Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon Sandbox vs Deep Instinct Prevention Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Ranking in Anti-Malware Tools
15th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
7
Ranking in other categories
No ranking in other categories
Deep Instinct Prevention Pl...
Ranking in Anti-Malware Tools
21st
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
18
Ranking in other categories
Endpoint Protection Platform (EPP) (40th)
 

Mindshare comparison

As of July 2025, in the Anti-Malware Tools category, the mindshare of CrowdStrike Falcon Sandbox is 1.3%, up from 0.9% compared to the previous year. The mindshare of Deep Instinct Prevention Platform is 1.3%, down from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools
 

Featured Reviews

Abhimanyu Raj - PeerSpot reviewer
Alerts and notifications have enhanced malware detection capabilities
These features are probably the most essential for me. I find the notifications and alerts received from CrowdStrike server to be invaluable. They analyze Falcon and provide output regarding any kind of infected malware devices or files. We have seen returns on our investment in more than thousands of instances, which is the most important part for us.
Elena Yau - PeerSpot reviewer
Prevention, in advance, saves us remediation time
We have a PHI (protected health information) committee, and some of the things that we review on a weekly basis are incidents. For example, if there was malware or adware or some kind of phishing attempt, or even ransomware, we would have to investigate and see if there was any PHI impact. We've seen small things because some kind of adware made its way through the browser from some malicious link, and it's really hard to prevent those. We're putting more levels of filtering around that. There are some product development ideas that we have been working on alongside the DI team, and they've been super helpful. There are definitely a lot more little areas of improvement for the interface. Also, we have talked with the DI team about adding the forensic piece, which is what we do a lot. That would be added value and they've just recently provided more individuals to think about the roadmap. That's part of their strategy and one of the good features that they want to bring on. Hopefully, they can bring that to fruition and that will ease our workflow a little bit more. The additional predictive and prevention capabilities in the 3.0 version, that don't require special rules and configuration, help our organization. The only caveat is that when things get done automatically, I would appreciate more logging of what's happening in the background, if it is doing some kind of intervention. If we need to do some forensics, we should be able to backtrack from the log that gets uploaded to our cloud instance and see, forensically, what the root cause was. We should be able to see what instigated that trigger by DI and what exactly was done. That's a missing piece. It does a good job of preventing, but then we don't know what were the symptoms of the prevention. Let's say that there was like a PowerShell block. We'll see an indicator on the dashboard and we'll look at the logs and investigate. Sometimes we find that the logs that are captured locally on the endpoint itself are not very thorough. We were coached through our training with DI that, when troubleshooting, the DI team would always ask for the logs from the endpoint. We know what we need to do to look at something. But the logging for DI doesn't capture everything. There are some things that are missing. When it comes to root-cause analysis, or kill-chain analysis, and figuring out exactly what happened, it's very hard to do that right now on the product. I have used Carbon Black before and they're pretty good with the forensic analysis. That does save some efforts of my one engineer and myself when we have to go through the PHI committee. Right now, with Di, that feels like a blind spot. Another area for development is making the license clean-up a little bit easier. We always have to manually uninstall agents. If there were some way to remove the licensing and do better license management on the platform, that would help my team as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"The tool helps to obtain information about potential company breaches. The malware analysis capability is very effective. We check files from various sources, such as emails, USBs, and cloud drives."
"The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint."
"It provides a safe way to analyze and review documents that may have sensitive information without uploading them to a public platform. Additionally, provides an easy way to spin up a VM without requiring additional resources and patching of personal or team-managed virtualization."
"On a scale of 1-10, I rate CrowdStrike Falcon Sandbox a 10 out of 10."
"I find the notifications and alerts received from CrowdStrike server to be invaluable."
"I don't have any suggestions, because the solution is company-maintained and I believe the company is adopting every feature based on their needs and requirements."
"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"I like the dashboard. It looks very simple."
"The most valuable feature is its ability to detect and eradicate ransomware using non-signature-based methods."
"It has a very low false-positive ratio. That is important because it means we're not wasting time... We're able to run that entire 20,000-endpoint base with just a handful of engineers."
"Good detections for PowerShell. and good user interface."
"The support is very good. They reply and respond very quickly."
"The CPU consumption is low compared to what I have been using in my current environment, which is Sophos. The footprint is a lot smaller, about a quarter of Sophos. It is very small."
"The product offers integration capabilities and is also easy to use."
"Deep Instinct's detection rate is close to 100 percent."
 

Cons

"While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate."
"The product needs integration with SOAR products to add more integration points, which is important for various clients."
"While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate."
"As of now, there is nothing specific in need of improvement."
"The detailed report is very valuable, but not always accurate. This is a great resource to share amongst team members and stakeholders after analysis."
"One of the valuable features of the solution is to impressively detect threats without any impact on the end point performance. The solution ensures that the end users have a seamless experience."
"The technical support is medium - they could improve, as communication is sometimes slow or late. There are missing detections that other tools catch. For improvements, we need easier ways to view full incident information and better presentation of data. Adding risk indicators for incidents would help decide on immediate actions. The platform should provide more information about incident risks to help less knowledgeable staff make decisions."
"The CrowdStrike support is not good; the support team does not come remotely, and we repeatedly ask them to collect logs and analyze them before providing a solution via email."
"I would love to see a really exceptional, outstanding level of reporting. I know that's like asking for a unicorn to leap out of the sky with any of these products... When everything works, clients began to wonder: "Everything's fine. Why do we need you?" That's where the reporting capabilities would allow us to really demonstrate: "Hey, here's what's actually going on, Mr. Customer.""
"The interface on the endpoint could be a little more descriptive and more valuable. It doesn't always tell you the data you need to see. Improvement there would be very helpful."
"I am looking forward to them adding Linux in Q1 or Q2 of 2019, as this is often requested by my partners and customers. Currently, Deep Instinct only has Windows, Mac, Android, and iOS."
"When things get done automatically, I would appreciate more logging of what's happening in the background... we should be able to backtrack from the log that gets uploaded to our cloud instance and see, forensically, what the root cause was."
"The Management Console is not localized."
"Its support for Linux and Unix operating systems can be improved. Currently, they cover macOS and Windows, but they don't cover Linux and some of the Unix products. Pricing is also an issue. Its pricing is not as aggressive as it could be, and its price makes it difficult to sell. Customers feel that they can get an antivirus for a lower price, even though it is not a similar product. It is technically different. Their SLAs can be better. They have to give you 24/7 support, but their SLAs are not very good. They should be better documented, and the offerings should also be a little bit better. What happens is that the SLAs end up in the hands of the intermediary, seller, or the local partner of Deep Instinct in a country. The customers want very fast SLAs in a very short time, but Deep Instinct doesn't give them at the same speed. Having said that, SLAs are important when you have a lot of issues, but this product doesn't have too many issues, so it is not a big concern. However, for a customer who doesn't know the product, it could be a concern."
"Some features are too resource intensive."
"If the client is working remotely and doesn't have a VPN then the deployment is difficult to do."
 

Pricing and Cost Advice

"CrowdStrike Falcon Sandbox is not cheap; however, whether it should be more affordable is a decision best left to the company."
"Price-wise, the tool is a bit above mid-range, maybe 7 out of 10, where 10 is the most expensive."
"In comparison to the other products out there, it's exceptionally competitively priced. When you consider the lower administrative overhead that it facilitates, it's an absolute value."
"If I include the false positive rate and the detection rate in the comparison, Deep Instinct is worth its price."
"One thing about their licensing program that I like is that just one covers the server as well as on the endpoint as well as mobile devices. There is no complexity in calculating how many SKUs I need for mobile, for laptop, for desktop, and for servers. It's very simple and that makes it much easier to budget."
"Their pricing is very competitive. It is good, fair, and a lot cheaper than what we were doing with Cylance."
"There are no additional costs on the price, and our company has a support contract, which bundles in those services anyway."
"There is a need for customers of the product to pay towards the licensing costs of the tool."
"The pricing is a little bit expensive but we are satisfied with DI's performance."
"Pricing and licensing are very straightforward. It's two SKUs, one is for the console and the other is for the client."
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
12%
Comms Service Provider
11%
Government
9%
Computer Software Company
20%
Financial Services Firm
11%
Healthcare Company
7%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about CrowdStrike Falcon Sandbox?
I don't have any suggestions, because the solution is company-maintained and I believe the company is adopting every feature based on their needs and requirements.
What needs improvement with CrowdStrike Falcon Sandbox?
We face problems during installation for mass deployment; we need any third-party mass deployment tool to achieve full deployment.When we push the agent from CrowdStrike Falcon Sandbox for mass dep...
What do you like most about Deep Instinct?
The product offers integration capabilities and is also easy to use.
What is your experience regarding pricing and costs for Deep Instinct?
There is a need for customers of the product to pay towards the licensing costs of the tool.
What needs improvement with Deep Instinct?
The solution's stability is good. If the tool was able to provide fine-tuning capabilities from the product's end depending on the environment of its user, then it would be a good improvement in th...
 

Overview

Find out what your peers are saying about CrowdStrike Falcon Sandbox vs. Deep Instinct Prevention Platform and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.