Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon vs Microsoft Defender External Attack Surface Management comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon
Ranking in Attack Surface Management (ASM)
1st
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
123
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Endpoint Protection Platform (EPP) (3rd), Identity Management (IM) (6th), Threat Intelligence Platforms (2nd), Endpoint Detection and Response (EDR) (1st), Active Directory Management (2nd), Extended Detection and Response (XDR) (1st), Ransomware Protection (1st), Identity Threat Detection and Response (ITDR) (3rd), AI-Powered Cybersecurity Platforms (1st)
Microsoft Defender External...
Ranking in Attack Surface Management (ASM)
10th
Average Rating
8.0
Reviews Sentiment
5.7
Number of Reviews
1
Ranking in other categories
Microsoft Security Suite (28th)
 

Mindshare comparison

As of February 2025, in the Attack Surface Management (ASM) category, the mindshare of CrowdStrike Falcon is 21.6%, down from 30.4% compared to the previous year. The mindshare of Microsoft Defender External Attack Surface Management is 2.7%, down from 3.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Attack Surface Management (ASM)
 

Featured Reviews

Chintan-Vyas - PeerSpot reviewer
Easy to set up with good behavior-based analysis but needs a single-click recovery option
Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files. The product could be more accurate in terms of performance. We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.
SF
Better at protecting from cyberattacks and haven't had any problems with the scalability of this solution
With Microsoft, support is always crazy, it's not easy to get support. That's their weakness. They need to improve their support. Microsoft will always give good support to their big customers or partners, but we're not a big company. If you had a thousand employees and were a big customer, maybe they'd offer better support. But in my 35 years of IT experience, it's always been the same with Microsoft. They transfer us to Europe because we speak French, but when we want to speak in English, they transfer us to people who don't know the product. Most of the time, we find a solution before they call us back.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ability to remote into other devices for investigation and the way it presents a graphical representation of the detection, like the parent-child process, are valuable features."
"I like the vulnerability assessment and proactive hunting features of CrowdStrike Falcon."
"It has definitely minimized resources. When everything was on-prem, there was a lot more work maintaining it. One of the big value tickets: I don't have lists of hundreds of exceptions for certain applications that I have to maintain, add, delete, and move. The very nature of the product has lessened my workload considerably."
"Among CrowdStrike Falcon's most valuable capabilities are its UEBA and SOAR functionalities, along with its seamless integration with any other SIEM solution."
"I value the overall behavior analysis of CrowdStrike. The engine of this product is what drew us to this solution."
"The most valuable features of CrowdStrike Falcon are the AI in detecting and real-time detections."
"The most valuable feature is its threat analysis."
"The EDR is amazing and ease of integration with Splunk is a big plus. Integration with BigQuery is also a plus for me and workflow creation is easy. Overall, CrowdStrike Falcon is a great product."
"It seems to be better at protecting from cyberattacks."
 

Cons

"I would like to see the machine learning feature enhanced."
"In the future release of CrowdStrike Falcon, they should add a sandbox feature."
"I've found that CrowdStrike's technical support could benefit from increased technical expertise."
"Unfortunately, native applications are not supported."
"The technical support team often just replies to an issue with a link to an article rather than actually calling back and talking to someone and making sure the problem is solved. To me, that's kind of weak."
"Forensic controls have room for improvement."
"The current database schema presents challenges and has potential for improvement."
"The management of the solution could improve."
"With Microsoft, support is always crazy, it's not easy to get support."
 

Pricing and Cost Advice

"Crowdstrike Falcon is relatively cheap."
"We bought a very small number of licenses, then ran it for a year. We bought a 100 licenses for a year, so we didn't actually do a proof of concept. We just bought them. Then, the next year, we bought 10,000 licenses."
"CrowdStrike Falcon offers excellent value for the money for our organization, particularly given our lean IT team."
"The cost of CrowdStrike Falcon in Latin America seems high relative to the economic conditions in the region."
"While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours."
"CrowdStrike is well priced. On a yearly basis, it costs between $60 and $100 per user."
"Years ago, when we bought CrowdStrike, you got everything it had. I was a little concerned when they broke this out into a la carte modules where you can buy EDR, Spotlight, etc., picking and choosing off the menu. I was a little worried that the solution would get watered down. However, I realized in my previous organization when we had the full suite that there were a bunch of features in it that we didn't have time to operationalize. So, I warmed up to it. I get the whole, "Look, you can pick and choose. Okay, everybody buys a steak, but do you want mashed potatoes, or do you want lobster mac and cheese?" So, you can pick the sides that you want, so you can buy the solution that you want and operationalize versus paying a lot of money and getting a bunch of things, but not using 60 percent of the tools in the box."
"There are three to four licensing models available to choose from for CrowdStrike Falcon. The price of CrowdStrike Falcon depends on the distributor and the reseller partner. The price we received was good."
Information not available
report
Use our free recommendation engine to learn which Attack Surface Management (ASM) solutions are best for your needs.
832,138 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Computer Software Company
20%
Financial Services Firm
13%
Retailer
6%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
What is your experience regarding pricing and costs for Microsoft Defender External Attack Surface Management?
I don't see a big difference in pricing compared to its competitors. With "intelligent" or "smart" antivirus, people are willing to pay a little more for something that could make a difference for ...
What needs improvement with Microsoft Defender External Attack Surface Management?
With Microsoft, support is always crazy, it's not easy to get support. That's their weakness. They need to improve their support. Microsoft will always give good support to their big customers or p...
What is your primary use case for Microsoft Defender External Attack Surface Management?
The kind of companies using it typically have one hundred or more users and are in various sectors, like manufacturing and insurance. We use it to protect against cyberattacks.
 

Also Known As

CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
No data available
 

Overview

Find out what your peers are saying about CrowdStrike, Trend Micro, Darktrace and others in Attack Surface Management (ASM). Updated: January 2025.
832,138 professionals have used our research since 2012.