No more typing reviews! Try our Samantha, our new voice AI agent.

Bitdefender GravityZone EDR vs Sangfor Endpoint Secure comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Bitdefender GravityZone EDR
Ranking in Endpoint Detection and Response (EDR)
25th
Average Rating
8.4
Reviews Sentiment
6.3
Number of Reviews
62
Ranking in other categories
No ranking in other categories
Sangfor Endpoint Secure
Ranking in Endpoint Detection and Response (EDR)
30th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
11
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.6%, down from 3.9% compared to the previous year. The mindshare of Bitdefender GravityZone EDR is 1.5%, down from 2.5% compared to the previous year. The mindshare of Sangfor Endpoint Secure is 0.8%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.6%
Bitdefender GravityZone EDR1.5%
Sangfor Endpoint Secure0.8%
Other94.1%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
HarshBhardiya - PeerSpot reviewer
SOC Engineer at a outsourcing company with 10,001+ employees
Provides detailed event investigation and endpoint control but needs better Mac support and UI improvements
I find the advanced behavioral analytics feature in Bitdefender GravityZone EDR a little gimmicky, as I don't usually find much use for it. The advanced behavioral analytics feature needs to be optimized to be more user-friendly and easier to work with. We don't specifically look for the customizable dashboards within Bitdefender GravityZone EDR; rather, we get the logs on our SIEM solution, QRadar, where we have created the dashboards. We also have Tableau and Power BI, so we don't utilize any dashboards on the EDR front. I would like to optimize the incident response area as well, especially when comparing my experience with CrowdStrike, which is relatively more responsive and easier to navigate when there are multiple hosts involved. Other areas of improvement for Bitdefender GravityZone EDR include its lack of support for Mac devices.
OA
Coordinator Associate at National Institute of Cardiovascular Diseases
Quick threat response and behavior analysis while enhancing network security
The main use case is usually related to security. It deals with attacks that come day-to-day such as zero-day attacks and APT attacks. Our main task is to secure the network infrastructure in the hospital where I work It facilitates the departments of IT and other departments to procure and…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its ability to react to cyber data attacks is awesome. That is pretty much the use of it. What blows your mind is the ability to access your assets remotely and see what is actually going on with them. You can not only see them in a console. You can also react very rapidly to your assets that are compromised."
"The scalability of Cortex XDR by Palo Alto Networks is very good."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"From the Palo Alto side, whatever they buy, they integrate that really well into their integration suite, and that makes a massive difference."
"It collects and caches and the knowledge of machine learning from different customers to take to the cloud, it makes it better to use for everybody, it allows for quick learning and updates and can, therefore, offer zero-day malware security, and this sharing of metadata helps make the solution very safe."
"We can visualize and control the activities in the environment from anywhere."
"The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
"Automation and playbooks have helped me significantly, as Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context, efficiently detecting and blocking malicious attacks with firewalls while eliminating workload and speeding responses for next-generation operations."
"If you detect a virus, you can isolate the PC from the network and prevent access to the internet, network and routers. Once fixed, you can give access back to the client. We have not had this functionality using other solutions."
"The most valuable feature of Bitdefender GravityZone Ultra is the ETX and ETM endpoint protection."
"We have had no issues with the support and consider it to be good, even when it comes to accredited resellers."
"Great protection against malware, ransomware, and any other forms of malicious software."
"The most valuable features are the anti-malware and firewall policies, and the runtime scans and execution have been beneficial to our business."
"What I have found to be valuable is after every new release of the solution there are more features. At the time that we bought Bitdefender GravityZone, it was their top solution. We went from their Enterprise version to Elite, Elite HD, Ultra, and now there is an Ultra Plus available."
"The product is worth the investment."
"You can control everything, including monitoring of all websites and blocked devices, from one place."
"The product's initial setup phase was straightforward."
"The real-time monitoring feature of Sangfor Endpoint Secure is truly real-time, with no delay compared to other solutions."
"The most valuable feature I have found in the system is its comprehensive end-to-end protection."
"The tool's most valuable features are control access, endpoint security, and load balancing of ISPs."
"Sangfor Endpoint Secure has some good policy certificates."
"The user-friendliness of Sangfor Endpoint Secure is particularly impressive. Even with basic technical knowledge, users can easily navigate the system, make changes, and implement updates."
"It has a quick response time, threat intelligence, cybersecurity features, quick report generation, behavior analysis, dynamic detection, and quarantine features."
"What stands out to me is the dual-end user interface they provide."
 

Cons

"I have seen lagging with Cortex XDR by Palo Alto Networks. There was one time when we faced a threat actor trying to gain access to our system. When our team utilized the tool, we were all on the same dashboard and we faced a lag issue at that time of around five minutes, which was quite significant."
"The solution eats memory of the computer, unlike anything I've ever seen."
"The solution lags to the real-time scenarios here and there."
"Limited remote connection."
"I would like to see them include NDR (Network Detection Response). Then it would work well with SIEM Response."
"However, if you do not have Palo Alto in your environment, you are paying these additional services just for Cortex XDR by Palo Alto Networks, so it is not a cost-effective solution."
"Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
"On the pricing aspect, Cortex XDR by Palo Alto Networks needs to have a more reasonable rate, particularly for customers in Sri Lanka and Asian countries."
"The software itself is solid. It would be better if it was more of a real-time solution, like SentinelOne. The one thing that holds me back on the SentinelOne side is that I can blacklist websites and stuff like that, but it's not as granular as Bitdefender. With Bitdefender, I feel like I have more control over what I can whitelist and blacklist."
"The only problem we have, and I don't know if maybe it's the package we bought, is that it lacks the parts of data protection and application blacklisting."
"It would be better if it was more of a real-time solution, like SentinelOne."
"They need to improve their encryption capabilities."
"There's room for improvement in terms of protection. That's my primary concern."
"The firewall security could be better."
"The only issue an end user might have is in the case where a website has some kind of monitoring software included, where they want to track use, and it might unnecessarily block the site for the user."
"The on-premises setup for Bitdefender sometimes faces issues with connectivity. Management of Windows Defender is a bit easier compared to Bitdefender."
"When an issue occurs, the response time for first-level support and the time taken for meetings could be improved."
"I believe Sangfor Endpoint Secure could improve in terms of its user interface and management capabilities."
"Currently, the tool lacks reporting functionalities."
"It is complicated to establish a tunnel due to technical issues in the VPN system."
"Sometimes, the VPN is not secure and doesn't work properly in Sangfor Endpoint Secure."
"The interface has too many buttons, making it cluttered."
"I face issues while migrating from Kaspersky to Sangfor Endpoint Secure."
"There are a few areas for improvement. We have encountered licensing issues on occasion, and sometimes updates don't apply properly."
 

Pricing and Cost Advice

"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"I don't recall what the cost was, but it wasn't really that expensive."
"I feel it is fairly priced."
"It is "expensive" and flexible."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"The pricing is competitive."
"There are some differences. It's more cost-effective, yet it provides the same functionalities as Defender. That's why I've been exploring the comparisons. We pay for it annually, and it's a per-seat payment."
"Bitdefender GravityZone EDR is cost-effective and has the best pricing."
"If you look at the solution's price point, it's actually low market value, especially in comparison to other ones."
"The solution's price is mid-ranged."
"We need to pay for a yearly license for the solution."
"There are different packages available that vary in terms of licensing fees."
"Licensing is done on a yearly basis and it's workstation-based."
"We were using Hyper-V. So, we switched to Sangfor because of the pricing."
"Sangfor Endpoint Secure is not a cheap solution."
"Its "pay as you grow" model offers cost-effectiveness compared to major cloud providers."
"The solution is cheap. It is cheaper than other products by 15-20 percent."
"Price-wise, Sangfor Endpoint Secure can be considered a competitively priced product in the market as it offers quite low prices compared to other solutions."
"The product is expensive compared to other vendors."
"Sangfor Endpoint Secure's pricing is cheap. I rate it seven out of ten."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
913,924 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Comms Service Provider
12%
Outsourcing Company
10%
Construction Company
10%
Manufacturing Company
6%
Financial Services Firm
17%
Comms Service Provider
11%
Media Company
7%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise9
Large Enterprise11
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Bitdefender GravityZone Ultra?
The cost is reasonable, with the license costing approximately six to eight dollars per user.
What needs improvement with Bitdefender GravityZone Ultra?
I would like to see improvements in Bitdefender GravityZone EDR to better support older machines. From my experience,...
What is your primary use case for Bitdefender GravityZone Ultra?
My usual use cases for Bitdefender GravityZone EDR mostly involve zoning, reviewing EDR policies, and vetting for pos...
What needs improvement with Sangfor Endpoint Secure?
The interface has too many buttons, making it cluttered. It would be better if it were a simplified version with fewe...
What is your primary use case for Sangfor Endpoint Secure?
Sangfor Endpoint Secure is easy to handle with its user-friendly interface. The four engines it utilizes for endpoint...
What advice do you have for others considering Sangfor Endpoint Secure?
At first, people might not understand the interface, which is why it should be simplified. However, once they underst...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Bitdefender GravityZone Ultra, Bitdefender GravityZone
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Mentor Graphics, Rudersdal Kommune
Information Not Available
Find out what your peers are saying about Bitdefender GravityZone EDR vs. Sangfor Endpoint Secure and other solutions. Updated: September 2026.
913,924 professionals have used our research since 2012.