OFFICIAL PARTNER · CYBER BOOST

Trellix

An open XDR platform for the SOC

Trellix was formed in 2022 by merging FireEye and McAfee Enterprise. It combines EDR, NDR, SIEM (Helix), Email Security and DLP in one XDR platform with the Trellix Wise GenAI assistant.

XDR SIEM (Helix) EDR NDR DLP Email Security
KEY FACTS
40,000+
customers worldwide
$2B
annual revenue
5,000
employees
2022
founded (STG)
Combines FireEye and McAfee Enterprise technology
Trellix logo
Open XDR Platform
Gartner Recognized FireEye + McAfee
CATEGORY
SecOps · XDR
EDR · NDR · SIEM
DELIVERY MODEL
SaaS + On-Prem
Hybrid deployment
PARTNERSHIP
CYBER BOOST
Official partner in Uzbekistan
PRODUCTS AND MODULES

What the platform includes.

Trellix XDR Platform combines detection and response tools for the whole attack surface: endpoints, network, email, data and cloud.

XDR Platform
Trellix XDR
An open and native XDR platform: one console to investigate incidents, with events correlated from all sources.
Endpoint Security
EDR / ENS
Endpoint detection and response built on McAfee ENS and MVISION EDR. Protects Windows, macOS and Linux.
SIEM
Trellix Helix
A cloud SIEM with built-in SOAR. Collects and correlates events, keeps logs for compliance and has ready-made playbooks.
Network Detection
Trellix NDR
Detects network threats by analyzing traffic behavior. Built on FireEye Network Security (NX).
Email Security
Trellix Email
Email protection against phishing, BEC, ransomware and attacks using malicious attachments and URLs.
Data Protection
Trellix DLP
Controls data leaks on endpoints, in the network and in the cloud. Classifies sensitive data and applies policies automatically.
Threat Intelligence
Trellix Intelligence
Global threat intelligence from the Trellix Advanced Research Center. Attack attribution, IOC feeds and TTP analytics.
GenAI Assistant
Trellix Wise
A GenAI assistant for the SOC. It automates investigations, writes queries, adds context to alerts and helps reduce MTTR.
Forensics & Investigation
Helix Forensics
Digital forensics and incident analysis, built on Mandiant/FireEye tools for in-depth investigation.
CAPABILITIES

Key capabilities.

Open XDR

Open XDR takes data from any source, Trellix or third-party. You don’t have to replace your current tools.

Event Fabric

Trellix Event Fabric normalizes and enriches events from all sources, so they can be correlated and analyzed together.

GenAI with Trellix Wise

GenAI-assisted investigations: automatic context for alerts, natural-language search and response suggestions.

Ransomware Detection

Trellix XDR Platform for RDR covers every stage of a ransomware attack, from initial intrusion to encryption.

Advanced Research Center

The Trellix ARC research center: global telemetry, threat attribution and threat intelligence feeds for the SOC.

SIEM with SOAR

Helix combines SIEM and SOAR. Ready-made automation playbooks, case management and integration with ticketing systems.

MVX Multi-Vector

MVX technology, originally from FireEye, runs malicious code in an isolated environment and analyzes it across multiple vectors.

Compliance Reporting

Ready-made reports for PCI DSS, HIPAA, ISO 27001 and local regulators. Audit logs and log retention.

USE CASES

Who uses Trellix and how.

Enterprise SOC

One console for tier 1-3 analysts. Events from EDR, NDR, SIEM and cloud sources are correlated in one investigation.

Ransomware protection

Trellix RDR detects every stage of the attack chain: phishing, lateral movement, exfiltration and encryption attempts. AI helps with remediation.

Financial sector

SIEM logging for PCI DSS. Email protection against BEC and phishing. Monitoring of privileged DBA and admin operations.

Public sector

A SOC for government systems: centralized log collection, threat hunting for APT campaigns, reporting for regulators.

MSSP / MDR

Multi-tenant architecture for MSSPs. You can move your SOC to a service provider that uses Trellix XDR.

Replacing a legacy SIEM

Migration from legacy on-prem SIEMs to cloud-based Helix. Lower TCO and fast onboarding of new log sources.

DEPLOYMENT OPTIONS

Choose the right model.

Trellix supports SaaS, on-prem and hybrid deployment models. CYBER BOOST will help you choose the best option.

SAAS

Trellix Cloud (SaaS)

A fully managed XDR platform in the cloud. Helix SIEM, EDR Cloud Management, automatic updates.

  • Fast onboarding
  • Automatic scaling
  • Trellix Wise out of the box
ON-PREMISE

On-Prem Deployment

Deployed in your own data center. For regulated industries that must keep data in the country.

  • Data inside the perimeter
  • Air-gapped environments
  • Full customization
HYBRID

Hybrid Deployment

A combination of on-prem sources and cloud analytics. Logs stay local, while correlation happens in Helix.

  • Gradual migration
  • A single SOC policy
  • AWS partnership for XDR
40,000+
customers worldwide (at founding)
$2B
annual revenue
5,000
Trellix employees
2022
founded (FireEye + McAfee Enterprise)
INTEGRATIONS

Open XDR, with no vendor lock-in.

Trellix Helix XDR has one of the broadest sets of integrations and needs very few native components.

CLOUD PLATFORMS
AWS Microsoft Azure Google Cloud Oracle Cloud
ENDPOINT AND IDENTITY
CrowdStrike Microsoft Defender SentinelOne Active Directory Microsoft Entra ID Okta
SIEM AND ITSM
Splunk IBM QRadar Microsoft Sentinel ServiceNow Jira Service Management
NETWORK AND PERIMETER
Palo Alto Networks Fortinet Check Point Cisco Zscaler
COMPARING MODULES

Which module to choose.

CYBER BOOST will help you choose the right set of Trellix products.

Capability Trellix XDR Helix SIEM EDR Email Security
Correlation of events from all sources✓✓--
Endpoint protection (Windows/macOS/Linux)✓-✓-
SOAR playbook automation✓✓--
Email protection (phishing, BEC)✓--✓
Trellix Wise (GenAI)✓✓Partially-
Compliance logging✓✓--
File sandbox analysis (MVX)✓-Partially✓
Trellix ARC threat intelligence feeds✓✓✓✓
DeploymentSaaS / HybridSaaSCloud / On-PremSaaS
FAQ

Frequently asked questions

How is Trellix different from McAfee and FireEye?
Trellix was formed in January 2022 from the enterprise business of McAfee (ENS, EDR, DLP) and FireEye (Helix, NX, MVX). All products are now developed under one brand, Trellix XDR Platform.
What is Trellix “Open XDR”?
It is an open XDR architecture. Trellix XDR Platform takes data from Trellix products and also from CrowdStrike, Microsoft, Palo Alto and others. You don’t have to replace the tools you already use.
What can Trellix Wise do?
Trellix Wise is a GenAI assistant for the SOC. It automates incident investigation: it adds context to alerts, writes search queries from plain-language requests, suggests responses and helps reduce MTTR.
Can Trellix be deployed on-premise in Uzbekistan?
Yes. Trellix supports on-prem deployment for regulated industries. As a partner, CYBER BOOST will help with architecture, licensing and on-site setup.
REQUEST

Request a demo or a quote

We reply within one business day.