CrowdStrike Falcon and Cortex XSIAM both compete in the cybersecurity solution space, with CrowdStrike having a stronger emphasis on interactive endpoint security and Cortex focusing on integration and automation. CrowdStrike currently holds the upper hand in endpoint security, whereas Cortex leads in integration capabilities.
Features: CrowdStrike Falcon stands out for its robust EDR capabilities, AI-driven features, and minimal system impact, which secure endpoints effectively. Cortex XSIAM excels in extensive third-party integration and automated forensic analysis, making it a strong contender in network security operations. Both platforms provide comprehensive security solutions.
Room for Improvement: CrowdStrike Falcon should enhance report functionalities, improve native application support, and reduce false positives. Cortex XSIAM could benefit from performance optimization and expanding integration options. Both solutions require enhancements in different areas, with Falcon focusing on integration and reporting, and Cortex on performance optimization.
Ease of Deployment and Customer Service: CrowdStrike Falcon offers deployment flexibility across public, private, and hybrid clouds, including on-premises, but has mixed feedback on customer support, needing improvement in response times and ownership of cases. Cortex XSIAM mainly deploys on public cloud platforms and is noted for competent technical support.
Pricing and ROI: CrowdStrike Falcon, although more expensive, provides good value for larger enterprises with operational savings and integration flexibility. Cortex XSIAM has high pricing but offers reasonable value given its advanced features and integration abilities. Both platforms justify their costs through robust security benefits, with Falcon delivering more direct ROI and Cortex offering a comprehensive security suite.
It is ineffective in terms of responding to basic queries and addressing future requirements.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
Without proper integration, scaling up with more servers is meaningless.
When it comes to scalability, it is entirely based on premium models according to demand.
The product was easy to install and set up and worked right.
I have never seen instability in the CrowdStrike tool.
In terms of incident response automation, it is quite poor due to the lack of integration with all security tools, making manual intervention necessary.
Cortex could improve the detection and online resolution of security vulnerabilities.
False positive reductions are needed.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
It would be helpful if there were cost-cutting measures.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
The flexibility for creating manual workflows stands out.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
CrowdStrike has improved our incident response capabilities.
CrowdStrike provides a lot of visibility in their tool.
Cortex XSIAM acts as a critical element for SOC foundations, integrating SIEM and EDR capabilities, valued for threat detection and seamless security orchestration with Palo Alto Networks products.
Organizations find Cortex XSIAM beneficial for SOC foundations due to its capability to integrate SIEM and EDR tools, facilitating data collection, detection, and response. It connects with third-party data sources while reducing management effort and offering cost-effective alternatives to competitors like CrowdStrike and Trend Micro. Featuring automation and integration with Palo Alto Networks products, Cortex XSIAM enhances threat detection. Unified architecture allows a comprehensive view of attacks, further supported by machine learning and integration with existing vendor solutions, ensuring that users gain insights without significant manual log analysis.
What are Cortex XSIAM's key features?
What benefits are evident in Cortex XSIAM reviews?
Industries implement Cortex XSIAM mainly in technology-driven sectors where centralized endpoint protection and automation of forensic investigation are paramount. By integrating several third-party systems for incident response, companies in competitive markets leverage its attributes for heightened operational security efficiency. However, users note areas for improvement, such as Attack Surface Management and integration enhancements, to better suit tech-heavy industries needing extensive connectivity with cybersecurity solutions.
CrowdStrike Falcon provides endpoint protection and threat intelligence using a cloud-based platform for real-time detection and response. Its minimal impact on system performance and ease of deployment are key benefits along with advanced logging and reporting for compliance and forensic analysis.
CrowdStrike Falcon is known for its efficacy in identifying malware, ransomware, and sophisticated cyber threats. The platform's cloud-native architecture and advanced AI capabilities ensure comprehensive endpoint visibility and rapid response times. Users appreciate the lightweight agent and seamless deployment process, along with detailed reporting features. Integration with security tools and efficient customer support are essential features, although some users highlight high pricing, occasional detection delays, and challenges with integration. Frequent alerts and the mobile app's performance are areas for improvement.
What are the key features of CrowdStrike Falcon?
What are the benefits or ROI of CrowdStrike Falcon?
In industries like finance, healthcare, and retail, CrowdStrike Falcon is often used for critical security due to its robust threat detection capabilities. Financial firms value its rapid response and detailed reporting for compliance, while healthcare providers appreciate the minimal system performance impact. Retailers benefit from its comprehensive endpoint visibility and integration with other security tools.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.