CrowdStrike Falcon is used for endpoint protection for businesses. It's used for identifying threats.
Business Development Manager - Security at a computer software company with 201-500 employees
Intelligent and easy to use endpoint protection and threat identification solution
Pros and Cons
- "Easy to use, intelligent, and stable threat detection software."
- "The installation process for this software needs to be simplified."
What is our primary use case?
What is most valuable?
Most of the entry-level security provisions are based on identification, but CrowdStrike Falcon is a market changer because it does not need any kind of signature to identify or update threats.
All organizations face the big challenge of maintaining and updating their security processes. They need to do the update, but then it doesn't go beyond 90%, so CrowdStrike Falcon moved away from the update requirement, so there won't be a need to upgrade for certain types of technology, or for new technology. Not needing to update means the job of maintaining the updates will be taken off the plate of the IT department, which could mean big relief for the customers.
CrowdStrike Falcon is able to identify threats based on processes, rather than looking at signatures and this is what I like about this solution.
I like that it's easy to use, as expected from any cloud solution. CrowdStrike Falcon is an intelligent solution. It's as good as the top solution in the market.
We haven't seen anybody complaining about CrowdStrike Falcon, and we haven't had any customer using this solution who had been attacked by ransomware, so this is proof of how good this solution is.
What needs improvement?
Setting up and installing CrowdStrike Falcon is not easy, so an area for improvement is for that process to be simplified.
For how long have I used the solution?
We've been using CrowdStrike Falcon for two years.
Buyer's Guide
CrowdStrike Falcon
January 2025
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
I find CrowdStrike Falcon a stable solution.
How was the initial setup?
Installing this solution was not easy. One challenge from the installation is that you always have to replace something, e.g. your Crowdstrike password, macros, etc., before you're able to complete the setup.
What other advice do I have?
We are not carrying CrowdStrike Falcon Complete because it's a managed service, so customers have not really gotten to that level. What we're working with is CrowdStrike Falcon.
Deployment of this solution took us three to five days. We have 2,000 users of CrowdStrike Falcon, and we have 110 different locations across India and some other parts of the world. We have people who manage this solution, but it doesn't require much managing, because the only challenge is removing the old solution, then replacing it with the new one.
I'm recommending CrowdStrike Falcon to other people who are looking into using it, because it's a good solution.
I'm rating CrowdStrike Falcon an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Cyber Security Analyst with 1,001-5,000 employees
Detailed incident reporting, stable, and the technical support team is well trained
Pros and Cons
- "The most valuable feature is the indicator of compromise, which show you what file was either quarantined or removed."
- "Any kind of integration that you want to do, such as using the API to connect to a SIEM, is complex and it will be expensive to do."
What is our primary use case?
The primary use case is digital security investigations using the dashboard.
How has it helped my organization?
Every week, a manager would look at a detailed report to see what kind of CrowdStrike incidents we had.
What is most valuable?
The most valuable feature is the indicator of compromise, which shows you what file was either quarantined or removed. It shows you the malicious files in question, as well as the exact time, the machine, the endpoint, and the host IP address. Everything you need to know is right there in a single dashboard.
What needs improvement?
Any kind of integration that you want to do, such as using the API to connect to a SIEM, is complex and it will be expensive to do. It is quite a pricey product.
For how long have I used the solution?
I used CrowdStrike Falcon in my last two cybersecurity jobs, over a period of at least two years.
What do I think about the stability of the solution?
The product is stable as a rock. I have never seen any crashes. When it came to patching updates, we were always notified. It is not Windows-based, but rather Linux or Unix-based. It was more stable than any Windows product.
What do I think about the scalability of the solution?
We had a small shop, so we never had any reason to scale.
How are customer service and technical support?
The technical support is pretty good. They're trained in their product and they have a system in place where if the first line of support does not resolve the issue, they are emailing us directly back and forth, and they'll hand over the problem from one shift to the next.
It is not very difficult to get in touch with the support team, although it does require clearance from whoever handles the money aspect. You have to be really careful because they will charge you fees for any kind of solution that they provide.
I have used them twice, once for each company that I was working for. The first time, we used the CrowdStrike service to do the investigation so that we could focus our time on other products. They have teams that will act like a managed service provider to take care of incidents. We handled major incidents in-house but we let them handle the minor ones.
With the second company, we had to do the investigations as the incidents came in, so it was two totally separate vantage points. Both worked extremely well in both manners and forms.
Which solution did I use previously and why did I switch?
CrowdStrike was already in place before I arrived, at both places where I have used it.
We were also using Carbon Black, as well as other tools, but they were not being used to the same degree. I think that we were using Carbon Black for white-listing applications.
I also spent a lot of time using Nessus, which is a vulnerability scanner. I would look at scans to see what kind of vulnerabilities were present, and patch management updates with other teams.
How was the initial setup?
I was not there for the initial setup, but what I did learn was that the implementation team came in and worked with our engineering team. They set it up and then our team verified that all of the endpoints where there and that we had the visibility we needed for all of the subnets in all of the locations.
When I spoke with my teammate, I was told that it was pretty much straightforward and out of the box. The fact that it is a cloud-based deployment made it easier, too.
What's my experience with pricing, setup cost, and licensing?
Our licensing fees were between $50,000 and $60,000 per year, which was pretty expensive for a small business. It is not a one-time payment. Any upgrades that you want to do, you're going to have to pay multiple times.
What other advice do I have?
My advice for anybody who is implementing CrowdStrike Falcon is to get in touch with the vendor and then follow best practices. They have a lot of documentation and everything is there. For the most part, I would suggest looking at the technical support documentation first and then contacting a representative at the vendor to continue the process.
Most companies have it integrated with the SIEM and with their ticketing system, although I did not use it in that capacity because it costs more money.
Most of the time, you're not going to have to lay a finger. Once it finds an infected file, you might have to reboot the computer if it can't immediately remove it, or other such minor stuff. In general, however, it's never given me any issues and it's never given me a headache. Overall, it's very straightforward and just one tool out of the whole.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
CrowdStrike Falcon
January 2025
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
CTSO at Cyb3r
Provides efficient security posture and has diverse threat intelligence capabilities
Pros and Cons
- "The platform is very scalable."
- "Enhancements in reporting and forensic analysis could benefit the product."
What is our primary use case?
Our primary use case for the product is to enhance our threat intelligence capabilities. We use it to ensure comprehensive security coverage.
How has it helped my organization?
The solution has significantly improved our threat detection capabilities. It has helped us identify and respond to potential threats more effectively, contributing to our security posture. There have been no notable drawbacks; the solution meets our needs and complies with local regulations.
What is most valuable?
The product's most valuable features include its global reach and extensive threat data. Its wide exposure helps gather diverse threat intelligence, crucial for effective security management.
What needs improvement?
Enhancements in reporting and forensic analysis could benefit the product. CrowdStrike could publish detailed threat reports and analyses more consistently than other providers.
For how long have I used the solution?
I have been using CrowdStrike Falcon Threat Intelligence since early 2016.
What do I think about the stability of the solution?
I rate the platform's stability an eight.
What do I think about the scalability of the solution?
The platform is very scalable. It can effectively accommodate growing security needs, which is crucial for organizations with evolving threat landscapes.
How are customer service and support?
Customer service and support vary based on the level of service. Premium support is excellent, but standard support can be less responsive.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used a different solution. We switched to CrowdStrike due to its comprehensive threat intelligence capabilities and global reach, which we found to be more effective for our needs.
How was the initial setup?
The initial setup was straightforward, with the installation taking less than two hours. However, fine-tuning alerts and configuring rules required additional time and effort.
What about the implementation team?
The implementation was carried out in-house.
What was our ROI?
The product has helped us detect threats that might have gone unnoticed, contributing to overall security.
What's my experience with pricing, setup cost, and licensing?
The product is expensive.
Which other solutions did I evaluate?
We evaluated several other options before choosing CrowdStrike. Our decision was based on the product's effectiveness and ability to meet our security requirements.
What other advice do I have?
Overall, it is a robust solution that meets our security needs. However, potential users should know the cost implications and ensure the product meets their requirements.
I rate it an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Last updated: Aug 3, 2024
Flag as inappropriateCloud Operations Center Analyst at a pharma/biotech company with 10,001+ employees
Easy to set up with good vulnerability monitoring but the performance could be better
Pros and Cons
- "It's very easy to set up."
- "The performance could be better."
What is our primary use case?
The solution is for alerts. It will trigger if there is malicious traffic or some scripting attack. Any attack that is there, then it'll alert automatically.
What is most valuable?
We can protect against the worst level of attacks. We can see everything from the dashboard.
The vulnerability monitoring is great.
It's very easy to set up.
What needs improvement?
The performance could be better. It's a bit slow. When we click to launch the dashboard, it should be more responsive.
For how long have I used the solution?
I've been using the solution for the last six months.
What do I think about the stability of the solution?
The performance could be better. It's a little bit slow.
It's not very stable. We can't seem to support the latest version.
What do I think about the scalability of the solution?
We don't really handle the scaling. I can't speak to that aspect of the product.
We have about 300 to 400 agents running.
How are customer service and support?
Technical support is great.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did previously use a different solution. The security team made the decision to switch. It wasn't a decision from an operations standpoint.
How was the initial setup?
We just install the agent and whatever other notes you need to monitor.
It is straightforward to set up the solution.
There's no deployment. We just run the agents and those will take care the deployments. The security team will take care of the deployment part. Therefore, we just install the agents and hand over the environment to them. They will monitor everything.
What about the implementation team?
We don't need any outside help, really. Mostly they will give you the links and how you need to deploy everything. Based on that information, we'll follow that advice.
What's my experience with pricing, setup cost, and licensing?
I'm not sure of the exact cost of the solution.
What other advice do I have?
We are on the latest update of the solution.
There isn't really any specific knowledge required to use CrowdStrike, apart from maybe general knowledge of cyber security.
I'd rate the solution seven out of ten. If it had better performance, I would rate it higher.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of IT Department at a pharma/biotech company with 10,001+ employees
Effective cyber attack prevention, light on resource, and great user expereince
Pros and Cons
- "The most valuable feature is the machine learning that they use to check certain patterns in the endpoint devices. It checks the whole ecosystem or entire environment."
What is our primary use case?
CrowdStrike Falcon is leading the market in EDR. They are the first that to have this kind of solution against malware. They have an advantage in respect to the rest of the competitors. They offer a certain amount to protect in case of malware or cyber-attacks. They have a policy or insurance connected to the service. That's the reason why we choose CrowdStrike over other solutions.
What is most valuable?
The most valuable feature is the machine learning that they use to check certain patterns in the endpoint devices. It checks the whole ecosystem or entire environment.
I am very happy with CrowdStrike Falcon because it does not use a lot of resources in the endpoint, it's a lightweight solution. It provides good protection and it is very effective. Additionally, it is easy to integrate, has great features, good capabilities, and the users have a positive experience.
For how long have I used the solution?
I have been using CrowdStrike Falcon for approximately one year.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
I have found CrowdStrike Falcon to be scalable.
How are customer service and support?
I have not needed to use technical support.
What's my experience with pricing, setup cost, and licensing?
The cost of CrowdStrike Falcon could be reduced. It is quite expensive if you compare it to other solutions, such as Blue Coat, Symantec, McAfee, or Kaspersky.
What other advice do I have?
My advice to those wanting to use CrowdStrike Falcon is to try it out to see if it works well in their environment. I consider CrowdStrike Falcon is a very accurate solution. They are confident about the capabilities of their solutions because they offer money or payback if there is a high-impact cyber incident or cyberattack while using the solution.
They need to have special consideration about the different plans and budgets that they need to get the solution that they want.
I rate CrowdStrike Falcon a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of Cloud Architecture at a energy/utilities company with 10,001+ employees
We are happy with its ease of use and touch notification
Pros and Cons
- "We have seen a reduction to the performance hit to our operating systems."
- "We are happy with CloudStrike's ease of use and touch notification."
- "We have had to open a case with the technical support to get some issues and bugs resolved."
What is our primary use case?
We use it for threat management.
How has it helped my organization?
We are now able to pick up more alerts than we were with McAfee. A lot of things were being missed by our security team using McAfee.
We are happier with CloudStrike's ease of use and touch notification than McAfee's.
What is most valuable?
I noticed that the performance hits on our operating systems are a more minimal than they were on McAfee.
What needs improvement?
We have had to open a case with the technical support to get some issues and bugs resolved, but they were resolved relatively quickly.
For how long have I used the solution?
Less than one year.
What do I think about the scalability of the solution?
The scalability has been good so far. We have been using it on-premise and on the cloud. We can move it to a different cloud platform, because it is cloud agnostic.
Which solution did I use previously and why did I switch?
We just moved over from McAfee to CrowdStrike, which detected a lot of things that McAfee did not. We detected a malicious code on our on-premise system, even though we are migrating our application to the cloud. It was able to detect it right away to send us what the code had tried change and execute.
Our company decided to make the switch between the two products, and I have seen the value-add since then.
How was the initial setup?
It was pretty easy to set up. We baked it into our subscripts during the start-up process.
Its integration has been pretty seamless.
What other advice do I have?
I would anyone to look at this product based on our company's experience so far.
We have both the on-premise and AWS versions of the product.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Product Manager at a comms service provider with 51-200 employees
A highly stable solution that provides EDR and security functionalities to its users
Pros and Cons
- "The solution offers great stability."
- "CrowdStrike Falcon needs to improve their host management system."
What is our primary use case?
I use CrowdStrike Falcon for EDR and security purposes. Also, I am using file integrity monitoring, asset management, and patch management modules. Additionally, I'm also utilizing an identity protection module.
What needs improvement?
CrowdStrike Falcon needs to improve their host management system.
For how long have I used the solution?
I have been using CrowdStrike Falcon for a year and a half. I am using the latest version. I am a partner of CrowdStrike.
What do I think about the stability of the solution?
The solution offers great stability. I have faced no issues with the tool.
What do I think about the scalability of the solution?
There are 5,000 users using the solution.
How are customer service and support?
I only contacted technical support to ask a few questions, and they helped me out.
How was the initial setup?
The solution's initial setup process was easy. The deployment process took only 10 hours for 5,000 clients.
What's my experience with pricing, setup cost, and licensing?
The tool is a little bit expensive compared to other products, but I think it's okay owing to its quality.
What other advice do I have?
Protection has been good in the solution. I got only one false positive in a year and a half, which is great.
There is no suggestion to provide because it is easy to implement, and there are no exclusions or testing required. If you plan to try it, it should work well without any issues.
Overall, I rate the product a nine point seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
DGM IT at Union Bank of Colombo
A highly scalable solution that offers robust protection, and good management functions
Pros and Cons
- "As an EDR tool, we can integrate log management and event management. The solution deals with threats automatically, that's the advantage."
- "I would like to see equal support across all versions. Aside from that, I would say most of the features are there."
What is our primary use case?
We use CrowdStrike for endpoint protection.
What is most valuable?
As an EDR tool, we can integrate log management and event management. The solution deals with threats automatically, that's the advantage.
What needs improvement?
I would like to see equal support across all versions. Aside from that, I would say most of the features are there.
For how long have I used the solution?
We have been working with the solution for six months.
What do I think about the stability of the solution?
Yes, CrowdStrike is stable.
What do I think about the scalability of the solution?
The solution is scalable, we have 1900 users.
How are customer service and support?
We have only required our local support, they have been sufficient for our needs.
Which solution did I use previously and why did I switch?
We previously used a Symantec product, but there was no local vendor support so we switched to CrowdStrike Falcon.
How was the initial setup?
The initial setup is straightforward, we deployed in two to three weeks.
What about the implementation team?
We implemented the solution through our vendor, they proposed the solution.
What was our ROI?
As the solution is a preventative measure, it's hard to say exactly what the ROI is.
What's my experience with pricing, setup cost, and licensing?
We have a yearly subscription and find the price to be good. I'd give it a rating of four out of five for price, we got a good discount.
What other advice do I have?
I would rate this solution an eight out of ten. There is still some grey area for us, as we haven't been using the product long enough to give a full evaluation of all the features.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Endpoint Detection and Response (EDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Identity Management (IM) Threat Intelligence Platforms Active Directory Management Extended Detection and Response (XDR) Attack Surface Management (ASM) Ransomware Protection Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Cisco Secure Endpoint
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
Check Point Harmony Endpoint
Trend Vision One
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?