Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon Cloud Security vs SonarQube comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

CrowdStrike Falcon Cloud Se...
Ranking in Application Security Tools
13th
Average Rating
8.2
Number of Reviews
20
Ranking in other categories
Container Security (9th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), Cloud-Native Application Protection Platforms (CNAPP) (7th), Cloud Infrastructure Entitlement Management (CIEM) (4th), Application Security Posture Management (ASPM) (3rd)
SonarQube
Ranking in Application Security Tools
1st
Average Rating
8.0
Number of Reviews
113
Ranking in other categories
Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
 

Featured Reviews

Ravikant Kaware - PeerSpot reviewer
Jan 30, 2024
Boasts a wide range of features while remaining exceptionally lightweight and improves our security posture
The CrowdStrike platform boasts a wide range of features while remaining exceptionally lightweight. Compared to traditional antivirus software, its impact on system resources is minimal. In terms of specific figures, CPU utilization typically ranges from one to two percent, while memory usage falls between 12 and 15 MB. This translates to a very small footprint on our system. CrowdStrike utilizes signatureless technology, eliminating the need for regular signature updates on endpoint systems. It provides protection based on processes and activity behavior observed on the endpoint. The platform collects raw telemetry data from the endpoint and leverages it to proactively offer prevention and EDR capabilities. This approach offers multiple benefits, including eliminating the need for manual scans and providing broader protection against both known and unknown threats.
Wang Dayong - PeerSpot reviewer
May 10, 2023
Easy to integrate and has a plug-in that supports both C and C++ languages
We use the product to review our software codes. We have integrated the product to review our new delivery code When we deliver a code, the solution scans the code and reports whether the code has bugs or any other vulnerability issues. Thus the solution helps us identify issues and improve the…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Falcon Cloud Security is its comprehensive threat-hunting ability."
"CrowdStrike utilizes signatureless technology, eliminating the need for regular signature updates on endpoint systems."
"The solution has login features like multi factor authentication."
"The RTR feature stands out as particularly valuable to me due to its capability to log into machines."
"The most valuable feature of CrowdStrike Falcon Cloud Security is its lightweight sensor, taking minimal space and not impacting server performance."
"The initial setup is easy ."
"The scalability of the product has been great."
"The immediate mitigation of potential threats and instant alerts are valuable."
"SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications."
"This solution is simple to use and can be quickly deployed."
"I like that it helps us maintain our work quality and code security."
"One of the most valuable features of SonarQube is its ability to detect code quality during development. There are rules that define various technologies—Java, C#, Python, everything—and these rules declare the coding standards and code quality. With SonarQube, everything is detectable during the time of development and continuous integration, which is an advantage. SonarQube also has a Quality Gate, where the code should reach 85%. Below that, the code cannot be promoted to a further environment, it should be in a development environment only. So the checks are there, and SonarQube will provide that increase. It also provides suggestions on how the code can be fixed and methods of going about this, without allowing hackers to exploit the code. Another valuable feature is that it is tightly integrated with third-party tools. For example, we can see the SonarQube metrics in Bitbucket, the code repository. Once I raise the full request, the developer, team lead, or even the delivery lead can see the code quality metrics of the deliverable so that they can make a decision. SonarQube will also cover all of the top OWASP vulnerabilities, however it doesn't have penetration testing or hacker testing. We use other tools, like Checkmarx, to do penetration testing from the outside."
"Improve the code coverage and evaluates the technical steps and percentage of code being resolved."
"When comparing other static code analysis tools, SonarQube has fewer false-positive issues being reported. They have a lot of support for different tech stacks. It covers the entire developer community which includes Salesforce or it could be the regular Java.net project. It has actually sufficed all the needs in one tool for static code analysis."
"The solution has a plug-in that supports both C and C++ languages."
"SonarQube is scalable. My company has 50 users."
 

Cons

"The tool could give us more templates so that people who are not updated with the platform can easily get acquainted with how to secure and utilize the product more."
"There were some integration issues with this product."
"The only suggestion for improvement would be the pricing."
"I would not say the tool's integration capabilities were straightforward because the complexity depends on the volume of the data."
"The only challenge lies in token verification."
"It would be more convenient if there was an easier way to install CrowdStrike, perhaps through better integration with Active Directory."
"The tool is expensive."
"Incorporating threat intelligence into the system would be a valuable addition."
"The product's pricing could be lower."
"The implementation of the solution is straightforward. However, we did have some initial initialization issues at the of the projects. I don't think it was SonarQube's fault. It was the way it was implemented in our organization because it's mainly integrated with many software, such as Jira, Confluence, and Butler."
"In terms of analysis and findings, other tools provide more in-depth insights and detailed steps to mitigate or handle issues."
"Monitoring is a feature that can be improved in the next version."
"The product must improve security analysis."
"I would like to see improvements in defining the quality sets of rules and the quality to ensure code with low-performance does not end up in production."
"A better design of the interface and add some new rules."
"There needs to be a shareable reporting piece or something we can click and generate easily."
 

Pricing and Cost Advice

"CrowdStrike Falcon Cloud Security is pricy."
"CrowdStrike Falcon is very expensive."
"The pricing is reasonable, neither overly expensive nor excessively cheap, making it competitive compared to other market options."
"It's an expensive package but does what it says it will do."
"CrowdStrike Falcon Cloud Security is very expensive for us. Last month, we had a big issue that took much time and money to resolve. It slowed down our business and required our management team to get involved. We had a problem similar to the "Blue Screen of Death" issue many US companies faced. This incident used up many of our IT resources in just a few months. That's why we're looking for a replacement tool now."
"I am not the one who handled the pricing. A different team worked on it, but it is pretty expensive."
"The price is not too high, it is okay."
"The pricing is fair for what you get. I'd rate them a solid nine out of ten in terms of pricing."
"We are using the Developer Edition and the cost is based on the amount of code that is being processed."
"The licence is standard open source licensing"
"The product’s price is lower than Veracode’s price."
"For the Community edition, there is no extra cost. It's totally free. The Enterprise edition, Data Center edition, and Developer edition are the paid versions."
"It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."
"There are many different packages with different pricing options available. We are able to try what we have and if we need extra features we can upgrade the license."
"I am satisfied with the pricing."
"The costs for this application, for the kind of job it does, are pretty decent."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
801,634 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
16%
Manufacturing Company
9%
Insurance Company
6%
Financial Services Firm
17%
Computer Software Company
15%
Manufacturing Company
13%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about CrowdStrike Falcon Cloud Security?
It's easy to gather insights and conduct analysis about existing threats.
What is your experience regarding pricing and costs for CrowdStrike Falcon Cloud Security?
It's an expensive product. The solution costs around $60 for a single user on a yearly basis. I would rate the pricing a four out of ten.
What needs improvement with CrowdStrike Falcon Cloud Security?
I am not part of the current monitoring team, so I do not know how they feel about the tool. I am sharing information related to the tool based on the feedback and on my experience deploying it fou...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
 

Also Known As

CrowdStrike Falcon ASPM
Sonar
 

Learn More

 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Information Not Available
Find out what your peers are saying about CrowdStrike Falcon Cloud Security vs. SonarQube and other solutions. Updated: September 2024.
801,634 professionals have used our research since 2012.