Falcon Sandbox is used to quarantine files, scan them, and ensure there are no malicious threats or IOCs related to these files. It provides threat feed to the CrowdStrike endpoint, assisting in detection and response. It is used in the client's environment, where Mahmoud's team implements and supports the product.
CTSO at a tech services company with 11-50 employees
Enhanced threat detection through automated malware analysis and proactive threat feeds
Pros and Cons
- "The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint."
- "The product needs integration with SOAR products to add more integration points, which is important for various clients."
What is our primary use case?
How has it helped my organization?
It benefits a lot by ensuring every file is clean, significantly reducing the attack surface for the organization. It automates file analysis, reducing manual work and improving security incident response times.
What is most valuable?
The most valuable features include malware detection, threat rating related to files, studying the metadata of the files, and providing threat feeds to the endpoint.
What needs improvement?
The product needs integration with SOAR products to add more integration points, which is important for various clients. Additionally, integrating behavior detection alongside IOCs and threat detection would enhance the product.
Buyer's Guide
Anti-Malware Tools
December 2025
Find out what your peers are saying about CrowdStrike, ANY.RUN, Hatching International and others in Anti-Malware Tools. Updated: December 2025.
879,768 professionals have used our research since 2012.
For how long have I used the solution?
The solution has been used since the launch of the product, which is almost four years now.
What do I think about the stability of the solution?
The stability of Falcon Sandbox is rated at eight out of ten.
What do I think about the scalability of the solution?
The scalability of the solution is rated at nine out of ten.
How are customer service and support?
CrowdStrike customer service is very good, especially if you have tiered support like the world tier. They provide timely responses and informative support without delays.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy, and it usually takes one day for full integration, including ensuring Threat Intelligence is delivering the right IOCs.
What about the implementation team?
The implementation was handled by our team which included five engineers. One engineer is typically enough to deploy the product.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike is generally considered a bit expensive compared to other vendors. Falcon Sandbox is one of the modules of CrowdStrike, and the overall product's pricing is rated seven out of ten.
What other advice do I have?
Mahmoud recommends CrowdStrike Sandbox as it is one of the best products on the market. However, additional modules are required for effective integration and usage. I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Anti-Malware Tools Report and find out what your peers are saying about CrowdStrike, ANY.RUN, Hatching International, and more!
Updated: December 2025
Product Categories
Anti-Malware ToolsPopular Comparisons
Microsoft Defender for Endpoint
Microsoft Exchange Online Protection (EOP)
Check Point Harmony SASE (formerly Perimeter 81)
VirusTotal
CyberArk Endpoint Privilege Manager
F-Secure Total
Deep Instinct Prevention Platform
AVG Internet Security Business Edition
Cuckoo Sandbox
Quick Heal Total Security
OPSWAT Filescan Sandbox
Hatching Triage
TotalAV Antivirus Pro
Buyer's Guide
Download our free Anti-Malware Tools Report and find out what your peers are saying about CrowdStrike, ANY.RUN, Hatching International, and more!
Quick Links
Learn More: Questions:
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Do we need to use both EDR and Antivirus (AV) solutions for better protection of IT assets?
- Looking for alternatives to Symantec Cloud Protection Engine
- Who provides a better antivirus solution: Bitdefender or Sophos?
- Which antivirus is best for isolated work PCs?
- How do you identify malware?
- Why are Anti-Malware Tools important for companies?
- When evaluating Anti-Malware Tools, what aspect do you think is the most important to look for?
- When evaluating Antimalware Tools, what aspect do you think is the most important to look for?
















