No more typing reviews! Try our Samantha, our new voice AI agent.

Malwarebytes Teams vs ThreatLocker Zero Trust Platform comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 17, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Malwarebytes Teams
Ranking in Endpoint Protection Platform (EPP)
24th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
37
Ranking in other categories
No ranking in other categories
ThreatLocker Zero Trust Pla...
Ranking in Endpoint Protection Platform (EPP)
5th
Average Rating
9.2
Reviews Sentiment
7.1
Number of Reviews
82
Ranking in other categories
Network Access Control (NAC) (3rd), Advanced Threat Protection (ATP) (5th), Application Control (1st), ZTNA as a Service (5th), ZTNA (6th), Ransomware Protection (1st)
 

Mindshare comparison

As of September 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, up from 3.8% compared to the previous year. The mindshare of Malwarebytes Teams is 1.6%, down from 2.2% compared to the previous year. The mindshare of ThreatLocker Zero Trust Platform is 1.3%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.8%
ThreatLocker Zero Trust Platform1.3%
Malwarebytes Teams1.6%
Other93.3%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2594097 - PeerSpot reviewer
Chief Executive Officer at a wholesaler/distributor with 11-50 employees
Exceptional malware protection with regular updates and behavior-based detection
There are no built-in backups or integrated backup options, which could be an opportunity. The free version is effective, however, the paid version is pricey compared to it. Other customers have mentioned issues with false positives. It lacks enterprise-level management and more enterprise functionality. CrowdStrike and SentinelOne are much more enterprise-grade solutions. Malwarebytes has limited integration with cybersecurity tools and lacks enterprise integrations because it is not an enterprise product.
Santo Joy - PeerSpot reviewer
Head Of Cyber Security at a outsourcing company with 201-500 employees
Security controls have been strengthened with granular application, ringfencing, and access policies
The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most are the Ringfencing, elevation control, storage control, and application whitelisting functionality. For examples of how these features benefit my company, we were looking for a solution across various vendors to actually implement application whitelisting controls. ThreatLocker's agent, which is very lightweight and does not use much CPU or RAM, helped us achieve that solution. Ringfencing was an add-on that ticked off a lot of Australian framework security controls, which is the reason we chose it. My impression of the allowlisting feature in terms of managing which software, scripts, and libraries run on my devices is that ThreatLocker's community page has a lot of information around this, which is very helpful. Not only that, the Cyber Hero support that ThreatLocker provides gives us insights and best practices, helping us achieve that solution and guiding us to the right platform. The impact of Ringfencing on controlling the behavior of approved applications has been a big winner for us because it is something that many other platforms do not provide as a functionality. Having that allowed us to identify what applications talk to each other, which is something that many other platforms do not do. The network control feature impacts my ability to manage network traffic across my endpoints and servers. We have not used this widely across all our partners, but wherever required, we use it. It has been an easy solution for those customers to get that control implemented. The elevation feature's role in facilitating just-in-time administrative access for approved applications shows that elevation control helps in many use cases involving remote control platforms, door usage, and security system platforms that require local admins. There are many solutions that provide this functionality, but the licensing cost seems to be expensive, and it also adds another solution into the mix. Rather than doing that, we try to use ThreatLocker Zero Trust Endpoint Protection Platform to achieve that control. Regarding the storage control feature, I have used it. The primary function is USB blocking, which is very widely adopted, and also just locking down and allowing certain users to access certain file locations helps us there. When it comes to enforcing policy-driven access over various storage devices, it depends on the business risk adapted by the companies that we support, but generally the use case is USB and external storage devices where companies know that is a risk, but they do not have appropriate solutions. There are EDR platforms that claim to do this, but ThreatLocker Zero Trust Endpoint Protection Platform does it at an advanced level. My assessment of the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites leads me to think that Web Control is another functionality within ThreatLocker Zero Trust Endpoint Protection Platform that is an add-on on top of the current set. That is another solution that we use based on what is required for the company, but again, that is not widely adapted yet for our partners.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"WildFire AI is the best option for this product."
"The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."
"Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most."
"Cortex XDR by Palo Alto Networks has helped us a lot with securing the whole environment and the whole IT structure, giving us full knowledge of what is happening on the client and enabling us to take action right away from a single point for managing security operations on the hosts."
"Cortex XDR's most valuable feature is its intelligence-based dashboards."
"We use Cortex XDR by Palo Alto Networks for its ability to detect based on behavior rather than simple virus scan to prevent malicious activities."
"The solution doesn't need a high level of technical training."
"The most valuable features of Malwarebytes are the EDR and the complete feature set provided."
"This solution helps us by providing central management of anti-malware and anti-exploit functionality."
"The solution was successfully deployed and so far has been able to stop all ransomware attacks, which has been extremely beneficial to the organization."
"The most valuable features of the solution are malware scanning and malware removal."
"Ten times a day, improved signatures will be downloaded, so it is very up-to-date in terms of malware experience."
"For a company with about 100 or more PC units, the solution is quite effective, makes monitoring easy, offers a lot of reporting, and provides protection for many applications including Windows and Zoom."
"The dashboard actually is good and it is simple."
"The product keeps our company safe."
"Essentially, ThreatLocker Zero Trust Endpoint Protection Platform is super easy to use, very informative, and it does everything quickly and easily."
"The sandbox functionality is fantastic."
"We are seeing a return on investment, especially with our managers and customers."
"For companies that are considering ThreatLocker Zero Trust Endpoint Protection Platform, my advice would be to go for it, as it truly changes how you secure your clients and offers more opportunities to provide services to clients that were not feasible before."
"ThreatLocker Zero Trust Endpoint Protection Platform has helped our company save on operational costs and expenses significantly."
"The application management on any workstation with the solution is valuable. I find it valuable that it indicates whether the software is part of our pre-approved list, adding a nice layer of protection. It works great because people cannot just install or download any app from the web."
"The pre-built policies and the fact that I get notified when a user requests an application are significant."
"The biggest positive impact ThreatLocker Zero Trust Platform has had on my organization is improved security."
 

Cons

"We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do."
"It automatically detects security issues. It should be able to protect our network devices while operating autonomously."
"The downside to the solution is that there are a large number of false positives."
"Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats."
"The server sometimes stops continuously to check things so it would be helpful to receive access updates or technical reasons."
"The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part."
"If Palo Alto reduces the pricing slightly for their products, it would make them more scalable in markets such as India and globally for cybersecurity."
"For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible."
"Strictly in terms of cyber security, the release cycle should be quarterly, at most. It shouldn't be more frequent than that because, for one thing, keeping up with tech support is difficult."
"Its price can also be improved. It is really expensive."
"In my opinion, it's not very scalable, at least the way we use it at this point in time."
"They can include advanced scanning and improve reporting. I scan malware on the pen drive. Some more reports need to be added for that. It should also provide better protection because we have a new version of the malware."
"This solution reports far too many false positives!"
"It is one of the worst products which I have ever used."
"Malwarebytes should improve its mobile compatibility."
"I would like to see integration with other vendors going forward."
"While ThreatLocker Zero Trust Platform is a strong zero trust platform, especially for application allowance and least privileges, areas for improvement include policy management, reporting dashboards, user experience, and notifications."
"The Cyber Hero certification exam could use a bit of love, but overall, I have been very satisfied with the platform."
"It is a little frustrating on my end since I like to go as quickly as I possibly can, and it slows me down."
"I have encountered some problems with stability, however, they are resolved quickly."
"The only improvement I would suggest for ThreatLocker Zero Trust Endpoint Protection Platform is the ability to stop automatic processes when pushing out updates or applying new policies to your computers."
"It has not reduced helpdesk tickets. It has probably increased them by blocking applications and doing its job, resulting in people raising more tickets to know why they cannot use certain things."
"It has not helped reduce our help desk tickets. We are still in learning mode, and after we are fully knowledgeable, we will be able to see some ticket reductions."
"ThreatLocker could offer more flexible training, like online or offline classes after hours. The fact that they even provide weekly training makes it seem silly to suggest, but some people can't do it during the day, so they want to train after work. They could also start a podcast about issues they see frequently and what requires attention. A podcast would be helpful to keep us all apprised about what's going on and/or offline training for those people who can't train during the week."
 

Pricing and Cost Advice

"This is an expensive solution."
"The tool's price is moderate."
"Its pricing is kind of in line with its competitors and everybody else out there."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"The price of the solution is high for the license and in general."
"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"We expect to pay $1,000 USD a month, depending on the number of users."
"Yearly, it is around $50 per client."
"It is really expensive. We've got between 30 and 40 licenses every year, and for the number of licenses that we have, we're finding that Malwarebytes on average costs between $900 and $1,000 more per year than comparable options. We're paying about $3,300 per year for these licenses. There are no additional costs beyond the standard licensing fee."
"The cost may be something in the ballpark of $20-25 a year per computer."
"The price of Malwarebytes is in the middle range compared to other vendors."
"I rate the tool's pricing a five out of ten."
"I would say that it's affordable. It costs much less than Sentinel One, CrowdStrike, or anything of that nature. But, at the same time, you are getting what you pay for. So I would say it's one of the best when you're comparing traditional NextGen AVs like Webroot that aren't the best in the bunch."
"Malwarebytes is a cost-effective product."
"The pricing works fine for me. It's very reasonably priced."
"We have not had any real issues with the pricing. As they have added more features, due to the way our contracts are structured with our customers, we have had to hold off on adopting the new features because they do add costs."
"I do not deal with pricing, but I assume it is cost-effective for us. We choose a solution based on functionality and affordability."
"Although the pricing seems good, there have been inconsistencies in contract negotiations."
"The pricing is fair and there is no hard sell."
"The price of ThreatLocker Allowlisting is reasonable in the market, but it is not fantastic."
"Others say ThreatLocker is too expensive, and I tell them they're dreaming. It's well-priced for what it does."
"I believe ThreatLocker's pricing model is fair and flexible, allowing account managers to offer customized deals based on our specific needs."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
912,818 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
9%
Comms Service Provider
12%
Financial Services Firm
10%
Construction Company
8%
Outsourcing Company
7%
Manufacturing Company
11%
Financial Services Firm
11%
Computer Software Company
11%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise8
Large Enterprise6
By reviewers
Company SizeCount
Small Business56
Midsize Enterprise14
Large Enterprise13
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Malwarebytes?
I really hate the automatic rebilling without officially confirming it with me. It's an annoyance and they should at ...
What needs improvement with Malwarebytes?
It takes up too much space when it's trying to run in the background.
What is your primary use case for Malwarebytes?
My primary use case is that it's protecting me against malware.
What is your experience regarding pricing and costs for ThreatLocker Allowlisting?
I am not sure about operational or cost expenses because we have not really experienced that.
What needs improvement with ThreatLocker Allowlisting?
When it comes to ThreatLocker Zero Trust Platform's policy making, it is very granular, but the moment you zoom out, ...
What is your primary use case for ThreatLocker Allowlisting?
ThreatLocker Zero Trust Platform's main use case for us was data storage access control.We used ThreatLocker Zero Tru...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Protect, Allowlisting, Network Control, Ringfencing
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Knutson Construction
Information Not Available
Find out what your peers are saying about Malwarebytes Teams vs. ThreatLocker Zero Trust Platform and other solutions. Updated: September 2026.
912,818 professionals have used our research since 2012.