Try our new research platform with insights from 80,000+ expert users

Intercept X Endpoint vs Wazuh comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Intercept X Endpoint
Ranking in Extended Detection and Response (XDR)
11th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
103
Ranking in other categories
Endpoint Protection Platform (EPP) (6th), Endpoint Detection and Response (EDR) (7th), ZTNA (9th), Managed Detection and Response (MDR) (8th), Ransomware Protection (3rd)
Wazuh
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
45
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (2nd)
 

Mindshare comparison

As of January 2025, in the Extended Detection and Response (XDR) category, the mindshare of Intercept X Endpoint is 2.0%, down from 5.1% compared to the previous year. The mindshare of Wazuh is 11.8%, up from 4.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR)
 

Featured Reviews

Khandokar Rabbi - PeerSpot reviewer
Used for endpoint security, ransomware protection, virus protection, and server security
Intercept X Endpoint is deployed on the cloud in our organization. Previously, we had two ransomware attacks when we were using Kaspersky as an endpoint security. We didn't face any ransomware attacks after using Intercept X Endpoint for endpoint security. Intercept X Endpoint has simplified our malware detection. Since we have already implemented the policies in the cloud, all the malware is automatically detected. The solution also detects and removes new malware that can also come from the cloud AI engine. Integrating Intercept X Endpoint with our current security infrastructure was very easy. In my opinion, Sophos is a better solution because we are using Sophos endpoint security and network security. These two things sync with each other and monitor the packets and network traffic. No other vendor has simultaneous devices to check everything. I would recommend the solution to other users. Overall, I rate the solution an eight out of ten.
Sandip_Patel - PeerSpot reviewer
Evaluating robust file monitoring with insights for community support improvements
Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs. These aspects are vital as they provide alerts for changes and facilitate the monitoring of compliance. The platform is also relatively easy to set up and operate. Reports are straightforward to extract and prove useful for compliance requirements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The Managed Detection and Response service provided by Intercept X Endpoint is highly valuable. With a team of 600-700 individuals monitoring systems, they swiftly respond to attacks, either informing us to isolate or directly removing threats. This full MDR service is especially recommended for sectors like finance, where data security is critical. The deep learning technology within Intercept X Endpoint enhances our security posture by analyzing behaviors and algorithms to differentiate between legitimate users and threats, effectively preventing attacks on our network infrastructure."
"It is a practically maintenance free intelligent system that independently protects environments from malicious attacks."
"We have found the pricing to be reasonable."
"The product efficiently prevents data leakages."
"The most valuable features are ease of use and the GUI."
"The solution protects us."
"The most valuable features are the cloud administration and the strength of the ransomware protection."
"The most valuable feature of Sophos Intercept X is a web filtering and URL sanity checks. Overall the solution is well balanced with all its features."
"Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors."
"One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability."
"Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs."
"Wazuh's logging features integrate seamlessly with AWS cloud-native services. There are also Wazuh agent configurations for different use cases, like vulnerability scanning, host-based intrusion detection, and file integrity monitoring."
"Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms."
"It is a stable solution."
"It offers built-in modules for file integrity and vulnerability management."
"It allows you to aggregate all your logs in one place and provides a unified view to monitor your security environment."
 

Cons

"I would inquire why it is not sold directly to end users."
"This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it."
"The tool should be made compatible with Linux and Microsoft operating systems."
"We've had difficulty with uninstalling the solution. When we try to uninstall an old version of the basic Sophos Antivirus, it doesn't seem to uninstall completely."
"I have not done it, but integrating it with authenticating the users on the Windows system looks a bit complicated to me. It could be because I don't understand it."
"I recommend that Intercept X Endpoint should include a patch assessment feature. Various vendors offer virtual patching solutions, which could be a game-changer, especially for the financial sector where frequent service restarts are challenging. These solutions allow patching servers without the need for restarts. Incorporating these features into Intercept X Endpoint would enhance its effectiveness in securing endpoints and servers."
"They should keep doing what they're doing. Both of them have entered the EDR/MDR space, and they're keeping up with their competitors. I have a hard time understanding why their capabilities aren't garnering more attention."
"If we can lower the price, it will be fantastic because it will generate more revenue for us."
"Scalability is a constraint in the on-prem version of Wazuh in terms of the volume of logs we can manage."
"I have yet to find the same capability in Wazuh to get logs from different sources into the system"
"The tool does not provide CTI to monitor darknet."
"Wazuh currently fails to provide its users with AI and ML."
"The product's configuration part and lack of AI capabilities are some of the major concerns associated with Wazuh."
"The tool doesn't detect anomalies or new environments."
"The biggest part that's missing is threat intelligence. It isn't inbuilt, and if a sudden incident occurs, we don't get that feedback inside the SIEM tool. That's a big gap, I see. It would be better if we could get the threat intelligence feeds integrated with the SIEM tools. That would help us push value solutions to the clients in a big way."
"They need to go towards integrating with more cloud applications and not just OS like Windows and Linux."
 

Pricing and Cost Advice

"You are able to purchase more licenses for the number of devices or servers that you require. There are many other features available but our license does not include them, such as XDR, which is endpoint detection and response. We have not explored the new features as of yet but plan to in the coming future."
"It is not very expensive but I don't have specific pricing details. The licensing is usually done on yearly basis."
"I have found the price of Sophos Intercept X to be reasonable."
"As I am not responsible for paying the bills I cannot comment on the pricing."
"One can pay for the license annually, or at two and five year intervals."
"The price of this solution is a little high compared to competitors because they do not have a proper pricing structure."
"Licensing is based on the number of users. They give a discount for editors who are considered as important members. From what I know, Sophos products are not expensive. If you have a license extension, you just need to contact the editor or partner to change the mode of licensing or extend the license to cover more people."
"We were able to eliminate the ransomware using the one-month, full-featured trial license."
"There is not a license required for Wazuh."
"Wazuh is free and open source."
"The solution's pricing is very competitive."
"Wazuh is an open-source tool, which means it is freely available for use."
"Wazuh is not an expensive solution."
"It is a cost-effective solution."
"My client uses the open-source version of Wazuh."
"Wazuh is a good tool, but the open-source version has scalability limitations."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
20%
Manufacturing Company
6%
Financial Services Firm
6%
Government
6%
Computer Software Company
16%
Comms Service Provider
7%
University
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Crodwstrike Falcon compare with Sophos Intercept X?
I like that Crowdstrike Falcon allows me to easily correlate data between my firewalls. Its detection and machine learning are very valuable features. Crowdstrike Falcon also successfully prevents ...
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I am investigating more about the community support for Wazuh. I can't provide a definitive answer yet. An issue I noticed is with tag values in certain rules not functioning properly. It's unclear...
What is your primary use case for Wazuh?
I am currently evaluating and using Wazuh for file monitoring and compliance reporting. We are in the process of conducting a POC to understand how the rules work. I lead this effort to explore and...
 

Also Known As

Sophos Intercept X
No data available
 

Learn More

 

Overview

 

Sample Customers

Flexible Systems
Information Not Available
Find out what your peers are saying about Intercept X Endpoint vs. Wazuh and other solutions. Updated: December 2024.
831,158 professionals have used our research since 2012.