No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon vs OpenText EnCase eDiscovery comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
OpenText EnCase eDiscovery
Average Rating
7.8
Reviews Sentiment
7.7
Number of Reviews
8
Ranking in other categories
eDiscovery (8th)
 

Mindshare comparison

Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
eDiscovery Mindshare Distribution
ProductMindshare (%)
OpenText EnCase eDiscovery3.9%
kCura Relativity5.2%
Commvault Cloud4.7%
Other86.2%
eDiscovery
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
Alejandro Stromer - PeerSpot reviewer
Director Consulting SAP OpenText en Entelgy at DCL Consultores EIM SL
A stable and scalable hybrid solution with easy setup
The solution is scalable. It has three levels. You have the presentation area that can be escalated to the balance sheet. You have the back-end area that can be escalated using higher viability to configure more application servers. Also, the area of storage can be increased. We usually cater to enterprise solutions but have small- and medium-sized customers. It starts with 25 users and goes up to 100s and 1000s.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Stability is a primary factor, and then there's the ease of distribution and policy management; Cortex XDR by Palo Alto Networks is very easy to work with, and we're quite happy with them."
"The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
"The stability of this product is very good."
"Its interface and pricing are most valuable, and it is better than other vendors in terms of security."
"Being a cloud solution it is very flexible in serving internal and external connections and a broad range of devices."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"It detected stuff that other things wouldn't detect."
"Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because it gives us a lot of granularity on what goes on, what processes are being run, and what is actually being executed if anyone is trying to get onto our endpoints."
"My advice to others is this is a good solution that does not require a lot of attention."
"The EDR is amazing and ease of integration with Splunk is a big plus. Integration with BigQuery is also a plus for me and workflow creation is easy. Overall, CrowdStrike Falcon is a great product."
"Falcon has decreased the load on our analyst team because they don't have to manually contact the system owners to stop that particular event from happening as Falcon detects threats and quarantines the machines itself."
"Enables us to understand what processes are running on the system, what registry keys have been enabled."
"CrowdStrike has a much lower rate of false positives than Cylance and the dashboard makes it easier to use."
"It's given me a level of confidence that my network is secure — the fact that it's not finding anything; however, I am not experiencing the issues that competitors are saying I should be experiencing."
"The pay-as-you-go model enabled me to deploy quickly from the AWS Marketplace management account, scaled protection for workloads without upfront commitments, and reduced the initial operational overhead."
"It is a very useful tool; it is worth buying irrespective of price."
"Data Recovery: Its ability to repair damaged partitions and uncover hidden partitions from within the tool, and allow further analysis."
"It indexes much faster, and is more reflexive because of the Enscripts."
"It speeds up the process, so I can meet my deadlines."
"Image creation and image analysis in one program, basically for ease of use."
"The solution has been quite good, and, overall, the features we need are available to us."
"The most important feature we've found is the Enscripts, as it allows me to customize the scripts and deploy them as and how I need them, for example to segregate and index files efficiently."
"I like the processing feature on the product because it does everything at once, i.e, indexing, recovery, keyword searches, etc."
 

Cons

"The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
"It would be good to have a better way to search for a file within the UI."
"The tool needs to be improved in terms of integration and interface."
"I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."
"The GUI could be improved."
"I have run into some detection issues with Cortex XDR. It needs to be better at detection of internal attacks."
"Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
"It automatically detects security issues. It should be able to protect our network devices while operating autonomously."
"We'd like to see more integration capabilities."
"The KDR solution is immature. They do not have much preemption in ITDR. Threat prevention should be their first priority, and false positive reductions are needed."
"They respond quickly on the weekdays, but the weekend response times are slower."
"The technical support team often just replies to an issue with a link to an article rather than actually calling back and talking to someone and making sure the problem is solved. To me, that's kind of weak."
"Basically, they don't cover legacy OS or applications. That's the only issue we're concerned about."
"The installation process for this software needs to be simplified."
"I would also like to see the endpoint firewall component produce some level of logging and feedback."
"Not being able to complete the deployment in an efficient manner is one of the huge weaknesses."
"There were minor UI bugs."
"Ease of use and learning curve need improvement."
"​Sometimes the application can take more time to complete the image processing or fail at the end of the process.​"
"From a customer service standpoint, this is unacceptable."
"The reporting is a bit unreliable. It needs to be better."
"We have come across problems with the end-case. We could not find an email discovery type of module and there was not flexibility with the email."
"In the past, incident response time for tech support was slow."
"I would like to see a capability to ingest and absorb more data. That would be really good. It currently is lacking this function."
 

Pricing and Cost Advice

"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"Cortex XDR's pricing is ok."
"The pricing is a little high. It is per user per year."
"Very costly product."
"CrowdStrike Falcon's price is good."
"This solution has a very competitive price."
"As I'm part of the technical team, not the budgeting team, I don't have information on CrowdStrike Falcon pricing."
"The price is too high."
"Our company pays approximately US$ 65,000 annually for 900 machines."
"The price of CrowdStrike Falcon is reasonable."
"Crowdstrike Falcon is relatively cheap."
"The price of CrowdStrike Falcon is expensive and should be reduced."
"EnCase is an affordable solution."
"We have a license. And, we found the cost high. We contacted them and talked to them about the ratio of the US dollar versus the Indian rupee and then we came to a solution."
"We have a license. And, we found the cost high. We contacted them and talked to them about the ratio of the US dollar versus the Indian rupee and then we came to a solution."
"​The product is affordable and user-friendly.​"
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,630 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
10%
Manufacturing Company
9%
Outsourcing Company
9%
Computer Software Company
8%
Outsourcing Company
12%
Construction Company
9%
Performing Arts
8%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise3
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
Ask a question
Earn 20 points
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
EnCase eDiscovery
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Ontario Ministry of Government, Aerospace Company, Chesterfield Police Department
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
913,630 professionals have used our research since 2012.