Symantec Advanced Threat Protection vs. Trellix Network Security

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Symantec Advanced Threat Protection
Score 9.0 out of 10
N/A
Symantec Advanced Threat Protection is a single unified solution that uncovers, prioritizes, and remediates advanced attacks. The product fuses intelligence from endpoint, network, and email control points, as well as Symantec’s massive global sensor network, to stop threats that evade individual security products. It leverages existing Symantec Endpoint Protection and Symantec Email Security.cloud investments, so it does not require the deployment of any new agents. It includes functionality…N/A
Trellix Network Security
Score 8.6 out of 10
Enterprise companies (1,001+ employees)
Trellix Network Security (formerly FireEye Network Security and Forensics products) combines network traffic analysis and network forensics for attack analysis .
$0
per appliance/ per mbps
Pricing
Symantec Advanced Threat ProtectionTrellix Network Security
Editions & Modules
No answers on this topic
SmartVision
$0
per appliance/ per mbps
Offerings
Pricing Offerings
Symantec Advanced Threat ProtectionTrellix Network Security
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
Symantec Advanced Threat ProtectionTrellix Network Security
User Ratings
Symantec Advanced Threat ProtectionTrellix Network Security
Likelihood to Recommend
6.7
(0 ratings)
9.0
(0 ratings)
Likelihood to Renew
7.0
(0 ratings)
-
(0 ratings)
Usability
7.0
(0 ratings)
-
(0 ratings)
Support Rating
8.0
(0 ratings)
-
(0 ratings)
Implementation Rating
8.0
(0 ratings)
-
(0 ratings)
User Testimonials
Symantec Advanced Threat ProtectionTrellix Network Security
Likelihood to Recommend
I think Symantec ATP is more of a medium or large-scale product where a company has a lot of endpoints. It is burdensome for smaller companies with limited IT support to try and get the product up and running. In addition I feel the new own, Broadcomm, is also trying to angle their product more to the large customer base. A medium or large scale customer in the need of end-to-end protection for their network really cannot go wrong with the product once configured correctly.
Read full review
It’s a dedicated Network Advanced Threat Detection and
Prevention solution. Easy maintenance and low operating costs fit perfectly for
SMEs. Variety of appliance selection makes NX the perfect choice for large
enterprises. As it’s a dedicated solution with its own appliance, price is higher
compared to NGTP add on solutions. FireEye is an ecosystem therefore when you’ve
the EX or HX vice versa, you should be looking to NX. Otherwise, you’re missing
the threat intel exchange on the network side reverse is the true. Sizing is
important before the purchase, if you select a low end model for a busy network
you lose your initial investment. For multiple NX deployments I highly
recommend CMS. Without CMS you’ll lose the threat intel exchange and this will
negatively reduce the risk scores.
Read full review
Pros
  • It was easy to install on machines in an active directory environment, and maintain/update whenever we needed without having to physically go to clients.
  • The interface was pretty well locked down for clients, which was good in order to stop accidental meddling.
  • Symantec has good online resources for current threats, including messages or warning signs and what to do/where to find them on a machine in case SATP cannot deal with it on its own.
Read full review
  • Advanced detection of targeted attacks.
  • Mandiant team effort is a big plus.
  • Inline mitigation capabilities particularly well.
  • Different deployment models for specific needs.
  • License and information sharing selection 1 way or 2 way mode.
  • Frequent updates.
  • Low false positive rates.
  • FireEye sandboxing is immune to sandboxing attacks.
  • Central management (CMS) capabilities for managing several NX's.
  • Extra IPS/IDS functionality in the product.
  • Smartvision specific to lateral movement detection.
  • Upgrades and updates with zero down time.
  • Local FireEye support is superb.
  • Multiple deployment scenarios (span, inline) in the same NX for different interface pairs.
  • SSL inspection support.
  • No need to maintain, build or updates the images. It's highly automatic.
Read full review
Cons
  • Supplier support - Really dire. Technical support off shore was passable, but account management was non existent. Really reflects on Symantec poorly given our spend per annum with them.
  • Cost per annum. At the upper end of protection systems. With little or no account support this was poor value.
  • Proactive communications with customer
Read full review
  • Very first detected APT sample can pass the NX even it's inline blocking mode.
  • Performance optimization for busy networks is cumbersome.
  • CMS does not provide all the management capabilities, CLI or local config. Should be done for advanced customization.
  • Constant limitations of tcpdump/ packet capture for 10G interfaces.
  • IPS functionality is a bit cumbersome, not a full feature IPS, lack of signatures and customization of IPS signatures.
  • It's not a full NDR solution or a UBA solution.
  • Lack of device or user mapping.
  • Forensics is based on the specific APT. May not provide the whole story and need some additional tools.
  • You cannot make manual submission to NX (needs AX).
  • You cannot access the kernel directly for deep analy[sis] or troubleshooting (assist from FireEye Support should be taken).
Read full review
Likelihood to Renew
Symantec Advanced Threat Protection has done a sufficient job at identifying true positives. However, the UI could be improved and the amount of false positives is a little too frequent for my liking
Read full review
No answers on this topic
Usability
There is a small learning curve, but compared to other AV products it is fairly simple and easy to catch onto
Read full review
No answers on this topic
Support Rating
Support responds fast for higher priority issues, they have always been good at solving the problems we encounter.
Read full review
No answers on this topic
Implementation Rating
No, besides to review documentation prior to beginning. That is what helped lead to a smooth implementation
Read full review
No answers on this topic
Alternatives Considered
Proofpoint Advanced Threat Protection is a software with a high potential to detect and respond quickly to threats that target email, however Symantec Advanced Threat Protection provides a more complete protection that protects the entire network or devices and endpoints that are managed on a daily basis and has incredible ease of use. While Proofpoint Advanced Threat Protection is not a software that is very easy to use, it requires high maintenance and its protection is based on attacks that enter through email; this is why Symantec Advanced Threat Protection was finally chosen.
Read full review
FireEye NX is a solid product. It gives you sustainable
security throughout the organization. NX detection engines are more capable
compared to others. Its catch rate is higher, FP rate is lower, [and] speed is
awesome. NX can work for highly regulated environments with 1 way solution.
Operation costs are much lower. Software quality is very good. It may have bugs, but these bugs do not compromise the security in general. SOC team loves the
FireEye NX for its pinpoint detection capabilities. Local and partner support
is exceptional.
Read full review
Return on Investment
  • We haven't ever suffered from a serious security compromise, and I owe that to our Symantec AV.
  • Once installed and set up, it's difficult to pull it out of the environment and try something else, so it has a way of keeping itself stable.
  • Some customers have a hard time paying the price because they don't "see" it do anything, and wonder what they are paying for.
Read full review
  • As [a] financial company on the digital markets, we need to be safeguard for 0days and targeted attacks. FireEye NX provides the best updated protection with its enhanced capabilities.
  • Security score based on detection/prevention metrics [is] very high ensuring the highest level of security.
  • APTs in our region successfully detected and mitigated by the NX.
  • For the ROI, in a six month period FireEye is paying off its [investment].
  • One negative thing, especially with increasing network bandwidths, [is that] you need to make [the] investment every two or three years.
Read full review
ScreenShots

Trellix Network Security Screenshots

Screenshot of Network Security Dashboard- Summary view of alerts and threats to organizationScreenshot of Alerts dashboard- detailed information around alerts discovered by FireEye Network SecurityScreenshot of Configuration for FireEye Network Security Product.