Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

3 AWS reviews

External reviews

56 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Marco-VIVALDELLI

It works with all devices and operating systems easily to provide integrated security

  • April 30, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Falcon to investigate threats and reduce risks in our environment. It covers multiple departments within the same building and company. All units are attached to one controller, so we can manage them from one point. 

We can implement different kinds of policies on sensitive data for various departments. For example, I can limit how data can be changed if I'm dealing with financial data. It's the same for production or logistics. We can set rules for data sharing and access because some departments need to share data with customers.

How has it helped my organization?

CrowdStrike's AI-driven analytics have improved our security considerably. It's sharing information from across the infrastructure and applying machine learning to prevent issues. This is a powerful, proactive approach to cybersecurity. It takes action in time to prevent the problem, so we don't need to remedy it after the fact. Sometimes, by the time you take action, it's already too late. 

Before deploying Falcon, I would avoid taking action due to potential risks. With CrowdStrike, I don't worry about recovering data, so I can focus on preventing situations. In two years, I have never had that problem. When I look at the platform, I can see all the notifications and the actions taken. I can see how potential attacks can possibly reach the server and create a significant incident. Thus, I can directly measure the quality of the service.

Falcon is easy to integrate with our infrastructure because we can control the entire network through our fiber router and switch. CrowdStrike can interface with all devices easily and provide integrated security. Falcon gives you greater control without any problems.

The agent will recognize issues immediately, and we can follow up to create a plan for if this problem reappears or is still present on the infrastructure. Falcon enables instant remediation. It doesn't take two or three days. It's in real-time.

What is most valuable?

Falcon has the capacity to identify potential problems quickly. The administrator can deploy the agent, and the users cannot change it. This assures you that the agent remains on this device. Also, the agent can act preemptively to provide alerts about potential problems. 

When there's a problem, you can follow the rules. For example, you can put a file that might be infected into quarantine or lock the device, preventing it from propagating the threat to other devices or networks. The agents are collecting information and feeding that back into the CrowdStrike platform, so you have 24/7 control and visibility. 

Falcon's deep learning capabilities are flexible and work across multiple operating systems. You can control everything from the same place, whether you're dealing with a Windows, Linux, or Mac device. You can define your policies precisely and decide how you want the platform to respond in any situation. 

CrowdStrike's AI approach is interesting because it improves the capacity to correlate information based on all the deployments on devices worldwide. It analyzes this data to identify something anomalous that could potentially be a problem in your environment. Falcon can isolate the issue to determine if it's a real threat. You will get an email saying the platform has identified a potential problem they are investigating. 

Falcon explains the steps they are taking. After the issue has been resolved, you will get another message showing CrowdStrike's analysis and evidence that the problem is now under control. I get about 20 emails from CrowdStrike daily. 

What needs improvement?

I want more ability to customize how you summarize the data. The default views are fine, but it would be interesting to be able to customize them based on the kind of data you want to see immediately. This can help the administrator gain an immediate overview and reduce the investigation time.

For how long have I used the solution?

We have used Falcon for two years.

How are customer service and support?

I rate CrowdStrike support 10 out of 10. They have one of the best teams that I've worked with. They're very fast and professional, with a high level of skill and knowledge. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Sophos. It's a good solution that works well with other Sophos infrastructure, like firewalls, etc. For example, if the firewall is from Sophos, it can interact with the software to identify a problem. However, CrowdStrike is more powerful when using hardware from different vendors. It doesn't rely on specific hardware because it works with an agent, so you're more flexible and less constrained. 

Overall, Falcon is more powerful than other solutions. It is light on resource consumption. It has a minimal effect on the client when you have installed the system because everything is controlled by our cloud platform where you can see the portfolio of devices.

How was the initial setup?

The installation was quite easy. The platform is based in the cloud, but you need to download agents based on your operating system. After you install the agents, you only need to configure the various devices on the cloud platform. CrowdStrike's platform is managed by the vendor. You can log in and manage your portfolio of devices and define your policy or apply profiles to groups of users and devices. 

What was our ROI?

We feel like Falcon is worth what we pay.  The cost of the solution is minimal compared to restoring data from a potential attack. 

What's my experience with pricing, setup cost, and licensing?

Falcon's price is accessible, and it's a good value for the level of quality we get. We don't have any objections based on the cost, and we understand that you will pay more for an enterprise solution. There is no objection to the cost. It's appropriately priced for the service that we receive.

What other advice do I have?

I rate CrowdStrike Falcon 10 out of 10.

Which deployment model are you using for this solution?

Public Cloud


    Roberto Massa

Is user-friendly, maintenance-free, and stable

  • April 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

We are a CrowdStrike Falcon distributor that helps clients monitor their environments for malicious activity coming from the internet.

How has it helped my organization?

Both users and administrators find CrowdStrike Falcon easy to use.

What is most valuable?

I like the vulnerability assessment and proactive hunting features of CrowdStrike Falcon.

What needs improvement?

To simplify the budgeting process for our clients, CrowdStrike should consider offering bundled packages that include essential features. The separate model pricing structure can make it challenging for clients to gain approval for their security needs.

CrowdStrike could consider regional pricing models to better reflect the economic realities of different markets.

For how long have I used the solution?

I have been using CrowdStrike Falcon for 2 years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

CrowdStrike Falcon is scalable.

Which solution did I use previously and why did I switch?

We have also used Sophos. CrowdStrike Falcon is a better solution but Sophos is more affordable.

How was the initial setup?

The deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

The cost of CrowdStrike Falcon in Latin America seems high relative to the economic conditions in the region.

What other advice do I have?

I would rate CrowdStrike Falcon 9 out of 10.

To realize the benefits of CrowdStrike Falcon, it's recommended to conduct a proof of concept first. You should then start to see the advantages within a few months.

No maintenance is required from our end.

To ensure the successful implementation of CrowdStrike Falcon, it's essential to have a complete network map and inventory of all resources and devices.

Which deployment model are you using for this solution?

Public Cloud


    Sri Ram Gude

Excels at identifying suspicious activity, helps mitigate potential security breaches, and is easy to use

  • April 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use CrowdStrike Falcon to investigate security detections for malicious activities in our environment.

CrowdStrike utilizes machine learning algorithms and detection rules to generate alerts for suspicious activity within our environment. We then investigate these detections individually, analyzing the details of each event.

In addition to automated detection, CrowdStrike allows for custom queries. For instance, if we need to investigate a specific host, we can leverage a cloud security language to examine its activity. Similarly, we can use CrowdStrike to search for activity related to particular users or hosts.

How has it helped my organization?

CrowdStrike Falcon provides significant additional value. It excels at identifying suspicious activity the moment an application appears in the environment, immediately bringing these incidents to the attention of our response team. Upon receiving an alert, our team can investigate and take appropriate action if anything malicious is found. In essence, CrowdStrike Falcon acts as a strong barrier against attackers.

In the past 3 years, we have encountered many scenarios where CrowdStrike Falcon has helped mitigate potential security breaches.

What is most valuable?

The detection and response console is the most valuable feature.

What needs improvement?

We encounter occasional issues, such as when disabling network access for a host that uses CrowdStrike. In these cases, the access disable process can be quite slow.

I'm using CrowdStrike Query Language, and I've noticed an issue with event backups. Searches exceeding a certain event threshold aren't capturing all results. For instance, if I run a search that returns 10,000 events in a single day, only 2,000 events are backed up. This limitation with CrowdStrike Query Language needs to be investigated.

For how long have I used the solution?

I have been using CrowdStrike Falcon for over 3 years.

What do I think about the stability of the solution?

CrowdStrike Falcon is generally stable, although event searches may occasionally experience slow performance.

What do I think about the scalability of the solution?

CrowdStrike Falcon's scalability is dependent on the license acquired.

How are customer service and support?

The technical support live chat can experience long wait times. Submitting a ticket may result in a quicker response.

Which solution did I use previously and why did I switch?

The company was using Carbon Black before I joined. When I came on board, they decided to switch to CrowdStrike.

What other advice do I have?

I would rate CrowdStrike Falcon 9 out of 10.

CrowdStrike Falcon is deployed across multiple end-user systems and locations.

I recommend CrowdStrike Falcon. It's a wonderful security platform that's easy to use and requires minimal effort to maintain.

Which deployment model are you using for this solution?

Public Cloud


    Dinesh Yadav

Blocks suspicious activities and protects endpoints and servers from attacks

  • March 28, 2024
  • Review provided by PeerSpot

What is our primary use case?

A lot of customers face ransomware and malware attacks. The solution helps protect endpoints and servers from ransomware and malware attacks.

How has it helped my organization?

The solution has multiple layers of security, including web security. We can monitor endpoints, conduct root cause analysis, and find geolocations. If the tool finds any suspicious activity, it blocks and remediates it.

What is most valuable?

The solution makes our security operations easier. After an incident, we get complete reports and insights. The product provides good monitoring features. The product also has teams that help customers find suspicious activities. The team calls and asks us to check the updates and remediate issues. If the system can remediate it, the team does it through the system. The detection and response are in real-time. There are no security breaches. Resolving issues doesn’t take much time.

What needs improvement?

The tool is more expensive than other products in the market.

For how long have I used the solution?

I have been using the solution for more than 3 years.

What do I think about the stability of the solution?

I did not have any stability issues.

What do I think about the scalability of the solution?

It is easy to scale up. We just need to add the licenses. The product is suitable for small, medium, and large businesses. We must buy a minimum of 50 licenses.

How are customer service and support?

The support is excellent. We rarely need support.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is pretty simple and clear. The time taken for deployment depends on the endpoints. It's a cloud solution. We can use Active Directory or the group policies to deploy it.

What was our ROI?

The product has a lot of use cases. There are companies that need to run their operations 24/7. It will be a big challenge if their server or infrastructure goes down. They cannot afford downtime. They need to choose the right solution for their needs.

What's my experience with pricing, setup cost, and licensing?

The price depends on the kind of service we need. If we need excellent service, we must pay a reasonable price. We can choose any pricing model if we do not want excellent service. The product is excellent. We need to pay a premium price for the tool.

Which other solutions did I evaluate?

Microsoft Defender Threat Intelligence, IBM, and Cisco are some competitors. CrowdStrike entered the market with a USP to protect endpoint servers. It has a different approach. Malwarebytes has a similar setup. I prefer CrowdStrike, though.

What other advice do I have?

I will recommend the tool to others depending on their budget. If customers have a good budget and need a premium product, they can choose CrowdStrike. No product is perfect. Overall, I rate the tool an 8 out of 10.


    reviewer2384499

Is user-friendly, improves performance, and protects our end users

  • March 28, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use CrowdStrike Falcon for endpoint protection and cybersecurity.

We implemented CrowdStrike Falcon to ensure our systems were secure and there were no infiltrations to our system.

We deploy CrowdStrike Falcon across a variety of platforms, including cloud and edge environments. We ensure it meets rigorous security standards, is properly certified, and adheres to our data management policy.

How has it helped my organization?

We integrated CrowdStrike Falcon with our end-user systems and servers.

Since implementing CrowdStrike Falcon, we haven't experienced any serious threats, and we've seen a decrease in phishing and ransomware emails. This suggests it's been very effective in mitigating those threats.

The UI is easy to use and comprehensive.

CrowdStrike Falcon's performance has improved our user productivity.

What is most valuable?

CrowdStrike Falcon offers a comprehensive dashboard that is highly effective in protecting against and blocking external infiltration attempts.

What needs improvement?

The pricing structure should allow for some flexibility.

For how long have I used the solution?

I have been using CrowdStrike Falcon for almost 3 years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

I would rate the scalability of CrowdStrike Falcon 8 out of 10.

How are customer service and support?

The technical support is good. We have not had any issues with them.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment was straightforward. The deployment doesn't take more than one day. Those involved with the deployment are system engineers, IT analysts, and software engineers.

What about the implementation team?

The implementation was completed in-house.

What's my experience with pricing, setup cost, and licensing?

The price is fixed with no room for negotiation.

What other advice do I have?

I would rate CrowdStrike Falcon 8 out of 10.

We have deployed CrowdStrike Falcon in multiple departments, locations, and satellite offices.

CrowdStrike Falcon doesn't require maintenance from our end other than the updates.

I recommend CrowdStrike Falcon to others.


    Leena R.

Falcon Identity protection review

  • March 27, 2024
  • Review provided by G2

What do you like best about the product?
we use this for identify unusual user behavior,
as it uses Zero Trust security for risk analytics
it has so many features which make this easy first one GUI
What do you dislike about the product?
Its high cost for subscription Falcon Identity
What problems is the product solving and how is that benefiting you?
it is work as baselines of individual user behavior for indicating different attacks / unauthorized access into our oranisation, falcon identity protection detect and gather data from cloud SSO


    Sandesh Dumbre

Good incident response, effective prevention policies, and a straightforward setup

  • March 26, 2024
  • Review provided by PeerSpot

What is our primary use case?

CrowdStrike Falcon is used as an endpoint detection and response platform. It's basically an antivirus solution. It is deployed on all the endpoints, including workstation servers, et cetera.

How has it helped my organization?

We previously had another solution. However, it was a combination of signature-based and anomaly-based detection methods. When we implemented CrowdStrike in our organization, it helped us minimize the critical gap where, in some cases, we could not identify malicious behavior.

What is most valuable?

CrowdStrike is behavioral-based; therefore, it has a behavioral-based detection method. It's not a signature-based tool. It helps us to identify the threats according to the behavior of any process that is running on any particular system. It helps immensely to identify any malicious behavior on any endpoints.

They have a service called Overwatch. It's an incident response feature, which CrowdStrike usually provides for most of the customer's premium customers. They will be looking for particular instances. If anything really suspicious or malicious happens, they will inform us. That is one kind of feature that is really great as compared to other tools.

The ransomware protection and behavior-based detection are the best features. 

The solution has effective prevention policies. They help prevent cyber attacks or any other malicious activity.

The real-time response capability supported our incident response efforts. Whenever there is a case of any critical incident or any security breach, at the time of security breach, we can utilize RTR (real-time response) features to know what process is running. Then, we can kill the process. We can get to know, for example, what active connections are. Also, in case of quarantine, if we quarantine a particular machine with CrowdStrike, we still have access to that machine with the real-time response feature. That's quite useful.

What needs improvement?

File integrity monitoring could be improved. They need to have more clarity on the policies and how we can apply them to get the file modification details. In terms of vulnerability management, CrowdStrike doesn't have the network scanning feature, which other competitors have.

We sometimes get false positives. We have had to create some exceptions. However, we have been able to minimize the noise. 

For how long have I used the solution?

I have been using CrowdStrike for more than 3 years.

What do I think about the stability of the solution?

This is a very stable solution. I'd rate the solution 9 out of 10. 

What do I think about the scalability of the solution?

We have a single instance across multiple locations. People in the company work from different locations, and we have agents installed to workstations, et cetera. We have around 8,000 workstations and around 5,000 servers. Then, we have about 20 people working on it directly regularly.

The solution is absolutely scalable, and companies can scale it as needed. I'd rate the solution 9 out of 10 in terms of scalability. 

How are customer service and support?

I'm absolutely satisfied with CrowdStrike's support. They have a robust support team that is always there to help.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were previously using Symantec. CrowdStrike has a wider range of features and has been the market leader in its category. After a quick POC, we decided to move to it. 

How was the initial setup?

The initial setup was straightforward. There were no major hiccups in implementing it. We were clearly guided by the CrowdStrike team. We just followed the steps provided. It took 45 to 60 days to implement.

CrowdStrike is a cloud-based solution. We don't have to deploy any instance on-premises or cloud. CrowdStrike provides us access to their instance. We simply have to install the agents on our systems. Those agents will communicate to the CrowdStrike Falcon cloud. It will all be managed by CrowdStrike, and we will have access to the console. On the console, we have all the features and all the different options we need to manage the platform. There is no maintenance required.

We had 3 people participating in the deployment. From the system side, there are multiple teams involved from the deployment point of view. That said, 90% of the work was done by the security platform team.

I'd rate the ease of deployment 4.5 out of 5. 

What was our ROI?

We have witnessed an ROI. It's been the first line of defense for us. It has saved us on costs. However, those are hard to quantify as we haven't faced a breach.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive, however, if you look at the features, it's worth the cost.

What other advice do I have?

I'm a customer and end-user.

I would absolutely recommend this product to any organization with a prior POC under its belt. A company needs to test it in their environment. That said, I would highly recommend anyone to test it out.

I'd rate the solution 9 out of 10. 

Which deployment model are you using for this solution?

Public Cloud


    ManojKumar42

Provides real-time response, helps reduce malware risk, and provides advanced investigation capabilities

  • March 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our organization uses CrowdStrike Falcon for a variety of security tasks, including incident response, investigations, malware analysis, and threat hunting. This comprehensive platform excels at detecting malware across various technologies and endpoints within our environment.

CrowdStrike Falcon functions as a threat detection platform. It identifies malware based on pre-defined signatures and rules. Upon detection, it triggers a response and provides a dashboard for further analysis. This allows us to assess if the malware poses a risk to our organization or if it's a false positive. For confirmed threats, we can then delve deeper for a thorough investigation to uncover any underlying malicious intent.

Our primary goal is to prevent malware-related risks proactively. By leveraging CrowdStrike Falcon, a premium endpoint detection and response tool, we can safeguard our organization from malware exploitation attempts employed by hackers.

How has it helped my organization?

The primary advantage of CrowdStrike Falcon is twofold: reducing malware risk and providing advanced investigation capabilities. Traditional antivirus solutions struggle to keep pace with ever-evolving malware threats. CrowdStrike Falcon utilizes cutting-edge technology to proactively prevent these threats, minimizing the risk of infection. Falcon also features a threat intelligence platform that keeps us informed about the latest global malware threats and compromised tactics. This real-time awareness empowers us to proactively prevent threats before they impact our environment.

Recently CrowdStrike Falcon detected and mitigated malware that would have compromised several vulnerabilities in our environment.

Falcon's real-time response capability ensures we can quickly access any compromised host. This is a valuable advantage over other EDR tools.

What is most valuable?

The most valuable features of CrowdStrike Falcon include Falcon Fusion workflows and endpoint detection capabilities.

What needs improvement?

I've found that CrowdStrike's technical support could benefit from increased technical expertise. In my experience, their representatives haven't been able to resolve my issues as effectively as I would have liked.

For how long have I used the solution?

I have been using CrowdStrike Falcon for 1.5 years.

What do I think about the stability of the solution?

I would rate the stability of CrowdStrike Falcon nine out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of CrowdStrike Falcon eight out of ten.

How are customer service and support?

I've found the technical support staff to be less knowledgeable than I'd expect. Ideally, they should have expertise in all CrowdStrike modules, as we utilize a wide range of them.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used security solutions from Symantec, Trend Micro, Trellix, and Mandiant. However, CrowdStrike Falcon stood out as a more premium offering. Its advanced capabilities and comprehensive approach to security ultimately led us to switch providers after careful consideration of several factors.

How was the initial setup?

The initial deployment was straightforward and took less than 15 days to complete.

There were between 30 to 40 people involved in the deployment. 

What about the implementation team?

Our security engineering team implemented CrowdStrike Falcon entirely in-house. We also received some support from our internal desktop team and leveraged the expertise of an internal managed service provider team. No third-party vendors were involved in the deployment.

What's my experience with pricing, setup cost, and licensing?

CrowdStrike Falcon is more expensive than other EDR solutions with similar features.

What other advice do I have?

I would rate CrowdStrike Falcon nine out of ten.

After deployment, there are some simple maintenance tasks to keep everything functioning well.

New users should learn about the different modules of CrowdStrike Falcon and their functionalities to work effectively with the tool.

Which deployment model are you using for this solution?

Hybrid Cloud


    Khushru_Mistry

The integration is flexible, helps identify required patches, and excels in external media control

  • March 15, 2024
  • Review provided by PeerSpot

What is our primary use case?

CrowdStrike Falcon is our platform for IT security, encompassing endpoint security, cloud security, and EDR capabilities.

How has it helped my organization?

CrowdStrike protected us from a cyberattack. That's why I believe it's a very effective product. It's already prevented attacks on 2 occasions. It successfully quarantined suspicious files, essentially making our organization much safer.

We also leverage CrowdStrike Falcon Overwatch, a managed threat-hunting service offered by CrowdStrike. This service complements CrowdStrike's EDR functionality, which provides automated detection and response capabilities against external attacks. In our case, CrowdStrike successfully identified and automatically contained a cyberattack launched against our organization.

Our CrowdStrike Falcon integration with our SIEM is proving to be flexible.

What is most valuable?

The most valuable aspects of CrowdStrike Falcon for me are its device observability, identification, and software and OS recognition. It also excels in external media control, particularly USB access. The ability to disable USB access to flash drives significantly improves security.

Furthermore, Falcon helps identify patches needed for Windows, Mac, and other operating systems. This provides valuable reports and insights into our system vulnerabilities, allowing us to proactively address them.

What needs improvement?

If CrowdStrike can further expand its support for XDR compatibility, that would give it an edge over all the other competing new products.

For how long have I used the solution?

I have been using CrowdStrike Falcon for 2 years.

What do I think about the stability of the solution?

I would rate the stability of CrowdStrike Falcon 8 out of 10.

What do I think about the scalability of the solution?

We've deployed CrowdStrike Falcon across all 3,000 of our endpoints, and it has demonstrated excellent scalability. Therefore, scalability is not a concern for CrowdStrike in terms of performance or its ability to handle growth.

I would rate the scalability a 9 out of 10.

How was the initial setup?

The deployment was straightforward, taking 2 months for 3,000 endpoints. We implemented it directly where needed. The process was simple and easy. We believe this approach offers advantages due to its lower complexity compared to other methods. Careful planning was essential, and with a clear plan for sensor installation, we were able to execute the deployment successfully.

What about the implementation team?

While a third party handled the implementation, the OEM provided us with direct training on Falcon alongside CrowdStrike.

What was our ROI?

CrowdStrike Falcon has demonstrably provided a positive return on investment. We've already encountered two specific instances where, without CrowdStrike, the company would have faced millions in damages. In one case, we would have likely lost our entire SAP system.

What's my experience with pricing, setup cost, and licensing?

The pricing of CrowdStrike Falcon is competitive.

Which other solutions did I evaluate?

After evaluating SentinelOne, we found CrowdStrike to be a superior solution. CrowdStrike offers advantages in dashboard compatibility and a feature called Overwatch, which gives it a competitive edge.

What other advice do I have?

I would rate CrowdStrike Falcon 8 out of 10.

CrowdStrike Falcon is deployed in multiple branches across India.

No maintenance is required from our end.

I recommend CrowdStrike Falcon. It is not a solution we need to think twice about using.

Which deployment model are you using for this solution?

Hybrid Cloud


    Niranjan N

The threat score helps us prioritize remediation and cross-reference with other products

  • March 15, 2024
  • Review provided by PeerSpot

What is our primary use case?

We provide a service for our clients with CrowdStrike Falcon. Alerts come into the CrowdStrike Falcon dashboard, and we investigate them based on the process tree and commands running. We check everything for any infections in the host or internal connections. If a threat is confirmed, we place it into the containment section inside Falcon. 

How has it helped my organization?

CrowdStrike improves our detection capabilities. We use multiple tools like Symantec and this one. CrowdStrike reports on the processes and services, allowing us to investigate forensically. We can conduct a deep analysis and identify the threat at the memory level. We can do more investigation of the process to see where it started and where it is going. We can see the commands running on the backend, CPU utilization, and memory consumption. All of that information is helpful. 

What is most valuable?

CrowdStrike displays a threat score when it detects an infection. This is helpful because not all detections are the same. It will classify them as ransomware, malware, phishing, etc. This feature helps us prioritize and cross-check with other EDR tools. 

It's integrated with multiple threat intelligence sources, such as the AbuseIPDB. That integration helps because we can easily cross-check between CrowdStrike and other solutions like an MDR or Azure AD. Hybrid analysis is integrated with CrowdStrike in our environment. There's also sandbox analysis. It's more informative. We perform a routine activity in our test environment where we simulate the process and file.

What needs improvement?

CrowdStrike Falcon sometimes wrongly flags things as malicious. Let's say a user is active on Chrome only. Sometimes, our cross-segmenting will fetch from the backend data and show that it is malicious because of memory or CPU utilization.

For how long have I used the solution?

I have used Falcon for more than two years. 

What do I think about the stability of the solution?

CrowdStrike Falcon is a stable solution.  

What do I think about the scalability of the solution?

CrowdStrike is scalable. We can query large amounts of data, and the solution responds well, whereas Splunk takes a longer time to perform a search operation.

How are customer service and support?

I rate CrowdStrike support 10 out of 10. They respond quickly and don't take much time to resolve all our issues.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used Symantec and Rapid7.

How was the initial setup?

Falcon was already deployed when I started working. It requires some maintenance. We need to make some adjustments for some use cases, or we might need to implement upgrades that require downtime. 

What's my experience with pricing, setup cost, and licensing?

CrowdStrike Falcon is expensive because it's based on the number of services. 

What other advice do I have?

I rate CrowdStrike Falcon 10 out of 10. It has delivered some good results. 

Which deployment model are you using for this solution?

On-premises