Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs Trellix Endpoint Security (ENS) vs VMware Carbon Black Endpoint comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
CrowdStrike Falcon boosts efficiency and cost savings while enhancing security and performance without increasing system slowdown.
Sentiment score
7.5
Trellix Endpoint Security is effective yet costly, with reduced IT workload and mixed ROI due to false positives and incidents.
Sentiment score
7.1
Users reported significant ROI with VMware Carbon Black Endpoint, citing reduced malware and ransomware incidents, and 10% cost savings.
 

Customer Service

Sentiment score
7.0
CrowdStrike Falcon’s support is praised for responsiveness, but some report slow responses and inconsistency, especially on weekends.
Sentiment score
8.5
Trellix Endpoint Security's support is praised for responsiveness but criticized for slow resolutions and regional inconsistencies.
Sentiment score
6.4
VMware Carbon Black Endpoint support is generally praised as effective and knowledgeable, but some report delays and issues with tiered support.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
They could improve by initiating calls for high-priority cases instead of just opening tickets.
I rate the support from Trellix a perfect ten.
They were fairly responsive and able to resolve the issue.
 

Scalability Issues

Sentiment score
7.9
CrowdStrike Falcon's scalability and cloud-based architecture support rapid deployment and seamless expansion for diverse business security needs.
Sentiment score
9.0
Trellix Endpoint Security is praised for effective scalability and adaptability to various environments and operating systems.
Sentiment score
7.5
VMware Carbon Black Endpoint is highly scalable and adaptable for various enterprises, praised for ease of adding tenants and managing environments.
It has adequate coverage and is easy to deploy.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
When it comes to scalability, it is entirely based on premium models according to demand.
 

Stability Issues

Sentiment score
8.1
CrowdStrike Falcon offers stable, reliable performance across environments, managing endpoints effectively despite minor update challenges and connectivity issues.
Sentiment score
8.5
Trellix Endpoint Security is stable and reliable, with occasional performance issues and consistent updates for optimal performance.
Sentiment score
7.6
VMware Carbon Black Endpoint is stable, lightweight, reliable, and highly rated, though minor issues with sensors and updates occasionally occur.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
The biggest issue occurred when every computer worldwide experienced a blue screen.
 

Room For Improvement

CrowdStrike Falcon users seek better third-party integration, intuitive UI, threat detection, support, pricing, and forensic tools.
Trellix ENS needs improved performance, usability, integration, scalability, and support, with enhanced security features and user-friendly documentation.
VMware Carbon Black Endpoint struggles with mobile support, complex UI, performance issues, inadequate reporting, and insufficient third-party integration.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Threat prevention should be their first priority.
Some customers feel that the Trellix Endpoint Security (ENS) agent consumes more memory and resources in their environment.
 

Setup Cost

CrowdStrike Falcon provides robust security at premium pricing, with flexible licensing but may be costly for some businesses.
Trellix ENS offers enterprise-focused pricing with flexible licensing and support, providing value through performance and forensic analysis.
VMware Carbon Black Endpoint licensing is seen as expensive and inflexible, with prices ranging from $15 to $7,000 per node.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
The licensing cost and setup costs are affordable.
The solution is a bit expensive.
 

Valuable Features

CrowdStrike Falcon provides advanced, efficient threat protection with AI capabilities, ease of management, and comprehensive detection and prevention features.
Trellix Endpoint Security excels in threat detection, integration, scalability, and AI-driven updates, enhancing security with ease of deployment.
VMware Carbon Black Endpoint offers robust remote security with intuitive real-time detection, AI-driven threat response, and centralized cloud control.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Being an EDR solution, it helps us identify attacks in real-time.
They find Trellix Endpoint Security (ENS) easy and user-friendly for their environment, which is why they choose Trellix.
Trellix Endpoint Security seems to do a good job in terms of protecting my infrastructure from malware.
 

Mindshare comparison

As of May 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of CrowdStrike Falcon is 10.9%, up from 9.3% compared to the previous year. The mindshare of Trellix Endpoint Security (ENS) is 1.5%, down from 1.9% compared to the previous year. The mindshare of VMware Carbon Black Endpoint is 1.6%, down from 2.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Featured Reviews

Chintan-Vyas - PeerSpot reviewer
Easy to set up with good behavior-based analysis but needs a single-click recovery option
Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files. The product could be more accurate in terms of performance. We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.
Shreyansh Sharma - PeerSpot reviewer
Our main antivirus tool and offers adaptive threat prevention tool
The technical support needs some improvement. When product distribution errors occur, we have to contact technical support, which is a very tedious and time consuming task. After raising the call onto the technical support portal, usually receive a notification after 24 hours. It usually takes 3 to 4 days to conclude and resolve the issue. If 24/7 online support or a phone line where we could speak directly with technical support for real-time troubleshooting, that would be very helpful. Licensing is another aspect where trellix should look into. Different purchases are grouped together in single user account get mixed up. Categorization of purchases and their grant numbers is not available to end user.
KarthikR1 - PeerSpot reviewer
The solution has an easy setup but needs to mature on cloud environment security
The maturity of the Kubernetes security is absent in Carbon Black CB Defense. The solution has to mature on container security and a lot of cloud environment security. Security is available only for Windows, while security for Linux and Mac is not very strong. The deadlock issue causes me to put more effort into installing an upgrade. The numerous issues with the environment of the product solution should be addressed. Work orders are taking more than two months to get resolved. There's been one issue open for two months, and the solution they gave is being implemented step by step. Still, it is not meeting the requirements and breaking the system. Hence, our business is completely disturbed.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
852,098 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Computer Software Company
15%
Financial Services Firm
13%
Government
12%
Manufacturing Company
11%
Computer Software Company
15%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
How does McAfee Endpoint Security compare with MVISION?
The flexible manageability of McAfee Endpoint Security is one of our favorite aspects of this solution. You can deplo...
How does Crowdstrike Falcon compare with FireEye Endpoint Security?
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effec...
What do you like most about McAfee MVISION Endpoint?
The product's initial setup phase was straightforward.
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What do you like most about Carbon Black CB Defense?
VMware Carbon Black Endpoint is a highly stable solution.
 

Also Known As

CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
McAfee MVISION Endpoint, Trellix Endpoint Security (HX)
Carbon Black CB Defense, Bit9, Confer
 

Overview

 

Sample Customers

Information Not Available
Tech Resources Limited, Globe Telecom, Rizal Commercial Banking Corporation
Netflix, Progress Residential, Indeed, Hologic, Gentle Giant, Samsung Research America
Find out what your peers are saying about Microsoft, CrowdStrike, SentinelOne and others in Endpoint Protection Platform (EPP). Updated: May 2025.
852,098 professionals have used our research since 2012.