No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Sandbox vs ThreatLocker Zero Trust Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.1
Users have mixed feelings about CrowdStrike Falcon Sandbox ROI, but it effectively reduces incident response and detection downtime.
Sentiment score
6.4
ThreatLocker Zero Trust Platform boosts security, cuts operational costs by 40%, enhances efficiency, and generates revenue through client recommendations.
If something were to happen without ThreatLocker, the cost would be huge, and thus, having it is definitely worth it.
Tier 1 IT Engineer at a retailer with 11-50 employees
Based on what we use ThreatLocker Zero Trust Endpoint Protection Platform for with the same functionalities and packaging, it was around 13 or 14 hours.
Head Of Cyber Security at a outsourcing company with 201-500 employees
We have the MDR package as well, and just knowing someone is watching those endpoints at 3:00 a.m. is a lifesaver that you cannot put a dollar figure on.
System Administrator at Gwynedd Mercy University
 

Customer Service

Sentiment score
5.7
CrowdStrike Falcon Sandbox support is praised for fast, responsive service, resolving issues quickly, despite some remote support difficulties.
Sentiment score
7.9
ThreatLocker Zero Trust Platform's support is praised for its speed, efficiency, and industry-leading customer service, available anytime.
They respond within two hours after I raise a support ticket.
Security Senior Engineer at a consultancy with 51-200 employees
If I would rate support on a scale of 0 to 10, with 10 being the best, I would give them nine points.
Presales Consultant at Cyber Knight Technologies FZ LLC
We repeatedly ask them to collect logs and analyze them before providing a solution via email.
IT Manager at Gigabit Technologies Pvt Ltd
They have been very responsive, helpful, and knowledgeable.
Systems Security Analyst & Deputy Security Officer at a financial services firm with 201-500 employees
I would rate their customer support a ten out of ten.
Director, Managed Services at a consultancy with 11-50 employees
Their support is world-class.
Supervisor, Client Security at a consultancy with 11-50 employees
 

Scalability Issues

Sentiment score
6.7
CrowdStrike Falcon Sandbox is scalable and adaptable, praised for supporting diverse business sizes with effective, flexible performance.
Sentiment score
7.7
ThreatLocker Zero Trust Platform efficiently manages growth and adapts to diverse needs, offering seamless integration and flexible deployment.
I would rate the scalability of the solution as very scalable, as it can support medium businesses, small businesses, and large enterprise businesses as well.
Presales Consultant at Cyber Knight Technologies FZ LLC
I started off with just the servers, and within a month and a half, I set up the entire company with ThreatLocker.
Technical Engineer at Cloud 1 Solutions
It seems to primarily operate on the endpoints rather than at a central location pushing out policies.
Systems Security Analyst & Deputy Security Officer at a financial services firm with 201-500 employees
ThreatLocker Zero Trust Endpoint Protection Platform scales very smoothly with our growing needs.
CEO at Mostro
 

Stability Issues

Sentiment score
7.6
CrowdStrike Falcon Sandbox is widely regarded as stable, with most users rating its performance confidence as eight out of ten.
Sentiment score
7.7
ThreatLocker Zero Trust Platform offers stable performance with minor glitches, resolved quickly; implementation may require policy tuning.
For five years, we have not had a problem.
Supervisor, Client Security at a consultancy with 11-50 employees
Once deployed, it downloads the policies locally, so even if the computer doesn't have internet, it doesn't matter.
Information Cybersecurity Technology Specialist at Freez.it
It has been very stable, reliable, and accessible.
COO at Panda Technology
 

Room For Improvement

CrowdStrike Falcon Sandbox needs interface improvements, enhanced detection and integration, faster processing, and better incident presentation.
ThreatLocker Zero Trust Platform needs enhanced UX, integration, compatibility, reporting, and logging, plus intuitive learning mode and training communication.
While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate.
Security Senior Engineer at a consultancy with 51-200 employees
When we push the agent from CrowdStrike Falcon Sandbox for mass deployment, the agent is not properly installed on the user end, leading to communication issues and agent corruption.
IT Manager at Gigabit Technologies Pvt Ltd
Additional integrations will be beneficial to cover the whole use cases.
Presales Consultant at Cyber Knight Technologies FZ LLC
Controlling the cloud environment, not just endpoints, is crucial.
COO at Panda Technology
ThreatLocker Zero Trust Endpoint Protection Platform could improve by being a little more hands-off, perhaps by having a team inside ThreatLocker that does all the vetting of patches; having one person hired by ThreatLocker to check out patches means that a million other industries using ThreatLocker Zero Trust Endpoint Protection Platform do not have to vet the same patch, ultimately saving time and money around the world.
Technical Support Engineer at CMIT Solutions of Central Orlando
This feedback would help us understand what is learned in real-time, especially during a one-hour learning mode setup, ensuring we remain aware of potentially unnecessary learned items.
Server Administrator at Clay County Sheriff's Office
 

Setup Cost

CrowdStrike Falcon Sandbox pricing is usage-based, perceived as above mid-range, with varying opinions on its affordability.
ThreatLocker Zero Trust Platform is praised for fair, flexible pricing, offering good value and practicality for enterprise customers.
Pricing is based on the number of endpoints and the features I need, operating on a usage-based cost structure.
Security Senior Engineer at a consultancy with 51-200 employees
I think it can be expensive, but it depends on the products.
IT- Manager at Orient Craft Ltd.
After conversations with other partners, it became clear we underpriced it initially, which caused most of our issues.
Director, Managed Services at a consultancy with 11-50 employees
We are moving towards the Unified solution, where they basically bundle everything together, providing us better stability with the ability to bring in new product offerings without having to go back to the customer and say, 'This is going to cost you.'
Supervisor, Client Security at a consultancy with 11-50 employees
Money is saved because it is not costly, and I would suggest it for other companies.
Helpdesk Engineer at Computer Network Infrastructure (CNI) Consultants
 

Valuable Features

CrowdStrike Falcon Sandbox provides efficient threat detection, robust analysis, and seamless integration, ensuring comprehensive security and minimal impact on performance.
ThreatLocker Zero Trust Platform enhances security with application control, allowlisting, ease of use, and proactive endpoint protection.
One of the key features is its policy-based notifications, which alert us to unauthorized actions.
Security Senior Engineer at a consultancy with 51-200 employees
This product is powerful in detection, which is the most important part because any customer wants a solution that detects what's happening.
Presales Consultant at Cyber Knight Technologies FZ LLC
I find the notifications and alerts received from CrowdStrike server to be invaluable.
Senior Consultant at Ernst & Young
ThreatLocker Zero Trust Endpoint Protection Platform's ability to block access to unauthorized applications has been excellent.
Cyber Security Specialist at Bremmar Consulting
It protects our customers.
CTO at Zettabytes
The major benefit is fewer breaches overall, as nothing can be run without prior approval. This helps my company protect its data and secure itself effectively.
Tier 1 IT Engineer at a retailer with 11-50 employees
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
9
Ranking in other categories
Anti-Malware Tools (12th)
ThreatLocker Zero Trust Pla...
Average Rating
9.2
Reviews Sentiment
7.1
Number of Reviews
75
Ranking in other categories
Network Access Control (NAC) (4th), Endpoint Protection Platform (EPP) (6th), Advanced Threat Protection (ATP) (5th), Application Control (1st), ZTNA as a Service (4th), ZTNA (5th), Ransomware Protection (1st)
 

Mindshare comparison

While both are Endpoint Security solutions, they serve different purposes. CrowdStrike Falcon Sandbox is designed for Anti-Malware Tools and holds a mindshare of 1.6%, up 1.2% compared to last year.
ThreatLocker Zero Trust Platform, on the other hand, focuses on Endpoint Protection Platform (EPP), holds 1.3% mindshare, up 0.7% since last year.
Anti-Malware Tools Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon Sandbox1.6%
Microsoft Defender for Endpoint6.9%
VirusTotal3.1%
Other88.4%
Anti-Malware Tools
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
ThreatLocker Zero Trust Platform1.3%
Microsoft Defender for Endpoint7.0%
CrowdStrike Falcon6.2%
Other85.5%
Endpoint Protection Platform (EPP)
 

Featured Reviews

AS
IT- Manager at Orient Craft Ltd.
Cloud deployment offers flexibility with performance and stability
The impact of CrowdStrike Falcon Sandbox on automated features is maintained by the partner. Customizable reports partly help me with my team's investigations. We are not using any other security tools; we are only using the Falcon. In my organization, approximately 50 users are using CrowdStrike Falcon Sandbox. There is nothing that requires maintenance; the partner handles it. I rate CrowdStrike Falcon Sandbox eight out of ten.
Santo Joy - PeerSpot reviewer
Head Of Cyber Security at a outsourcing company with 201-500 employees
Security controls have been strengthened with granular application, ringfencing, and access policies
The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most are the Ringfencing, elevation control, storage control, and application whitelisting functionality. For examples of how these features benefit my company, we were looking for a solution across various vendors to actually implement application whitelisting controls. ThreatLocker's agent, which is very lightweight and does not use much CPU or RAM, helped us achieve that solution. Ringfencing was an add-on that ticked off a lot of Australian framework security controls, which is the reason we chose it. My impression of the allowlisting feature in terms of managing which software, scripts, and libraries run on my devices is that ThreatLocker's community page has a lot of information around this, which is very helpful. Not only that, the Cyber Hero support that ThreatLocker provides gives us insights and best practices, helping us achieve that solution and guiding us to the right platform. The impact of Ringfencing on controlling the behavior of approved applications has been a big winner for us because it is something that many other platforms do not provide as a functionality. Having that allowed us to identify what applications talk to each other, which is something that many other platforms do not do. The network control feature impacts my ability to manage network traffic across my endpoints and servers. We have not used this widely across all our partners, but wherever required, we use it. It has been an easy solution for those customers to get that control implemented. The elevation feature's role in facilitating just-in-time administrative access for approved applications shows that elevation control helps in many use cases involving remote control platforms, door usage, and security system platforms that require local admins. There are many solutions that provide this functionality, but the licensing cost seems to be expensive, and it also adds another solution into the mix. Rather than doing that, we try to use ThreatLocker Zero Trust Endpoint Protection Platform to achieve that control. Regarding the storage control feature, I have used it. The primary function is USB blocking, which is very widely adopted, and also just locking down and allowing certain users to access certain file locations helps us there. When it comes to enforcing policy-driven access over various storage devices, it depends on the business risk adapted by the companies that we support, but generally the use case is USB and external storage devices where companies know that is a risk, but they do not have appropriate solutions. There are EDR platforms that claim to do this, but ThreatLocker Zero Trust Endpoint Protection Platform does it at an advanced level. My assessment of the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites leads me to think that Web Control is another functionality within ThreatLocker Zero Trust Endpoint Protection Platform that is an add-on on top of the current set. That is another solution that we use based on what is required for the company, but again, that is not widely adapted yet for our partners.
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
896,510 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Manufacturing Company
13%
Comms Service Provider
11%
Construction Company
9%
Computer Software Company
14%
Financial Services Firm
11%
Manufacturing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise3
By reviewers
Company SizeCount
Small Business51
Midsize Enterprise13
Large Enterprise11
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Sandbox?
I am not sure if there is a financial benefit; maybe, maybe not, as we did not evaluate that aspect. I think it can be expensive, but it depends on the products.
What needs improvement with CrowdStrike Falcon Sandbox?
As for room for improvement, we can mention that maybe some additional integrations will be beneficial to cover the whole use cases.
What is your primary use case for CrowdStrike Falcon Sandbox?
The major use case for CrowdStrike Falcon Sandbox is that we are using it with customers who need to check and validate the data the users are uploading to them, to check all the files and all the ...
What is your experience regarding pricing and costs for ThreatLocker Allowlisting?
My experience with pricing, setup cost, and licensing for ThreatLocker Zero Trust Endpoint Protection Platform is good because it has a nominal price.I would say ThreatLocker Zero Trust Endpoint Pr...
What needs improvement with ThreatLocker Allowlisting?
ThreatLocker Zero Trust Endpoint Protection Platform can be improved by providing admin rights that allow us to manage it from the server by providing some token IDs or any kind of OTP if someone h...
What is your primary use case for ThreatLocker Allowlisting?
My main use case for ThreatLocker Zero Trust Endpoint Protection Platform is to secure the server.A specific example of how I use ThreatLocker Zero Trust Endpoint Protection Platform to secure my s...
 

Also Known As

No data available
Protect, Allowlisting, Network Control, Ringfencing
 

Overview

Find out what your peers are saying about Microsoft, SentinelOne, Check Point Software Technologies and others in Anti-Malware Tools. Updated: May 2026.
896,510 professionals have used our research since 2012.