cases, and the responses are strong and very helpful.
I assess the effectiveness of Trellix Helix Connect's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike. It provides detailed visibility reports and granular reporting.
How was the initial setup?
The initial deployment of Trellix Helix Connect is neither easy nor complex; I would rate it as medium because if you are a technical person familiar with antivirus and security products, you can handle it.
What about the implementation team?
More people are needed for deployment; at least two or three people are necessary to cover all aspects and security postures in one solution, as it is not possible for one person to deploy everything.
Deployment for Trellix Helix Connect may take about two to three weeks if you are managing around 100 to 300 users.
Which other solutions did I evaluate?
I am currently also working with Microsoft, Kaspersky, and Symantec, along with Trellix Helix Connect.
I also work with Kaspersky and Symantec because they are cheaper solutions, but Trellix Helix Connect is the overall complete cybersecurity solution, covering all aspects in one package. That is why I prefer Trellix Helix Connect for cybersecurity.
What other advice do I have?
The orchestrated workflows of Trellix Helix Connect enhance threat response by providing detailed reporting, integration dashboards, and detailed feature reporting through Trellix ePolicy Orchestrator .
I rate the technical support from Trellix an eight out of ten.
I rate Trellix Helix Connect a nine out of ten as a product in general.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Reduces detection and response times through automation and alert correlation
What is our primary use case?
My main use case for Trellix Helix Connect is to provide an MDR service to our clients. We use Trellix Helix Connect to correlate the alerts and automate the response most often.
For example, we use Trellix Helix Connect for MDR services with our clients when we have XDR for Trellix Helix Connect to analyze the alerts and set up the SOAR workflows. It depends on the client needs.
In our day-to-day operations, we have the main use case of Trellix Helix Connect which allows us to reduce MTTD and MTTR, and we have the KPIs to support this.
What is most valuable?
The best features that Trellix Helix Connect offers are SOAR , automation, hyperautomation, and the correlation of alerts and threat intelligence, for example, when the alerts cross through MITRE ATT&CK, which stand out most to me.
Out of those features, automation, alert correlation, and threat intelligence have made my work easier and more effective as we integrate many cybersecurity solutions into the XDR and set up the use cases to reduce MTTD and MTTR from days to minutes.
I would add that the level of integration with other brands is something that surprises me about the features of Trellix Helix Connect.
Trellix Helix Connect has positively impacted my organization as it is the most important tool to provide MDR service to our clients, which has resulted in specific outcomes and improvements.
What needs improvement?
To improve Trellix Helix Connect, I think it is possible to enhance the dashboard to share more information about the incidents. For example, if I want to check a MITRE technique, maybe it is necessary to have a quick link to check this technique in the dashboard.
I think the usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements.
For how long have I used the solution?
I have been using Trellix Helix Connect for one year.
What do I think about the stability of the solution?
Trellix Helix Connect is very stable, and I have experienced almost no downtime or issues, as the downtime is mainly about maintenance time, confirming its reliability.
What do I think about the scalability of the solution?
Trellix Helix Connect's scalability is excellent as the solution has a library to make integrations with other brands, allowing it to handle growth easily via API.
How are customer service and support?
The customer support for Trellix Helix Connect is well in Latin America because there are many people in the region, which enhances the experience.
Which solution did I use previously and why did I switch?
I previously used legacy SIEMs before choosing Trellix Helix Connect.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that the licensing for XDR is good, though the hyperautomation feature is expensive.
What was our ROI?
We have seen a return on investment with Trellix Helix Connect, and we can share relevant metrics as we reduce the MTTD and MTTR and have KPIs indicating our ROI.
Which other solutions did I evaluate?
What other advice do I have?
The most important metrics are the reduced MTTD and MTTR because the clients' legacy solutions provide faster response when they use this tool, showing measurable benefits.
I advise anyone considering Trellix Helix Connect to review the different solutions of the XDR ecosystem, focusing on the capability to integrate with other brands without shadow cost and the capability to respond and reduce MTTD and MTTR. I would rate this product at a nine out of ten.