Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.
N/A
Trellix Intrusion Prevention System
Score 7.8 out of 10
N/A
Trellix Intrusion Prevention System (replacing the former McAfee Network Security Platform) is an intrusion detection and prevention system (IDPS) for on-prem or virtual networks.
In a multi-account/multi-tenant environment, GuardDuty often alerts us to possible malicious traffic before it becomes an issue. The ability to automatically enable GuardDuty creates baseline security which is crucial when an account is first created. It also helps greatly in environments where other users are able to create resources as often GuardDuty alerts us to insecure resources we did not know about. It can however sometimes be a little overzealous with its assessments alerting on benign activity which then requires suppression rules.
McAfee Network Security does do what it promises, and it integrates nicely with other McAfee services my work computer has. Sometimes I do feel though that McAfee does hinder your computer/internet performance, but maybe it's a trade-off that's worth it. I do wish they would refine their threat detection so some websites that I don't think are harmful and want to visit for work purposes aren't blocked. There's been times where I google a question and a website has the answer but McAfee will block it. If you're in a position at a financial company like me, where you're dealing with sensitive/private information, it's important to have this type of software to protect data.