No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon vs Symantec Endpoint Security comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.4
Cortex XDR delivers cost savings, reduces security incidents, and attracts customers by replacing multiple solutions, offering high ROI.
Sentiment score
6.8
CrowdStrike Falcon boosts security, reduces costs, increases efficiency, and enhances threat response, leading to improved productivity and ROI.
Sentiment score
5.4
Symantec Endpoint Security increases financial satisfaction by reducing downtime and enhancing threat response, offering competitive pricing and automation.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cyber Security Manager at Welab bank
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
Detection and Response Consultant at Inovasys
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
Network Security Engineer at Cyberwell Solution
Catching issues early enough saves us from having to disable multiple users, which may be part of a later phishing event or disruption event in our environment.
Director, Information Security Services at a university with 10,001+ employees
We have to have cyber liability insurance, and knowing that we have CrowdStrike Falcon definitely helps when it comes to the bottom line and helping our insurance rates stay at a fair level.
Information Security Manager Iam at ExactCare Pharmacy
CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.
IT consultant at Asuransi Ramayana
Symantec Endpoint Security filled gaps in our toolset, particularly with the ability to control network firewall on hosts remotely, which was greatly appreciated.
OT Technologist at a energy/utilities company with 201-500 employees
 

Customer Service

Sentiment score
7.0
Cortex XDR's support is fast and knowledgeable, highly rated despite some regional and process-related challenges.
Sentiment score
7.1
CrowdStrike Falcon support offers mixed feedback, with praised efficiency and premium service but noted inconsistencies in standard support.
Sentiment score
6.0
Symantec Endpoint Security customer service is highly rated, but post-acquisition support quality fluctuates with some language and delay issues.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
Head of data centers at a non-profit with 10,001+ employees
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
Senior Process Expert at A.P. Moller - Maersk
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
Chief of IT Architecture at a financial services firm with 10,001+ employees
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
Cyber Security Architects at VaporVM
Everybody is friendly, knowledgeable, and wants to help, and you can feel that they want to keep your business.
Information Security Manager Iam at ExactCare Pharmacy
The onboarding team deserved a ten.
IT Support Engineer at a media company with 51-200 employees
In some cases, it rates as high as ten out of ten, while in others, it can be as low as eight.
Head of Information System at EEC
There is no support in the German language, which is a problem for many public tenders.
Cyber Security Pre-Sales at SoftwareONE
 

Scalability Issues

Sentiment score
7.4
Cortex XDR offers strong scalability and flexibility, managing thousands of endpoints efficiently while simplifying cloud-based expansion and integration.
Sentiment score
7.7
CrowdStrike Falcon offers scalable, cloud-based security, efficiently managing thousands of endpoints, suitable for both large and small enterprises.
Sentiment score
6.9
Symantec Endpoint Security is scalable, efficient for large deployments, and adaptable, with minor integration and support challenges noted.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Assistant Security Architect at Cloudnomics
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Junior Security Analyst at ITSEC Asia
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
Head of data centers at a non-profit with 10,001+ employees
It has adequate coverage and is easy to deploy.
Senior Principal Information Security Analyst at Veritas Technologies LLC
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
Cyber Security Architects at VaporVM
There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.
Large account Manager at Softcell Technologies Limited
Symantec Endpoint Security is quite scalable, and it is very important for large clients.
Cyber Security Pre-Sales at SoftwareONE
The scalability of the servers is good, as it requires computational powers.
Senior Security Delivery Analyst at Accenture
 

Stability Issues

Sentiment score
8.0
Cortex XDR is praised for stability, reliability, minimal bugs, and superior performance, despite occasional false alerts and update issues.
Sentiment score
8.1
CrowdStrike Falcon is highly stable and reliable, with minimal issues, efficient performance, and excellent user ratings.
Sentiment score
7.6
Symantec Endpoint Security is praised for stability and reliability, despite occasional crashes and compatibility issues during updates.
Cortex remains fast and responsive, even with increasing data and alerts.
Final Year Student at Gitam University
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Senior Process Expert at A.P. Moller - Maersk
Cortex XDR by Palo Alto Networks can be trusted completely.
Soc Analyst at Softcell Technologies Limited
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.
IT Security Analysts at Royal Business Bank
I have never seen instability in the CrowdStrike tool.
Security Analyst at NTT Ltd
We are following N-1 versions across our environment, which is stable.
Senior Principal Information Security Analyst at Veritas Technologies LLC
I have encountered issues where I had to uninstall and reinstall the product on end users' computers to view the logs again.
OT Technologist at a energy/utilities company with 201-500 employees
Previously, we used to have multiple servers such as GUP servers and numerous servers for pushing updates, but we reduced it and transitioned almost 30,000 devices to CrowdStrike, which was easy to manage.
Senior Security Delivery Analyst at Accenture
 

Room For Improvement

Cortex XDR needs interface improvements, better integrations, cost-effectiveness, enhanced automation, real-time monitoring, and ease of use.
Users seek enhanced compatibility, user-friendliness, AI, support, and flexible pricing for CrowdStrike Falcon, emphasizing deployment complexity and cost.
Symantec Endpoint Security suffers from high resource usage, management complexity, outdated interface, and ineffective virus detection and support.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
Final Year Student at Gitam University
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
Pre Sales Architect at network techlab
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
Cyber Security Information Security Specialist at MHM Holding GmbH
Documentation is abysmal and needs to be improved dramatically.
Senior Security Engineer at a financial services firm with 10,001+ employees
If I bring up a device, I want a quick button there to contain it because if I'm clicking on that device, there's something I'm looking into and most likely I've been alerted of something, so I should probably contain it first and then ask questions later.
Network Security Engineers at Silver State Schools Credit Union
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Security Analyst at NTT Ltd
Device management is not very good and I am not enabling it in my organization due to security reasons.
System Administrator at Aljazera Market co
I would like to see improvements in the scanning part of the solution, specifically to enhance the CPU and hard disk usage during scanning and updates to prevent disruption during work hours.
Head of Information System at EEC
It is cumbersome to use, particularly in handling firewall management.
OT Technologist at a energy/utilities company with 201-500 employees
 

Setup Cost

Cortex XDR offers advanced features with perceived high costs, pricing varies by organization size, subscription, and potential extra feature charges.
CrowdStrike Falcon pricing reflects endpoint volume and modules, offering strong security value for $60-$100 per user annually.
Symantec Endpoint Security's pricing is diverse, being both negotiable and adaptable for different budgets and organizations' needs.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
Consultant at a tech services company with 1,001-5,000 employees
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Senior Process Expert at A.P. Moller - Maersk
Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
Soc Analyst at Softcell Technologies Limited
It is approximately 60 dollars per endpoint at MSRP.
Senior Secops Engineer at a program development consultancy with 1,001-5,000 employees
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
Senior Principal Information Security Analyst at Veritas Technologies LLC
The licensing cost and setup costs are affordable.
Computer Engineer at OIC, Alshirawi
It seems to be half the cost or more affordable than other solutions.
OT Technologist at a energy/utilities company with 201-500 employees
The pricing is very low compared to other companies like SentinelOne and others.
System Administrator at Aljazera Market co
I rate the pricing, setup cost, and licensing around nine out of ten.
Head of Information System at EEC
 

Valuable Features

Cortex XDR excels in threat detection and response with AI integration, multi-layered security, and user-friendly automation features.
CrowdStrike Falcon excels with real-time threat detection, integration, scalability, reducing workloads, and enhancing security through its unified platform.
Symantec Endpoint Security provides integrated, user-friendly protection for multiple platforms with advanced malware detection and comprehensive endpoint management.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
Cyber Security Manager at Welab bank
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
Pre Sales Architect at network techlab
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
Final Year Student at Gitam University
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
Security Analyst at NTT Ltd
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Cyber Security Architects at VaporVM
Being an EDR solution, it helps us identify attacks in real-time.
Information Security Specialist at Arab Open University
Symantec Endpoint Security offers great features such as reporting capabilities with a customized dashboard that pulls in EDR timelines, threat maps, and compliance metrics into one view.
Senior Cybersecurity Engineer at Kyndryl
Symantec Endpoint Security offers many valuable features, such as file explosion, application learning, DLP, injection detection, and EDR solutions for traffic control.
System Administrator at Aljazera Market co
The incident response capabilities allow me to resolve authentication and support issues promptly, ensuring the system operates without downtime.
Head of Information System at EEC
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon
Ranking in Endpoint Protection Platform (EPP)
3rd
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Detection and Response (EDR) (2nd)
Symantec Endpoint Security
Ranking in Endpoint Protection Platform (EPP)
8th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
146
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, up from 3.8% compared to the previous year. The mindshare of CrowdStrike Falcon is 5.7%, down from 8.2% compared to the previous year. The mindshare of Symantec Endpoint Security is 3.7%, up from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Cortex XDR by Palo Alto Networks3.8%
Symantec Endpoint Security3.7%
Other86.8%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Behavioral protection has blocked ransomware and now saves extensive recovery and audit time
The best feature of Symantec Endpoint Security is its effectiveness in malware protection. Its malware protection capabilities stand out due to their ease of management. Although multiple tools assist in this process, managing them all can sometimes be challenging. In terms of malware protection, Symantec Endpoint Security performs well, and its mechanisms, tactics, and techniques are effective. Symantec Endpoint Security offers robust features such as advanced reporting capabilities with a customizable dashboard that integrates EDR timelines, threat maps, and compliance metrics into a single view. Additionally, reports can be exported to PDF or CSV formats, making reporting one of its strong points. It also provides comprehensive device control features, which block unauthorized USB devices and support whitelisting. This helps prevent data exfiltration and phishing scenarios without disrupting user workflows.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
912,801 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
9%
Financial Services Firm
10%
Manufacturing Company
9%
Outsourcing Company
9%
Computer Software Company
8%
Comms Service Provider
13%
Outsourcing Company
12%
Financial Services Firm
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise32
Large Enterprise63
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about CrowdStrike Falcon vs. Symantec Endpoint Security and other solutions. Updated: September 2026.
912,801 professionals have used our research since 2012.