Anomali ThreatStream vs. Trellix Enterprise Security Manager

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Anomali ThreatStream
Score 7.1 out of 10
N/A
ThreatStream from Anomali in Redwood City speeds detection of threats by uniting security solutions under one platform and providing tools to operationalize threat intelligence. ThreatStream also automates many of the tasks typically assigned to security professionals, freeing analysts to quickly handle threats. ThreatStream collects threat intelligence data from hundreds of third party sources.N/A
Trellix Enterprise Security Manager
Score 7.1 out of 10
N/A
Trellix Enterprise Security Manager (formerly McAfee Enterprise Security Manager) is security information and event management (SIEM) software.N/A
Pricing
Anomali ThreatStreamTrellix Enterprise Security Manager
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Anomali ThreatStreamTrellix Enterprise Security Manager
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details——
More Pricing Information
Community Pulse
Anomali ThreatStreamTrellix Enterprise Security Manager
Top Pros
Top Cons
Features
Anomali ThreatStreamTrellix Enterprise Security Manager
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Anomali ThreatStream
-
Ratings
Trellix Enterprise Security Manager
8.4
9 Ratings
7% above category average
Centralized event and log data collection00 Ratings8.69 Ratings
Correlation00 Ratings7.09 Ratings
Event and log normalization/management00 Ratings8.09 Ratings
Deployment flexibility00 Ratings8.39 Ratings
Integration with Identity and Access Management Tools00 Ratings9.37 Ratings
Custom dashboards and workspaces00 Ratings9.39 Ratings
Host and network-based intrusion detection00 Ratings8.37 Ratings
Data integration/API management00 Ratings9.32 Ratings
Behavioral analytics and baselining00 Ratings8.72 Ratings
Rules-based and algorithmic detection thresholds00 Ratings8.72 Ratings
Response orchestration and automation00 Ratings8.02 Ratings
Reporting and compliance management00 Ratings8.72 Ratings
Incident indexing/searching00 Ratings7.72 Ratings
Best Alternatives
Anomali ThreatStreamTrellix Enterprise Security Manager
Small Businesses
AlienVault USM
AlienVault USM
Score 8.0 out of 10
AlienVault USM
AlienVault USM
Score 8.0 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Splunk Enterprise
Splunk Enterprise
Score 8.4 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Microsoft Sentinel
Microsoft Sentinel
Score 8.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Anomali ThreatStreamTrellix Enterprise Security Manager
Likelihood to Recommend
8.9
(3 ratings)
9.0
(9 ratings)
Support Rating
-
(0 ratings)
6.5
(2 ratings)
User Testimonials
Anomali ThreatStreamTrellix Enterprise Security Manager
Likelihood to Recommend
Anomali
Anomali ThreatStream is excellent in scenarios where we deliver Managed Security Services to customers. It offers exhaustive volumes of information in the form of threat bulletins, IOCs, Threat Actor profiling, and details related to campaigns in the wild which can be used to a great extent by MSSPs. For an enterprise SOC, I believe it is a little less suited purely because of the pricing aspect as it is slightly towards the expensive side of the spectrum.
Read full review
Trellix (FireEye + McAfee)
I believe that McAfee Enterprise Security Manager is best-suited for anyone in an office setting with a computer containing sensitive information. McAfee Enterprise Security Manager is constantly working to make sure that your device is free from an threats. Our field workers, however, probably wouldn't have a need for McAfee Enterprise Security Manager. They do not use computers for work and have no sensitive information stored in a work-related cloud.
Read full review
Pros
Anomali
  • Indicators of Compromise
  • Signatures
  • Community Sharing
Read full review
Trellix (FireEye + McAfee)
  • McAfee Enterprise Security Manager has a large library of pre-made correlations that reduces the amount of work needed to make it functional.
  • This is a core McAfee product that is still getting support.
  • It has a substantial amount of compatibility and integration with other products.
Read full review
Cons
Anomali
  • The user interface, perhaps there is some room for improvement although it is good already.
  • Confidence assigning process for IOCs needs to be more robust and transparent.
  • While integration with SIEM solutions is a cakewalk, there is definitely added value if SIGMA rule conversion and YARA rule creation are provided from the platform.
Read full review
Trellix (FireEye + McAfee)
  • The user interface is not the best, it is still based on Flash player (but they have plans to migrate to HTML5).
  • While the "user" interface is pretty straight forward, the management interface is fairly complicated.
Read full review
Support Rating
Anomali
No answers on this topic
Trellix (FireEye + McAfee)
McAfee Enterprise Security Manager overall is a great tool. It is effective in today's setting, wherein lots of potential threats are lurking. Its operations within the network are seamless. Users won't even notice that a SIEM is working in the background. But in today's trend, most of the businesses is heading towards the migration to cloud, which McAfee should improve its integration with.
Read full review
Alternatives Considered
Anomali
Many of the products that can be used to be ingested into a security event management software can be cumbersome with threat streamThere are many opportunities to continue fine-tuning the environment and providing great context in regards to threat research. When compared to other products threat stream stands out from usability and features.
Read full review
Trellix (FireEye + McAfee)
We selected McAfee Enterprise Security Manager because the pricing is competitive in the industry. It is very reliable. The vendor offers good support in real time. Offers the results that we have been looking for. The ability to get the logs may be of last 2 years in a matter of seconds. The ability to retain logs for a very long time.
Read full review
Return on Investment
Anomali
  • After the Initial startup cost, it has overall had a positive impact by increasing efficiency of the team and freeing up analysts to do manual threat hunting
Read full review
Trellix (FireEye + McAfee)
  • Centralisation of events form NIDS/IPS/IDS, Firewall(s), Web Proxy and Endpoint
  • Ability to have third party management
  • Actively upgraded product with good vendor support
Read full review
ScreenShots