Reviews from AWS customer

2 AWS reviews

External reviews

9 reviews
from

External reviews are not included in the AWS star rating for the product.


    reviewer2840397

Centralized threat triage has improved endpoint control but still needs better cloud insights

  • May 13, 2026
  • Review provided by PeerSpot

What is our primary use case?

I have been using Trellix Helix Connect for about 1.5 years now.

The main use case for Trellix Helix Connect is to see the detections and the endpoint results of the endpoints involved in those detections. For example, if a user generates an alert by doing something suspicious, we get the alert on Trellix EDR, and then we get a link to Helix Connect through which we can check the details about the user and their machine.

Checking those details in Helix Connect helps me in my day-to-day work because, for example, if someone downloaded something that they were not supposed to download and we get a flag on the EDR, we see that person is the user on the EDR system and we go to Helix Connect to search out the username or maybe the hostname. We get the full device details, and from the device, we can contain the device, restrict the device, or delete that file from the device. We can also quarantine or un-quarantine the particular file based on the business needs of the company. This is how it makes it easier for us to mitigate things.

What is most valuable?

The best features Trellix Helix Connect offers are that it provides readily available connection and the speed of deployment. It comes with a set of pre-built rules, integrations, and analytics which eliminate months of hard work and research that we have to do on the rule-making part. Trellix Helix Connect is also easy to implement and integrate as both come from the same parent company. With the existing data sources, we can connect it, and it also has many connectors and over 490 third-party connectors which help us get prioritized AI-guided responses. The GenAI triage, which used to be called Trellix Wise before, is now accessible to both current and new customers. This GenAI-powered alert triage helps us in the automation of triaging the detections.

The pre-built rules and analytics save us a lot of time and have positively impacted my team's workflow because whenever we migrate to a new tool, we basically have to sit for months to form the rules and alerts. Trellix Helix Connect provided a very ready-to-go data source with connectors, which made it easy for us to implement the things from the start. It did not take a long time for us to set it up and launch into operations practically.

Trellix Helix Connect has positively impacted our organization by helping us quarantine and un-quarantine files and manage our full asset inventory. We can watch every host and what is happening with them, whether the host is being deleted, onboarded, or off-boarded. It has also helped with our monthly reviews and the reports through which we can observe the types of malware affecting us, the malware that is not impacting us anymore, and the trends in malware activity.

What needs improvement?

Trellix Helix Connect can definitely be improved, especially regarding cloud and SaaS telemetry gaps. It could enhance its native cloud and SaaS telemetry integration. Additionally, sometimes when we open the details of a file, it lacks meta fields altogether, and we must manually ask the user for the meta fields, such as when the file was created, last opened, last updated, and its hash value. Helix does not perform as expected in this regard. There are also many false positives flagged that should not be, and there is no on-premises option for FireEye Helix. Lastly, the GUI and dashboard feel very old-school and legacy, needing improvement, as all competitors have far superior GUIs and UI/UX interfaces.

I would add that we have experienced specific problems with session timeouts where we randomly log out from the system after some time and face issues in logging back in. This required us to contact customer service frequently, which is also not very reliable or prompt.

For how long have I used the solution?

I have been using Trellix Helix Connect for about 1.5 years now.

What do I think about the stability of the solution?

Trellix Helix Connect has stability issues as it experienced downtimes during off-hours that affected our night shifts and late hours; however, the outages were only about 30 minutes to one hour long. Sometimes, this caused a mismatch in detections, but it is still manageable and not significant enough to cause major disruptions.

What do I think about the scalability of the solution?

The scalability of Trellix Helix Connect is good as it has over 400 ready-to-go connectors, which is a strong feature.

How are customer service and support?

The customer support is not very good, not that responsive, and not that fast either. We often wait for weeks to get a response from the engineering team due to a long relay process from customer representatives to the engineering team and then back to us.

Which solution did I use previously and why did I switch?

We previously used Defender, and we switched to Trellix Helix Connect because the client wanted a more affordable solution.

What was our ROI?

I have not seen explicit ROI metrics since that part was handled by the sales representatives of our company and the client's company. However, from an analyst's perspective, it has required fewer L2 operators since we already have a broader view of what is happening with the endpoint machines, which helps us form a verdict quickly and results in fewer employees needed.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Trellix Helix Connect showed that the pricing was definitely competitive. We mainly chose this solution because of the pricing factor alone; many other options were more lucrative feature-wise, but for pricing, it was quite competitive at the time.

Which other solutions did I evaluate?

Before choosing Trellix Helix Connect, we evaluated other options, including CrowdStrike and Palo Alto.

What other advice do I have?

My advice to others considering Trellix Helix Connect is to proceed only if you are getting competitive pricing; otherwise, it is nothing special and simply offers what many other connectors, such as CrowdStrike, Palo Alto, and Defender, already offer. Those options are far superior in terms of GUI and UI/UX standards. If you find competitive pricing that seems worthwhile, then proceed; otherwise, I would not recommend it. I gave this product a rating of 7 out of 10.


    Melih Karasu

Alarm correlation has improved incident investigations and streamlines multi-vendor security operations

  • May 07, 2026
  • Review provided by PeerSpot

What is our primary use case?

Correlating the alarms is the priority for us, and Trellix Helix Connect was capable of doing that, and we were happy for this feature because we connect some third-party resources as well. We are not only using Trellix products but also other third-party firewalls and other security tools.

It helped streamline our incident management by reducing our investigation time; not extremely, but it helped.

What is most valuable?

Correlating the alarms is the priority for us, and Trellix Helix Connect was capable of doing that, and we were happy for this feature because we connect some third-party resources as well. We are not only using Trellix products but also other third-party firewalls and other security tools.

It helped streamline our incident management by reducing our investigation time; not extremely, but it helped.

What needs improvement?

There is room for improvement for Trellix Helix Connect; I see some direction that they still could improve.

The most problematic part was the integration part because in their catalog, they have so many third-party vendors, but some of them were not fully supported, so we requested some development and feature requests. Sometimes we saw that some documentation was not enough to integrate the third-party vendor's product. However, they improved their documentation, so it was a good experience.

Everyone expected that we could use an XDR solution as on-premises; they could make some improvement on this point, which is a priority for some institutions.

I am not sure what additional functionalities I would like to see in the future for Trellix Helix Connect; they could add some AI features, basically machine learning capabilities, and also improvements in the chatbot feature, but it was at the first stage an average.

For how long have I used the solution?

I am not sure how long we were using it in our company; maybe two years or three years.

What do I think about the stability of the solution?

SLA times were okay for us; I cannot complain about anything for support. However, sometimes we can face some level one support engineers, at which point we had some problems.

We do not face much performance issues.

How are customer service and support?

I would rate the technical support an eight from one to ten.

SLA times were okay for us; I cannot complain about anything for support. However, sometimes we can face some level one support engineers, at which point we had some problems.

Which solution did I use previously and why did I switch?

Because of the budget, we are not using any XDR right now.

We stopped using FireEye Helix six or seven months ago.

I only used Trellix XDR, Helix Connect before Trellix Helix Connect.

How was the initial setup?

The initial setup for Trellix Helix Connect was straightforward.

What's my experience with pricing, setup cost, and licensing?

It is not the pricing of the product; basically, it was related to our own budget.

We had some issues, but it took some time, and we handled the problems.

We do not face much performance issues; for pricing, it was close to other competitors, but again, as I mentioned, it was directly related to our own budget.

Which other solutions did I evaluate?

The architecture has changed a little bit; there are new competitors according to me. So we may need to make POCs again and evaluate again.

What other advice do I have?

I can say that I was working with Trellix Helix Connect overall, and the product was great; on the other hand, the concept has changed a little bit. We do not have any issue with the product. I was okay.

I used the integration feature of Trellix Helix Connect.

We also use NX, network security, and email security appliances and solutions as well, so with the ecosystem, it was excellent.

I leveraged some reports, and I can say that is all.

In general, I can say that Trellix Helix Connect impacted my organization positively.

I tried to integrate with Check Point and also Symantec mail security product, Secure Mail Gateway, which were the most problematic vendors.


    Abdullah Al Hadi

Long-term use has improved incident response and supports adaptable security workflows

  • May 05, 2026
  • Review provided by PeerSpot

What is our primary use case?

I have been working with Trellix Helix Connect for a long period of time, almost nine years. I have worked on different products including Application Control, encryption, email security, EDR, XDR, and all the newly added products in Trellix.

The orchestrated workflows in Trellix Helix Connect have helped enhance my threat response. In the orchestration, we are getting the reporting site and an investigation report. If you are using DLP or XDR, we get the DLP report on the orchestrated platform. For SaaS-based EPO that is already in the cloud, customers have no hassle because all upgradations and products are upgraded automatically on the cloud side. However, for on-premises platforms, customers want different types of reporting. For example, if any incident happens, it instantly shows in the dashboard, and from this, we can get detailed reporting on that attack surface and incident report. I think if these types of things are added to the platform, it would be helpful for customers and for us.

What is most valuable?

The features that I find most valuable in Trellix Helix Connect are the incident response capabilities, which include EDR and XDR, along with the SoC capabilities added in the new advanced Trellix AI intelligence. These things are very important to all organizations.

Additionally, DLP is also very essential for our organization, as they are already using it. We are trying to introduce the Trellix layer security, but we still need some time to introduce all aspects to our own customers. We are working at our level best to achieve that.

The customizable alerts and reports in Trellix Helix Connect assist my team in adapting security strategies. When using cloud sites with products such as EDR and XDR, you are not left with vulnerabilities, but when you are using third-party tools, you can analyze that your site is totally secured. This is something customers sometimes require. For example, with this type of report submitted to CrowdStrike, that product shows their reporting and sends the email to that customer particularly, and they are very happy about that. In Trellix, we need these types of reports where you are giving information for analyzing or reporting, and scanning shows that your site is very secure and you are using a high-level, advanced-level threat protection detection product. This type of report could sometimes be sent to the customer, stating that you are using it and you are totally secure. This would be helpful for us.

What needs improvement?

I would assess the effectiveness of Trellix Helix Connect's threat detection capabilities as improved nowadays. Some aspects of Trellix are improved using the AI technological sector, particularly EDR, which is Extended Detection and Response, capable of visualizing the incidents and the response. However, from my perspective, compared to other products, we need to improve the integration of detection and response in the product. For example, if I consider CrowdStrike, they provide their EDR capabilities, the scanning report, and vulnerability in the product, and they have provided third parties to analyze the report. Trellix has not provided their actual report on whether there is any vulnerability on the cloud side or not. This is the type of thing that customers sometimes recommend, in that they need a report showing clear visualization and that AI has detected something on the cloud service which needs to be reported. These types of things are required for customers nowadays.

Trellix Helix Connect can be improved in various ways. There are some issues such as high CPU utilization that we have experienced in the past whenever we were using Trellix Endpoint Security in the cloud system, which prevented anyone from working properly. I think they are reducing this with the upgradation of the Endpoint Security product and other products, but the main concern is sometimes the client cannot work properly when using Endpoint Security because it takes high CPU utilization. We also sometimes face issues with encryption. We are worried about this because sometimes some systems are taking the encryption as inactive. The encryption is happening, but it is not active and is showing as inactive. However, for reporting purposes in the EPO, it is showing that it is active when it is not actually active. These types of mismatches between the customer and Trellix platform side need to be improved.

For how long have I used the solution?

I have been working almost nine years.

How are customer service and support?

I would rate technical support for Trellix Helix Connect as eight out of ten based on my calculations and perspective.

What other advice do I have?

I do use the integration feature in Trellix Helix Connect. Trellix is now not only on-premises but also working on the SaaS base. In the SaaS-based EPO, we are integrated with the on-premise or SaaS base, and we are transferring the system to the SaaS base. Some clients are trying to transfer their system to the cloud and some are using that cloud DLP. The problem is with the DLP integration. Another product is Solidcore, which is related to Application Control, Change Control, and Execution Monitoring, and it is not properly integrated with the SaaS-based EPO. It is a main concern that we need proper integrations to the cloud services for Application Control, Change Control, and integrity monitoring for Solidcore devices.

I can share that the efficiency improvement Trellix Helix Connect brought to my customer's security operations varies because for different customers, their expectations, design, and requirements are different. For example, banks have different requirements than customers on the medical side, such as pharmaceuticals. In some banking sectors, they want proper visualization, reporting, and a customized dashboard that can help them submit their report to higher authorities. On the other hand, if you consider the pharmaceutical sector, they want total security where nobody can access and nobody can get any internal report or internal information. They want to secure their site. This is the difference between companies using it, as their requirements are totally different. Some use Application Control for ATM security for banks, but on the other hand, if you consider pharmaceuticals, they do not need any ATM security level of protection. They need high-level data protection as that is a high concern for them. Overall, the different products and their working capabilities are different, and customers want to get their organization secure in that way. I think penetration testing and other things could be added which would be helpful for customers for future reporting purposes, protection purposes, or detection purposes. My overall rating for Trellix Helix Connect is eight out of ten.


    Sheikh Abdul Hannan

Advanced integrations have improved threat detection and now provide comprehensive attack visibility

  • April 22, 2026
  • Review from a verified AWS customer

What is our primary use case?

Trellix Helix Connect is typically used for monitoring hidden events, such as malware events that a normal team might not detect, including phishing attacks. This is the most powerful case of an XDR, enabling easy detection of phishing scams and malware events.

How has it helped my organization?

I assess the effectiveness of Trellix Helix Connect's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike. It provides detailed visibility reports and granular reporting.

The orchestrated workflows of Trellix Helix Connect enhance threat response by providing detailed reporting, integration dashboards, and detailed feature reporting through Trellix ePolicy Orchestrator.

Metrics about the efficiency improvements Trellix Helix Connect has brought to our security operations demonstrate that its settings are the best when compared with other solutions in effectiveness.

What is most valuable?

The main advantage of Trellix Helix Connect is the vast integration with over 4,000 applications. This extensive support for integration is a major advantage of this product.

Trellix Helix Connect easily integrates with Office 365 and also integrates well with FortiGate, Palo Alto, and Barracuda, especially within AWS environments.

What needs improvement?

The weak point of Trellix Helix Connect is the data storage capacity; more storage must be purchased as the data grows, which is a disadvantage because the cost increases when more space is needed on the cloud.

It is quite costly, especially if the events are increasing daily. The overall solution is fine but requires purchasing more space on the cloud, which can be expensive.

For how long have I used the solution?

I have been working with Trellix Helix Connect for around four to seven years. Before Trellix Helix Connect, it was known as McAfee, and I worked with McAfee for around 18 to 20 years.

What do I think about the stability of the solution?

Earlier, the technical support from Trellix was not good, but currently, there has been very significant improvement in technical cases, and the responses are strong and very helpful.

How are customer service and support?

Earlier, the technical support from Trellix was not good, but currently, there has been very significant improvement in technical cases, and the responses are strong and very helpful.

I assess the effectiveness of Trellix Helix Connect's threat detection capabilities as robust, making it more powerful than Trend Micro and other solutions like CrowdStrike. It provides detailed visibility reports and granular reporting.

How was the initial setup?

The initial deployment of Trellix Helix Connect is neither easy nor complex; I would rate it as medium because if you are a technical person familiar with antivirus and security products, you can handle it.

What about the implementation team?

More people are needed for deployment; at least two or three people are necessary to cover all aspects and security postures in one solution, as it is not possible for one person to deploy everything.

Deployment for Trellix Helix Connect may take about two to three weeks if you are managing around 100 to 300 users.

Which other solutions did I evaluate?

I am currently also working with Microsoft, Kaspersky, and Symantec, along with Trellix Helix Connect.

I also work with Kaspersky and Symantec because they are cheaper solutions, but Trellix Helix Connect is the overall complete cybersecurity solution, covering all aspects in one package. That is why I prefer Trellix Helix Connect for cybersecurity.

What other advice do I have?

The orchestrated workflows of Trellix Helix Connect enhance threat response by providing detailed reporting, integration dashboards, and detailed feature reporting through Trellix ePolicy Orchestrator.

I rate the technical support from Trellix an eight out of ten.

I rate Trellix Helix Connect a nine out of ten as a product in general.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    reviewer2646834

Reduces detection and response times through automation and alert correlation

  • November 12, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for Trellix Helix Connect is to provide an MDR service to our clients. We use Trellix Helix Connect to correlate the alerts and automate the response most often.

For example, we use Trellix Helix Connect for MDR services with our clients when we have XDR for Trellix Helix Connect to analyze the alerts and set up the SOAR workflows. It depends on the client needs.

In our day-to-day operations, we have the main use case of Trellix Helix Connect which allows us to reduce MTTD and MTTR, and we have the KPIs to support this.

What is most valuable?

The best features that Trellix Helix Connect offers are SOAR, automation, hyperautomation, and the correlation of alerts and threat intelligence, for example, when the alerts cross through MITRE ATT&CK, which stand out most to me.

Out of those features, automation, alert correlation, and threat intelligence have made my work easier and more effective as we integrate many cybersecurity solutions into the XDR and set up the use cases to reduce MTTD and MTTR from days to minutes.

I would add that the level of integration with other brands is something that surprises me about the features of Trellix Helix Connect.

Trellix Helix Connect has positively impacted my organization as it is the most important tool to provide MDR service to our clients, which has resulted in specific outcomes and improvements.

What needs improvement?

To improve Trellix Helix Connect, I think it is possible to enhance the dashboard to share more information about the incidents. For example, if I want to check a MITRE technique, maybe it is necessary to have a quick link to check this technique in the dashboard.

I think the usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements.

For how long have I used the solution?

I have been using Trellix Helix Connect for one year.

What do I think about the stability of the solution?

Trellix Helix Connect is very stable, and I have experienced almost no downtime or issues, as the downtime is mainly about maintenance time, confirming its reliability.

What do I think about the scalability of the solution?

Trellix Helix Connect's scalability is excellent as the solution has a library to make integrations with other brands, allowing it to handle growth easily via API.

How are customer service and support?

The customer support for Trellix Helix Connect is well in Latin America because there are many people in the region, which enhances the experience.

Which solution did I use previously and why did I switch?

I previously used legacy SIEMs before choosing Trellix Helix Connect.

How was the initial setup?

My experience with pricing, setup cost, and licensing is that the licensing for XDR is good, though the hyperautomation feature is expensive.

What was our ROI?

We have seen a return on investment with Trellix Helix Connect, and we can share relevant metrics as we reduce the MTTD and MTTR and have KPIs indicating our ROI.

Which other solutions did I evaluate?

Before selecting Trellix Helix Connect, I evaluated other options including Palo Alto XDR, Cisco XDR, and Rapid7 with the new generation SIEM.

What other advice do I have?

The most important metrics are the reduced MTTD and MTTR because the clients' legacy solutions provide faster response when they use this tool, showing measurable benefits.

I advise anyone considering Trellix Helix Connect to review the different solutions of the XDR ecosystem, focusing on the capability to integrate with other brands without shadow cost and the capability to respond and reduce MTTD and MTTR. I would rate this product at a nine out of ten.


    Daniel_Martins

Experiencing frequent disconnections and support challenges but benefits from quick implementation and integration capabilities

  • July 17, 2025
  • Review from a verified AWS customer

What is our primary use case?

We use Trellix Helix Connect because it is a SaaS solution. I think it has its own infrastructure rather than AWS or another provider. We use the Helix SaaS and a component called Evidence Collector that gets the logs from on-premise infrastructure and sends them to SaaS. I believe everything about Trellix Helix Connect is SaaS-based.

We use Evidence Collector which can be installed with the on-premise infrastructure to collect components such as files and IPS. This product receives the logs from the infrastructure and sends the information to Helix.

What is most valuable?

The best feature of Trellix Helix Connect is its quick implementation.

The integration with Mandiant is another significant advantage. When investigating an incident, we have access to IOCs and can receive results from Mandiant about these IOCs, similar to what VirusTotal offers. We can search and utilize this integration effectively.

We utilize the artificial intelligence capabilities in Trellix Helix Connect. We can perform some customization by providing parameters in the YARA from Helix, which provides valuable analysis points.

The solution allows users to create reports more quickly with comprehensive information, which can be expanded within minutes. This demonstrates the effectiveness of Trellix Helix Connect's automation capabilities for reducing incident response times.

What needs improvement?

The timeout of the tenant is an area that needs improvement. When investigating and gathering information from the Helix tenant for extended periods, disconnections occur. This results in lost work and the need to restart investigations due to disconnected sessions.

It is problematic when progress is lost and investigations must be restarted, resulting in lost information and significant time wastage.

The capability to integrate with other TIPs or cybersecurity intelligence sources could be improved to determine whether IOCs are malicious, similar to Mandiant's functionality.

The capacity to reduce false positives needs improvement as we receive many alerts from Helix that turn out to be false positives upon investigation. Enhanced capability in this area would make the system more efficient and easier to use.

The dashboards could be improved as customers frequently request real-time SOC dashboard displays for Helix.

How are customer service and support?

The support for Trellix Helix Connect is not satisfactory. We experience difficulties accessing personnel with deep knowledge of Helix. We have numerous tickets to understand and resolve problems. It is not an easy product to support on a daily basis.

The support would rate a three out of ten. It can take one to four weeks to connect with someone who truly understands Helix and can provide solutions. This makes the product difficult to maintain.

What other advice do I have?

The solution can be challenging for analysts with lower skill levels. The syntax for finding findings requires specific knowledge, making it more difficult for initial users.

Trellix Helix Connect is generally easy to use, but the Evidence Collector component presents more challenges.

This review rates Trellix Helix Connect as 6 out of 10.


    reviewer2406618

AI capabilities streamline incident resolution and natural language search empowers security management

  • February 12, 2025
  • Review provided by PeerSpot

What is our primary use case?

I am a presales manager for a cybersecurity company, and I use Trellix Helix to manage software for cybersecurity. I sell software to enterprise customers, and my main use case involves data protection, email security, and endpoint security.

What is most valuable?

One of the most valuable features of Trellix Helix is its AI capability for the XDR platform, enabling me to reduce the time to resolve incidents. The software correlates data from the security environment and allows searches in natural language. It is crucial for enterprise companies worldwide, not just in the United States. Trellix Helix offers more than 400 connectors for integration and supports both small and large environments.

What needs improvement?

I have just released this solution to the market, and my customers' response has been great. While Trellix Wise is seen as a top vendor with its AI implementation for accelerating incident investigation, there have been some support issues due to a recent fusion and merger in the company, which could be improved.

For how long have I used the solution?

I have been working with Trellix Helix for two months.

What do I think about the stability of the solution?

The stability of Trellix Helix is really good. Although there have been some incidents, these were related to support issues rather than product instability. My solutions need to be highly available because they are critical for my customers.

What do I think about the scalability of the solution?

The scalability of Trellix Helix is impressive. I support the largest companies in the world, and the solution is not just restricted to small or medium businesses. It can scale to support large environments.

How are customer service and support?

The technical support for Trellix Helix is rated four out of five. Despite the ongoing transformation due to a fusion and merger of the company, the support could be better as there have been some challenges with staffing and information.

How was the initial setup?

The initial setup of Trellix Helix was rated nine and a half out of ten. Although no software is ever one hundred percent, my experience was good and easy to use. The installation process is simple with straightforward configuration.

What's my experience with pricing, setup cost, and licensing?

The price of Trellix Helix is competitive in the market. It is not the cheapest but also not the most expensive. As for additional costs beyond standard licensing fees, there are none.

What other advice do I have?

I advise moving quickly to adopt Trellix Helix to improve operations and get faster response times for incidents. I rate Trellix Helix overall ten out of ten.


    Kumaresan B

Helps us detect some advanced malware and offers some automated collaborations enabled internally

  • July 02, 2024
  • Review provided by PeerSpot

What is our primary use case?

It helps prevent web security threats and other things.

We use Trellix ePO. We also use Trellix Endpoint Security and DLP encryption.

How has it helped my organization?

We are currently integrated with fewer security devices. It helps us understand deductions and analysis and provides collaborative input as a first priority.

What is most valuable?

We are able to block some advanced malware and other things. I think we use the appliance-based Helix.

It helps us detect some advanced malware. That's one of the major advantages. We also have some automated collaborations enabled internally. So, if there's a new attack or alert, we have visibility on it.

However, we are not experts in automation, but we do get some automation in the Trellix product. We want to test it further.

What needs improvement?

Trellix needs to address the price for the product to be more appealing to customers.

For how long have I used the solution?

It has been anywhere between six months to a year.

What do I think about the stability of the solution?

I would rate the stability a nine out of ten.

What do I think about the scalability of the solution?

I would rate the scalability a nine out of ten. The scalability is good.

How are customer service and support?

It's proper support. So no delays. They always respond on time and the responses are informative.

Which solution did I use previously and why did I switch?

We chose Trellix among the variety of products on the market because other vendors support cloud-based threat intelligence, requiring us to interact with the cloud.

With Trellix Helix, we have on-premises offerings and we are able to collaborate on our logs within our premises. We don't want to send data outside our organization because we support banking customers. We can maintain everything internally.

How was the initial setup?

If you understand the concept of Trellix Helix, it's easy to deploy.

It took a couple of days. We haven't integrated it with any solutions yet. We just have some minimal solutions that need to be integrated. If we have any issues in the future, we'll let you know.pen_spark

What was our ROI?

There could be some financial benefits, but we are focused on security and threat prevention, not the financial aspect.

What's my experience with pricing, setup cost, and licensing?

It could be a bit expensive. I would give it an eight out of ten, with ten being expensive.

Which other solutions did I evaluate?


What other advice do I have?

I recommend Helix. I have a good experience with it. If I get a POC, I can easily give it to the customer and evaluate it.

The solution is stable and addresses advanced malware. It's also easy to access support in India.

Overall, I would rate it a nine out of ten.


    Daniel_Martins

Offers extensive platform visibility, event tracking, and integrations

  • May 23, 2024
  • Review provided by PeerSpot

What is our primary use case?

We work for a company that provides secret services related to XDR and NSS. We offer the Helix solution to many companies in Brazil. We manage the implementation and provide solutions to our customers. We are a Helix service provider for ten companies in Brazil.

How has it helped my organization?

We have started working with various customers, one of whom is particularly concerned about adjacency. We have identified several use cases where automation is possible. However, we face challenges with FSO tools, regarding integration versions. For example, our platform uses API V2, while Cisco uses V3 in some integrations. This has caused issues with professional services.

What is most valuable?

We are currently working with a provider where I need to send a lot of reports and queries to my customers. Instead, I create reports manually and provide customers with information about the solution.

What needs improvement?

We often rely on Martins to create logs and provide professional threat services rather than basic support. However, accessing these services can be inconsistent. Sometimes, responses are quick and valuable, but other times, they are delayed. For example, I've waited up to seven months for Martins to resolve an issue with Azure WAF in Helix. It can also be challenging to get timely responses from partners regarding updates and new features

How was the initial setup?

When we undertake projects to install Helix, initially, our company had all the logistical information needed from the installation guide. However, there are details not included in the manuals that we sometimes discover only through direct communication with Trelix experts. This process has become more manageable over time, but initially, we encountered significant challenges, such as issues with connectors, which handle different log formats. These discrepancies weren't clearly outlined in the manuals and caused delays.

For instance, it took about a month to deploy components like SSO and group collection for our customer's infrastructure. Each deployment involves specialized roles—one focusing on connections and another on development and automation with CFA. With these two roles, we can effectively implement Helix.

What's my experience with pricing, setup cost, and licensing?

When the merge of the companies start to use some about the price of the issue. We are using the FSO and security administrator.

I have some case of sources with some customer that returned with some a big security and and can resolve with some attacks.

What other advice do I have?

I have numerous advantages with ten client customers who use our services. We have a dedicated team working directly with the Helix system at PeerSpot within our company, providing maintenance and generating reports for our customers.

The solution offers extensive platform visibility, event tracking, and integrations. While we explore other integration possibilities like CNA, we haven't found a comparable solution yet. Integrating with other vendors and multi-platform environments presents challenges, especially in ensuring API compatibility and staying current with integrations.

I strongly recommend Helix to our new customers for its capabilities and reliability.

Overall, I rate the solution a nine out of ten.


    KarimBondok

Covers the encryption, solid choice for medium-sized businesses and offers fast local support

  • April 22, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Helix in a very restrictive environment that doesn't allow solutions to be connected to the cloud. Some solutions, like CrowdStrike and some XDR solutions, need to be connected to an external cloud. The same goes for Trellix, but with Helix, we have one option.

If we need DDI feeds or IOC feeds from vendors or customers, Helix will provide these IOCs via DDI push from Trellix to our side, even if we haven't faced any incidents.

How has it helped my organization?

It's very easy to integrate Helix into IT workflows in general, especially if you have the original system. If you have the full portfolio from Trellix or solutions that integrate easily, like XSOAR or some buckets of vendor flow or vendors like Kaspersky, then we won't be facing many problems.

I have worked on implementations with Huawei and IBM QRadar. Now, when it's a Helix operation. Sometimes, I remember that IBM told me to open a request for enhancement from both sides, Huawei and IBM, which, until now, hasn't happened. These tickets have been open for about three years. That caused the customer to replace Huawei with a Cisco engine to make the integration very easy.

I am aware that Helix is investing in the development to enhance its solutions. I already attended multiple webinars regarding cybersecurity solutions from Trellix's cybersecurity solutions.

However, I’m not sure if it can integrate with other vendors like IBM’s EDR or cloud-based solutions. But as far as its core functionality goes, it’s spot-on.

What is most valuable?

Enrichments. It's all about enrichments. Helix is a robust solution.

Helix, it's a good solution. Since management, I've been working with the team; I like the Helix ecosystem.

What needs improvement?

There is room for improvement in the integration capabilities of third-party tools.

It has no problem connecting all solutions to Helix. Right now, we only connect one of Trellix's appliances to the Helix solution, the EDR solution. That's it.

We faced many problems regarding integrating some with Helix or integrating the ITSM with Helix; the system refused that.

So, it depends on the customer's environment and regulations.

For how long have I used the solution?

I have been using it for one and a half years.

What do I think about the stability of the solution?

In terms of stability, I’d rate it a strong nine out of ten, where ten is the most stable. Very reliable overall.

What do I think about the scalability of the solution?

Since I haven’t worked with Helix extensively, I can’t give it a perfect ten, but I’d rate the scalability of this solution an eight out of ten.

For small businesses, they might not initially opt for Helix. Instead, they often choose solutions like Kaspersky antivirus or EDR SIP.

However, for medium and large enterprises, Helix is a solid choice. I’ve also heard that big customers tend to prefer CrowdStrike and Fidelis.

How are customer service and support?

The customer service and support are very fast. Trellix’s vendor support is excellent. They have responsive experts who can assist us without delay. We don’t need to go through lengthy processes; our local support team handles Helix cases efficiently. For critical issues, they usually respond within thirty minutes to an hour. Overall, their professionalism stands out.

Which solution did I use previously and why did I switch?

I worked with a customer that had a McAfee EDR from Kaspersky and another vendor's NDR. They faced many issues, and eventually, they paid much money for little value.

The main competitors are CrowdStrike and Fidelis. In terms of customers, they don't have a problem with cloud connection. We will put CrowdStrike as the first competitor because of customers' worries about the cloud connection. Most of the POCs I saw were Fidelis and Trellix, or Cortex, against Linux. I see these two at customers all the time.

How was the initial setup?

The initial setup is very simple. Before we bought Trellix, we had some other competitors like Kaspersky and Fidelis. During the proof of concept (POC), we found it very hard to integrate in that situation.

And capability-wise, Fidelis is also big for enterprises, but the main issue was integration and management, especially that the appliance management of services is not that good.

On the other hand, Trellix has the SIEM appliance, which can create custom rules and make your EDR and NDR talk to each other and provide more enrichments and more insights into incidents, whether it is a true positive or false positive. But it's good to have, especially when we talk about EDR and NDR, it is very recommended to have both solutions from the same vendor to avoid any integration and configuration issues.

We primarily manage Helix software for API cloud. The appliances are physical and managed in the data centre.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable compared to its competitors.

What other advice do I have?

Overall, I would rate the product a nine out of ten. I would recommend it to other users.