Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon Sandbox vs Microsoft Defender for Endpoint comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Ranking in Anti-Malware Tools
15th
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
6
Ranking in other categories
No ranking in other categories
Microsoft Defender for Endp...
Ranking in Anti-Malware Tools
1st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
192
Ranking in other categories
Endpoint Protection Platform (EPP) (1st), Advanced Threat Protection (ATP) (2nd), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (5th)
 

Mindshare comparison

As of April 2025, in the Anti-Malware Tools category, the mindshare of CrowdStrike Falcon Sandbox is 1.3%, up from 0.5% compared to the previous year. The mindshare of Microsoft Defender for Endpoint is 17.0%, down from 22.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools
 

Featured Reviews

Abhimanyu Raj - PeerSpot reviewer
Alerts and notifications have enhanced malware detection capabilities
These features are probably the most essential for me. I find the notifications and alerts received from CrowdStrike server to be invaluable. They analyze Falcon and provide output regarding any kind of infected malware devices or files. We have seen returns on our investment in more than thousands of instances, which is the most important part for us.
AnuragSrivastava - PeerSpot reviewer
Provides detailed visibility into threats but the ability to add exceptions needs improvement
One major item for improvement is the ability to add exceptions. We can add some exceptions, but not at the level we need to. The second major area for improvement involves enhanced capabilities for different operating systems or platforms. That is, even though we have coverage for different operating systems or platforms such as Linux, we don't get all of the controls and enhanced capabilities that are available with Windows devices. Reporting could also be improved because, at present, we get limited results at times. For example, in an environment with more than 100,000 devices, you may just get 10,000 results when you run a report.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool helps to obtain information about potential company breaches. The malware analysis capability is very effective. We check files from various sources, such as emails, USBs, and cloud drives."
"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"I don't have any suggestions, because the solution is company-maintained and I believe the company is adopting every feature based on their needs and requirements."
"The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint."
"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"We have seen returns on our investment in more than thousands of instances, which is the most important part for us."
"I find the notifications and alerts received from CrowdStrike server to be invaluable."
"It provides a safe way to analyze and review documents that may have sensitive information without uploading them to a public platform. Additionally, provides an easy way to spin up a VM without requiring additional resources and patching of personal or team-managed virtualization."
"In terms of the installation, ease of use, and user interface, Defender has been great so far."
"The most valuable feature is that it comes with the package, so there is no additional installation of third-party software. It's also easy to use."
"It captures data through machine learning, which is built-in on the back-end. It also provides built-in analytics and a threat intelligence feature. It is a one-stop solution that doesn't require an antivirus because it comes prebuilt into Windows 10."
"Endpoint's most valuable feature is deep analysis."
"The most valuable feature is ransomware protection, which can detect malicious activity from IPs or a malicious payload in DLLs, or other things that can corrupt the system."
"A few years ago, when I was using a different product, I was affected by a virus that destroyed everything. Since using Microsoft Defender, I have not had this kind of problem."
"We apply the DLP policies across a range of endpoints and it is very accurate when reporting vulnerabilities, including those in email attachments."
"Defender for Endpoint is a robust solution that works well out-of-the-box."
 

Cons

"The detailed report is very valuable, but not always accurate. This is a great resource to share amongst team members and stakeholders after analysis."
"As of now, there is nothing specific in need of improvement."
"While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate."
"One of the valuable features of the solution is to impressively detect threats without any impact on the end point performance. The solution ensures that the end users have a seamless experience."
"The product needs integration with SOAR products to add more integration points, which is important for various clients."
"The technical support is medium - they could improve, as communication is sometimes slow or late. There are missing detections that other tools catch. For improvements, we need easier ways to view full incident information and better presentation of data. Adding risk indicators for incidents would help decide on immediate actions. The platform should provide more information about incident risks to help less knowledgeable staff make decisions."
"While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate."
"We encountered some misbehavior between Microsoft Office Suite and Defender. We had issues of old macros being blocked and some stuff going around the usage of Win32 APIs. There is some improvement between the Office products and Defender, and there is a bunch of stuff that you can configure in your antivirus solutions, but you have several baselines, such as security baselines for Edge, security baselines for Defender, and security baselines for MDM. You have configuration profiles as well. So, there a lot of parts where we can configure our antivirus solution, and we're getting conflicting configurations. This is the major part with which we're struggling in this solution. We are having calls and calls with Microsoft for getting rid of all configuration conflicts that we have. That's really the part that needs to be improved."
"Microsoft Windows Defender doesn't have a game mode."
"With regards to the interface, a challenge I found was that there was not enough documentation on how to tune it. I had to read multiple sources on the internet to learn how to configure the tool appropriately."
"Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some."
"The documentation could be better. When they update their manuals, sometimes they refer to products by their old names, so it is a little confusing. For example, the documentation might still say "Advanced Threat Protection" instead of Defender for Endpoint."
"I have accounts for administrators and corporate employees, but I also have accounts for students. I can't split these types of accounts. I need a separate configuration for both... I need to research how I can get alerts for only the administrative machines."
"Defender is free for one year. Once that year is over, we will switch to Kaspersky."
"There is room to improve the security of the solution."
 

Pricing and Cost Advice

"Price-wise, the tool is a bit above mid-range, maybe 7 out of 10, where 10 is the most expensive."
"CrowdStrike Falcon Sandbox is not cheap; however, whether it should be more affordable is a decision best left to the company."
"There are different licenses, such as E3 and E5."
"It is so expensive. It isn't cheaper than McAfee or other solutions."
"We sell this product as part of Office 365 and it is not expensive."
"Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs."
"The solution comes as part of Microsoft Windows."
"Everybody would like to see a lower price on everything. The Slovenian market is basically an SME market with clients having up to 100 seat licenses, comprising 90% of the company. They're very price sensitive. So, the price could be cheaper."
"The price for Microsoft Defender for Endpoint is about three euros, which is considered reasonably priced."
"I'm not too familiar with costs as I'm an architect, though I know about online pricing, as I help two teams with online purchasing and procurement. Nowadays, everyone has an enterprise agreement, such as an E3 license, which we provide to our customers."
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
12%
Comms Service Provider
12%
Educational Organization
11%
Educational Organization
27%
Computer Software Company
11%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about CrowdStrike Falcon Sandbox?
I don't have any suggestions, because the solution is company-maintained and I believe the company is adopting every feature based on their needs and requirements.
What is your experience regarding pricing and costs for CrowdStrike Falcon Sandbox?
Pricing is based on the number of endpoints and the features I need, operating on a usage-based cost structure.
What needs improvement with CrowdStrike Falcon Sandbox?
As of now, there is nothing specific in need of improvement.
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior solution. Microsoft Defender for Endpoint is a cloud-delivered endpoint security s...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Information Not Available
Petrofrac, Metro CSG, Christus Health
Find out what your peers are saying about CrowdStrike Falcon Sandbox vs. Microsoft Defender for Endpoint and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.