Try our new research platform with insights from 80,000+ expert users

Bitdefender Sandbox Analyzer vs Microsoft Defender for Endpoint comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Bitdefender Sandbox Analyzer
Ranking in Advanced Threat Protection (ATP)
27th
Average Rating
9.0
Reviews Sentiment
7.4
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Microsoft Defender for Endp...
Ranking in Advanced Threat Protection (ATP)
2nd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
192
Ranking in other categories
Endpoint Protection Platform (EPP) (1st), Anti-Malware Tools (1st), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (5th)
 

Mindshare comparison

As of April 2025, in the Advanced Threat Protection (ATP) category, the mindshare of Bitdefender Sandbox Analyzer is 0.9%, down from 2.0% compared to the previous year. The mindshare of Microsoft Defender for Endpoint is 9.1%, down from 11.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Advanced Threat Protection (ATP)
 

Featured Reviews

Basawaraj  Vastrad - PeerSpot reviewer
Automated and manual threat analysis provides deep insights for potential threat remediation
The most valuable features of Bitdefender Sandbox Analyzer ( /products/bitdefender-sandbox-analyzer-reviews ) include manual and auto-submission. The sandbox analyzer provides a combination of technologies including machine learning-based technologies. Network analytics is performed, and the tool analyzes using threat feeds. Manual and automated submissions allow suspicious files or URLs to be analyzed thoroughly, providing deep insights for further investigation. This information is crucial for making informed decisions on remediating potential threats.
AnuragSrivastava - PeerSpot reviewer
Provides detailed visibility into threats but the ability to add exceptions needs improvement
One major item for improvement is the ability to add exceptions. We can add some exceptions, but not at the level we need to. The second major area for improvement involves enhanced capabilities for different operating systems or platforms. That is, even though we have coverage for different operating systems or platforms such as Linux, we don't get all of the controls and enhanced capabilities that are available with Windows devices. Reporting could also be improved because, at present, we get limited results at times. For example, in an environment with more than 100,000 devices, you may just get 10,000 results when you run a report.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like the fact that it works pretty well. It can be a little aggressive at times, but I'd rather have it be a little bit aggressive than not catch what it's supposed to catch. We've been running that platform for about five years, and we've not really had any viruses or malware get through. It's also easy to set up, and it's easy to manage."
"Bitdefender has shown fantastic stability over the past eight years with no major incidents reported."
"Sandbox Analyzer is easy to use. It's simple to drill down into the data. In a lot of the competing products, an extremely informed end-user can do battle with the tools provided, but in today's market, end-users have less and less time to try and keep up. The CSAW alerts come out every day, and they're huge. Adobe did a master patch last Thursday and another one a few days later."
"The solution is useful in the event of a gray file or grayware, as there are certain files users may download of which we know little about."
"It is easy to use, and there is a lot of automation. So, users don't need to worry about that."
"Microsoft Defender can block some viruses or malware. So, it can protect my files. It can save files on Office 365 OneDrive. I use encryption for some files, then I can recover them from OneDrive."
"It's a Microsoft product; it's easier to deploy this product than other options."
"It is already integrated with Windows 10, so you don't need to worry about that."
"Defender is stable. The performance is good."
"Defender is integrated into the operating system. It's integrated with everything. You don't have to spend time analyzing what you have to do to be sure that the integration is okay between the security tool and all the other apps. This, from my point of view, is the main advantage."
"There are a couple of features, such as isolating the devices or connecting the device and connecting live response."
"It is a straightforward setup."
"The most valuable aspect is information, specifically the automatic investigation of packages."
 

Cons

"We would like to see the time it takes for the sandbox to analyze a file reduced from its ten or fifteen minute duration to five."
"It does everything we need. We haven't been able to throw anything at it that it couldn't handle."
"One area that needs improvement in Bitdefender Sandbox Analyzer is the addition of an asset management feature."
"We propose the on-premises solution to most of our customers, for which we must provide a license, although no such request accompanies customers who want a cloud-based solution."
"It would be better if there were real-time alerts. The whole suite, unlike most anti-virus consoles that just ping you when there's an infection or something, for some inexplicable reason, Bitdefender doesn't do that. The most you could do is get an hourly email, or maybe if there's an outbreak that affects 30% of our machines, it sends me an email. There's no real-time alert to say, "Hey, so-and-so literally 30 seconds ago just had this happen on their machine." Real-time reporting would be a huge improvement. All in all, it's a pretty nice product, generally speaking. They do a pretty good job. They can pretty much go toe to toe with just about anybody. But it's that kind of real-time nature. I've not had occasion to use the EDR portion to actually try and do any kind of custom scripting to drill into things that are going on at the endpoints. But my understanding from reading comments of others is that it's not particularly flexible in that regard to be able to do things like that."
"It should be more secure. There should be more protection, especially for non-signature-based malware. It works fine for non-signature-based malware, but I expect it to become a bit more advanced to be able to cope with future or upcoming environments."
"The initial setup can be a bit complex."
"The system can always be simplified and have a better integration check. More detailed reports would be good. When it does the integrated check, it just shows if the system is okay but I want to know what happened."
"I have accounts for administrators and corporate employees, but I also have accounts for students. I can't split these types of accounts. I need a separate configuration for both... I need to research how I can get alerts for only the administrative machines."
"The automation could be simpler on the mitigation side. It has a learning curve. Otherwise, it's pretty easy."
"The end-user also cannot do some advanced actions on it. It's a little bit complicated for our end-user, so it needs to be simplified."
"I would like to see integrations with other products, such as Spunk and other CM solutions. That would create possibilities for me, and for a SOC, to consolidate all events in an older console, not one provided by Microsoft but provided by a third party, and use it to create more insights."
"The pricing could be a bit better."
"The product itself does not necessarily need improvement, but the support and implementation of the product are the disaster cases."
 

Pricing and Cost Advice

"You need a license to a certain extent. You need to pay for advanced features. For corporate accounts, it isn't is really a problem, but pricing is an important thing for many companies."
"I think it's probably less expensive than something like CrowdStrike. We got a really good deal because it was literally their year-end, and they were trying to close all the sales for the week. So we bought a three-year contract from them. It roughly ended up costing me somewhere around $17 for an endpoint per year. It was really quite a nice pricing. I've talked to other folks where they got CrowdStrike, and it's like $60 for an endpoint for a year. It does, and they can be pretty aggressive if you're dealing with them directly, and I have. So no complaints there."
"I do not have to purchase antivirus solutions anymore because Microsoft Defender for Endpoint is integrated into Windows and comes free."
"Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs."
"There is no license needed, the solution comes with Microsoft Windows."
"The cost is high, compared to other products in the market, if you look at it as a separate product. If you look at the cost where it is part of a bundle, the cost is okay."
"For me, the pricing is very good, but for management it's very expensive. Other solutions are less expensive. But when I present all the information and all the reports they say, "Well, it's expensive, but the cost-benefit is very good.""
"Its price at the moment is very good because you get a lot of value for your money, especially with the subscriptions. If you have the E1, E3, or E5 enterprise subscription, you pay per month per user, and you get almost an infinite number of solutions. If you compare the price to the number of solutions that you get, it is a very good deal."
"The price is fair for the features Microsoft delivers. If you want tailor-made features, you have to mix different licenses. It isn't straightforward."
"You just pay Windows 10 prices, then you have antivirus software. As a price comparison, Defender's costs are very low."
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
846,617 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
10%
University
9%
Healthcare Company
7%
Educational Organization
27%
Computer Software Company
11%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior solution. Microsoft Defender for Endpoint is a cloud-delivered endpoint security s...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Archdiocese, Northstar, SeSa, W&W Informatik, Yamaha Motor Europe
Petrofrac, Metro CSG, Christus Health
Find out what your peers are saying about Bitdefender Sandbox Analyzer vs. Microsoft Defender for Endpoint and other solutions. Updated: March 2025.
846,617 professionals have used our research since 2012.