No more typing reviews! Try our Samantha, our new voice AI agent.

Malwarebytes Teams vs Sophos Endpoint comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 19, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Malwarebytes Teams
Ranking in Endpoint Protection Platform (EPP)
23rd
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
37
Ranking in other categories
No ranking in other categories
Sophos Endpoint
Ranking in Endpoint Protection Platform (EPP)
25th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
64
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, up from 3.7% compared to the previous year. The mindshare of Malwarebytes Teams is 1.5%, down from 2.2% compared to the previous year. The mindshare of Sophos Endpoint is 1.4%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.8%
Malwarebytes Teams1.5%
Sophos Endpoint1.4%
Other93.3%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2594097 - PeerSpot reviewer
Chief Executive Officer at a wholesaler/distributor with 11-50 employees
Exceptional malware protection with regular updates and behavior-based detection
There are no built-in backups or integrated backup options, which could be an opportunity. The free version is effective, however, the paid version is pricey compared to it. Other customers have mentioned issues with false positives. It lacks enterprise-level management and more enterprise functionality. CrowdStrike and SentinelOne are much more enterprise-grade solutions. Malwarebytes has limited integration with cybersecurity tools and lacks enterprise integrations because it is not an enterprise product.
Ashutosh Jha - PeerSpot reviewer
Project engineer at IT Solution india private limited
Endpoint protection has strengthened malware defense and simplifies web and peripheral control
I would give Sophos Endpoint a rating of nine out of ten because it is working very well. I have cut one point because it has no solution for on-premises. Additionally, it has no solution for any Linux-based system endpoints. I have to install the server protection on Linux machines, which is why I am cutting one point for Sophos Endpoint. Sophos Endpoint should include the Linux endpoint agent and should provide a solution for Linux endpoints as well, because the server license is costly and nobody wants to use the server license on an endpoint machine. Sophos Endpoint should have a Linux endpoint independent agent as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
"The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
"The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind."
"We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for."
"We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool."
"If you are looking for security, mainly for advanced threat prevention from ransomware and malware attacks, I would recommend Cortex."
"The product is very good, it has caught a lot of exploits that most products would not."
"Cortex XDR alerts us on the dashboard when there's a threat, which allows us to restrict that user and helps secure our infrastructure."
"It is intuitive and easy to use. For the most part, it does a good job of catching things. It is good at stopping stuff. I did a couple of tests with a password cracker. I tried to load that on, and Malwarebytes didn't let me do that, which was pretty good. It has a rollback feature that I haven't seen with any other company. If one of your endpoints are hit with mass ransomware, you could actually roll it back. I watched a demo of them do that, and it was pretty sweet."
"The protection is really good with Malwarebytes. It's also user friendly and quite easy to set up."
"The dashboard actually is good and it is simple."
"It comprehensively finds and removes malicious software."
"It enhanced our performance in our company."
"I like the solution's ability to detect potentially unwanted programs. For some reason, it seems superior to other solutions, or at least in comparison to McAfee."
"The solution was successfully deployed and so far has been able to stop all ransomware attacks, which has been extremely beneficial to the organization."
"The endpoint protection and response that allows us to restore a machine back to a pre-infected state are the most valuable features."
"Fast response time and protection are great; these are the main advantages."
"The most valuable feature is endpoint detection and response."
"Really I could give it a nine because I can recommend the product as an excellent solution."
"The most valuable feature is the central administration and management."
"Intercept X is the most valuable feature in the solution. It's more or less pretty standard. The endpoint feature allows you to basically see what is happening, and stop a wide range of threats. It's been the most unique identifier for Sophos."
"Sophos EPP Suite has the capability to stop infections from spreading around the internal network even after the problems have infiltrated it."
"Provides good control and can implement policies and on-the-web control."
"The solution is very stable, with no significant bugs or glitches, and it doesn't crash or freeze."
 

Cons

"The connection to the internet has not performed as expected."
"Being able to filter the events to see those that are related to the actual alert would save time spent by the engineer."
"Cortex XDR by Palo Alto Networks could improve by offering remote management. It would be useful to look at the client's issue to fix it."
"In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
"On the pricing aspect, Cortex XDR by Palo Alto Networks needs to have a more reasonable rate, particularly for customers in Sri Lanka and Asian countries."
"It would be good to have a better way to search for a file within the UI."
"I would like to see some additional features related to email protection included."
"The solution should force customers to integrate with network traffic to see the full benefits of XDR."
"They could come up with better reporting capabilities."
"I'd like to see increased efficiency in terms of detecting false positives because we sometimes have cases where detections are repeated despite requests for them to be identified as false positives."
"It's not covering everything as we just started in EDR. In Malwarebytes, there's no response. The response is very limited, and integration is very limited."
"Notifications are lacking."
"It would be better if updates could be downloaded, and deployed, on-premises to avoid low bandwidth causing issues."
"My clients have frequently encountered some tech support scams where when you go to a particular website, it throws up a fake warning to you and states that you need to call this number."
"The product's stability needs improvement."
"I would like to see integration with other vendors going forward."
"The encryption features are not as good as McAfee's."
"The only drawback is that it requires a little more system configuration."
"If you are not an IT expert, the solution is difficult to use."
"Sophos is lacking in the granularity of optimization, so having more control would be better."
"Scalability is a bit limited. There are times you are supposed to open up the APIs for other vendors or developers to plug in their product information; however, currently, Sophos integrates well only with its own products."
"The product's filtering and stability can be better."
"This signature-based malware prevention method is a little out of date."
"The resource usage of the agent should be less intensive on the CPU and RAM."
 

Pricing and Cost Advice

"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"I don't have any issues with the pricing. We are satisfied with the price."
"The cost depends on your chosen license type, like Pro or other licenses."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"It is "expensive" and flexible."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"On a scale of one to ten, where one is a low price and ten is a high price, I rate the product's pricing a seven."
"The price of Malwarebytes is in the middle range compared to other vendors."
"The licensing is per seat, with clients being a little less expensive than servers. If we need more licenses, we can accomplish that within a day. As Malwarebytes adds new features to their product, such as DNS filtering and a patching module, they want to charge us more even though we're a premium user, which isn't ideal."
"Yearly, it is around $50 per client."
"It is really expensive. We've got between 30 and 40 licenses every year, and for the number of licenses that we have, we're finding that Malwarebytes on average costs between $900 and $1,000 more per year than comparable options. We're paying about $3,300 per year for these licenses. There are no additional costs beyond the standard licensing fee."
"Malwarebytes is a cost-effective product."
"We expect to pay $1,000 USD a month, depending on the number of users."
"Its licensing is annual. There are no additional costs beyond the standard licensing fee."
"It may be possible to negotiate licensing cost based on volume."
"A yearly subscription has to be purchased or made towards the licensing cost of the solution. The solution is an affordable or an economical one for corporate houses."
"The platform is expensive but worth it."
"We are on an annual license to use the solution."
"I rate the price of Sophos EPP Suite a four out of five."
"There is an annual license to use the solution."
"The solution for an enterprise license costs around 13 million Philippine pesos."
"Willing to discount when you are switching from another product. Upgrading services will end up costing more, as expected."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Comms Service Provider
12%
Financial Services Firm
10%
Construction Company
8%
Manufacturing Company
8%
Outsourcing Company
14%
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise8
Large Enterprise6
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise8
Large Enterprise14
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Malwarebytes?
I really hate the automatic rebilling without officially confirming it with me. It's an annoyance and they should at ...
What needs improvement with Malwarebytes?
It takes up too much space when it's trying to run in the background.
What is your primary use case for Malwarebytes?
My primary use case is that it's protecting me against malware.
What is your experience regarding pricing and costs for Sophos EPP Suite?
The setup cost is good and licensing is good. The pricing is slightly increased, but it is good because Sophos Endpoi...
What needs improvement with Sophos EPP Suite?
For endpoint protection, I do not see many weaknesses. The weakest point from Sophos is that in many cases, it is not...
What is your primary use case for Sophos EPP Suite?
I am conducting an information search to understand what other firewall solutions are doing rather than looking for a...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
EPP Suite
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Knutson Construction
EK Services
Find out what your peers are saying about Malwarebytes Teams vs. Sophos Endpoint and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.