No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon vs Fortinet FortiGuard comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
Fortinet FortiGuard
Average Rating
8.2
Reviews Sentiment
5.9
Number of Reviews
5
Ranking in other categories
Threat Intelligence Platforms (TIP) (14th)
 

Mindshare comparison

Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGuard1.6%
Recorded Future6.1%
Anomali3.9%
Other88.4%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
Muhammad Kamran Khan - PeerSpot reviewer
Chief information security officer at a financial services firm with 201-500 employees
Improves email filtering and network protection but has limited accessible support and feature discovery
When going for support and asking for support for features, the support team asks to go for professional services, which are not covered in the support agreement. This is the reason exploration of the product features has been limited. To learn or explore something about the product, professional services need to be taken. When creating a ticket for support with configuration features, the support is reluctant to provide that support. This is the reason every feature of Fortinet FortiGuard cannot be explored. Currently Fortinet FortiGuard is working fine with no issues, but newsletters or communications about new features in the product are not being received from Fortinet. This limits knowledge of what new features are available in the product. There is no knowledge about the behavior analytics feature in Fortinet FortiGuard.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Overall, it's a great platform; it integrates very well with other solutions from Palo Alto and also with our vendors, the ease of use is excellent, I love the root cause analysis from Cortex, which is amazing, and in a few clicks you can have the full root cause."
"The solution's most valuable feature is its ability to rapidly detect certain hardware files."
"One of the main benefits of the solution is its intelligence to correlate the events into an incident."
"The dashboard is customizable."
"Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
"The stability of this product is very good."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"It collects and caches and the knowledge of machine learning from different customers to take to the cloud, it makes it better to use for everybody, it allows for quick learning and updates and can, therefore, offer zero-day malware security, and this sharing of metadata helps make the solution very safe."
"The managed services are distinguished, responsive, dynamic, flexible, and assertive when taking action."
"Scalability hasn't been an issue for us."
"The most valuable features of CrowdStrike Falcon include Falcon Fusion workflows and endpoint detection capabilities."
"CrowdStrike's advantage is that the agent is light, so it doesn't require many resources on the machines, it's easy to install, and the results are useful to the organization."
"Since using CrowdStrike Falcon, I have seen a lot faster incident response actions, containment, and it helps me mitigate many threats automatically that I previously handled manually."
"CrowdStrike Falcon has helped my customers predict and prevent potential breaches because of its proactive approach."
"Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making our response time much quicker and giving me confidence in the alerts and information we receive."
"Most of our customers in my country use CrowdStrike Falcon, and ever since then, they do not have serious incidents, such as a ransomware that has taken effect on all their critical infrastructures, including servers."
"The best features in Fortinet FortiGuard that I appreciate are the nice interface, ease of use, and straightforward administration and setup."
"The most valuable features of the solution are its ease of use and efficiency."
"The content filtering feature helps protect data by filtering potentially dangerous websites and brings significant benefit to the organization."
"The main benefits Fortinet FortiGuard provides are that it secures the network from external threats, it provides security, and it has a very perfect graphical user interface that is very easy to use."
"The benefits I gain from using Fortinet FortiGuard include peace of mind; it has contributed to ensuring that we are always available and can meet our availability targets, which means that productivity is maintained and revenues will rake in as planned."
 

Cons

"Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth."
"The main issue I could point out is the offline agents and the way that it is missing."
"Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."
"A potential area of improvement for Cortex XDR by Palo Alto Networks is the cost."
"The downside to the solution is that there are a large number of false positives."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
"Previously, the endpoint would leave the environment, not being on our VPN, essentially unable to interact with the server to upload files. It was unable to retrieve new file verdicts. It was using a thing called "local analysis" to determine if something was a malicious file or not. There was no dynamic analysis."
"Improvement is always possible. It's challenging to gauge how much future mitigation is provided, especially since we've only been using the product for about one and a half years. Every product faces this challenge because nothing is ever completely foolproof. So, besides relying on technology, we also focus on increasing our staff's awareness of security issues. Feedback from my colleagues suggests that the reporting and dashboarding of incidents could be improved."
"The console is a little cluttered and at times, finding what you're looking for is not intuitive."
"The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool."
"It would be nice if the dashboard had some more information upfront, and looked a little better."
"They should provide us with good visibility for everything."
"The technical support team often just replies to an issue with a link to an article rather than actually calling back and talking to someone and making sure the problem is solved. To me, that's kind of weak."
"The product is quite expensive."
"One area for improvement in CrowdStrike Falcon could be the user interface and reports; it requires some improvements to be easily handled."
"If the tool can be cheaper or less expensive, it can be good for users."
"When creating a ticket for support with configuration features, the support is reluctant to provide that support."
"The dashboard is an important and integral part of the product that could be improved."
"I think that automated response could be improved if they can add automated response features into Fortinet FortiGuard."
"Currently, for our usage, the areas that have room for improvement are pricing and customization."
 

Pricing and Cost Advice

"The pricing is a little bit on the expensive side."
"I don't recall what the cost was, but it wasn't really that expensive."
"I feel it is fairly priced."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"The pricing is okay, although direct support can be expensive."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours."
"The price is too high."
"In my opinion, the pricing of CrowdStrike Falcon seems aggressive."
"CrowdStrike Falcon's price is good."
"The pricing is not bad. It's on the higher end of the market, but you get what you pay for."
"I would like them to further reduce the price, because it is quite pricey at the moment."
"Different components are additional price points. We got the components that were right for us, but other organizations may require more (or less) components to suit their needs."
"We are at about $60,000 per year."
"If one is very cheap and ten is very expensive, I rate the tool's price as a six to seven."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,924 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
10%
Outsourcing Company
9%
Manufacturing Company
9%
Computer Software Company
8%
Educational Organization
12%
Construction Company
10%
Outsourcing Company
9%
Healthcare Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
What is your experience regarding pricing and costs for Fortinet FortiGuard?
Regarding pricing, I must say it is quite pricey, but if you look at the value it gives you, I think the value justif...
What needs improvement with Fortinet FortiGuard?
When going for support and asking for support for features, the support team asks to go for professional services, wh...
What is your primary use case for Fortinet FortiGuard?
Fortinet FortiGuard is used to filter emails coming to the email server. Fortinet FortiGuard threat intelligence is u...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
913,924 professionals have used our research since 2012.