No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Sandbox vs VirusTotal comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Ranking in Anti-Malware Tools
12th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
9
Ranking in other categories
No ranking in other categories
VirusTotal
Ranking in Anti-Malware Tools
5th
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
10
Ranking in other categories
Threat Intelligence Platforms (TIP) (6th)
 

Mindshare comparison

As of September 2026, in the Anti-Malware Tools category, the mindshare of CrowdStrike Falcon Sandbox is 1.5%, up from 1.3% compared to the previous year. The mindshare of VirusTotal is 3.0%, down from 4.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools Mindshare Distribution
ProductMindshare (%)
VirusTotal3.0%
CrowdStrike Falcon Sandbox1.5%
Other95.5%
Anti-Malware Tools
 

Featured Reviews

BL
Soc Manager at County of Orange, California
Detailed sandbox reports have strengthened investigations and now provide clearer threat decisions
The additional quota was a factor that led us to consider a change; we went from five detonations per day to 250 per month. Multi-platform analysis in CrowdStrike Falcon Sandbox has helped identify threats. The effectiveness of CrowdStrike Falcon Sandbox has been roughly 90 to 100 percent for our operations. Custom indicators of compromise in CrowdStrike Falcon Sandbox add to our cybersecurity strategy; it is a small part of the strategy, but it plays a significant part in keeping all of the tenants that we have onboarded up to date on relevant files that we are seeing in our environment. That memory forensic capability in CrowdStrike Falcon Sandbox is not something we utilize significantly, but we know of its importance. We utilize memory forensics sometimes in CrowdStrike Falcon Sandbox to review the entropy snapshot; if we see a high level of entropy in the Sandbox report, that could lead to a decision that the file is most likely suspicious, but we use that as an additional item to review. Regarding how features of CrowdStrike Falcon Sandbox have benefited my organization, there is a real-time feature in CrowdStrike Falcon Sandbox, so we can deploy the operating system of choice; we can also analyze archived files, and those features have been helpful as we can interact with the file in certain ways and get additional interaction metrics. I rate CrowdStrike Falcon Sandbox overall as a solution at a nine out of ten. A higher interaction time with the file would give CrowdStrike Falcon Sandbox a ten out of ten for us. If you utilize Falcon Endpoint Protection, I would highly recommend CrowdStrike Falcon Sandbox because the telemetry goes hand-in-hand with that other product.
reviewer2588199 - PeerSpot reviewer
Security Specialist at a tech vendor with 10,001+ employees
Improves security alerts and analysis with comprehensive insights
I would like to see improvements in the score consistency and accuracy. VirusTotal should add more details like those from competitors such as URL Void or Symantec URL Checker, which show the category of websites. The addition of a file selection option to analyze files would also enhance the service.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have seen returns on our investment in more than thousands of instances, which is the most important part for us."
"I find the notifications and alerts received from CrowdStrike server to be invaluable."
"If you utilize Falcon Endpoint Protection, I would highly recommend CrowdStrike Falcon Sandbox because the telemetry goes hand-in-hand with that other product."
"The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint."
"Since I'm working with CrowdStrike Falcon Sandbox, I would say that the solution enhances a company's threat intelligence, as it's a very powerful solution."
"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"It provides a safe way to analyze and review documents that may have sensitive information without uploading them to a public platform. Additionally, provides an easy way to spin up a VM without requiring additional resources and patching of personal or team-managed virtualization."
"The tool helps to obtain information about potential company breaches. The malware analysis capability is very effective. We check files from various sources, such as emails, USBs, and cloud drives."
"The most valuable feature is the worldwide malware information database."
"It allows us to see if there have been previous reports on certain indicators of compromise, providing insights from other security professionals."
"It gives detailed information about suspicious IPs, which is one of its most valuable features."
"The product is easy to use with coding, such as Python or Java, via its API."
"With VirusTotal, I can check for any hash, malware, file, domain, IP URL, or malicious URL, and Kaspersky stays clean."
"It is quite simple for anyone if they just want to check some suspicious URLs."
"VirusTotal provides 95% to 98% accurate information."
"It can scan the dark web and find if an email ID has been compromised. This is another area that we have not explored yet."
 

Cons

"One of the valuable features of the solution is to impressively detect threats without any impact on the end point performance. The solution ensures that the end users have a seamless experience."
"The product needs integration with SOAR products to add more integration points, which is important for various clients."
"The detailed report is very valuable, but not always accurate. This is a great resource to share amongst team members and stakeholders after analysis."
"I think one of the limitations of CrowdStrike Falcon Sandbox is the amount of interaction time when we interact with the file; I believe there is a limitation to how long we can interact with the file, along with the types of operating systems available."
"As of now, there is nothing specific in need of improvement."
"One area that could be improved about CrowdStrike Falcon Sandbox is its console; it should be more user-friendly."
"The technical support is medium - they could improve, as communication is sometimes slow or late. There are missing detections that other tools catch. For improvements, we need easier ways to view full incident information and better presentation of data. Adding risk indicators for incidents would help decide on immediate actions. The platform should provide more information about incident risks to help less knowledgeable staff make decisions."
"While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate."
"The platform could improve in the areas of endpoints and networks."
"They can improve the telemetry. Whenever we handle a sample, they cannot provide any information about a victim."
"There is room for improvement, particularly in making some of the most useful features more accessible in the non-paid version."
"I would like to see improved correlation with other threat intelligence sources, not just reliant on its own database, to enhance the database of threat intelligence that VirusTotal offers."
"I would like to see an improved user interface and some automation."
"VirusTotal needs better advertisement and promotion, especially in the Middle East, since it is not yet widely recognized or popular in that region."
"There should be room for improvement, particularly in the API side of things."
"I would like to see improvements in the score consistency and accuracy."
 

Pricing and Cost Advice

"CrowdStrike Falcon Sandbox is not cheap; however, whether it should be more affordable is a decision best left to the company."
"Price-wise, the tool is a bit above mid-range, maybe 7 out of 10, where 10 is the most expensive."
"We are using VirusTotal with free licenses, managing the license limits across three or four accounts, thus incurring no costs."
"The pricing is very economical."
"VirusTotal is an expensive solution."
"The pricing is reasonable."
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
13%
Manufacturing Company
11%
Comms Service Provider
10%
Comms Service Provider
12%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Sandbox?
I was not involved much on the pricing, setup costs, and licensing of CrowdStrike Falcon Sandbox, but I did have some interaction with a quote; however, the quote compared to other options was one ...
What needs improvement with CrowdStrike Falcon Sandbox?
I think one of the limitations of CrowdStrike Falcon Sandbox is the amount of interaction time when we interact with the file; I believe there is a limitation to how long we can interact with the f...
What is your primary use case for CrowdStrike Falcon Sandbox?
My main use cases for CrowdStrike Falcon Sandbox are for additional telemetry and a confidence score on files, specifically from email or even from endpoints.
What is your experience regarding pricing and costs for VirusTotal?
I do not know about the pricing or licensing as our organization services VirusTotal for our clients.
What needs improvement with VirusTotal?
I would like to see improvements in the score consistency and accuracy. VirusTotal should add more details like those from competitors such as URL Void or Symantec URL Checker, which show the categ...
What is your primary use case for VirusTotal?
As I work in an incident response role, my daily task is to mitigate the security alert and perform the analysis part. When any alerts come, I check the IPs from where they originate and the locati...
 

Overview

Find out what your peers are saying about CrowdStrike Falcon Sandbox vs. VirusTotal and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.