Try our new research platform with insights from 80,000+ expert users

Microsoft Defender Threat Intelligence vs VirusTotal comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Defender Threat I...
Ranking in Threat Intelligence Platforms
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
31
Ranking in other categories
Advanced Threat Protection (ATP) (11th), Microsoft Security Suite (18th)
VirusTotal
Ranking in Threat Intelligence Platforms
3rd
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
11
Ranking in other categories
Anti-Malware Tools (3rd)
 

Mindshare comparison

As of February 2025, in the Threat Intelligence Platforms category, the mindshare of Microsoft Defender Threat Intelligence is 2.4%, up from 2.0% compared to the previous year. The mindshare of VirusTotal is 4.1%, up from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Intelligence Platforms
 

Featured Reviews

Nim Nadarajah - PeerSpot reviewer
A native Microsoft solution the provides great ROI and continuously improves its offering
We have Microsoft bias. We generally don't have any significant negative feedback or improvement points around Defender, EDR and CMDR platforms. It does a good job across the board. The price point is something they can improve slightly for those who don't have an M 365 E5. I believe it's a $2.80 cents add-on. In Canadian, that's expensive. If they can drop it to a dollar, for those who don't have M 365 E5, they're going to open up market share and increase affordability for an entire market segment in the medium business category. Other than that, we have no major negative feedback.
Chinmay Banerjee - PeerSpot reviewer
Helps businesses collect threat data while keeping privacy in mind and apable of detecting, blocking, and removing viruses and malware
There are two gray areas I still need to explore. I have worked with VirusTotal because it easily integrates with over seventy antivirus scanners and blacklisting services. In addition to those there is much scope to improve and add other services or integrations. The areas for improvement are that VirusTotal is not using much AI or generative AI models, while other competitors are starting to build them. For example, VirusTotal's work is based on the setup done by their engineers. If you want to do scanning or protection activities for a specific site, app, or device, that is the area VirusTotal is currently focused on. But other competitors are building AI models that can do things like left-side scanning and provide auto-generated reports. VirusTotal has predefined reports, but there is a lot of manual effort involved. Secondly, the API is very limited if I want to integrate VirusTotal with other applications. They need to build more connectors and provide support for Webhook connectors for the API. If you can't build your own connector, it's always good to have provisions for Webhook setup connectors across platforms. Thirdly, Kaspersky, a competitor of VirusTotal, is using a methodology called "gatekeeper." A gatekeeper is a security system that protects the inside of a building from outside threats. This is the model Kaspersky is currently using. You have your website set up, but the entire army of VirusTotal or Kaspersky is standing guard, protecting you from the first gate itself. Right now, VirusTotal detects threats from your domain, but it is always better to verify inside the domain and protect it from the first level when people or malware are entering. This first level of protection is lacking in VirusTotal right now. The security bridge and protection gate are missing.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Offers easy integration with a cloud-based infrastructure"
"The tool can proactively detect potential incidents."
"The most valuable aspects are its integration capabilities with other Microsoft products like Intune, Office 365, and Azure cloud applications."
"The product's anti-spam and malware-scanning features are useful. We scan email attachments, documents, and malicious codes."
"It is very scalable. There are approximately 2,000 endpoints and up to 200 servers in our company."
"Microsoft Defender Threat Intelligence assesses machines for vulnerabilities and gives remediations."
"The product’s most valuable feature is the ability to provide threat detection and protection simultaneously."
"The solution is well integrated with other Microsoft security products."
"VirusTotal provides 95% to 98% accurate information."
"It provides detailed insights into possible malicious behavior, dropped files, and TCP connections."
"It allows us to see if there have been previous reports on certain indicators of compromise, providing insights from other security professionals."
"The feature I like the most is the ability to see the MD5 or SHA-256 signature of the file, and also the composition of the file according to its segments."
"With VirusTotal, I can check for any hash, malware, file, domain, IP URL, or malicious URL, and Kaspersky stays clean."
"VirusTotal provides 95% to 98% accurate information."
"The most valuable feature is the worldwide malware information database."
"It gives detailed information about suspicious IPs, which is one of its most valuable features."
 

Cons

"Having up-to-date documentation and real-time reflections in all portals would be beneficial to keep users informed about any changes. Additionally, the frequent changes in Microsoft's UI and the movement of features between different products in the set pose difficulties."
"Microsoft Defender Threat Intelligence is evolving and needs to fix and enhance numerous issues like stability and licensing. The continuous rebranding and licensing changes are confusing."
"A stable licensing model is absent"
"We encounter problems connecting the product deployed on the user endpoints with the servers."
"It's a bit complicated to manage because you have many dependencies of servers, many dependencies in queue, and so on. Entries or different endpoints, and you make different configuration topics for each one. So that's a major problem."
"One area that can be improved is reducing false positives."
"Some of the customization features could be improved by providing a portion of it as open source."
"Technical support could be a bit better."
"I would like to see improvements in the score consistency and accuracy."
"I would like to see an improved user interface and some automation."
"I would like to see improvements in the score consistency and accuracy."
"They can improve the telemetry. Whenever we handle a sample, they cannot provide any information about a victim."
"VirusTotal is hard to understand because you need to know Google Docs to create queries, and it doesn't have documentation for that."
"The platform could improve in the areas of endpoints and networks."
"VirusTotal needs better advertisement and promotion, especially in the Middle East, since it is not yet widely recognized or popular in that region."
"VirusTotal has predefined reports, but there is a lot of manual effort involved."
 

Pricing and Cost Advice

"The product’s pricing is worth it."
"The product is a part of my Microsoft 365 subscription, so there is no additional cost. It is cost-effective."
"I rate the product's price a six or seven on a scale of one to ten, where one is expensive, and ten is cheap."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a six or seven out of ten."
"The solution's pricing is reasonable and not very expensive."
"Considering Microsoft is constantly changing licensing, I would give it a seven out of ten. It can be difficult to get your head around it, especially for small to medium-sized enterprises (SMEs)."
"I use the product's default version, which is a free one and not the licensed version."
"It is an expensive product."
"VirusTotal is an expensive solution."
"The pricing is very economical."
"The pricing is reasonable."
"We are using VirusTotal with free licenses, managing the license limits across three or four accounts, thus incurring no costs."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms solutions are best for your needs.
832,138 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
11%
Educational Organization
11%
Government
9%
Computer Software Company
16%
Financial Services Firm
10%
Government
10%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Microsoft Defender Threat Intelligence?
It just runs in the background. I don't have to worry about, making sure it's Intelligence. So, you know, this kind of makes it very easy, have to worry about installing. It is easy to use.
What needs improvement with Microsoft Defender Threat Intelligence?
There are weaknesses, and Microsoft is working on addressing them. Over the past three to four years, the ATP and other components have improved significantly, and the integration has also advanced...
What is your primary use case for Microsoft Defender Threat Intelligence?
The product helps us monitor business devices for authentication and response on all endpoints, servers, passwords, and plans.
What do you like most about VirusTotal?
With VirusTotal, I can check for any hash, malware, file, domain, IP URL, or malicious URL, and Kaspersky stays clean.
What is your experience regarding pricing and costs for VirusTotal?
I do not know about the pricing or licensing as our organization services VirusTotal for our clients.
What needs improvement with VirusTotal?
I would like to see improvements in the score consistency and accuracy. VirusTotal should add more details like those from competitors such as URL Void or Symantec URL Checker, which show the categ...
 

Overview

Find out what your peers are saying about Microsoft Defender Threat Intelligence vs. VirusTotal and other solutions. Updated: January 2025.
832,138 professionals have used our research since 2012.