Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs Mimecast Incydr vs Trellix Endpoint Security Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
CrowdStrike Falcon enhances productivity and security, reducing costs and downtime while efficiently managing threats with rapid deployment and detection.
Sentiment score
7.5
Mimecast Incydr improved cost efficiency, ensured data recovery, enhanced security, reduced downtime, and provided significant financial and administrative savings.
Sentiment score
8.0
Trellix Endpoint Security offers valuable ROI by reducing threats and costs, with high satisfaction despite some false positives.
CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.
We have observed tremendous return on investment after implementing Trellix Endpoint Security as it is a more cost-effective solution compared to other products.
Clients appreciate the solution’s customization capabilities and ongoing product improvements.
There are two parts: one is the encryption which is standard and no AI is needed, but the data protection part could benefit from AI to detect new types of data and protect it.
 

Customer Service

Sentiment score
7.0
CrowdStrike Falcon support is valued for responsiveness and expertise, though growth causes delays; premium support is highly rated.
Sentiment score
8.8
Mimecast Incydr's customer service excels in prompt, knowledgeable support, offering efficient issue resolution and valuable online resources.
Sentiment score
6.9
Trellix Endpoint Security Platform support is generally praised, though some users note response time inconsistencies and platform-specific service gaps.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
They could improve by initiating calls for high-priority cases instead of just opening tickets.
The response time is a notable issue.
I would rate their customer service nine out of ten.
When we implemented Trellix Endpoint Security in their network, multiple malwares were detected.
 

Scalability Issues

Sentiment score
7.9
CrowdStrike Falcon's scalability and adaptability make it ideal for diverse platforms, though costs may limit expansive deployments.
Sentiment score
7.9
Mimecast Incydr seamlessly scales from small to large deployments, supporting expansion with efficient licensing and storage management.
Sentiment score
7.8
Trellix Endpoint Security efficiently scales across diverse environments, handling thousands of endpoints with seamless expansion and robust performance.
It has adequate coverage and is easy to deploy.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.
I would rate the scalability of the solution as a six out of ten, indicating some challenges due to downtime requirements.
Trellix Endpoint Security is scalable.
 

Stability Issues

Sentiment score
8.1
CrowdStrike Falcon is highly regarded for its stability, efficiency, and reliability, with minor update issues quickly resolved.
Sentiment score
7.8
Mimecast Incydr is reliable and stable, with minor issues swiftly resolved, offering robust performance and minimal service disruptions.
Sentiment score
8.2
Trellix Endpoint Security Platform is stable, reliable, and handles high loads well, though some performance issues are acknowledged.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
The biggest issue occurred when every computer worldwide experienced a blue screen.
I would rate its stability as nine out of ten.
I would rate the stability of Trellix Endpoint Security as near perfect, close to ten out of ten.
I think it's stable enough; earlier it had glitches, but now it's stable enough.
 

Room For Improvement

CrowdStrike Falcon needs system integration, better reporting, reduced false positives, enhanced support, advanced features, and flexible pricing.
Mimecast Incydr needs better usability, integration, reporting, legal hold, Safari support, and admin features to enhance user experience.
Users seek performance, UI, integration improvements in Trellix Endpoint Security, along with faster updates and better support.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Threat prevention should be their first priority.
What needs improvement in Trellix Endpoint Security is the reduction of resource consumption by the scanning feature.
Improvements are needed in forensic analytics to detect specific vulnerabilities.
The product does not seem to be cloud-native.
 

Setup Cost

CrowdStrike Falcon's pricing ranges from $30-$100 per user annually, ideal for large enterprises but costly for smaller businesses.
Mimecast Incydr offers competitive, transparent pricing with negotiable discounts, praised flexibility, and valued support, though complex licensing challenges smaller businesses.
Trellix Endpoint Security is competitively priced, offering flexible licensing and value, though renewal costs might increase over time.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
The licensing cost and setup costs are affordable.
The solution is a bit expensive.
The license costs are very reasonable, around 1,000 to 1,200 rupees per year.
Trellix Endpoint Security is cost-effective and provides excellent value for money.
 

Valuable Features

CrowdStrike Falcon provides robust threat intelligence, AI-driven detection, and seamless integration with minimal system impact and intuitive interface.
Mimecast Incydr provides seamless, secure data protection with versatile features and robust customer support, enhancing user trust and efficiency.
Trellix Endpoint Security provides advanced threat protection, ease of use, and customizable policies for effective ransomware and malware defense.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Being an EDR solution, it helps us identify attacks in real-time.
Trellix Endpoint Security is a proven, robust, and cost-effective solution that protects the organization from different types of ransomware and attacks.
Including options like Application Control (formerly Solidcore), integrated monitoring, change control, DLP, and advanced threat protection, the solution offers comprehensive security.
The detection capability of Trellix Endpoint Security is higher than traditional antivirus solutions.
 

Mindshare comparison

Extended Detection and Response (XDR) Market Share Distribution
ProductMarket Share (%)
CrowdStrike Falcon12.7%
Wazuh10.7%
Darktrace8.3%
Other68.3%
Extended Detection and Response (XDR)
Data Loss Prevention (DLP) Market Share Distribution
ProductMarket Share (%)
Mimecast Incydr2.1%
Microsoft Purview Data Loss Prevention13.0%
Forcepoint Data Loss Prevention9.1%
Other75.8%
Data Loss Prevention (DLP)
Endpoint Protection Platform (EPP) Market Share Distribution
ProductMarket Share (%)
Trellix Endpoint Security Platform3.9%
Microsoft Defender for Endpoint10.0%
CrowdStrike Falcon8.2%
Other77.9%
Endpoint Protection Platform (EPP)
 

Featured Reviews

Waleed Omar - PeerSpot reviewer
Provides effective real-time threat detection with potential for cost optimization
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
Chuck_Mackey - PeerSpot reviewer
Provides comprehensive visibility and protection, helps in identifying the gaps in security, and comes with excellent onboarding support
In a couple of instances, we had a little bit of trouble in getting it distributed throughout the organization. We ultimately managed to do it, but they talk about it being a pretty simple process, and it became a little laborious. It would just turn away. The agents were not being distributed. It was just churning and churning and churning. When we were looking for specific categories of data, it was getting bogged down, but that was not even so much Code42, although some of it was their issue. It really has to do with the overall infrastructure and what the organization is prepared to do. If the infrastructure or the networking is a little hinky or you don't have a really finely tuned network infrastructure environment and your patches aren't up to date on your servers and your endpoints, it could get a little sticky. Other than that, it was okay. We really didn't have much problem beyond that. It took a couple of days to sort that out, but it was no big deal.
Abdullah Al Hadi - PeerSpot reviewer
Customization capabilities allow clients to autonomously deploy policies
There are a few areas where Trellix Endpoint Security can improve. Firstly, the high CPU utilization when agents are installed can negatively impact client systems. Another issue is with end-users outside the network, where the agent handler sometimes fails to deploy the product properly. Improvements are needed in forensic analytics to detect specific vulnerabilities. It would also help if detection specifics were identified more quickly and the problem-solving process accelerated, especially to meet larger clients' expectations.
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
866,391 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
9%
Government
6%
Manufacturing Company
11%
Computer Software Company
11%
Performing Arts
8%
University
6%
Government
13%
Manufacturing Company
13%
Computer Software Company
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise33
Large Enterprise61
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise24
Large Enterprise30
By reviewers
Company SizeCount
Small Business67
Midsize Enterprise36
Large Enterprise59
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
What is your primary use case for Code42 Incydr?
Data Leakage Protection on large scale environments. This can be to protect against leakage on endpoints and servers ...
How does McAfee Endpoint Security compare with MVISION?
The flexible manageability of McAfee Endpoint Security is one of our favorite aspects of this solution. You can deplo...
How does Crowdstrike Falcon compare with FireEye Endpoint Security?
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effec...
What do you like most about McAfee Endpoint Security?
It provides a robust defense against cybersecurity threats while offering user-friendly features like notifications a...
 

Also Known As

CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
Code42 Next-Gen DLP, Code42 Next-Gen Data Loss Protection, Code42 Forensic File Search, Code42 Backup + Restore
McAfee Endpoint Security, McAfee Endpoint Protection, Intel Security Total Protection for Endpoint, McAfee Complete Endpoint Protection, Trellix Endpoint Security (ENS)
 

Overview

 

Sample Customers

Information Not Available
Adobe, Okta, Samsung, Taylormade, Boston University, Lending Club, North Highland, Stanford University, Ping Identity, Qualcomm, Pandora.
inHouseIT, Seagate Technology
Find out what your peers are saying about CrowdStrike, Microsoft, SentinelOne and others in Extended Detection and Response (XDR). Updated: August 2025.
866,391 professionals have used our research since 2012.