Transform your AWS security operations with Falcon Next-Gen SIEM. Stop threats fast with unified visibility across AWS security tools and your security ecosystem. Prioritize the alerts that matter most and streamline investigations with automation and AI. Meet key compliance requirements with prebuilt dashboards and log retention. Get started in minutes with automated onboarding and flexible, pay-as-you-go consumption billing.
Get started today with up to $500 in usage credits during your 30-day free trial. Trial ends when credits are consumed or at the end of the 30-day period, whichever comes first. After your trial ends, you will be automatically enrolled in CrowdStrike Pay-as-you-go and billed monthly as part of your AWS invoice using the payment method associated with your AWS account. You will pay only for what you use and can cancel anytime.
Falcon Next-Gen SIEM delivers rapid threat detection, investigation, and response for AWS environments. It unifies AWS telemetry with data from endpoints, identities, and other security tools to eliminate silos, reduce noise so SOC teams can find and stop threats quickly. Designed for frictionless activation on AWS, Falcon Next-Gen SIEM provides immediate visibility and rapid time-to-value without complex setup.
With automated onboarding and built-in detections for AWS services including GuardDuty, Security Hub, and CloudTrail, security teams can get up and running in minutes. Security analysts can investigate and respond to threats in real time, while AI and automation streamline triage and reduce alert fatigue. Powered by CrowdStrike frontline adversary intelligence, Falcon Next-Gen SIEM surfaces adversary activity involving stolen credentials, AWS key abuse, privilege escalation, and lateral movement to accelerate detection and response. Prebuilt compliance dashboards and centralized log retention also help teams meet key regulatory requirements with less manual effort.
Key benefits:
Transform AWS Security Operations:
Quickly identify threats like stolen AWS keys, unauthorized access, privilege escalation, and unusual traffic by unifying data from key AWS services and your security tools.
Accelerate detection and response:
Reduce MTTD and MTTR with AI-powered detections and stop threats at machine-speed in Falcon Fusion SOAR.
Set up your SIEM in minutes:
Quickly discover active AWS services, onboard data sources through a guided wizard, and activate parsers and hundreds of prebuilt detections to start monitoring and finding threats on day one.
Meet key compliance requirements:
Out-of-the-box dashboards and centralized log retention help teams meet major regulatory and industry requirements including FISMA, GDPR, HIPAA, ISO 27001:2022, NERC CIP, NIST SP 800-53, PCI DSS v4.0.1, and SOX.
Transform AWS Security Operations.
Get unified visibility across AWS security tools, endpoints, identities, and more.
Accelerate detection and response.
Accelerate MTTD and MTTR AI-powered detections and Falcon Fusion SOAR.
Set up your SIEM in minutes.
Automated onboarding and hundreds of out-of-the-box detections let teams find and stop threats on day 1.
Out of the box dashboards support compliance requirements (FISMA, GDPR, HIPAA, ISO 27001:2022, NERC CIP, NIST SP 800-53, PCI DSS v4.0.1, SOX).
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing bills by actual usage, added to your monthly AWS invoice. You can mix and match any of the four dimensions. One dimension covers Next-Gen SIEM, charged per MB of non-Falcon data ingested, with 13-month retention included. The other three cover Cloud Security Runtime protection and scale with what you run: per hour for each running host, per hour for each container worker node, and per hour for each Fargate instance. Charges stop when you uninstall sensors or disable data connectors. There are no tiers; you pay only for what you use.
Top-of-mind questions for buyers
What counts as one host, worker node, or Fargate instance for Cloud Security Runtime billing?
A host is any running cloud instance with the sensor, such as an EC2 or Workspaces machine. A worker node is one node inside a container cluster. A Fargate instance is one managed container. Each is metered per active hour. Metrics post daily to AWS.
Am I charged for hosts or containers that are powered off or stopped?
Cloud Security Runtime charges apply per active sensor-hour. Charges stop automatically when you uninstall sensors. A fully stopped host stops accruing software charges. For Next-Gen SIEM, charges tie to data you ingest, so idle systems that send no data add no ingest cost.
Which dimension drives most of my bill, and how do the four combine?
The four dimensions bill independently and appear on one AWS invoice. Next-Gen SIEM cost scales with data volume ingested from non-Falcon sources. The three Runtime dimensions scale with how many hosts, worker nodes, and Fargate instances run and for how long. Your workload mix decides which dominates.
go.crowdstrike.com
Helpful?
Vendor refund policy
All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The AI-native CrowdStrike Falcon Platform provides comprehensive protection across all areas of enterprise risk - devices, identities, data, endpoints and cloud. Powered by a single agent, crowdsourced data, expert threat intelligence, and advanced AI, the Falcon Platform simplifies security operations and stops breaches.
Accelerate your CrowdStrike Falcon Next-Gen SIEM deployment with Noventiq’s structured implementation service. We onboard data sources, configure connectors and parsers, validate log ingestion, and deliver production ready dashboards and correlation use cases aligned to best practices.
Platform has unified threat visibility and delivers lightweight protection for every endpoint
Reviewed on Sep 03, 2026
Review provided by PeerSpot
What is our primary use case?
CrowdStrike Falcon is primarily used because we are a system integrator that sells a solution to our customers, so most of it is endpoint security.
We are not the one operating CrowdStrike Falcon, but when we do an implementation, once we install the agent and complete the implementation, we see what it has detected from day one of the implementation until the turnover to the operations team. The Falcon Complete dashboard is intuitive, especially OverWatch, which highlights every risk that we need to manage, and also the detection field and incident field where we can see the entire timeline and all the things that happened. There is also a network map where you can see, for example, if there is one detection on a workstation, which other users or other devices it communicated with.
We are primarily utilizing Charlotte AI within CrowdStrike Falcon platform. We use it extensively on CrowdStrike Falcon EDR, plus also NG-SIEM, because with Charlotte, it can help us create queries without doing it manually.
What is most valuable?
One of the key advantages of CrowdStrike Falcon is its lightweight sensor, so it is easy to deploy compared to other security solutions.
CrowdStrike Falcon provides results because, until now, no customer of ours has gotten ransomware or been infected.
The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of the companies that I mentioned earlier had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.
There is no impact on endpoint performance. On some of the other products that I compared CrowdStrike Falcon with, some of them cause high utilization. We have not experienced that with CrowdStrike Falcon.
For me as the one who implements CrowdStrike Falcon, it has a real impact because it is easy to deploy. Even though the customer does not have software deployment tools, you can deploy CrowdStrike Falcon by having a simple GPO, a Group Policy Object, load it there, and then you can install it easily.
For endpoint performance, it is great because it is very lightweight. It is not the traditional antivirus from before where when you do a scan and install it, the CPU and memory will spike up and the user cannot do anything about it. CrowdStrike Falcon is very lightweight. With that, users do not need to balance between usability and security because with CrowdStrike Falcon, you can have both.
What needs improvement?
CrowdStrike Falcon can improve their supportability of legacy devices. This is where CrowdStrike Falcon has been edged out by other cybersecurity vendors because some of them support legacy operating systems, unlike CrowdStrike Falcon that primarily uses one level higher of operating system than others.
For how long have I used the solution?
In the cybersecurity field, I have been working for more than ten years. We have been working with CrowdStrike Falcon since 2022 to now.
What do I think about the stability of the solution?
In terms of reliability, ever since I used CrowdStrike Falcon platform, I think it is still okay because the GUI, the dashboard, and the console are easy to use because all of their solutions are in one platform, so you will not get lost. They have OverWatch and a detection incident where all the detection is already consolidated there. Once you click it, you are going to see all the details.
What do I think about the scalability of the solution?
The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of those companies that I mentioned had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.
How are customer service and support?
When we had an issue, for example, on an agent installation because of one legacy device or when we were installing it with another endpoint application, we had CrowdStrike Falcon support come in with us. They are very helpful because they were able to resolve our issue.
Which solution did I use previously and why did I switch?
We had one experience with one of our customers where at first, they were not a CrowdStrike Falcon user. They had a ransomware with a different solution, not CrowdStrike Falcon. After that, we asked them to try CrowdStrike Falcon and install it, then we could see other detections that their previous vendor or solution did not see. After we were able to help them clean their environment, they transitioned to CrowdStrike Falcon with Falcon Complete, with the managed detection and response of CrowdStrike Falcon.
The most common solution right now in my country is NG-SIEM. Before, they used a different SIEM, like Splunk, Rapid7, Exabeam, or QRadar, but now that they see the value of CrowdStrike Falcon XDR and they want it to work together, most of them are trying to move to NG-SIEM so that you can have your XDR and your SIEM in one platform, plus the telemetry that CrowdStrike Falcon endpoint provides. This will really help them secure their environment.
What other advice do I have?
I think it is very great that we have a solution as CrowdStrike Falcon which has many different security functionalities because threats are evolving. As the defender, we need to evolve as well. We are fortunate to have CrowdStrike Falcon that is continuing to evolve, even now in the AI era because threats are more complex than before. Before you just needed to worry about the zero-day and the signature. Now it is different with AI. We are fortunate we have CrowdStrike Falcon with us.
I am confident that CrowdStrike Falcon is up to par to protect you and your customers from AI threats.
Most of our customers in my country use CrowdStrike Falcon, and ever since then, they do not have serious incidents, such as a ransomware that has taken effect on all their critical infrastructures, including servers.
One value or benefit that customers can have from CrowdStrike Falcon is not having their solutions in silos. If it works in silos, it is going to be hard to keep track of threats, especially now that AI is moving at AI speed. If we are working in silos or have different solutions, it is going to be hard to catch up. Did they get anything on the identity solution? Did they get anything on the cloud solution? With CrowdStrike Falcon, it is all in a single sensor and a single platform. Customers are going to have a single pane of glass that they can look at.
The impact of AI features such as Charlotte AI on our security operations makes our lives easier, not only for us but also for our customers. Before, when they were going to do a query, they needed to drill down multiple times before they got to the one event that they wanted to see. Now, if you ask Charlotte, it is one click of a button and enter, and Charlotte will give you everything. It is much faster than drilling down to all the events and all the reports.
Customers usually get Falcon EDR first, Falcon Pro. After that, they expand to Falcon Complete, meaning adding the MDR services, and now they are trying to go to NG-SIEM plus the identity. Now that they have heard about Falcon Guardian, they might look into that as well.
If I were to give advice for someone who is evaluating or considering CrowdStrike Falcon platform, I think they need to try it so they can feel the experience and the protection and the security that CrowdStrike Falcon provides. I rate this solution a ten out of ten.
Prakash Pandey
Advanced endpoint protection has secured our servers and now reduces analyst investigation time
Reviewed on Sep 02, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for CrowdStrike Falcon is to monitor endpoint and end devices, find any anomalies, detect them, and provide a resolution to secure our endpoint devices.
I use CrowdStrike Falcon to examine different network traces and traffic around our Windows and Linux devices. CrowdStrike Falcon monitors how people are accessing our applications around those servers and logs, catching any blast radius such as a high volume of bombarding requests coming to a specific server or any unauthorized access to the server, whether internally or from disallowed external sources.
What is most valuable?
The best features CrowdStrike Falcon offers include endpoint device monitoring, protection from malware and external threats, and alerting on wrong policies being implemented or blocking such as an administrator applying certain policies, making CrowdStrike Falcon a great endpoint protection tool.
The feature I rely on most day to day is endpoint device protection, as CrowdStrike Falcon surpasses tools such as Symantec which do not have interactive monitoring or defensive methodology, allowing us to control and align policies across all servers in our organization.
CrowdStrike Falcon has positively impacted my organization by helping us to stay secure, resilient, and provide what our customers need all the time without impacting their data or disclosing their personal information.
I can share that CrowdStrike Falcon has prevented our end users from uploading malicious files to our applications on those servers, meaning our systems are well protected, and we avoid incidents or threats against our applications.
What needs improvement?
I chose nine out of ten because while CrowdStrike Falcon has the capabilities and features I want, the pricing for each different functionality or feature we want to add raises my concern about potentially having a compound or overall pricing increase.
For how long have I used the solution?
I have been using CrowdStrike Falcon for five years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable, and I have not witnessed any performance impact on our endpoints due to the Falcon sensor as they are running smoothly without issues. The sensor is deployed through our imaging tool quickly to all endpoints.
What do I think about the scalability of the solution?
CrowdStrike Falcon's scalability is excellent because it is software as a service, allowing us to deploy more agents without experiencing performance lags or issues.
How are customer service and support?
The customer support is excellent. We receive reliable enterprise support when we have issues, and they provide all the guidance we need.
Which solution did I use previously and why did I switch?
We previously used Symantec and Norton for some time before switching five or six years ago because they became obsolete and failed to keep pace with market advancements.
How was the initial setup?
Using CrowdStrike Falcon has significantly helped our security team by allowing them to get alerts and perform blast radius detection in a straightforward manner, making the process more automated without the need to look through logs.
Since our initial deployment, our use of CrowdStrike Falcon has expanded significantly, starting with the basic Falcon sensor and then gradually including more capabilities around AIDR and other tools.
What about the implementation team?
We utilize Charlotte AI within CrowdStrike Falcon to investigate endpoints and understand what certain actors did, allowing us to retrieve user and machine information quickly without manually browsing through CrowdStrike Falcon.
What was our ROI?
We have seen a return on investment with CrowdStrike Falcon as our security team has been optimized and scaled, allowing them to conduct more analyses around different security postures because CrowdStrike Falcon handles most of the groundwork.
What's my experience with pricing, setup cost, and licensing?
I am not very knowledgeable about pricing, but I am aware it is quite expensive.
Which other solutions did I evaluate?
We did not evaluate other options before choosing CrowdStrike Falcon.
What other advice do I have?
CrowdStrike Falcon has already improved significantly with its AI capability, Charlotte, and I am quite happy with what is being offered.
CrowdStrike Falcon's AI capabilities are remarkable, and I trust CrowdStrike to maintain governance, security, and data privacy with the tools they provide.
Regarding the AI capabilities, I have used Charlotte AI a couple of times, and I find it quite accurate, providing the right resiliency and detection during any investigation I perform.
Having multiple security capabilities on a single platform is excellent as it eliminates the need to navigate different tools to find anomalies or detect and analyze root causes, thereby saving time for analysts whenever security breaches or vulnerabilities are identified.
CrowdStrike Falcon helped our team detect a security incident where someone attempted a SQL injection on one of our secured Drupal-based application servers. CrowdStrike Falcon alerted our team, allowing us to block access and patch the vulnerability to avoid any future incidents.
CrowdStrike Falcon has significantly helped my security team reduce their efforts and time spent analyzing vulnerable resources or security mishaps and setting up enterprise policies across the organization.
My advice to others considering CrowdStrike Falcon is that it is a great product that reduces analyst time while providing greater security posture to meet industry standards. I gave this product a rating of nine out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
reviewer2895027
Platform has transformed threat detection speed and reduced false positives for my team
Reviewed on Sep 02, 2026
Review provided by PeerSpot
What is our primary use case?
My main use cases for CrowdStrike Falcon include detecting malicious behavior and identifying user trends.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making it faster and easier to respond to advanced threats.
In a security incident, CrowdStrike Falcon helps my team detect or stop threats by assisting in detecting unauthorized use of local binaries, such as those that are natively installed including PowerShell and scheduled tasks.
What is most valuable?
The benefits I have seen from multiple security capabilities on a single platform include solid control over consolidated information that can be accessed quickly.
I believe the value of having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform lies in the correlation of these different data sources, which is essential to identifying and disrupting advanced threats.
CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements. These improvements result from having fewer false positives, which means more time spent working on real, high-impact work.
CrowdStrike Falcon makes every analyst much more effective and informed than they would have been otherwise.
What needs improvement?
CrowdStrike Falcon can be improved by continuing to listen to customer feedback.
I believe that more integrations and support for Mac products should be included in the next release.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as reliable ever since the massive incident occurred.
I have not experienced any downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is none; it is a force accelerator.
How are customer service and support?
I evaluate customer service and technical support as excellent.
Which solution did I use previously and why did I switch?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools. The tools I replaced were those provided by legacy vendors, which operated for the sole purpose of one or two functions, and they were able to be replaced through the flexible approaches that CrowdStrike Falcon provides.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy and effective. What worked well includes the solid deployment process, though communication with lay users is always a challenge, which I would say resulted in limited to no issues.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon.
What other advice do I have?
I would rate CrowdStrike Falcon an eight on a scale from one to ten, as nothing is perfect. My advice to other organizations considering CrowdStrike Falcon is to adopt now or adopt later. I provided an overall review rating of eight.
Jason Terriquez
Integrated security platform has transformed incident response and reduced investigation time
Reviewed on Sep 02, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for CrowdStrike Falcon is incident response.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by improving the flow with the detections and the alerting. One of the things I also have is the MDR, so that also helps with mitigating a lot of the problems as well.
The benefits I have seen from having multiple security capabilities on a single platform include just the time to remediate and to stop the threat.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that you understand what you know and what you don't know. Having all the telemetry data feed into one main system actually helps in quickly detecting threats and also seeing trends, patterns, or connections.
CrowdStrike Falcon has greatly affected the workload and productivity of my security team, which is me, by reducing the time I spend in the platform. With some workflows and creating some automation around it, it has improved my work-life balance because many tasks that I ended up doing multiple times daily are now automated, allowing me to focus on other things that need to be addressed.
What needs improvement?
I think CrowdStrike Falcon can be improved by making the menu a little bit more intuitive. I know some people like how every menu looks the same, but I don't prefer it because it makes me forget where I am or where I'm going or how to get to some place.
For the next release, I would like to see UI improvements, and also to have it where I don't need to drill into a device's alerting or submenus to just hit contain. If I bring up a device, I want a quick button there to contain it because if I'm clicking on that device, there's something I'm looking into and most likely I've been alerted of something, so I should probably contain it first and then ask questions later.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as pretty solid; it's perfect.
I have experienced no downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
Since my initial deployment, my use of CrowdStrike Falcon hasn't expanded; I think we got rid of some portions. We still have Falcon Complete, but we used to have Falcon Recon, which we got rid of. Now, we are looking back into it because of the Guardian and new steps announced with Recon today. It seems we lowered our use primarily from a customer-facing and interaction standpoint, not due to the technology itself.
How are customer service and support?
For customer service and technical support, it can be spotty at times. With CrowdStrike Recon, we got rid of it due to customer service problems; however, since then, customer reps have been in touch, quite active, vocal, and checking in on us. The support has gotten better since the initial experience.
Which solution did I use previously and why did I switch?
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used is the experience with SentinelOne for EDR and using InsightVM for vulnerability management. I used Adaptive Shield, which is now Falcon Shield, but I would say in the case of Adaptive Shield, it only got worse, mainly from a UI perspective. When it was integrated into CrowdStrike Falcon, it lost its methodical structure, making it hard to navigate. In terms of EDR, I think SentinelOne has an advantage because if I drill into a host or endpoint, I can quickly perform a bunch of actions from the initial click while I already have received the alert and a high confidence rating from CrowdStrike Falcon.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy because I use NinjaOne, which automatically does it. It's great, buy NinjaOne.
What about the implementation team?
What worked well for me was NinjaOne, and I faced honestly zero challenges. The API was easy to set up on both sides within CrowdStrike Falcon and NinjaOne, allowing us to see detections and other things as soon as we were in there. One challenge I faced was on NinjaOne's side, not CrowdStrike Falcon's side, and I would like to see integrations where we have more choice with our third-party vendors.
What was our ROI?
I can say I've seen a return on investment with CrowdStrike Falcon in terms of time and energy spent gathering information about events, but since I'm not the one spending the money, I can't really say more.
Which other solutions did I evaluate?
CrowdStrike Falcon hasn't helped me consolidate other tools, but with the announcement of Guardian and using it, it has begun the process of talking about consolidating things because right now, I use InsightIDR as my SIEM and am looking to move to the next-gen SIEM and create more workflows from there.
We haven't yet consolidated, but the impact would be that all the telemetry and plugins and everything I do, especially the workflows, would happen from CrowdStrike Falcon and not third-party. The other impact would be that I can actually integrate more because with Rapid7, I struggle with integrations from a lot of our other partners.
What other advice do I have?
My advice to other organizations considering CrowdStrike Falcon is to take a look at their third-party integrations and see what opportunities exist within CrowdStrike Falcon before making a final purchase. This way, they know which portions of CrowdStrike Falcon they actually need or want, especially since some features tie in deeply with tools like NinjaOne, making daily tasks, deployments, and implementations much easier and more manageable. I would rate this product a 9 out of 10.
reviewer2631690
Consolidated endpoint protection has improved threat prevention and streamlined investigations
Reviewed on Sep 02, 2026
Review provided by PeerSpot
What is our primary use case?
My main use cases for CrowdStrike Falcon involve protecting all our endpoints and all our servers. CrowdStrike Falcon has allowed me to consolidate or replace other security tools.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because we feel a lot more secure as it is very good at stopping threats. It makes it very easy to investigate what happened and what triggered the event. Our response time is a little better when we have to actually dig into something.
The benefits I have seen from having multiple security capabilities on a single platform include that it makes it much easier to get to what I need quickly instead of trying to switch platforms. Sometimes switching between modules, the interface is not always the same and does not feel the same. However, largely it is usually very together and it works well.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that if we do have to open up other security tools, sometimes we can leverage what CrowdStrike Falcon sees to quickly get to what is another security tool because it exposes that information.
Using CrowdStrike Falcon has affected the workload or productivity of my security team because in a lot of ways it has actually lowered the workload as it does such a good job of preventing the threats. If something triggers on another system but CrowdStrike Falcon is not triggering it, we are automatically suspect whether it is a real problem.
What needs improvement?
I have not yet used AI within CrowdStrike Falcon. I cannot think of a way that CrowdStrike Falcon itself can be improved. I do not have any suggestions for additional features that should be included in the next release for CrowdStrike Falcon as it does a very good job by itself.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about six years.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as being awesome, other than the great CrowdStriking. I have experienced downtime, crashes, or performance issues.
The detail I can provide about the performance issues involves the same traumatic thing everyone has gone through, which is the great CrowdStriking. It was bad; I am a casino, so this was on a weekend, overnight.
What do I think about the scalability of the solution?
I have not noticed any impact on performance from the CrowdStrike Falcon sensor regarding endpoint performance and my ability to deploy security at scale.
How are customer service and support?
I would evaluate customer service and technical support by saying that every time I have had to access it, they have been very good.
Which solution did I use previously and why did I switch?
We used to use Bitdefender and it was not awesome, so we replaced it. We also have replaced some SIEM and some other detective systems with CrowdStrike Falcon.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as very easy. We have Active Directory, so we just deploy with Active Directory and it works very well. What worked well during the deployment was that it just worked, so there were not really a lot of challenges. It was configure this in Active Directory, deploy it, and it works.
What about the implementation team?
My use of CrowdStrike Falcon has expanded since the initial deployment as we started off with just workstations and now it is deployed to every surface we can get it on.
What was our ROI?
I believe I have seen a return on investment with CrowdStrike Falcon as I honestly believe it has saved us money and stopped threats.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is that everybody complains about pricing. I am not going to be that much different, but they are not outrageous, and I have dealt with companies that are outrageous. On a scale of one to 10, one being really super affordable and 10 being Palo Alto, I would say it is a seven or an eight.
Which other solutions did I evaluate?
What differentiates CrowdStrike Falcon from the other cybersecurity platforms I have used or evaluated is that the biggest differentiator is that it does not, to me, at the time when we got it, rely on knowing what the bad threat is. It sees the action of the threat and relies on that, so there are no signatures required and that is a pretty big deal.
What other advice do I have?
My advice for other organizations considering CrowdStrike Falcon is that it is worthwhile to test drive and compare it to other systems. I give this review a rating of 9.