Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs Trellix Endpoint Security (ENS) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 9, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
CrowdStrike Falcon boosts efficiency and cost savings while enhancing security and performance without increasing system slowdown.
Sentiment score
7.5
Trellix Endpoint Security is effective yet costly, with reduced IT workload and mixed ROI due to false positives and incidents.
 

Customer Service

Sentiment score
7.1
CrowdStrike Falcon’s support is praised for responsiveness, but some report slow responses and inconsistency, especially on weekends.
Sentiment score
8.5
Trellix Endpoint Security's support is praised for responsiveness but criticized for slow resolutions and regional inconsistencies.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
I rate the support from Trellix a perfect ten.
They were fairly responsive and able to resolve the issue.
 

Scalability Issues

Sentiment score
7.9
CrowdStrike Falcon's scalability and cloud-based architecture support rapid deployment and seamless expansion for diverse business security needs.
Sentiment score
9.0
Trellix Endpoint Security is praised for effective scalability and adaptability to various environments and operating systems.
Its scalability is good.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
When it comes to scalability, it is entirely based on premium models according to demand.
 

Stability Issues

Sentiment score
8.2
CrowdStrike Falcon offers stable, reliable performance across environments, managing endpoints effectively despite minor update challenges and connectivity issues.
Sentiment score
8.5
Trellix Endpoint Security is stable and reliable, with occasional performance issues and consistent updates for optimal performance.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
I find CrowdStrike to be stable; there are no issues, although there was one instance when we had an outage for updating the Falcon Agent.
 

Room For Improvement

CrowdStrike Falcon users seek better third-party integration, intuitive UI, threat detection, support, pricing, and forensic tools.
Trellix ENS needs improved performance, usability, integration, scalability, and support, with enhanced security features and user-friendly documentation.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
False positive reductions are needed.
Some customers feel that the Trellix Endpoint Security (ENS) agent consumes more memory and resources in their environment.
 

Setup Cost

CrowdStrike Falcon provides robust security at premium pricing, with flexible licensing but may be costly for some businesses.
Trellix ENS offers enterprise-focused pricing with flexible licensing and support, providing value through performance and forensic analysis.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
 

Valuable Features

CrowdStrike Falcon provides advanced, efficient threat protection with AI capabilities, ease of management, and comprehensive detection and prevention features.
Trellix Endpoint Security excels in threat detection, integration, scalability, and AI-driven updates, enhancing security with ease of deployment.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
CrowdStrike has improved our incident response capabilities.
They find Trellix Endpoint Security (ENS) easy and user-friendly for their environment, which is why they choose Trellix.
Trellix Endpoint Security seems to do a good job in terms of protecting my infrastructure from malware.
 

Categories and Ranking

CrowdStrike Falcon
Ranking in Endpoint Protection Platform (EPP)
2nd
Ranking in Endpoint Detection and Response (EDR)
1st
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
127
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Threat Intelligence Platforms (1st), Extended Detection and Response (XDR) (1st), Attack Surface Management (ASM) (1st), Identity Threat Detection and Response (ITDR) (3rd), AI-Powered Cybersecurity Platforms (1st)
Trellix Endpoint Security (...
Ranking in Endpoint Protection Platform (EPP)
26th
Ranking in Endpoint Detection and Response (EDR)
20th
Average Rating
7.6
Reviews Sentiment
7.6
Number of Reviews
55
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of CrowdStrike Falcon is 10.9%, up from 9.3% compared to the previous year. The mindshare of Trellix Endpoint Security (ENS) is 1.5%, down from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Q&A Highlights

NC
Nov 06, 2021
 

Featured Reviews

Chintan-Vyas - PeerSpot reviewer
Easy to set up with good behavior-based analysis but needs a single-click recovery option
Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files. The product could be more accurate in terms of performance. We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.
Shreyansh Sharma - PeerSpot reviewer
Our main antivirus tool and offers adaptive threat prevention tool
The technical support needs some improvement. When product distribution errors occur, we have to contact technical support, which is a very tedious and time consuming task. After raising the call onto the technical support portal, usually receive a notification after 24 hours. It usually takes 3 to 4 days to conclude and resolve the issue. If 24/7 online support or a phone line where we could speak directly with technical support for real-time troubleshooting, that would be very helpful. Licensing is another aspect where trellix should look into. Different purchases are grouped together in single user account get mixed up. Categorization of purchases and their grant numbers is not available to end user.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Answers from the Community

NC
Nov 6, 2021
Nov 6, 2021
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effective program. Its graphical design is such that it makes an extremely useful tool for securing computers from malware and viruses. All of the information that you need is gathered in a central location for careful analysis. It is also easy to navigate, which is a big plus in its ...
See 2 answers
DG
Oct 14, 2021
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effective program. Its graphical design is such that it makes an extremely useful tool for securing computers from malware and viruses. All of the information that you need is gathered in a central location for careful analysis. It is also easy to navigate, which is a big plus in its favor. Crowdstrike Falcon also offers the ability to access its protective software anywhere on the planet that has a connection to the internet. This makes it an easily accessible anti-malware program. The cloud component of the program makes it especially useful for large organizations. In a world where remote work is a crucial addition to companies of various sizes, unlimited access to software that can secure the future of their organization is crucial. A large staff will now have the ability to continue their business without the fear of malicious actors. A further aspect of the program which is impressive is its ability to both provide real-time data and at the same time keep the hardware running at normal speed. It maximizes security while not sacrificing the speed of the work that the user is trying to accomplish. These two aspects make Crowdstrike Falcon the type of program that has a clear advantage over its competitors. FireEye Endpoint Security offers its users the ability to integrate itself with other environments and software. This provides a level of flexibility that is valuable in any sort of software, much less an anti-viral program. It also has a simplicity of use and precision in spotting unknown malware. All of these qualities make it a pretty effective piece of software. However, FireEye does not offer a cloud option like Crowdstrike Falcon does. This serves to limit its usefulness to companies that operate remotely. Conclusion Crowdstrike Falcon definitely offers a flexible and versatile program that has much to offer for the relatively low price being paid. FireEye Endpoint Security lacks the cloud compatibility of Crowdstrike Falcon. Overall, Crowdstrike Falcon seems to be the far more effective software.
JR
Nov 6, 2021
Hello, I think it doesn't make sense to just compare device protection and automated response security solutions, it's missing to protect identities, devices, and insider access. I think: The best and most valuable option is Microsoft. Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks. With the integrated Microsoft 365 Defender solution, security professionals can stitch together the threat signals that each of these products receive and determine the full scope and impact of the threat; how it entered the environment, what it's affected, and how it's currently impacting the organization. Microsoft 365 Defender takes automatic action to prevent or stop the attack and self-heal affected mailboxes, endpoints, and user identities. Microsoft 365 Defender services includes:1. Microsoft Defender for Endpoint, is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats.2. Microsoft Defender for Office 365, Plan 1 protects email and collaboration from zero-day malware, phish, and business email compromise,  Plan 2 adds post-breach investigation, hunting, and response, as well as automation, and simulation (for training).3. Microsoft Defender for Identity, a cloud service that helps protect your enterprise hybrid environments from multiple types of advanced targeted cyber-attacks and insider threats.4. Microsoft Cloud App Security, is a Cloud Access Security Broker (CASB) that operates on multiple clouds. It provides rich visibility, control over data travel, and sophisticated analytics to identify and combat cyber threats across all your cloud services. If the end customer already has Microsoft 365 in companies or educational institutions, they already have the collaboration tools, only the security and endpoint management tools should be added, all with Microsoft 365 E5/A5, no more investment is being made, it is being consolidated, visibility is gained, responses are automated, the fatigue of operating so many security events that you do not have the time or personnel to review them decrease. I hope this has generated value for you.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Computer Software Company
15%
Financial Services Firm
13%
Government
12%
Manufacturing Company
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
How does McAfee Endpoint Security compare with MVISION?
The flexible manageability of McAfee Endpoint Security is one of our favorite aspects of this solution. You can deploy various components as desired with McAfee Endpoint Security, whereas many othe...
How does Crowdstrike Falcon compare with FireEye Endpoint Security?
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effective program. Its graphical design is such that it makes an extremely useful too...
What do you like most about McAfee MVISION Endpoint?
The product's initial setup phase was straightforward.
 

Also Known As

CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
McAfee MVISION Endpoint, Trellix Endpoint Security (HX)
 

Overview

 

Sample Customers

Information Not Available
Tech Resources Limited, Globe Telecom, Rizal Commercial Banking Corporation
Find out what your peers are saying about CrowdStrike Falcon vs. Trellix Endpoint Security (ENS) and other solutions. Updated: May 2025.
851,604 professionals have used our research since 2012.