Try our new research platform with insights from 80,000+ expert users

Microsoft Defender for Endpoint vs VirusTotal comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 20, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Defender for Endp...
Ranking in Anti-Malware Tools
1st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
197
Ranking in other categories
Endpoint Protection Platform (EPP) (1st), Advanced Threat Protection (ATP) (4th), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (4th)
VirusTotal
Ranking in Anti-Malware Tools
3rd
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
11
Ranking in other categories
Threat Intelligence Platforms (3rd)
 

Mindshare comparison

As of July 2025, in the Anti-Malware Tools category, the mindshare of Microsoft Defender for Endpoint is 15.6%, down from 21.0% compared to the previous year. The mindshare of VirusTotal is 5.1%, down from 6.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools
 

Featured Reviews

John Rallo - PeerSpot reviewer
Offers excellent visibility into vulnerabilities and the attack surface itself
Attack surface reduction and limiting attack surface vectors are valuable features. It's helpful to isolate specific devices and get super granular with the features they offer. The visibility into the attack surface is good. It gets highly granular. I don't work on that side, but the people who do tell me they get more visibility.
Chinmay Banerjee - PeerSpot reviewer
Helps businesses collect threat data while keeping privacy in mind and apable of detecting, blocking, and removing viruses and malware
There are two gray areas I still need to explore. I have worked with VirusTotal because it easily integrates with over seventy antivirus scanners and blacklisting services. In addition to those there is much scope to improve and add other services or integrations. The areas for improvement are that VirusTotal is not using much AI or generative AI models, while other competitors are starting to build them. For example, VirusTotal's work is based on the setup done by their engineers. If you want to do scanning or protection activities for a specific site, app, or device, that is the area VirusTotal is currently focused on. But other competitors are building AI models that can do things like left-side scanning and provide auto-generated reports. VirusTotal has predefined reports, but there is a lot of manual effort involved. Secondly, the API is very limited if I want to integrate VirusTotal with other applications. They need to build more connectors and provide support for Webhook connectors for the API. If you can't build your own connector, it's always good to have provisions for Webhook setup connectors across platforms. Thirdly, Kaspersky, a competitor of VirusTotal, is using a methodology called "gatekeeper." A gatekeeper is a security system that protects the inside of a building from outside threats. This is the model Kaspersky is currently using. You have your website set up, but the entire army of VirusTotal or Kaspersky is standing guard, protecting you from the first gate itself. Right now, VirusTotal detects threats from your domain, but it is always better to verify inside the domain and protect it from the first level when people or malware are entering. This first level of protection is lacking in VirusTotal right now. The security bridge and protection gate are missing.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are that it is flexible, and it is integrated with Microsoft products."
"One feature I like the most is vulnerability management, which shows any vulnerable software or OS present in my environment. Microsoft Defender for Endpoint provides a complete overview and also recommends the steps to mitigate the vulnerabilities or threats. Most of the other antivirus or EDR solutions generally don't provide vulnerability management. It is an add-on that Microsoft Defender for Endpoint provides."
"The endpoint detection of threats is valuable. The initial detection of things like ransomware and viruses and being able to shut down machines immediately and stop a threat is valuable. We can stop a threat at a source versus allow it to propagate it across the network."
"The biggest benefit to Windows Defender is that it is built-in to the operating system by Microsoft."
"The most valuable feature of Microsoft Defender for Endpoint is that it is embedded into the Windows system. Additionally, the performance is good and simple to maintain."
"Defender for Endpoint is a robust solution that works well out-of-the-box."
"Its real-time security is the most valuable."
"Integration between Microsoft products is very easy."
"The most valuable feature is the worldwide malware information database."
"It gives detailed information about suspicious IPs, which is one of its most valuable features."
"VirusTotal provides 95% to 98% accurate information."
"It allows us to see if there have been previous reports on certain indicators of compromise, providing insights from other security professionals."
"VirusTotal provides 95% to 98% accurate information."
"It is quite simple for anyone if they just want to check some suspicious URLs."
"It can scan the dark web and find if an email ID has been compromised. This is another area that we have not explored yet."
"With VirusTotal, I can check for any hash, malware, file, domain, IP URL, or malicious URL, and Kaspersky stays clean."
 

Cons

"The product development team makes frequent changes that affect the stability of the solution."
"Sometimes, there are difficulties in downloading a file considered as malicious."
"More integration with different platforms is an area for improvement for this product, and should be included in its next release."
"Microsoft Defender for Endpoint could improve by adding more security features."
"Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."
"The product should reduce updates since it is hard to keep up."
"I would like MDE to have the ability to isolate a certain amount of time on the timeline."
"We'd like to see integrations with more vulnerability scanning solutions like Tenable."
"There is room for improvement, particularly in making some of the most useful features more accessible in the non-paid version."
"I would like to see improvements in the score consistency and accuracy."
"They can improve the telemetry. Whenever we handle a sample, they cannot provide any information about a victim."
"VirusTotal is hard to understand because you need to know Google Docs to create queries, and it doesn't have documentation for that."
"VirusTotal needs better advertisement and promotion, especially in the Middle East, since it is not yet widely recognized or popular in that region."
"They can improve the telemetry. Whenever we handle a sample, they cannot provide any information about a victim."
"I would like to see an improved user interface and some automation."
"I would like to see improved correlation with other threat intelligence sources, not just reliant on its own database, to enhance the database of threat intelligence that VirusTotal offers."
 

Pricing and Cost Advice

"When customers haven't deployed the solution and don't have licenses, it can be expensive to start from scratch."
"Its price is fair. It has approximately the same price as the other products such as Kaspersky. It is much cheaper than Malwarebytes."
"You do not need to pay any additional costs for antivirus and anti-malware solutions for endpoint protection."
"We pay a yearly license for Microsoft Defender. We also have a support contract with them."
"Everybody would like to see a lower price on everything. The Slovenian market is basically an SME market with clients having up to 100 seat licenses, comprising 90% of the company. They're very price sensitive. So, the price could be cheaper."
"The license cost is around $35 per machine, which is not expensive compared to other products."
"I pay for it through the Windows Professional or Standard license. It is a one-time cost for me, and I use the same license."
"It is built into Windows 10. If our clients are using Microsoft Defender, the cost goes away for them."
"The pricing is very economical."
"The pricing is reasonable."
"VirusTotal is an expensive solution."
"We are using VirusTotal with free licenses, managing the license limits across three or four accounts, thus incurring no costs."
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
861,524 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Educational Organization
10%
Financial Services Firm
8%
Government
8%
Computer Software Company
19%
Financial Services Firm
8%
Government
8%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior solution. Microsoft Defender for Endpoint is a cloud-delivered endpoint security s...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
What do you like most about VirusTotal?
With VirusTotal, I can check for any hash, malware, file, domain, IP URL, or malicious URL, and Kaspersky stays clean.
What is your experience regarding pricing and costs for VirusTotal?
I do not know about the pricing or licensing as our organization services VirusTotal for our clients.
What needs improvement with VirusTotal?
I would like to see improvements in the score consistency and accuracy. VirusTotal should add more details like those from competitors such as URL Void or Symantec URL Checker, which show the categ...
 

Also Known As

Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Petrofrac, Metro CSG, Christus Health
Information Not Available
Find out what your peers are saying about Microsoft Defender for Endpoint vs. VirusTotal and other solutions. Updated: June 2025.
861,524 professionals have used our research since 2012.