Try our new research platform with insights from 80,000+ expert users

CrowdStrike Falcon Complete MDR vs Expel comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Complete...
Ranking in Managed Detection and Response (MDR)
1st
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
79
Ranking in other categories
No ranking in other categories
Expel
Ranking in Managed Detection and Response (MDR)
19th
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
1
Ranking in other categories
SOC as a Service (4th)
 

Mindshare comparison

As of April 2025, in the Managed Detection and Response (MDR) category, the mindshare of CrowdStrike Falcon Complete MDR is 14.1%, down from 15.3% compared to the previous year. The mindshare of Expel is 1.8%, down from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Managed Detection and Response (MDR)
 

Featured Reviews

Otis Brinson - PeerSpot reviewer
Helps users keep track of everything from one place
The most valuable features of the solution stem from the fact that we can track all of it in one place across all those different locations. Because it's cloud-based and reports up to the cloud, we also have access to the back end, and an incident response team monitors all incidents. We also have an escalation process in place. From my perspective, there are other pieces of CrowdStrike that the security architect team uses as well, but I don't get involved with those as much. I usually just wait for the end results or the notification if I need to get involved if there is an incident.
reviewer2578461 - PeerSpot reviewer
Rapid threat management and diverse technology integration for effective monitoring
Expel has made it easier for companies to monitor and manage various log sources. With its vast integration portfolio, customers can efficiently monitor diverse environments. Time to value is quick, as Expel can turn their service up very rapidly. They have both automated active responses and human processes that quicken threat resolution.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a cloud-based solution. You can easily scale it."
"I like Falcon's AI functionality and vulnerability management. That has been so helpful. Falcon Complete can manage vulnerabilities, quarantine threats, and do all kinds of forensic incident analysis. It's a lightweight solution that only uses 1% of the CPU, which is a game changer. Other EDRs have had high CPU usage."
"We've seen a tremendous improvement since implementing CrowdStrike Falcon. In the past few years, we were exposed to 30 different attacks, but now our environment is completely monitored, and everything is detected. It catches threats and attacks before they occur."
"CrowdStrike Falcon Complete has a very lightweight agent that provides signatureless detection protection from known and unknown malware or ransomware which is very useful."
"The features I have found valuable are artificial intelligence, which protects us against malicious forces of any kind, and device control through the remote execution tool."
"The threat response from this solution is very comprehensive. It not only allows us to detect the threat, but also to isolate it and check the recovery capability of the compromised system."
"It has good visibility, works well, and it is fast."
"The most valuable feature is the Managed Detection and Response."
"Their threat hunting protocol and process with AI and machine learning are strong, allowing for active and rapid responses."
 

Cons

"The only aspect where we've offered feedback for potential enhancement is essentially the user experience."
"At the moment, nothing is missing in CrowdStrike Falcon Complete. I'm amazed by it. It's perfect and I'm not aware of any other vendors that provide its features, but it would also depend on the configuration and policy management of the solution, for example, I can bring you an EDR solution and configure it badly, so it won't do anything. It also depends on the people, not just the technology you're obtaining, so this is the most important thing to do for all solutions, even for firewalls. You can obtain a firewall and if you permit everyone to go through it, then it's useless. What could be improved in CrowdStrike Falcon Complete is its management console. Currently, that console is on the cloud, so if the cloud is compromised, then the management console would also be compromised, and that's quite risky."
"People should be able to obtain training at any point of the engagement so that if somebody who doesn't have the basic knowledge is getting thrown into it, they are able to get trained, and CrowdStrike is able to help them out. CrowdStrike is really doing what they're supposed to be doing, but it is like anything else where they have to keep up on their research and development, or they'll fall behind. This is a fast-paced environment, and I've seen that vendors that were really good three years ago are terrible now. CrowdStrike is trying to stay ahead of the bad guys. They have AI. I have not had a problem with them missing anything. If they missed something, they should just make sure that they don't miss it again and understand why they missed it. I don't know if they did."
"The downside is that if you are using a device offline, not connected to the internet, you will potentially have exposure."
"Falcon Complete's user interface isn't very user-friendly, especially for writing rules."
"The installation could always be a bit easier. You need to install it manually at the endpoint."
"They are doing very well in continuously improving their product. The only thing is that it is completely cloud-based, and some customers don't really like that type of approach, but you can only provide such a solution when you have cloud-based intelligence. On the other end, we know that it is sometimes a breaking point for some of the customers. They could potentially have an on-prem or hybrid solution. Any antivirus needs to have its features updated. If there could be a relay between them, it would be helpful, but that's very hard to do. So, you either accept that approach and have the benefit with this little disadvantage."
"Like any other solution, a lower price would make CrowdStrike Falcon Complete more appealing."
"The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for management."
 

Pricing and Cost Advice

"The solution needs to have human involvement, they could improve by having more automation where the solution can take the necessary action on time and more accurately."
"CrowdStrike offers training at an additional cost, so many organizations wouldn't want that route."
"CrowdStrike is more expensive than SentinelOne. Licensing works on the number of agents and the modules you buy. CrowdStrike has different modules, such as Falcon, Falcon Overwatch, Falcon Complete, etc. The pricing depends upon the module that the customer wants. They have different Incident Response (IR) teams, which are very expensive."
"The pricing is a little bit expensive for our region."
"While CrowdStrike Falcon Complete is expensive, it offers great features and functionality."
"CrowdStrike has a reasonable price."
"The pricing could be lower."
"CrowdStrike Falcon Complete is expensive."
Information not available
report
Use our free recommendation engine to learn which Managed Detection and Response (MDR) solutions are best for your needs.
849,190 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Manufacturing Company
8%
Financial Services Firm
6%
Government
6%
Computer Software Company
19%
Financial Services Firm
10%
Manufacturing Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about CrowdStrike Falcon Complete?
It is a cloud-based solution. You can easily scale it.
What is your experience regarding pricing and costs for CrowdStrike Falcon Complete?
CrowdStrike has a reasonable price. It's a good price, but if CrowdStrike offered coupons or discounts on a monthly or quarterly basis, it would be more beneficial for smaller vendors trying to imp...
What needs improvement with CrowdStrike Falcon Complete?
There is room for improvement in the AI of CrowdStrike, known as Charlotte AI, which my team does not currently use. I have not had contact with it at this moment. Additionally, patch management in...
What is your experience regarding pricing and costs for Expel?
Expel's pricing has adapted as the market evolved and has become competitive over the past twelve months.
What needs improvement with Expel?
The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for m...
What is your primary use case for Expel?
I have experience reselling Expel. Customers often come to me wanting to evaluate multiple providers to make a choice based on their specific use cases, requirements, technology investments, and so...
 

Also Known As

Falcon Complete
Workbench, Expel SOC-as-a-Service
 

Overview

 

Sample Customers

Palm Beach State College, Mercedes-AMG, Pokemon, Telstra, Goldman Sachs, Zebra
Amanda Fennell CSO
Find out what your peers are saying about CrowdStrike, Huntress, Field Effect and others in Managed Detection and Response (MDR). Updated: April 2025.
849,190 professionals have used our research since 2012.