No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Sandbox vs Cybereason Next-Generation Antivirus comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Ranking in Anti-Malware Tools
12th
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Cybereason Next-Generation ...
Ranking in Anti-Malware Tools
29th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Anti-Malware Tools category, the mindshare of CrowdStrike Falcon Sandbox is 1.5%, up from 1.3% compared to the previous year. The mindshare of Cybereason Next-Generation Antivirus is 0.7%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon Sandbox1.5%
Cybereason Next-Generation Antivirus0.7%
Other97.8%
Anti-Malware Tools
 

Featured Reviews

ZakariaFawzy - PeerSpot reviewer
Presales Consultant at Cyber Knight Technologies FZ LLC
Unified threat analysis has strengthened detection accuracy and accelerated incident response
The multi-platform analysis in the product is very effective, as it helps to identify threats through powerful scanning and detection, and in response as well. Comparing to other products, this product performs very well in terms of stability and detection, which is important because other products may encounter problems in operations. This product is powerful in detection, which is the most important part because any customer wants a solution that detects what's happening. This is the real strength of CrowdStrike Falcon Sandbox. It's really powerful in detection; it detects any minor change, any minor injection in the data or whatsoever. The visibility is really good. CrowdStrike Falcon Sandbox has one unified platform to manage everything, which is really nice. It has one agent and one console. One agent to install in the machine, and this one agent will give capabilities. I can have visibility into one console, and through this one console, I can do multiple things and manage multiple solutions within CrowdStrike Falcon Sandbox. I know that the memory forensic feature in CrowdStrike Falcon Sandbox is well-regarded, as CrowdStrike Falcon Sandbox is really famous for this. It's one of the most well-known companies in forensics, and many customers are getting CrowdStrike Falcon Sandbox involved when they are in threat or when they face a threat. They do their forensics in a really good way, and they are reaching a very powerful result. I have experienced this with multiple customers who asked CrowdStrike Falcon Sandbox to interfere and do the forensics, knowing exactly what amount of harm or what amount of breach has been done into their network. CrowdStrike Falcon Sandbox can manage this and give them full visibility about what has been done, what has been remediated, and what has been lost. The API integrations they offer are extensive and improve threat analysis and collaboration in general, as they have a wide range of integrations with multiple products and multiple vendors, multiple solutions. Throughout the one year and a half, I didn't face any scenario with integrations except for the file monitoring for the AIX. This is the only case I have faced with them, as they don't support IBM AIX file monitoring. But aside from this, their integration spectrum is really wide, really big, and strong, allowing them to integrate with multiple products.
Peter Nowak - PeerSpot reviewer
Business Development Manager for Cybereason at Bechtle
Cross-platform capability enhances security integration
The single agent, combined with the EDR system, delivers additional information and data for the EDR. Regarding the use cases, or maybe it fits better into another question about the motivation of the customers, I can see two approaches. The first approach is where the customer has an existing EDR system running, and their contract comes to an end. They are looking to either prolong it, renew it, continue with the current system, or look for something cheaper or better. When they reevaluate the contract, it's a sales approach to suggest that for a similar amount of money, not very much more, they can get something much better. It's not only a plain EDR or plain antivirus system - it's antivirus plus EDR. The difference in price is not much. Especially for the antivirus, the cross-platform capability is significant, as it's for Windows and Linux workstations and servers. Having one system for all platforms is essential. This has helped in two ways. The majority of customers want one thing for all, however, some customers definitely want two systems, servers separated from workstations. I have a big data center for banks, and they separate Windows Servers from Linux Servers. It is important for them to have two different systems. By providing this multi-operating system capability, I have engaged with customers via the Linux servers because the Windows servers are handled differently, so they were looking for a second different system, which opened the door for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CrowdStrike is an excellent tool for managing all endpoint-related security tasks."
"The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint."
"I don't have any suggestions, because the solution is company-maintained and I believe the company is adopting every feature based on their needs and requirements."
"The CrowdStrike Falcon Sandbox is one of the most intelligent anti-virus solutions present in the market."
"The cloud deployment of CrowdStrike Falcon Sandbox benefits my organization because we can access it from anywhere and at any time we can get the information."
"The tool helps to obtain information about potential company breaches. The malware analysis capability is very effective. We check files from various sources, such as emails, USBs, and cloud drives."
"I find the notifications and alerts received from CrowdStrike server to be invaluable."
"We have seen returns on our investment in more than thousands of instances, which is the most important part for us."
"Especially for the antivirus, the cross-platform capability is significant, as it's for Windows and Linux workstations and servers."
"The solution's most valuable feature is its AI detection algorithm part, which helps and is Cybereason's way of detecting the unknown, not just the signature-based threats."
"I would rate the overall product as an eight out of ten."
"The tool's detection range works fine. Its most valuable features are its ease of employment and lightweightness. It's not heavy on resources. We focus on malware and ransomware detection."
 

Cons

"One area that could be improved about CrowdStrike Falcon Sandbox is its console; it should be more user-friendly."
"The product needs integration with SOAR products to add more integration points, which is important for various clients."
"As of now, there is nothing specific in need of improvement."
"As for room for improvement, we can mention that maybe some additional integrations will be beneficial to cover the whole use cases."
"While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate."
"The technical support is medium - they could improve, as communication is sometimes slow or late. There are missing detections that other tools catch. For improvements, we need easier ways to view full incident information and better presentation of data. Adding risk indicators for incidents would help decide on immediate actions. The platform should provide more information about incident risks to help less knowledgeable staff make decisions."
"The detailed report is very valuable, but not always accurate. This is a great resource to share amongst team members and stakeholders after analysis."
"One of the valuable features of the solution is to impressively detect threats without any impact on the end point performance. The solution ensures that the end users have a seamless experience."
"Cybereason Next-Generation Antivirus is not available in the local language, which can be inconvenient."
"I have been told several times that the stability of the sensor, not the back end, is an issue."
"Integrating other tools is sometimes an issue when using Cybereason Next-Generation Antivirus."
 

Pricing and Cost Advice

"CrowdStrike Falcon Sandbox is not cheap; however, whether it should be more affordable is a decision best left to the company."
"Price-wise, the tool is a bit above mid-range, maybe 7 out of 10, where 10 is the most expensive."
"I rate the solution's pricing a seven on a scale of one to ten, where one is cheap, and ten is expensive."
"I rate the solution's pricing a four out of ten. Its pricing is justified."
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Construction Company
13%
Manufacturing Company
12%
Comms Service Provider
10%
Performing Arts
13%
Construction Company
9%
Outsourcing Company
9%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise3
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Sandbox?
I am not sure if there is a financial benefit; maybe, maybe not, as we did not evaluate that aspect. I think it can be expensive, but it depends on the products.
What needs improvement with CrowdStrike Falcon Sandbox?
As for room for improvement, we can mention that maybe some additional integrations will be beneficial to cover the whole use cases.
What is your primary use case for CrowdStrike Falcon Sandbox?
The major use case for CrowdStrike Falcon Sandbox is that we are using it with customers who need to check and validate the data the users are uploading to them, to check all the files and all the ...
What needs improvement with Cybereason Next-Generation Antivirus?
I have been told several times that the stability of the sensor, not the back end, is an issue. After certain updates, it consumes too much processor time without utilizing the processor capacity e...
What is your primary use case for Cybereason Next-Generation Antivirus?
My use case involves providing endpoint security. When I introduce the EDR system, in many cases, it replaces the current antivirus system as well. Therefore, my use case is to replace an old antiv...
 

Also Known As

No data available
Cybereason NGAV
 

Overview

 

Sample Customers

Information Not Available
CONNECTICUT WATER, BEAM SUNTORY, CADWALADER, WICKERSHAM & TAFT, RTI Surgical, HOSPITAL REVENUE CYCLE MANAGEMENT COMPANY, MCBEE ASSOCIATES, FORTUNE 500 BANK
Find out what your peers are saying about CrowdStrike Falcon Sandbox vs. Cybereason Next-Generation Antivirus and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.