What I like most about Trellix NDR is the network visibility it provides for security monitoring and incident investigations. We use it to investigate suspicious network communications, identify unusual traffic patterns, and get additional context when investigating security alerts.
It is particularly useful when endpoint telemetry alone does not provide enough information. Being able to review network connections and related activity helps us understand what a system was communicating with and supports our incident response investigations.
The platform also works well as an additional layer alongside our existing security tools and helps provide broader visibility across the environment. Performance has been generally good for continuous network monitoring, although there is room for improvement in alert prioritization and investigation workflows. Review collected by and hosted on G2.com.
The main area I would like to see improved is the investigation experience. When there are a large number of alerts or network events, it can take additional effort to identify the activity that requires immediate attention.
The UI could be more intuitive, particularly when pivoting between network connections, alerts, and related events. Better correlation and automation would also reduce the amount of manual investigation required from analysts.
Integration with other security platforms is important in our environment, and having more out-of-the-box integrations and automated workflows would make the product more useful. Additional AI-driven alert summarization and prioritization could also help analysts quickly understand the context and focus on higher-value investigations. Review collected by and hosted on G2.com.