Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs Cybereason Endpoint Detection & Response vs Fortinet FortiSOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Extended Detection and Response (XDR) Market Share Distribution
ProductMarket Share (%)
CrowdStrike Falcon12.7%
Wazuh10.7%
Darktrace8.3%
Other68.3%
Extended Detection and Response (XDR)
Endpoint Detection and Response (EDR) Market Share Distribution
ProductMarket Share (%)
Cybereason Endpoint Detection & Response1.1%
CrowdStrike Falcon11.4%
Microsoft Defender for Endpoint10.1%
Other77.4%
Endpoint Detection and Response (EDR)
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Fortinet FortiSOAR4.3%
Microsoft Sentinel16.3%
Palo Alto Networks Cortex XSOAR9.7%
Other69.7%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Waleed Omar - PeerSpot reviewer
Provides effective real-time threat detection with potential for cost optimization
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
Ivan Burke - PeerSpot reviewer
Offers useful threat hunting and response capabilities but struggles to justify cost for smaller deployments
I mostly work with incident response, so I work with a bunch of them interchangeably, but mostly with the EDR components; I also get involved with some of the XDR components, especially for the cloud. Regarding analysis features, such as deep behavioral detection, I do use it sometimes; I usually don't use the automated version of it, as I prefer threat hunting directly, depending on if the season is available. I know some of them have pretty good analytics engines, but I tend to do the threat hunting on my own. I manage incident response for a bunch of companies, so some of them have Cybereason Endpoint Detection & Response integrated into Sentinel, some into Fortinet, and others into various tools. When considering cost-effectiveness, their pricing structure works such that if you're a large organization with more than a thousand endpoints to deploy to, then Cybereason Endpoint Detection & Response is worthwhile. But for anything less than 300, it's too expensive; obviously, the more you buy, the better the price, making it cheaper for you. Cybereason Endpoint Detection & Response best fits enterprise-level businesses such as huge corporations; however, we are in the process of removing it from many of our endpoint clients because it's not really showing enough value for them at the moment. We're trying to see how we can improve it with some of our clients, but at the moment, it's struggling compared to other EDR solutions that we have deployed. On a scale of one to ten, I rate Cybereason Endpoint Detection & Response a six.
Mahmoud Younes - PeerSpot reviewer
Automation streamlines workflow and integrates seamlessly with various applications
I serve as both a reseller and customer of Fortinet FortiSOAR. The solution is suitable for all types of businesses from small to enterprise. The integration capability of Fortinet FortiSOAR deserves a rating of 10. It can be integrated with any system, and we have the capability for custom connectors. Even if Fortinet FortiSOAR doesn't have a specific connector, you can easily create a custom connector using AI. Simply provide your requirements or solution needs, and Fortinet FortiSOAR will create the connector, enabling integration with any application. My final rating for Fortinet FortiSOAR would be 10 out of 10, where one is bad and ten is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"All the features are beneficial."
"CrowdStrike is a great solution."
"The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately."
"The platform is very scalable."
"Falcon's best feature is its detection and blocking of threats."
"The automatic alert feature is the most important feature of the solution."
"Among CrowdStrike Falcon's most valuable capabilities are its UEBA and SOAR functionalities, along with its seamless integration with any other SIEM solution."
"The detection is very reliable. Also, OverWatch is a great feature."
"It gives all the information in a clear response."
"Immediately we can pick up the computers in the network if any malicious operation that is triggered."
"Their EDR solution, the ability to mitigate issues through their command line, is probably the best feature that we've had. We use that all the time. It's very useful for doing investigations."
"Cybereason absolutely enables us to mitigate and isolate on the fly. Our managed detection response telemetry has dropped dramatically since we began using it. It's very top-of-mind. We were running some tabletop exercises and none of the detections were getting triggered by the managed security services provider. So we needed to find a solution that would trigger high-fidelity alerts. That was Cybereason and it dramatically changed our landscape from the detection and response perspective."
"The interface is user-friendly."
"I haven't had any issues with the solution. Stability-wise, I rate the solution a ten out of ten."
"The initial setup was straightforward."
"What I find most valuable is the clarity of the platform."
"The initial setup is straightforward."
"The product can be automated for network security purposes. The solution offers a great security automation response."
"It is a scalable solution...The implementation phase of the product was not tough or difficult."
"The solution's most valuable feature is playbook creation, which allows us to integrate all data ingestion into the same platform."
"The playbook and the dashboard of FortiSOAR are really informative."
"My final rating for Fortinet FortiSOAR would be 10 out of 10, where one is bad and ten is good."
"It has a quick detection and response time."
"The reputation of the brand is very good."
 

Cons

"The price is too high."
"The content-filtering features for children could be improved. We have young grandchildren aged 12 and 8. My daughter, their mother, wants to keep them from getting in trouble on the net. She looked at all these other solutions from Google, Microsoft, etc., and she couldn't figure out how to make any of those work. I told her that I bet CrowdStrike could handle this. Sure enough, CrowdStrike can do exactly that. It's the same solution that the Defense Department gets. It works, but it's a little complicated to implement. It could be simpler to set the policies."
"I would like to see a little bit more in the offline scanning ability. This just comes from my background in what I have done in other positions. They only scan on demand, so I always have this fear that we sometimes maybe email out a dormant virus and can be held liable for that. That is something where I would like to see a little bit more robustness to the tool."
"CrowdStrike Falcon could be enhanced by extending its security capabilities to include NDR and XDR."
"CrowdStrike needs to quit making up stuff about its features and functionality to bash its competition."
"I would like to see equal support across all versions. Aside from that, I would say most of the features are there."
"CrowdStrike Falcon could improve the logs by making them free to the API."
"They respond quickly on the weekdays, but the weekend response times are slower."
"The integration with Microsoft solutions and Microsoft capabilities needs to be improved."
"While the product is very good, there are still some areas for improvement. The initial triage area could be a bit simpler. They get into the weeds real fast; it gets very detailed very fast. I am still looking for an easier triage layer on top with the ability to dig deeper."
"The product's reporting isn't great."
"I feel that the product lacks reporting features and needs improvement."
"I feel it is a shame that I cannot create groups of groups with inheritance."
"Compared to our previous endpoint, we have a lot more false positives and a lot more duplication of alerts. So we're chasing more alerts."
"The deployment on individual endpoints is more geared toward larger organizations. It might prove to be a bit too complicated for a smaller organization. You need to know what you're doing when you're deploying the sensor."
"There can be problems with the EDI."
"Fortinet FortiSOAR's dashboard is not easy to understand."
"Technical support could be improved."
"FortiSOAR needs to improve the response time for executing playbooks."
"The ease of playbook creation on FortiSOAR needs improvement."
"The solution lacks proper documentation, so we have to test and trial each playbook and integration."
"I have found that Fortinet FortiSOAR needs a lot of improvement. The Orchestration needs to be improved."
"The UI design of the solution needs to be changed since it can get difficult for a newbie to operate."
"I don't currently see where the solution is lacking features. For us and for our clients it works very well and we're pleased with it."
 

Pricing and Cost Advice

"In my opinion, the pricing of CrowdStrike Falcon seems aggressive."
"The pricing is definitely high but you get what you pay for, and it's not so high that it prices itself out of the market."
"We are at about $60,000 per year."
"It is an expensive product, but I think it is well worth the investment."
"I am not aware of the price, but I believe that it is among the most expensive XDRs out there. Of course, this is dependent on the features you choose. Depending on the features, the price might increase."
"The price is high in comparison to similar brands."
"CrowdStrike is a reasonably priced tool."
"The price is fixed with no room for negotiation."
"In terms of cost, this is a good choice for our needs."
"We considered a few other solutions. Some were ridiculously overpriced, while others didn't have solutions for Mac endpoints. That was a deal-breaker because most of our organization is on Mac. It came down to two vendors: Cybereason and another. They had similar pitches and almost identical approaches, but in the end, Cybereason gave us the best value for our money."
"I had to go through a third-party to purchase it, which I wasn't really pleased about."
"I do not have experience with the licensing of the product."
"This product is somewhat expensive and should be cheaper."
"Though it is not the cheapest solution but it fits our budget. We pay an annual licensing fee."
"In terms of pricing, it's a good solution."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the pricing an eight."
"If you compare Fortinet FortiSOAR's price with the prices of the market leader, Palo Alto, then it can be considered a cheaper product."
"The price of the product should be lower. The brand value that Fortinet has, it has the reputation of being a reasonably priced product, and they have an enormous customer base in India. Most of the SME market is covered by FortiGate firewalls. It becomes an easy way for consultants, such as us, or even system integrators, to open the door with the Fortinet product lines."
"Since Africa is struggling with foreign exchange, the solution is pretty expensive there."
"Fortinet FortiSOAR is an expensive solution."
"Fortinet FortiSOAR is expensive."
"The solution offers both licensing and subscription models that are similar in price to other products."
"Pricing is fine compared to other solutions."
"Considering all the features of Fortinet FortiSOAR, I think it has a good price."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
868,183 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
9%
Government
6%
Computer Software Company
14%
Financial Services Firm
11%
Manufacturing Company
8%
Comms Service Provider
7%
Financial Services Firm
13%
Computer Software Company
12%
Healthcare Company
8%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise34
Large Enterprise61
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise4
Large Enterprise13
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise4
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
What is your experience regarding pricing and costs for Cybereason Endpoint Detection & Response?
Comparison with other products showed it be cheaper than some larger competitors. Set up cost for us were cheaper as ...
What is your primary use case for Cybereason Endpoint Detection & Response?
My main use case for Cybereason Endpoint Detection & Response is mostly for incident response.
What do you like most about Fortinet FortiSOAR?
Fortinet FortiSOAR is a very interactive and user-friendly solution.
What is your experience regarding pricing and costs for Fortinet FortiSOAR?
Regarding pricing, licensing, and setup costs for Fortinet FortiSOAR, the value proposition depends on your business ...
What needs improvement with Fortinet FortiSOAR?
Additional fine-tuning on ChatGPT could be added. This is the only area requiring improvement, with no other concerns...
 

Also Known As

CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
Cybereason EDR, Cybereason Deep Detect & Respond
CyberSponse, FortiSOAR
 

Overview

 

Sample Customers

Information Not Available
Lockheed Martin, Spark Capital, DocuSign, Softbank Capital
Information Not Available
Find out what your peers are saying about CrowdStrike, Microsoft, SentinelOne and others in Extended Detection and Response (XDR). Updated: August 2025.
868,183 professionals have used our research since 2012.