
Overview
As organizations strive to innovate and grow, they create highly complex interconnected networks of external partners, suppliers, vendors, contractors, and customers. Digital transformation initiatives have transformed both the nature and velocity of collaboration - introducing a largely unprotected attack vector, and creating significant challenges for security defenders.
Trellix Collaboration Security ensures people can work together securely across the extended enterprise.
- Real-time analysis of URLs and attachments to block suspicious emails - and extract those weaponized post-delivery
- Seamlessly integrate with platforms such as Slack, Microsoft 365, and Google Workspace to ensure the integrity of files as they're shared - without friction.
- Trust a single solution to inspect files shared by popular applications such as Salesforce, Ariba, Microsoft Azure, and Workday ensuring quick time to value.
Solution Options:
- Trellix Email Security
- Trellix IVX Cloud for Collaboration Platforms
- Trellix IVX Cloud Enterprise Applications
Before purchasing, please contact aws@trellix.com . Your account team will build an AWS Private Offer reflecting accurate SKUs, quantities, and qualified discounts.
Highlights
- Stops phishing, impersonation, and malwareless attacks
- AI- and ML-based detection with behavioral analytics
- Deployable as ICES or SEG
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
EMCLECE-AA | Email Security - Cloud Edition (w/o AV or anti-SPAM) - Per user (1 yr) | $55.44 |
EMCAECE-AA | Email Security - Cloud Edition (w/AV & anti-SPAM) - Per user (1 yr) | $81.50 |
IVXECE-AA | Intelligent Virtual eXecution (IVX) Cloud - Per User Pricing (1 yr) | $53.74 |
Vendor refund policy
Please contact aws@trellix.com for refund requests
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Standard support and customer success programs available support@trellix.comÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Endpoint protection has strengthened network control and has simplified global threat response
What is our primary use case?
My main use case for Trellix Collaboration Security is based on my experience with Trellix EPO and Trellix products, as I have over six years of experience managing Trellix EPO and all its features when it comes to antivirus protection, including its firewall and DLP functionality. You can also encrypt a drive instead of using BitLocker , integrate your whole network, deploy a fabric from Trellix, and this fabric serves as a private network that enhances secure communication. It becomes comparable to an EDR because you can integrate it with Trellix TIE services, a reputation service, and manage USBs for controlling data movement from the computer to the USB.
On top of that, you can run scans 24/7, which is called the on-access scan, or run on-demand scans whenever you prefer, perhaps once a day for a full scan. You have extensive management capabilities regarding the ports and IPs the computers communicate with, providing a lot of functionalities.
A specific example of how I have used Trellix Collaboration Security in my consulting work is in my current work environment, where I manage over 130,000 endpoints, allowing me to protect each endpoint with a firewall, which makes a significant difference because the entire network is not protected by a network firewall alone. Having an endpoint firewall is valuable, and being able to scan all applications for malicious content 24/7 with an on-access scan, which scans everything you click on in real-time, ensures effective security which I truly appreciate.
Day-to-day, we scan the endpoints once a week and conduct full scans weekly while also performing 24/7 scans through the on-access scans. We help people troubleshoot performance issues related to scanning and create exclusions for threat prevention, exploit prevention, and the on-access scan itself because a file, folder, or software may not need to be scanned continuously. My everyday tasks revolve around managing performance and connectivity, which may involve opening ports or ensuring domain reachability, as well as managing USBs, including creating new exclusions for new vendors of USBs. Additionally, you can integrate Trellix EPO with LDAP, which helps manage computers and users, enabling the creation of specific, more granular rules.
What is most valuable?
In my opinion, the best features Trellix Collaboration Security offers include the firewall, the on-access scan, and the ability to obtain daily signatures for the latest malware. These daily signatures, referred to as content, ensure that we are protected against the most recent malware threats recognized by other companies.
Another feature I particularly enjoy is the capability to maintain different locations that can communicate with the fabric, or DXL fabric as I refer to it, allowing me to create something akin to an EDR for immediate responses to resolve issues.
The DXL fabric has helped my organization by enabling communication between different locations, such as one in Europe, another in South America, and one here. This fabric communicates with a broker that interacts with the TIE servers, which maintain the reputation of files, certificates, and known signatures from various regions including Europe, South America, and Canada. When something suspicious occurs, such as a certificate appearing malicious on an application, I can easily click and indicate that I trust this file, and through the fabric, I can apply an exclusion for that application across all locations simultaneously.
Other features I find valuable include the SSOÂ integration with Trellix EPO, specifically SAML SSOÂ , allowing people not to have to manage usernames and passwords if they already utilize an SSO service for SAML; I consider this functionality to be quite beneficial.
What needs improvement?
Areas where Trellix Collaboration Security can be improved include the fact that it used to support OpenLDAP but now does not support it any longer; it only supports LDAP, which means open-source lightweight directories are not supported anymore.
While I find Trellix's support and performance to be satisfactory, I do have concerns. Sometimes Trellix uploads packages, identifies bugs, and removes them without notifying users, which requires us to wait for the next release or roll back, both undesirable situations. I need assurance that proper testing occurs before the release of new packages.
For how long have I used the solution?
I have been using Trellix Collaboration Security for approximately six years.
What do I think about the stability of the solution?
Trellix Collaboration Security can indeed be stable if you know how to manage its features effectively.
What do I think about the scalability of the solution?
Trellix Collaboration Security is very good when it comes to scalability, demonstrating impressive capacity for growth.
How are customer service and support?
I appreciate the customer support, particularly if you can effectively communicate the issue you are experiencing.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have previously used SonicWall for antivirus and network firewalls; however, Trellix exceeds SonicWall's offerings, which are more aligned with a SaaS solution. The absence of an on-premise console with SonicWall was a significant factor that led me to choose Trellix.
What was our ROI?
I observe that the return on investment is hindered by the lack of adequate training opportunities, with Trellix's own training being quite costly, ranging from 2,000 to 4,000 dollars, which many small or medium-sized businesses cannot afford. I believe the educational materials can be enhanced, as Trellix does not explain certain concepts well in their training, and having completed the training, I feel I could offer better instructional support.
What's my experience with pricing, setup cost, and licensing?
The experience with pricing, setup costs, and licensing indicates that while Trellix Collaboration Security is a great product, it tends to be on the pricier side. I do not possess complete knowledge of all the pricing details for licensing or support as I am only somewhat involved in the purchasing process, but I know that larger enterprises, such as a bank I previously supported, invest in it as they have the financial resources. However, I believe it might be less accessible for small to medium-sized businesses, and I wish there were more affordable options available for them.
Which other solutions did I evaluate?
Before selecting Trellix Collaboration Security, I evaluated other options, including Trend Micro, which many individuals discuss. Though I personally have not used Trend Micro, it appears that it is popular for file servers, possibly enabling faster scans for zip files and specific files that can take Trellix longer to unzip.
What other advice do I have?
My advice for those considering using Trellix Collaboration Security is to ensure your budget accounts for investing over 100,000 dollars to hire someone to manage the product, as professionals with this expertise tend to come at a high cost. I give this product an overall rating of ten out of ten.
Centralized sensors have improved threat visibility and have reduced staffing needs
What is our primary use case?
My main use case for Trellix Collaboration Security involves using Policy Orchestrator, email gateway, web gateway, and Trellix sensors, Security Manager, Network Security Manager.
What is most valuable?
I use Trellix Collaboration Security in my daily operations by utilizing different sites sensors and then integrating security manager, which controls network operations, traffic inspections, packet inspection, deep packet inspection, and SSL inspections.
The best features Trellix Collaboration Security offers include GTI threat intelligence and signatures upgrade database. Since I have integrated GTI and sensors along with network security manager, all sensors share information and reports effectively, allowing me to view attack reports from the dashboard easily.
I can customize dashboards in Trellix Collaboration Security to view information like top attacks, ransomware attacks, and critical high attacks. I can monitor sensor health, attacks, logs that generate, and customize these as per my needs, plus I can add emails and alerts.
I rely on Trellix Collaboration Security because the sensors are highly reliable and high-performance sensors that can handle traffic efficiently. CPU resources are effectively utilized while handling deep packet inspections and SSL inspections. Moreover, there are policies to be on networks, and there is a built-in firewall that I can use to block external attacks.
What needs improvement?
Trellix Collaboration Security can improve by addressing some zero-day attacks and enhancing VM-based protections.
I chose a nine out of ten because some improvements are required, especially concerning East-West traffic or zero-day vulnerabilities. To improve vulnerabilities, Trellix can use an automation process to check if the system is vulnerable.
For how long have I used the solution?
I have worked with Trellix Collaboration Security for over almost four and a half years.
What do I think about the stability of the solution?
Trellix Collaboration Security is very stable.
What do I think about the scalability of the solution?
Trellix Collaboration Security scalability allows me to use sensors on-cloud, on-premises, inside premises, and in a hybrid environment. I can use VM-based environments to effectively stop East-West attacks.
How are customer service and support?
I have interacted with the customer support team of Trellix Collaboration Security. The support team is good overall, though my experience with the Indian support team was not as satisfactory since they did not provide adequate support to rectify issues. I managed to identify and resolve the problem myself.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I previously tried to use the Fortinet solution, but the Fortinet solution was not providing good performance, making Trellix Collaboration Security a better choice for me.
What was our ROI?
I have seen a return on investment with Trellix Collaboration Security; specifically, money was saved and fewer employees were needed because I do not need employees on different sites. I only need a Network Security Manager deployed centrally to control all these sensors from one location.
What's my experience with pricing, setup cost, and licensing?
My experience with Trellix Collaboration Security regarding pricing, setup cost, and licensing was very good, and the setup cost was very cheap.
Which other solutions did I evaluate?
I evaluated other options, including Trend Micro-based sensors, but I found that Trellix Collaboration Security's performance is better.
What other advice do I have?
All is good with Trellix Collaboration Security.
I would rate Trellix Collaboration Security a ten out of ten.
My advice for others looking into using Trellix Collaboration Security is to ensure that data backup is performed before upgrading to the latest version, as Trellix should provide a proper plan for device upgrades and fallback options. Sometimes, if the sensors are located in different locations and the network security manager is positioned elsewhere, data may get corrupted during upgrades. Firmware files may become corrupt, leading to sensor instability, and I would have to go on-site to resolve this. Therefore, Trellix should develop options for sensors to restore firmware remotely in case of failures.
I have additional thoughts about Trellix Collaboration Security. Trellix has various security products working; however, it should improve its design and devices to effectively compete with Fortinet, which is a growing company with diverse, efficiently running products.
Real-time threat response has boosted detection accuracy and reduces manual investigation work
What is our primary use case?
I have worked with Trellix Collaboration Security for several years in different outsourcing services before Johnson & Johnson. At BNP Paribas Bank, a French bank, I worked with Trellix Collaboration Security . At Santander Bank, I also worked with Trellix Collaboration Security. Before the banking sector, I worked in a security operations center with Trellix Collaboration Security since the McAfee company.
At Johnson & Johnson, I am not currently using Trellix Collaboration Security. However, before Johnson & Johnson, I worked at Santander Bank where I participated in a project to implement the endpoint in different offices of the bank, coordinating the alignment and sending of policies, tasks, update tasks, and deployment of the new versions of the products.
What is most valuable?
Regarding threat intelligence, it helped us with signatures, IOCs, or reports related to geolocation, where we could use it to create correlation in the XDR to block and create a campaign to block different malicious activities based on the historical data published in the threat intelligence and based on reputation. It is very important because it is integrated, so it is not necessary to contact VirusTotal or put the hash in VirusTotal . Instead, I use the database and the threat intelligence from Trellix Collaboration Security. In the past, it helped me a great deal with detecting and confirming whether something was malicious or not.
Another feature I believe is very important is the real-time response capability. It is possible to collect artifacts, run scripts, kill processes, and isolate machines all without leaving the interface. For me, this serves as a bridge between detection and reaction, and it truly makes a difference in the tool.
In my view, Trellix Collaboration Security and other XDRs can help the company elevate the trust in operations. Of course, it is necessary to create automations and integrations with pipelines with CSVs, inventory, normalization of data, and automatically raising incidents for the agents and endpoints. In my view, this reduced manual activities significantly and increased the precision of the indicators. Everything helped the operations team and the engineering team respond more quickly to malicious activities detected. It helped us reduce risks, avoid silent failures, and improve the health in general in the environment. Another important point is that we have an improved security posture because it is possible to treat the findings, adjust policies, and block malicious hashes. With that, we reduced the noise according to the detections, increasing the capacity of prevention and detection. We also improved the resilience of the security tools inside the company.
What needs improvement?
One thing I really do not prefer in Trellix Collaboration Security is not related to the console. I am a McAfee fan since the McAfee tool, and I find the console of Trellix Collaboration Security to be very user-friendly and easy to use. However, I do not know if it is related to the architecture of the product. Of course, we have modern threats based on behaviors and zero days. We have today CrowdStrike and SentinelOne, where we have better results based on threats and behavior, where it is possible to create a simulation environment based on the file detected and based on it, confirm if it really is malicious or not. In general, I believe Trellix Collaboration Security improved the console based on the last console of McAfee, but I think it is possible to improve more. It really is a good product, but in my view, it needs to improve detection based on behaviors.
Regarding automations, I have implemented Trellix Collaboration Security here at Johnson & Johnson, and I implemented it in the same situation at Santander Bank and BNP Paribas Bank, where I created automations to export data for different metrics, including malicious detections, compliance, baselines, scans, last scans based on the seven days, and checking of patterns. I export everything to CSV files. Based on that, I create Power BI dashboards, and in these Power BI dashboards, I have a more executive view for different metrics to provide to myself, my manager, or director to create an executive view based on it. Another important point we use here at Johnson & Johnson and other companies is a data hub or a SIEMÂ solution, such as Elastic or ArcSight, where we select some logs to be sent and use it to build reports and metrics.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Another aspect is the unified detection and analysis of sandbox, URL, file inspection, and threat intelligence. This creates a more robust increase for a horizontal solution. It creates a good range of use because it really helps a lot. In my view, the limitation about scalability may be related to license and costs. When you include other modules and services, of course, you increase the cost, and because you need to adjust.
How are customer service and support?
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
We also saw a major reduction in noise. After tuning the ENS and aligning the threat intelligence with real detections, we dropped false positives around 20 to 30%, which directly reduced the number of tickets escalated to security operations. The real-time feature is a good capability, and we had good results in the past based on it because it prevents lateral movement and avoids more expensive downstream impacts, such as re-imaging and downtime.
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
Regarding integrations, Trellix Collaboration Security has good integration with a large list of products, and it is possible to integrate. Performance and integration are good, and support in my experience has provided good results during telephone calls and email requests. For public and private cloud, we had good results, but I prefer to work with the console of Trellix Collaboration Security as a SaaS solution, and it helped in the deployment for cloud, hybrid, or on-premises environments. It depends on the internet link, but in my last experience with Trellix Collaboration Security, I did not have issues related to deployment using the security solution in a cloud environment. We reached a good result during the deployment of new versions and new products without creating a saturation of the link.
Regarding deployment, we used AWSÂ as the main solution here and at Santander Bank. It is the same at BNP Paribas. In the last three experiences I have had, we used AWS.
My review rating for Trellix Collaboration Security is an 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Email protection solidifies threat coverage and fulfills customer needs
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
Which other solutions did I evaluate?
What other advice do I have?
Provides strong data protection with virtual patching and vulnerability assessments
What is our primary use case?
I primarily use it to monitor database access, particularly in banking and similar environments. It ensures that IT personnel and others do not create unauthorized accounts or users. Collaboration security assists in tracking database access and alerts in case of suspicious activity.
What is most valuable?
One of the most valuable features is the protection against vulnerabilities, particularly through virtual patching. This ensures that I am safe from potential threats affecting database security.
Another significant feature is the vulnerability assessment, which is effective for overall data protection.
What needs improvement?
There is a need for improved integration with totally different products, such as a rapid server. This is currently challenging since the management console becomes overloaded with logs, which complicates troubleshooting.
For how long have I used the solution?
I have been working with Trellix Collaboration Security for ten years.
What do I think about the stability of the solution?
Sometimes, integration can be challenging, impacting its stability, which is why I rate it a five out of ten.
What do I think about the scalability of the solution?
I rate it an eight out of ten. Scalability benefits me by allowing for growth, although sometimes adding users can be difficult due to licensing.
How are customer service and support?
The support isn't bad, but there is room for improvement in response time. Initially, I must generate a ticket, and then it gets escalated through tiers if the issue isn't resolved.
How would you rate customer service and support?
Neutral
How was the initial setup?
For me, setup is easy because of my extensive experience. I rate it ten out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is high at eight out of ten. It is quite expensive and should be reconsidered.
What other advice do I have?
Before installing, consider potential challenges with system performance, especially when integrating multiple tools, which could slow down performance. Overall, I rate the solution with an eight due to its impressive performance, however, integration with other systems needs improvement. My overall product rating is an eight out fo ten.