No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Sandbox vs Symantec Protection Engine comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Ranking in Anti-Malware Tools
12th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
9
Ranking in other categories
No ranking in other categories
Symantec Protection Engine
Ranking in Anti-Malware Tools
19th
Average Rating
7.6
Reviews Sentiment
6.1
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Anti-Malware Tools category, the mindshare of CrowdStrike Falcon Sandbox is 1.5%, up from 1.3% compared to the previous year. The mindshare of Symantec Protection Engine is 0.6%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon Sandbox1.5%
Symantec Protection Engine0.6%
Other97.9%
Anti-Malware Tools
 

Featured Reviews

BL
Soc Manager at County of Orange, California
Detailed sandbox reports have strengthened investigations and now provide clearer threat decisions
The additional quota was a factor that led us to consider a change; we went from five detonations per day to 250 per month. Multi-platform analysis in CrowdStrike Falcon Sandbox has helped identify threats. The effectiveness of CrowdStrike Falcon Sandbox has been roughly 90 to 100 percent for our operations. Custom indicators of compromise in CrowdStrike Falcon Sandbox add to our cybersecurity strategy; it is a small part of the strategy, but it plays a significant part in keeping all of the tenants that we have onboarded up to date on relevant files that we are seeing in our environment. That memory forensic capability in CrowdStrike Falcon Sandbox is not something we utilize significantly, but we know of its importance. We utilize memory forensics sometimes in CrowdStrike Falcon Sandbox to review the entropy snapshot; if we see a high level of entropy in the Sandbox report, that could lead to a decision that the file is most likely suspicious, but we use that as an additional item to review. Regarding how features of CrowdStrike Falcon Sandbox have benefited my organization, there is a real-time feature in CrowdStrike Falcon Sandbox, so we can deploy the operating system of choice; we can also analyze archived files, and those features have been helpful as we can interact with the file in certain ways and get additional interaction metrics. I rate CrowdStrike Falcon Sandbox overall as a solution at a nine out of ten. A higher interaction time with the file would give CrowdStrike Falcon Sandbox a ten out of ten for us. If you utilize Falcon Endpoint Protection, I would highly recommend CrowdStrike Falcon Sandbox because the telemetry goes hand-in-hand with that other product.
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Real-time file security has reduced incident tickets and improves threat detection accuracy
The best features of Symantec Protection Engine include machine learning, file reputation, and real-time scanning. It efficiently handles heavy loads through ICAP and cloud-based processing, reducing the burden on endpoints compared to Trend Micro and other endpoint security solutions. Its centralized control is also noteworthy. Through machine learning, it detects both known and unknown malware and malicious URLs, in addition to performing signature-based scans that assist SOC teams in analysis. The solution is highly effective in leveraging both machine learning and file reputation. Regarding centralized control, it offers a unified management console for policy deployment and provides real-time visibility through dashboards, helping save significant administrative time. Symantec Protection Engine has had a positive impact on our organization by enhancing our overall security posture. It effectively blocks a high volume of file-based threats across more than 200 servers, saves SOC analysts time in endpoint remediation, and streamlines compliance processes. It further strengthens security through real-time scanning and machine learning-based quarantine, blocking phishing payloads in SharePoint uploads before they reach endpoints, thereby reducing incidents by 30–40% compared to signature-only tools.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint."
"It provides a safe way to analyze and review documents that may have sensitive information without uploading them to a public platform. Additionally, provides an easy way to spin up a VM without requiring additional resources and patching of personal or team-managed virtualization."
"Since I'm working with CrowdStrike Falcon Sandbox, I would say that the solution enhances a company's threat intelligence, as it's a very powerful solution."
"We have seen returns on our investment in more than thousands of instances, which is the most important part for us."
"The CrowdStrike Falcon Sandbox is one of the most intelligent anti-virus solutions present in the market."
"The tool helps to obtain information about potential company breaches. The malware analysis capability is very effective. We check files from various sources, such as emails, USBs, and cloud drives."
"If you utilize Falcon Endpoint Protection, I would highly recommend CrowdStrike Falcon Sandbox because the telemetry goes hand-in-hand with that other product."
"Symantec Protection Engine provides me with the option of both cloud and on-premise solutions, which stands out for both me and my clients."
"Symantec Protection Engine has improved my security posture by helping me identify potentially malicious files before they reach users or critical systems, and the automated scanning process has also reduced manual efforts for my team, allowing us to focus on other security tasks and respond to threats more efficiently."
"The operational efficiency with the high-performance scanning of Symantec Protection Engine is very good."
"Symantec Protection Engine's been a game-changer for us at Kantar—blocks like 80-85% of file-based threats right at the gateway before they hit our 200 servers, cutting down endpoint incidents big time."
"What I appreciate in Symantec Protection Engine is the Virtual Policy Manager (VPM) and the Application Name feature, which are really effective."
"The best features that I like the most include the threat intelligence network, which is effective in protecting against evolving threats."
"The biggest advantage of Symantec Protection Engine is that one tool protects all, and it is centrally managed."
"Symantec Protection Engine is a cheaper and rock-solid product where basic anti-spam features and threat intelligence are needed."
 

Cons

"I think one of the limitations of CrowdStrike Falcon Sandbox is the amount of interaction time when we interact with the file; I believe there is a limitation to how long we can interact with the file, along with the types of operating systems available."
"One area that could be improved about CrowdStrike Falcon Sandbox is its console; it should be more user-friendly."
"The detailed report is very valuable, but not always accurate. This is a great resource to share amongst team members and stakeholders after analysis."
"As for room for improvement, we can mention that maybe some additional integrations will be beneficial to cover the whole use cases."
"As of now, there is nothing specific in need of improvement."
"One of the valuable features of the solution is to impressively detect threats without any impact on the end point performance. The solution ensures that the end users have a seamless experience."
"The product needs integration with SOAR products to add more integration points, which is important for various clients."
"The technical support is medium - they could improve, as communication is sometimes slow or late. There are missing detections that other tools catch. For improvements, we need easier ways to view full incident information and better presentation of data. Adding risk indicators for incidents would help decide on immediate actions. The platform should provide more information about incident risks to help less knowledgeable staff make decisions."
"I have concerns about scalability."
"We have scenarios in which Symantec Protection Engine misses some threats, spam, and targeted attacks that Proofpoint can catch with AI security features."
"Price is a significant area for improvement. The pricing is quite expensive, and it is particularly high for regular customers."
"For the improvement of Symantec Protection Engine, the engine did not work with their basic engine when I was working, which was almost three or four years before."
"To improve Symantec Protection Engine, I suggest simplifying its integration with other tools, as it is more complex compared to Trend Micro and CrowdStrike."
"I would like to see improvements in reporting and troubleshooting capabilities for Symantec Protection Engine, as more detailed insights and simplified diagnostics would make day-to-day administration easier."
"While I have mentioned many advantages of Symantec Protection Engine, there are areas for improvement, particularly the dashboard features."
"As for pricing, I would say it is a little expensive compared to competitors, and I think the vendor could achieve more market growth if the pricing were more reasonable."
 

Pricing and Cost Advice

"CrowdStrike Falcon Sandbox is not cheap; however, whether it should be more affordable is a decision best left to the company."
"Price-wise, the tool is a bit above mid-range, maybe 7 out of 10, where 10 is the most expensive."
Information not available
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
13%
Manufacturing Company
11%
Comms Service Provider
10%
Outsourcing Company
17%
Healthcare Company
13%
Construction Company
12%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business3
Large Enterprise4
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Sandbox?
I was not involved much on the pricing, setup costs, and licensing of CrowdStrike Falcon Sandbox, but I did have some interaction with a quote; however, the quote compared to other options was one ...
What needs improvement with CrowdStrike Falcon Sandbox?
I think one of the limitations of CrowdStrike Falcon Sandbox is the amount of interaction time when we interact with the file; I believe there is a limitation to how long we can interact with the f...
What is your primary use case for CrowdStrike Falcon Sandbox?
My main use cases for CrowdStrike Falcon Sandbox are for additional telemetry and a confidence score on files, specifically from email or even from endpoints.
What needs improvement with Symantec Protection Engine?
Symantec Protection Engine works well overall, but troubleshooting can sometimes take extra time when detailed logs need to be reviewed; other than that, my experience has been positive. I would li...
What is your primary use case for Symantec Protection Engine?
I mainly use Symantec Protection Engine for scanning files for malware, protecting emails, and web filtering URL protections. I use Symantec Protection Engine to scan files uploaded by users and sh...
 

Overview

Find out what your peers are saying about CrowdStrike Falcon Sandbox vs. Symantec Protection Engine and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.