We use CrowdStrike Falcon as a managed SOC for intrusion detection on our endpoints.

External reviews
External reviews are not included in the AWS star rating for the product.
Is a flexible, fully managed service, and provides peace of mind
What is our primary use case?
How has it helped my organization?
Being a cloud-native solution, CrowdStrike Falcon provides flexibility and always-on protection. This is extremely important to have the best protection available.
It is a fully managed service, so they provide all the necessary updates for us which is helpful.
While CrowdStrike Falcon provides us with better peace of mind in terms of protection, it also generates alerts for potential threats, requiring our investigation. However, the platform further alleviates our anxiety by automatically reviewing unaddressed alerts, offering an additional layer of security. This coverage fosters a heightened sense of security.
CrowdStrike Falcon has been instrumental in preventing breaches, allowing us to operate with significantly increased security compared to the past. This has provided us with much greater peace of mind. While no security solution is foolproof, Falcon has brought us remarkably close.
What is most valuable?
The anomaly detection is the most valuable feature.
What needs improvement?
The portal can be clunky to navigate at times and has room for improvement.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
I would rate the stability of CrowdStrike Falcon a nine out of ten. The only issue I have had is with an old version of the endpoint that was installed and has proven to be problematic.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable.
How are customer service and support?
The technical support is good and they provide prompt responses to all of our questions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We implemented CrowdStrike Falcon in response to a security incident. It was the first endpoint detection and response service we had ever used, and we've been utilizing it since 2021.
How was the initial setup?
Deploying the sensors to our endpoints is straightforward. We do have a manual process for deploying the sensors to our endpoints. There are also options to do it through a group policy. It doesn't seem overly complex.
We rolled the solution out to our entire estate which took just over one week. We had up to 300 endpoints and required a team of five people to complete the deployment.
What was our ROI?
CrowdStrike Falcon enables us to save on resources which in turn provides a 20 percent return on investment.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon offers excellent value for the money for our organization, particularly given our lean IT team. We lack the resources to replicate the full security services they provide without hiring additional personnel. The cost of Falcon is likely comparable to, or even less than, the salary and benefits we'd need for an extra employee. Furthermore, their on-call experts have more expertise, further enhancing the value proposition.
Which other solutions did I evaluate?
After a year, we reevaluated our endpoint security solution. We considered several options, including Arctic Wolf, SentinelOne, and Darktrace, alongside our existing Fortinet solutions. We participated in demos and ultimately determined that CrowdStrike's offering, both current and future, remained the best fit. While we hadn't initially explored other options before choosing CrowdStrike, external factors subsequently forced our hand. However, after a year of use and further evaluation, we reaffirmed our decision, concluding that CrowdStrike was still the most suitable solution for our needs.
What other advice do I have?
I would rate CrowdStrike Falcon a nine out of ten.
We have around 300 endpoints and three people who have access to the solution.
Three people are required for maintenance.
CrowdStrike Falcon was recommended by our head office in Germany.
I recommend CrowdStrike Falcon.
Has great threat intelligence, integrates well, and scales to our needs
What is our primary use case?
We use CrowdStrike Falcon as an XDR to replace our old antivirus solution.
We implemented CrowdStrike Falcon for better visibility into our environment and easy online access to the policies.
How has it helped my organization?
CrowdStrike Falcon's cybersecurity background allows for better integration with other tools.
What is most valuable?
The threat intelligence is the most valuable feature.
What needs improvement?
The support for different OS versions needs improvement because sometimes due to business conditions, updating our OS is impossible. For example, I have a production environment connected to the PNC that runs Windows XP on computers that CrowdStrike Falcon does not support.
For how long have I used the solution?
I have been using CrowdStrike Falcon for six years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
CrowdStrike Falcon has been able to scale to our needs with no issues.
How was the initial setup?
The initial deployment was straightforward. The deployment took one day to complete. Ten people were involved in the deployment.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon's price is good. I am looking for other partners and compared to Microsoft Defender and other vendors the price is lower.
What other advice do I have?
I would rate CrowdStrike Falcon a then out of ten.
Before purchasing CrowdStrike Falcon I suggest checking the policies, particularly those regarding internet connections, and conducting a proof of concept.
Which deployment model are you using for this solution?
Used few system resources, can easily isolate infected machines, and add modules
What is our primary use case?
We use CrowdStrike Falcon for endpoint security and response, and Horizon to manage and protect our data.
Following a 2021 security incident, the general response team recommended implementing CrowdStrike. We adopted their suggestion and found its network threat detection and prevention capabilities invaluable.
What is most valuable?
I like the feature called RTC, the remote time connector. It allows us to connect to a computer via the command line and execute commands for various functions and investigations. This eliminates the need for any additional programs. We can launch the connection and its subcommands from a single console.
The containment feature is another valuable tool. It allows us to isolate any machine exhibiting suspicious behavior or facing a detected threat. Once activated, containment immediately severs the machine's network connection and blocks user access.
What needs improvement?
Despite implementing tuning rules specifically designed to address them, we are still encountering a significant number of false positives. This issue persists even after collaborating with their support team to find a solution.
I have worked with their technical support on several problems that were never fully resolved.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
While we encountered some bugs with on-demand scanning, the overall performance and stability of the system are positive. CrowdStrike Falcon is less resource-intensive than our old McAfee solution, which often led to performance complaints due to its high memory consumption.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable. Adding new features or licenses to CrowdStrike Falcon is seamless, with no disruption to our system's performance. Installing new modules is easy because it uses the same sensor.
How are customer service and support?
While I've found screen sharing helpful with other support teams, CrowdStrike's technical support has never proactively suggested it. Instead, they've always initiated contact by calling me back after I submitted a ticket. We recently offered to screen share, but it seems it's not their preferred method. The support is good but it is not the best I have used.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we utilized Carbon Black for our endpoint security needs. However, we transitioned to CrowdStrike for several compelling reasons. As a prominent market competitor with widespread adoption among organizations, CrowdStrike offered a robust platform capable of meeting our evolving security requirements.
The 2021 incident further underscored the importance of robust security tools. CrowdStrike's capabilities proved invaluable in navigating the aftermath and instilled confidence in its continued effectiveness for future challenges.
Beyond its proven track record, CrowdStrike seamlessly integrates with our existing security ecosystem. The platform's comprehensive feature set simplifies endpoint management from a centralized console. Additionally, its granular telemetry across various modules provides invaluable insights during incident detection, enabling us to gather holistic information from each affected machine.
Furthermore, CrowdStrike consolidates our security stack by encompassing next-generation firewalls, endpoint detection and response, and real-time endpoint scanning, eliminating the need for separate solutions like McAfee. This streamlined approach enhances operational efficiency and simplifies security management.
How was the initial setup?
The initial deployment presented some challenges due to the need to install the solution on all machines. This phase, requiring careful coordination among ten people over several weeks, involved connecting all the computers to the network. However, once this foundation was laid, the subsequent rollout proceeded smoothly.
What about the implementation team?
The implementation was completed in-house by our people.
What was our ROI?
The return on investment is evident in the enhanced security posture achieved through continuous monitoring and immediate isolation of compromised machines. This proactive approach not only mitigates risk but also provides significant peace of mind for our team, alleviating concerns and optimizing their performance.
What's my experience with pricing, setup cost, and licensing?
While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours.
What other advice do I have?
I would rate CrowdStrike Falcon a nine out of ten.
CrowdStrike Falcon is a great tool. Investing in proper training on the CrowdStrike Falcon platform is highly recommended for any organization seeking to maximize its potential and avoid navigation struggles within the console. However, it's important to note that effective utilization of Falcon without CrowdStrike's managed services necessitates the formation of a dedicated team responsible for managing the solution.
Which deployment model are you using for this solution?
Great experience
Very good product
1. Identity Monitoring: It continuously monitors various data sources to detect any signs of identity theft or fraud, such as unauthorized use of your personal information.
2. Credit Monitoring: It keeps an eye on your credit reports and alerts you to any significant changes, helping you catch potential issues early.
3. Dark Web Monitoring: Falcon Identity Protection scans the dark web for your personal information, helping you stay informed if your data appears in suspicious places.
4. Identity Theft Resolution: If you become a victim of identity theft, the service provides assistance and support to help you resolve the situation and restore your identity.
5. Insurance Coverage: Some identity protection services offer insurance coverage to help cover expenses related to identity theft, such as legal fees or lost wages.
6. Customer Support: Many services have dedicated customer support teams to assist you with any questions or concerns you may have.
Please note that the specific features and benefits may vary depending on the identity protection service provider. It's essential to research and choose a service that best suits your needs and preferences.
1. Cost: These services typically come with a monthly or annual fee, which can add up over time.
2. Limited Coverage: Identity protection services can't guarantee complete protection against all forms of identity theft or fraud. They may focus on specific areas like credit monitoring or dark web scans, leaving some vulnerabilities unaddressed.
3. False Alarms: Sometimes, these services can generate false alerts, causing unnecessary concern or inconvenience.
4. Data Privacy: You need to share personal information with the service, which raises concerns about data privacy and security. Ensure you trust the provider and understand their data handling practices.
5. DIY Alternatives: Some of the features offered by identity protection services, like monitoring your credit reports, can be done independently for free. It may be more cost-effective to manage these tasks yourself.
6. No Preventative Measures: These services can help you detect identity theft, but they don't proactively prevent it.
7. Complexity: Depending on the service, there can be a learning curve in understanding how to use all of its features effectively.
Before choosing an identity protection service, carefully evaluate the pros and cons to determine if it's the right solution for your needs. Additionally, consider alternatives, such as monitoring your credit reports independently and implementing strong security practices to protect your identity.
1. **Identity Theft Detection**: Falcon Identity Protection helps detect signs of identity theft early, such as unauthorized use of your personal information. This can prevent more significant financial and personal losses.
2. **Credit Monitoring**: By monitoring your credit reports, it can alert you to any suspicious activity or unauthorized credit inquiries, allowing you to take action promptly.
3. **Dark Web Monitoring**: The service scans the dark web for your personal information, which can help you become aware if your data is being traded or used illegally.
4. **Resolution Assistance**: In the unfortunate event of identity theft, the service offers support in resolving the issues, which can be a complex and time-consuming process on your own.
5. **Peace of Mind**: Knowing that your identity is being actively monitored can provide peace of mind, reducing stress related to identity theft concerns.
6. **Insurance Coverage**: Some identity protection services offer insurance coverage to help cover the costs associated with identity theft, providing financial protection.
The benefits of Falcon Identity Protection and similar services are that they provide a layer of security and support in an increasingly digital world where identity theft is a prevalent concern. They can save you time and effort in monitoring your personal information and provide guidance in case of a security breach. However, it's essential to weigh these benefits against the cost and potential limitations of the service to determine if it's a worthwhile investment for your specific situation.
Falcon Identity: A Powerful Threat Protection Platfrom
Falcon Identity Protection - Good for End user behaviour analytics
2. Good threat hunting of user authentication events.
3. Offers good connectivity to Windows domain controllers with a single-agent deployment.