Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs Microsoft Defender Threat Intelligence comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
CrowdStrike Falcon boosts efficiency and cost savings while enhancing security and performance without increasing system slowdown.
Sentiment score
8.0
Microsoft Defender Threat Intelligence offers major ROI by saving 62% on budgets and providing comprehensive threat protection and business value.
 

Customer Service

Sentiment score
7.1
CrowdStrike Falcon’s support is praised for responsiveness, but some report slow responses and inconsistency, especially on weekends.
Sentiment score
7.4
Microsoft Defender support experiences vary; community platforms help, technical support is inconsistent, with level two proving effective.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
Level two support is knowledgeable and knows how the product works, which is very good.
 

Scalability Issues

Sentiment score
7.9
CrowdStrike Falcon's scalability and cloud-based architecture support rapid deployment and seamless expansion for diverse business security needs.
Sentiment score
7.8
Microsoft Defender Threat Intelligence is highly scalable, serving diverse businesses effectively, though costs may rise with increased users.
Its scalability is good.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
When it comes to scalability, it is entirely based on premium models according to demand.
If there were some customizations available, I would rate its scalability as nine out of ten.
 

Stability Issues

Sentiment score
8.2
CrowdStrike Falcon offers stable, reliable performance across environments, managing endpoints effectively despite minor update challenges and connectivity issues.
Sentiment score
8.3
Microsoft Defender Threat Intelligence offers high reliability and performance, with occasional regional outages, comparable to Office 365 stability.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
I find CrowdStrike to be stable; there are no issues, although there was one instance when we had an outage for updating the Falcon Agent.
It provides a high level of security and avoids phishing and scam emails.
 

Room For Improvement

CrowdStrike Falcon users seek better third-party integration, intuitive UI, threat detection, support, pricing, and forensic tools.
Improving pricing, integration, stability, and support could enhance Microsoft Defender Threat Intelligence's market accessibility and effectiveness.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
False positive reductions are needed.
Providing code customization would help keep pace with new vulnerabilities and threats.
 

Setup Cost

CrowdStrike Falcon provides robust security at premium pricing, with flexible licensing but may be costly for some businesses.
Microsoft Defender Threat Intelligence offers cost-effective bundling with E5 licenses, beneficial for enterprises but challenging for SMEs preferring E3.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
 

Valuable Features

CrowdStrike Falcon provides advanced, efficient threat protection with AI capabilities, ease of management, and comprehensive detection and prevention features.
Microsoft Defender Threat Intelligence offers advanced detection, seamless integration, robust security, proactive monitoring, and effective zero-day vulnerability management.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
CrowdStrike has improved our incident response capabilities.
One of the best features is that it provides a certain level of customization, allowing us to set our spam confidence levels.
 

Categories and Ranking

CrowdStrike Falcon
Ranking in Threat Intelligence Platforms
1st
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
127
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Endpoint Protection Platform (EPP) (2nd), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), Attack Surface Management (ASM) (1st), Identity Threat Detection and Response (ITDR) (3rd), AI-Powered Cybersecurity Platforms (1st)
Microsoft Defender Threat I...
Ranking in Threat Intelligence Platforms
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
31
Ranking in other categories
Advanced Threat Protection (ATP) (10th), Microsoft Security Suite (18th)
 

Mindshare comparison

As of May 2025, in the Threat Intelligence Platforms category, the mindshare of CrowdStrike Falcon is 9.2%, down from 12.3% compared to the previous year. The mindshare of Microsoft Defender Threat Intelligence is 2.8%, up from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Intelligence Platforms
 

Featured Reviews

Chintan-Vyas - PeerSpot reviewer
Easy to set up with good behavior-based analysis but needs a single-click recovery option
Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files. The product could be more accurate in terms of performance. We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.
Nim Nadarajah - PeerSpot reviewer
A native Microsoft solution the provides great ROI and continuously improves its offering
We have Microsoft bias. We generally don't have any significant negative feedback or improvement points around Defender, EDR and CMDR platforms. It does a good job across the board. The price point is something they can improve slightly for those who don't have an M 365 E5. I believe it's a $2.80 cents add-on. In Canadian, that's expensive. If they can drop it to a dollar, for those who don't have M 365 E5, they're going to open up market share and increase affordability for an entire market segment in the medium business category. Other than that, we have no major negative feedback.
report
Use our free recommendation engine to learn which Threat Intelligence Platforms solutions are best for your needs.
851,491 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Computer Software Company
15%
Financial Services Firm
14%
Educational Organization
10%
Government
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
What do you like most about Microsoft Defender Threat Intelligence?
It just runs in the background. I don't have to worry about, making sure it's Intelligence. So, you know, this kind of makes it very easy, have to worry about installing. It is easy to use.
What needs improvement with Microsoft Defender Threat Intelligence?
Some of the customization features could be improved by providing a portion of it as open source. This would allow integration with other solutions, enhancing Threat Intelligence. Providing code cu...
What is your primary use case for Microsoft Defender Threat Intelligence?
We are using Microsoft Defender ATP specifically as an email security solution, as well as for our critical servers as a web security solution. We have almost eleven hundred users utilizing it for ...
 

Also Known As

CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
No data available
 

Overview

Find out what your peers are saying about CrowdStrike Falcon vs. Microsoft Defender Threat Intelligence and other solutions. Updated: April 2025.
851,491 professionals have used our research since 2012.