These three sit at completely different points on the security tooling spectrum: one is the enterprise EDR name every CISO already knows, one is a free open-source SIEM a homelab admin can run tonight, and one is somewhere in between, a commercial security platform built on an open-source core. The pricing opacity of two of the three is itself worth understanding before comparing features.
CrowdStrike Falcon: the enterprise default, priced behind a sales call
CrowdStrike sells Falcon in named tiers, Falcon Go for small business, Falcon Pro, Falcon Enterprise, and Falcon Elite for the largest deployments, but none of them carry a published per-endpoint price on CrowdStrike's own site. Every real number comes from a sales conversation, and it varies by endpoint count, contract length, and which modules (threat intelligence, identity protection, cloud security) get bundled in. This isn't unusual for enterprise security software, but it's a real friction point for anyone trying to budget without first sitting through a sales cycle.
What CrowdStrike sells beyond the uncertainty is genuine market leadership. Falcon's single lightweight agent architecture avoids the performance hit of older signature-based antivirus stacked with a separate EDR tool, and its threat intelligence, built from visibility across a massive customer base, feeds detection models that smaller vendors can't easily replicate. It's the name that shows up in cyber insurance questionnaires and compliance audits as a default-safe choice, which carries real weight for companies that need to justify security spend to a board or an insurer.
The honest tradeoff, beyond the pricing opacity, is cost at scale. Reddit and Hacker News threads from security practitioners consistently describe CrowdStrike as excellent but expensive once an organization gets into the thousands of endpoints, and switching away from it later is its own project given how deeply Falcon integrates into incident response workflows once it's the system of record.
Wazuh: the free option that's genuinely capable, not a toy
Wazuh is completely free and open source, no license cost, no per-endpoint fee, ever. It self-hosts as a SIEM and XDR platform: log analysis, file integrity monitoring, vulnerability detection, and security configuration assessment, all included in the base install. The only real cost is infrastructure and the engineering time to run it, which for a lean security team is a genuine tradeoff worth taking seriously rather than dismissing as "you get what you pay for."
The catch is that free doesn't mean effortless. Wazuh requires real operational investment to deploy and tune correctly, rule sets need customization to cut down false positives, and there's no vendor support line to call when something breaks at 2 AM, only community forums and whatever in-house expertise exists. Detection quality depends heavily on how well the deployment is configured, which is a meaningfully different risk profile than paying CrowdStrike for a tuned, supported product out of the box.
For a security team with the skills to run it, Wazuh is a legitimate SIEM, not a downgrade dressed up as one. For a team without dedicated security engineering time, the free license can end up costing more in incident response after a missed detection than a supported commercial product would have.
Elastic Security: open-core, consumption-priced, sits in between
Elastic Security is built on the same Elastic Stack that powers Elastic's search and observability products, and its pricing follows Elastic's usual model: consumption-based billing through Elastic Cloud rather than a simple flat per-endpoint fee, with a free and open tier covering core SIEM functionality for teams willing to self-manage the infrastructure. That free tier is a real, meaningful option, not a crippled trial, but the paid tiers that unlock advanced detection rules, machine learning-based anomaly detection, and managed cloud hosting bill based on data volume and resource consumption, which makes predicting a monthly number harder than a straightforward per-seat SaaS tool.
The strength here is flexibility: an organization already running Elastic for logging or observability gets security functionality layered onto infrastructure it already operates, without standing up a separate platform. Elastic's detection rule library is actively maintained and the query language (the same one used across the whole Elastic ecosystem) is genuinely powerful for security analysts comfortable writing their own detections.
The tradeoff is that consumption-based pricing means costs can grow with data volume in ways that are harder to predict upfront than CrowdStrike's per-endpoint model or Wazuh's flat "free" cost, and getting real value out of Elastic Security requires more hands-on configuration than a fully managed EDR product, closer to Wazuh's operational demands than to CrowdStrike's out-of-box experience.
Why none of these three publish a clean price you can compare
This is worth stating plainly rather than working around: unlike most SaaS categories on this site, security platforms at this tier resist simple price comparison by design. CrowdStrike and Elastic both gate real numbers behind sales conversations or consumption estimates that depend on an organization's specific data volume and endpoint count. Wazuh is the only one of the three with a genuinely simple answer, zero dollars, license-wise, because it's fully open source. Anyone evaluating these three should expect to request real quotes from CrowdStrike and model expected Elastic Cloud consumption before committing, rather than trusting any published "starting at" number from a reseller or comparison site, including this one, as the actual price they'll pay.
Where each one actually fits
CrowdStrike fits organizations that need a supported, industry-standard EDR with minimal in-house security engineering overhead, and where the budget exists to pay for that convenience and market credibility, particularly where cyber insurance or compliance requirements effectively make "an EDR vendor with a strong reputation" part of the actual requirement.
Wazuh fits organizations with real security engineering capacity that want full control over their detection stack and see the free license as freeing up budget for headcount instead of software, government, education, and cost-conscious startups with technical security teams are the recurring profile in community discussions.
Elastic Security fits organizations already invested in the Elastic ecosystem for logging or observability, where adding security functionality onto existing infrastructure is more efficient than standing up a separate CrowdStrike deployment, and where the team is comfortable with consumption-based cost modeling rather than a flat per-seat number.
What third-party pricing estimates get wrong
Search around and it's easy to find blog posts and reseller pages quoting a specific CrowdStrike Falcon "starting price" per endpoint per month. Treat those numbers skeptically. They're typically either outdated snapshots from a specific deal size and term length, or estimates from a reseller trying to look competitive, not CrowdStrike's actual published rate card, because no such public rate card exists. The same caution applies to any third-party estimate of Elastic Cloud costs for a security workload: actual spend depends on log volume, retention period, and which detection features are enabled, and a generic "typical customer pays X" figure rarely matches what a specific organization's data volume will actually cost. The only reliable numbers come from CrowdStrike's own sales team for Falcon, or from running Elastic's own cloud pricing calculator against a realistic estimate of actual data volume.
The honest bottom line
Comparing these three on price alone doesn't really work, because two of them don't publish one and the third is free by design. The real decision is about operational capacity and existing infrastructure: pay CrowdStrike for a supported, best-in-class product if the budget and the lack of in-house security engineering time both point that way, run Wazuh if the team has the skills and wants to own the whole stack for the cost of infrastructure, or extend Elastic Security if the organization is already running Elastic for something else and can absorb the consumption-based cost model.