Provides effective real-time threat detection with potential for cost optimization
What is our primary use case?
We are protecting our endpoints, workstations, servers, and cloud workloads. This includes effective use of antivirus and detection and response capabilities.
I am working at Arab Open University, and we are using CrowdStrike Falcon as our security product.
What is most valuable?
The most beneficial part is the active response capability of the product. Being an EDR solution, it helps us identify attacks in real-time. The product runs in the background 24/7. The most interesting aspect is the behavior analysis functionality, which analyzes the behavior of any suspicious activity.
It identifies threats efficiently due to its built-in intelligence and AI capabilities, which has been extremely helpful for our organization.
What needs improvement?
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product.
We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
For how long have I used the solution?
We have been using the solution for almost four years.
What was my experience with deployment of the solution?
It is a straightforward plug-and-play deployment.
What do I think about the stability of the solution?
Sometimes there are minor glitches, approximately 1% of the time. The biggest issue occurred when every computer worldwide experienced a blue screen. However, they solved the problems and introduced a new feature for channel updates. This has been much more beneficial, and while human errors can occur in any product, we cannot solely blame CrowdStrike Falcon for such incidents.
How are customer service and support?
The customer service is good and efficient in terms of responding. They could improve by initiating calls for high-priority cases instead of just opening tickets. When we open a support ticket, they should call to discuss what happened and listen to our concerns.
How would you rate customer service and support?
How was the initial setup?
The setup is straightforward, and most of our integration is within the package. However, for the integration part, we need to purchase additional modules from CrowdStrike Falcon. If this functionality was included as a free standalone feature within the built-in solution, it would be more market competitive. Competitors such as SentinelOne and Microsoft Defender provide this functionality out of the box without additional charges.
What was our ROI?
We have not calculated the ROI extensively, as we typically only calculate it when there is dissatisfaction. On a scale of one to ten, the ROI would be five, which translates to approximately 60%.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit expensive.
Which other solutions did I evaluate?
We are using
Darktrace as an email security solution, not as an EDR.
What other advice do I have?
I would rate CrowdStrike Falcon a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Very good experience. Next level generation.
What do you like best about the product?
Ease of deployment, high detection rates.
What do you dislike about the product?
cost. depedency, complexity for beginners.
What problems is the product solving and how is that benefiting you?
Endpoints security and ransoware protection.
Prevent privilege escalation with highest credentials but have issues with updates
What is our primary use case?
We use the solution for Windows and non-Windows infrastructure. We have Falcon clients on all our machines.
How has it helped my organization?
We integrate with CyberArk, which includes DNA reporting, particularly for identifying old and ticket-based attacks. We’ve implemented this integration to receive risk-based scoring. Our strategy focuses on preventing privilege escalation, as our last major incident, NotPetya, resulted from this vulnerability. To address this, we’ve implemented measures through CyberArk and CrowdStrike.
What is most valuable?
When we encounter phishing attacks via email, we sandbox any reported items. Whenever a suspicious email is reported, we conduct sandboxing in CrowdStrike and block emails, domains, and IPs based on the resulting threat intelligence.
The most critical aspect is preventing privilege escalation, particularly for domain admins with the highest credentials. With our integration of CyberArk, passwords are never transmitted to the endpoint. Instead, a secure RDP file is created, and Falcon is used to prevent privilege escalation attempts.
What needs improvement?
As customers, we always update our systems whenever a new release is available, with clients connecting directly to the Internet for these updates. We have an agent who manages these updates on the clients, but as an organization, we don’t have control over them. CrowdStrike should assess the impact on endpoints before releasing such updates.
Our organization now seeks AI-based stock monitoring to prioritize thousands of alerts generated across various platforms. The AI integration is still in its early stages, so we would like to see Falcon develop tools that can integrate with multiple platforms and help identify the highest-priority alerts.
For how long have I used the solution?
I have been using CrowdStrike Falcon Threat Intelligence since 2017. We are using the latest version of the solution.
What do I think about the stability of the solution?
I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
The integration part is very good. CrowdStrike collaborates with most security vendors, so it's very easy to get one platform for our risk factors across the enterprise.
40 thousand devices are using this solution. We get many alerts from Falcon, sometimes from end users and sometimes from Internet-facing servers.
I rate the solution's scalability a nine out of ten.
How are customer service and support?
We struggle to get specialized resources from CrowdStrike in a few cases.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
CrowdStrike Falcon Black is an on-premise solution that was very complicated, so we faced performance issues. The main reason for the switch is the performance issues reported by multiple application owners.
How was the initial setup?
Initially, we faced many challenges because we had to open ports from each of our subnets to Falcon, as it’s a SaaS solution. Each client needs to communicate with Falcon servers for threat intelligence. Due to the complexity of our network, we had to carefully consider all security aspects when opening the external communication ports to Falcon.
It took 25 to 30 days to deploy it completely.
We began with our Tier 0 servers, which had the most critical and highest privileges. After securing those, we moved on to Tier 1 and Tier 2 as we continued deployment. Our approach was to first address the highest risk factors across the enterprise and then gradually move on to securing endpoints like user desktops and laptops.
I rate the initial setup as seven out of ten, where one is difficult, and ten is easy.
What about the implementation team?
We took professional services from CrowdStrike, so it was done in-house with only two people: one from the execution team and one from the cybersecurity team.
What was our ROI?
When we track the annual priority cases, especially the security incidents, we have made many improvements. That is ROI in terms of tracking security incidents.
What's my experience with pricing, setup cost, and licensing?
I rate the product’s pricing a six out of ten, where one is cheap and ten is expensive.
What other advice do I have?
Most customer requirements focus on email security, so we’ve implemented Mimecast. CrowdStrike Falcon integrates with Mimecast, allowing us to provide advanced security beyond Office 365’s capabilities. With DMARC in place, Falcon helps us identify domains that pose a risk to the organization.
I advise you to look for customer feedback, and then they should also look for Gartner and other industry leaders so you get the ranking.
Overall, I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Helps protect against malware and the maintenance is straightforward, but there are a lot of false positives
What is our primary use case?
Our organization relies on CrowdStrike, a standalone endpoint security solution, to safeguard our bare-metal machines. CrowdStrike continuously monitors for threats on all endpoints. If it detects any suspicious activity, such as malware or malicious processes, it immediately alerts us for investigation.
What is most valuable?
The malware protection is the most valuable feature of CrowdStrike Falcon.
What needs improvement?
The current database schema presents challenges and has potential for improvement.
The technical support response time can be improved.
There are a lot of false positives reported.
For how long have I used the solution?
I have been using CrowdStrike Falcon for almost four years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable.
How are customer service and support?
The technical support is good but the response time can be improved.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used VMware Carbon Black Endpoint. CrowdStrike Falcon is more of an EDR solution.
What other advice do I have?
I would rate CrowdStrike Falcon a seven out of ten.
The maintenance is straightforward.
CrowdStrike Falcon is deployed independently in our environment and we have 30 users.
While CrowdStrike Falcon offers valuable security tools for larger organizations with extensive infrastructure, its complexity might not be ideal for smaller businesses with limited IT resources.
Which deployment model are you using for this solution?
Public Cloud
great for detection of PUP and malware and minor issue.
What do you like best about the product?
OOTB the product is great for detection and prevention of mallwares and PUP. Comes with a lot of dashboards as well.
What do you dislike about the product?
Still missing some customation of specfic features and its hard to forward logs to 3rd party solution.
a lof of changes are occring which makes pages changed thier name quite frequently
What problems is the product solving and how is that benefiting you?
allows great visibility into endpoints with ability to response live to alerts.
Solution for Lack of visibility and threat hunting
What do you like best about the product?
1. Smaller or Mid-size companies does not have every single tool for incident analysis and incident response, so it’s not easy to find threat actor within their environment so Falcon Complete: Managed Detection and Response (mdr) can help the companies for analysis and incident response.
2. Falcon Complete Managed Detection and Response (mdr)’s Threat intelligence makes sure what’s going on inside and going outside of the company, MDR performs threat hunting to catch those little bugs in suspicious activity that’s going on in the company.
What do you dislike about the product?
Falcon Complete Managed Detection and Response (mdr)’s has access to your sensitive data or will have access to sensitive data to detect cyber-attacks or perform analysis and incident response.
What problems is the product solving and how is that benefiting you?
Smaller or Mid-size companies does not have that much budget to get every single tool for incident analysis and incident response, so it’s not easy to find threat actors within their environment so Managed Detection and Response (mdr) can help the companies for analysis and incident response.
Good but not optimal
What do you like best about the product?
It is a good and very intuitive solution to perform Threta intelligence and malware detonations in a sandbox
What do you dislike about the product?
Differently from the free solutions it offers just some little information more and the support
What problems is the product solving and how is that benefiting you?
We use it to perform malware analysis and threat intelligence, for example we insert the IoC in the solution and verify if it is malicious or not, continuing the investigation inside the solution given that it offers way to verify if some actors are connected to the IoC analyzed
Recommendations to others considering the product:
I suggest to perform a PoC of three solution to better choose the one best fit the company context, and for each perform a trial of 1 month
The Best is Yet to Come
What do you like best about the product?
Crowdstrike's Falcon does an excellent job in detecting malware and gives visibility into what the attack vector.
What do you dislike about the product?
Support for Mac's New OS, the new M1 chip and Linux support has been lacking.
What problems is the product solving and how is that benefiting you?
Complete security visibility into securing our endpoints and discovering if any of the endpoints have been compromised. Out of all our security tools Crowdstrike is usually the first to report about anomalous activity and in some cases has already prevented the attack.
Falcon!!
What do you like best about the product?
UI design and useful dashboards and log searches.
What do you dislike about the product?
Integration with splunk enterprise could be a bit smoother.
What problems is the product solving and how is that benefiting you?
We use the intelligence platform to check alerts and malicious content.