No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon vs Deepwatch comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
Deepwatch
Average Rating
8.0
Reviews Sentiment
7.7
Number of Reviews
1
Ranking in other categories
Managed Detection and Response (MDR) (25th), AI-Powered Cybersecurity Platforms (12th)
 

Mindshare comparison

Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
Managed Detection and Response (MDR) Mindshare Distribution
ProductMindshare (%)
Deepwatch0.6%
SentinelOne Wayfinder Threat Detection and Response6.2%
CrowdStrike Falcon Complete MDR4.5%
Other88.7%
Managed Detection and Response (MDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
Pranay Jain - PeerSpot reviewer
Senior software engineer at Simplify vms
Continuous monitoring has strengthened payment security and now reduces incident impact quickly
There are specific details that can be improved in Deepwatch. After implementing it, we tracked both response time and threat detection accuracy using the SIEM dashboard. We measured response time using MTTD and MTTR. There are areas that can be improved, such as every alert having a timestamp for detection time and acknowledgment. We observed the MTTR dropping from a few hours to under one hour after using Deepwatch, so baseline metrics can be enhanced. Deepwatch can reduce alert fatigue since sometimes it generates a high volume of alerts that overwhelm our team. This can create too many alerts in a short amount of time, making it hard for our team to understand what to do. Additionally, the dashboard can be improved for better user-friendliness for end-users, requiring better visualization of MTTR, threat trends, and risk scoring. Improvements can also be made in more automated playbooks for automated response to common threats, and there is room for deeper integration capabilities, as integration with some internal tools may require additional effort.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"Cortex XDR by Palo Alto Networks has changed the way my security team detects, investigates, and responds to threats, as we are able to see the files, unwanted files, unsecured files, and unauthorized files, so we are quarantining them."
"It has absolutely improved the way our organization functions, we are more secure, it is giving us more peace of mind, and it has found malicious activity happening on our endpoints that probably would not have been detected if we didn't have it."
"The protection offered by this product is good, as is the endpoint reporting."
"Once you become familiar with it, Cortex XDR by Palo Alto Networks is a more powerful tool and I would say that I prefer it over MDE because it is a stronger tool for me."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for."
"Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms."
"There are great security features on offer that are much better than other options in India at this time."
"The managed services are distinguished, responsive, dynamic, flexible, and assertive when taking action."
"The initial setup is very simple."
"The detection and response have been excellent overall."
"The main feature we rely on is the product's intelligence. We appreciate the advice from the team during implementation. One of the main reasons we chose this product is its compatibility with Office 365."
"CrowdStrike Falcon has done an excellent job at detecting breaches; it has allowed us to stay in business and kept our systems up while multiple partners and service providers have been taken down by ransomware and other cyberattacks."
"This solution consistently releases improvements. They have communicated their next two years of development which is powerful and covers all of our needs."
"CrowdStrike Falcon has positively impacted my organization by providing better visibility, host management, compliance, and real-time responses."
"Deepwatch positively impacts our organization by reducing incident response time because previously, there was no mechanism to follow up on incidents, such as any security breach in the payment gateway, and it has reduced response time by 40 to 60 percent while significantly improving threat detection accuracy with 24/7 monitoring even after business hours."
 

Cons

"The playbooks could be improved to include more functionalities or actions."
"Basically, they don't provide customer support tools just to investigate the logs."
"Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
"If Palo Alto reduces the pricing slightly for their products, it would make them more scalable in markets such as India and globally for cybersecurity."
"The tool needs to be improved in terms of integration and interface."
"There are some default policies which sometimes affect our applications and cause them to run around. In the hotel industry, we use a different type of data versus Oracle and SQL. By default, there are some policies which stop us from running properly. Because of this, the support level is also not that strong. We have to wait to get a results."
"The solution lacks real-time, on-demand antivirus."
"Dashboards do not allow everyone to see what's happening."
"CrowdStrike Falcon can be improved by strengthening the focus on AI and keeping up with responding to AI as it constantly evolves."
"I would like to see a more accurate integration and an option to check the local machine."
"CrowdStrike should add support for ransomware protection."
"CrowdStrike Suites and the way that it bundles things can be a bit challenging. It should be easier to integrate with the other stuff that they sell or be included with what they sell. We have one piece, then they are talking about another piece on vulnerability management all of the sudden, and we don't own that piece. We can see it in the console, but nothing shows up. It simply appears within the tool as an option, but we can't use it without purchasing it."
"The stability of the solution varies, several weeks ago I had some difficulties deploying CrowdStrike."
"Regarding CrowdStrike Falcon's AI capabilities, I think it still needs a little bit of time to learn and improve itself in the environment, but overall it has been pretty accurate."
"CrowdStrike Falcon needs to improve their host management system."
"CrowdStrike Falcon can be improved by continuing to adapt to everything that is going on with AI and other developments in the world."
"Deepwatch can reduce alert fatigue since sometimes it generates a high volume of alerts that overwhelm our team."
 

Pricing and Cost Advice

"I don't like that they have different types of licenses."
"Very costly product."
"The price of the solution is high for the license and in general."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"I feel it is fairly priced."
"We didn't have to pay any additional fee for the cloud instance. It just came with the renewal, which was nice."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"Our customers have expressed that the price is high."
"CrowdStrike Falcon offers excellent value for the money for our organization, particularly given our lean IT team."
"The cost is usually a challenge in the industry. I think we pay around sixty-eight dollars."
"All I can say about the licensing cost is that it's negotiable."
"It's an expensive solution but you get a very good product for the price. Compared to other products, SentinelOne is definitely cheaper and the Microsoft E5 package is probably more expensive. Not many companies are willing to purchase CrowdStrike Falcon in Turkey due to the cost, but the market is changing."
"CrowdStrike Falcon can be more expensive than some competitors, and its base price doesn't cover every feature."
"While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours."
"I'm not directly involved in sales, so I can't comment on the exact price, but I know the price decreases the higher the quantity we purchase."
"We bought a very small number of licenses, then ran it for a year. We bought a 100 licenses for a year, so we didn't actually do a proof of concept. We just bought them. Then, the next year, we bought 10,000 licenses."
Information not available
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
912,930 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
10%
Manufacturing Company
9%
Outsourcing Company
9%
Computer Software Company
8%
Construction Company
29%
Manufacturing Company
13%
Media Company
10%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
What needs improvement with Deepwatch?
There are specific details that can be improved in Deepwatch. After implementing it, we tracked both response time an...
What is your primary use case for Deepwatch?
Deepwatch provides continuous rest monitoring, detection, and response to protect our organization from cyberattacks....
What advice do you have for others considering Deepwatch?
My advice for others considering using Deepwatch is that if someone has an application where security threats are com...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Premise Health, Dover, Follett, Genuine Parts Company
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
912,930 professionals have used our research since 2012.