IBM Security QRadar EDR vs. Sophos Intercept X

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
IBM Security QRadar EDR
Score 7.5 out of 10
N/A
IBM Security QRadar EDR (formerly ReaQta) combines automation and dashboards to minimize analyst workloads, detect anomalous endpoint behavior and remediate threats in near real time. With visibility across endpoints, it combines expected features, like MITRE ATT&CK mapping and attack visualizations, with dual-engine AI and automation. For teams that need extended support, managed detection and response (MDR) services offers 24/7 monitoring and response to help keep users…N/A
Sophos Intercept X
Score 8.9 out of 10
N/A
Sophos Endpoint Protection (Sophos EPP) with Intercept X is an endpoint security product providing an antivirus / antimalware solution that when upgraded with Intercept X or Intercept X Advanced provides advanced threat detection and EDR capabilities.
$28
per year per user
Pricing
IBM Security QRadar EDRSophos Intercept X
Editions & Modules
No answers on this topic
Intercept X Advanced
$28
per year per user
Intercept X Advanced with XDR
$48
per year per user
Sophos Managed Threat Response
$79
per year per user
Offerings
Pricing Offerings
IBM Security QRadar EDRSophos Intercept X
Free Trial
YesNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeOptionalNo setup fee
Additional DetailsPricing is for a 3-year commitment. Government and Education pricing available.
More Pricing Information
Community Pulse
IBM Security QRadar EDRSophos Intercept X
Features
IBM Security QRadar EDRSophos Intercept X
Endpoint Security
Comparison of Endpoint Security features of Product A and Product B
IBM Security QRadar EDR
7.9
Ratings
8% below category average
Sophos Intercept X
8.9
Ratings
4% above category average
Anti-Exploit Technology8.00 Ratings7.10 Ratings
Endpoint Detection and Response (EDR)8.30 Ratings9.00 Ratings
Centralized Management7.90 Ratings10.00 Ratings
Hybrid Deployment Support7.30 Ratings8.00 Ratings
Infection Remediation7.90 Ratings10.00 Ratings
Malware Detection7.90 Ratings10.00 Ratings
Vulnerability Management00 Ratings8.40 Ratings
Best Alternatives
IBM Security QRadar EDRSophos Intercept X
Small Businesses
ThreatLocker
ThreatLocker
Score 9.5 out of 10
ThreatLocker
ThreatLocker
Score 9.5 out of 10
Medium-sized Companies
BlackBerry Protect (CylancePROTECT)
BlackBerry Protect (CylancePROTECT)
Score 9.1 out of 10
BlackBerry Protect (CylancePROTECT)
BlackBerry Protect (CylancePROTECT)
Score 9.1 out of 10
Enterprises
BeyondTrust Endpoint Privilege Management
BeyondTrust Endpoint Privilege Management
Score 9.8 out of 10
BeyondTrust Endpoint Privilege Management
BeyondTrust Endpoint Privilege Management
Score 9.8 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
IBM Security QRadar EDRSophos Intercept X
Likelihood to Recommend
8.2
(0 ratings)
9.0
(0 ratings)
Likelihood to Renew
-
(0 ratings)
10.0
(0 ratings)
Usability
-
(0 ratings)
9.0
(0 ratings)
Support Rating
-
(0 ratings)
8.1
(0 ratings)
Implementation Rating
-
(0 ratings)
9.0
(0 ratings)
User Testimonials
IBM Security QRadar EDRSophos Intercept X
Likelihood to Recommend
IBM Security QRadaar EDR provides all the security features at one place with a reasonable price. Though for smaller organizations, the price may be quite high. Plus since it can detect threats and malwares in real time, every business should try them out.
Read full review
Sophos Intercept-X is well suited for any environment big or small. There is even a home version that is free that I highly recommend for anyone at home. If you are looking for endpoint protection that is centrally managed, catches everything, and has many features this is the product for you.
Read full review
Pros
  • Uses advanced analytics to detect threats and malwares and vulnerabilities in real time.
  • Intuitive interface so everyone can use it.
  • Easy to implement and set it up.
Read full review
  • Sophos is a little too good at DLP. But it is indeed very good at not allowing our data to leave our endpoints without strict adherence to policy.
  • Sophos is very good at protecting endpoints against viruses and other malware.
  • Sopho is really good at informing us of what is happening on our endpoints. OOTB reporting is way better than expected.
Read full review
Cons
  • use AI to review previous false negatives that contributed wrongly in the AI suggestion on the follow alerts
  • easily run a script based on values from an hash, ips, path inside the boxes on the behavioral tree
  • apply the remediation to a range of endpoint instead to only the endpoint of the current alert
  • use ajax for example to update the alert page automatically while actions are happening
  • for api have profiles that allow only get actions, or just post on some actions
  • create users in bulk
Read full review
  • The migration from on-prem sophos to cloud sophos, could have been a little more seamless
  • Would love to get more insight on what was blocked or flagged and what it was trying to do
  • Better and more granular feature management from group policies
Read full review
Likelihood to Renew
No answers on this topic
We have gotten a great product for the price. Easy to maintain and set up on new devices. Support is great and easy to work with and understand.
Read full review
Usability
No answers on this topic
The usability has never been a problem. Sophos Intercept X is a program you can install and let protect your company without much intervention. Apart from a few policies, Sophos will keep you protected better than most any product on the market. Sophos Intercept X works quite well when you are looking to "tighten your grip" on user's access to websites, programs, and add-ons.
Read full review
Support Rating
No answers on this topic
Most of the support reps are fantastic. There have been a few though that have had to be escalated via Account Manager when they haven't followed up but this is a rare instance, and often followed up by the Support Manager for APAC.
Read full review
Implementation Rating
No answers on this topic
Best thing was the help pushing out via group policy and was able to get instructions for that on sophos site
Read full review
Alternatives Considered
Bitdefender GravityZone combines multiple security services into a single platform to reduce the cost of building a trusted environment for endpoints. bit the IBM provides a vast support and always there to guide when in need With the majority of our users working in hybrid mode we needed a strong security control that could provide top-class protection with the minimum amount of False Positives (and, of course, of True Positives).
Read full review
I don't feel it's fair to compare Sophos Intercept X with the versions of Symantec and AVG that I have used in the past - as that was such a long time ago. I'm sure those other companies have released far more features than I used all those years ago
Read full review
Return on Investment
  • NOCs and SOCs heavily use IBM Security QRadar EDR and IBM Security QRadar EDR reduced labor costs to identify endpoint security threats and the treat remediation
  • IBM Security QRadar EDR offers a consistent approach to endpoint threat identification and resolution, reduces enterprise security operations support costs
  • In general, IBM Security QRadar EDR enhances enterprise security posture
Read full review
  • Before we had Intercept X, we had several infections of ransomware. Since that time it has stopped at least 10 attempts, saving us thousands of man-hours and hundreds of thousands of dollars.
  • By decreasing the time needed for malware remediation, it has saved us the cost of .25 FTE in the IT department.
  • Initial setup was cumbersome and cost us .1 FTE in additional costs the first year.
Read full review
ScreenShots

IBM Security QRadar EDR Screenshots

Screenshot of Behavioral tree: 
A behavioral tree provides full alert and attack visibility.Screenshot of Behavioral tree storyline: 
A visual storyline is automatically created as an attack unfolds, including mapping to MITRE ATT&CK, for full visibility.Screenshot of Cyber Assistant alerts: 
The Cyber Assistant, an AI-powered alert management system, can autonomously handle alerts, reducing analysts’ workloads.Screenshot of Cyber Assistant recommends:
The Cyber Assistant learns from analyst decisions, then retains the intellectual capital and learned behaviors to make recommendations and help reduce false positives.Screenshot of Custom detection strategies: 
Detection Strategy (DeStra) scripting allows users to build custom detection strategies — beyond preconfigured models — to address compliance or company-specific requirements without the need to reboot the endpoint.

Sophos Intercept X Screenshots

Screenshot of Screenshot of Screenshot of