No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2894505 - PeerSpot reviewer
Security Analyst at a manufacturing company with 501-1,000 employees
Real User
Top 20
Sep 1, 2026
Always-on threat hunting has transformed how my team detects and responds to critical attacks
Pros and Cons
  • "CrowdStrike Falcon has positively impacted my organization by helping stop many breaches, and they are very good at alerting and following and escalating during critical alerts."

    What is our primary use case?

    My main use case for CrowdStrike Falcon is to remediate any time someone downloads something malicious. I tend to remediate it and check in on the users to make sure there are no false positives. If it is something malicious, then I have to triage it.

    A specific example of when I used CrowdStrike Falcon was when someone had downloaded something that they were not supposed to download. I looked at the hash value, saw that it was malicious, reached out to the user, warned them to exercise caution, and from there, they removed it and our IT team scanned their device.

    What is most valuable?

    The best features CrowdStrike Falcon offers include their 24/7 team that is always watching us and their next-generation team that is always actively threat hunting.

    What I appreciate about the 24/7 team and the next-generation team specifically is that during the time I am not working and on the weekends when I am not working, the people are able to watch over my company and my users and help me so I do not have to worry.

    CrowdStrike Falcon has positively impacted my organization by helping stop many breaches, and they are very good at alerting and following and escalating during critical alerts.

    A specific outcome that shows Falcon's positive impact is that they have called me around midnight several times when I would not often be working, but it was a critical alert, and they have saved the day due to escalating their policy.

    What needs improvement?

    To improve CrowdStrike Falcon, I suggest continuing what you are doing, continuing with customer support and checking quarterly schedules, and everything will be good.

    For how long have I used the solution?

    I have been working in my current field for about two and a half years.

    Buyer's Guide
    CrowdStrike Falcon
    September 2026
    Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
    912,788 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    CrowdStrike Falcon is stable.

    What do I think about the scalability of the solution?

    CrowdStrike Falcon's scalability is very good and very reliable.

    How are customer service and support?

    The customer support from CrowdStrike Falcon is very good and very trustworthy.

    What other advice do I have?

    I would rate CrowdStrike Falcon a 10 out of 10.

    I give CrowdStrike Falcon a 10 because they do what needs to be done and they do what we ordered it to do.

    Regarding CrowdStrike Falcon's AI capabilities, I think it has been doing well. I think everything with AI could always improve, but its capabilities right now have been good and sufficient.

    I think CrowdStrike Falcon's AI capabilities in terms of accuracy and reliability of its output are quite impressive, as Charlotte has been very descriptive any time an alert occurs, and the AI is doing very well at breaking down what needs to be done, including next steps and what happened in the alert.

    Using Falcon platform has changed the way my security team detects, investigates, and responds to threats by escalating detections and responding on our end because CrowdStrike already gives us the breakdown of what has happened.

    The benefits I have seen from having multiple security capabilities on a single platform include saving time and preventing us from constantly going to different multiple platforms, as we could just all look at one platform.

    A security incident where Falcon helped my team detect or stop a threat was during the time of the DPRK, North Korean attack, and they helped stop and prevent that.

    The impact that the Falcon sensor has had on endpoint performance and my ability to deploy security at scale is that the endpoint Falcon sensor has helped keep visibility into any and all devices that we have.

    I am using AI within Falcon platform to monitor which users use AIs and to make sure they are only using permitted AI, not every AI out there.

    What differentiates Falcon from other cybersecurity platforms I have used or evaluated is that they are constantly doing well and they have never let us down.

    The advice I would give to others looking into using CrowdStrike Falcon is to please hurry this process up, but trust Falcon, use the demo and attend their events, and you will appreciate the product.

    I am giving this review an overall rating of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 1, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2895027 - PeerSpot reviewer
    Security Operations at a financial services firm with 5,001-10,000 employees
    Real User
    Top 10
    Sep 4, 2026
    Platform has transformed threat detection speed and reduced false positives for my team
    Pros and Cons
    • "CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements."

      What is our primary use case?

      My main use cases for CrowdStrike Falcon include detecting malicious behavior and identifying user trends.

      Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making it faster and easier to respond to advanced threats.

      In a security incident, CrowdStrike Falcon helps my team detect or stop threats by assisting in detecting unauthorized use of local binaries, such as those that are natively installed including PowerShell and scheduled tasks.

      What is most valuable?

      The benefits I have seen from multiple security capabilities on a single platform include solid control over consolidated information that can be accessed quickly.

      I believe the value of having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform lies in the correlation of these different data sources, which is essential to identifying and disrupting advanced threats.

      CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements. These improvements result from having fewer false positives, which means more time spent working on real, high-impact work.

      CrowdStrike Falcon makes every analyst much more effective and informed than they would have been otherwise.

      What needs improvement?

      CrowdStrike Falcon can be improved by continuing to listen to customer feedback.

      I believe that more integrations and support for Mac products should be included in the next release.

      For how long have I used the solution?

      I have been using CrowdStrike Falcon for three years.

      What do I think about the stability of the solution?

      I assess the stability and reliability of CrowdStrike Falcon as reliable ever since the massive incident occurred.

      I have not experienced any downtime, crashes, or performance issues.

      What do I think about the scalability of the solution?

      The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is none; it is a force accelerator.

      How are customer service and support?

      I evaluate customer service and technical support as excellent.

      Which solution did I use previously and why did I switch?

      CrowdStrike Falcon has allowed me to consolidate or replace other security tools. The tools I replaced were those provided by legacy vendors, which operated for the sole purpose of one or two functions, and they were able to be replaced through the flexible approaches that CrowdStrike Falcon provides.

      How was the initial setup?

      I would describe my experience with deploying CrowdStrike Falcon as easy and effective. What worked well includes the solid deployment process, though communication with lay users is always a challenge, which I would say resulted in limited to no issues.

      What was our ROI?

      I have seen return on investment with CrowdStrike Falcon.

      What other advice do I have?

      I would rate CrowdStrike Falcon an eight on a scale from one to ten, as nothing is perfect. My advice to other organizations considering CrowdStrike Falcon is to adopt now or adopt later. I provided an overall review rating of eight.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 4, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      CrowdStrike Falcon
      September 2026
      Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
      912,788 professionals have used our research since 2012.
      reviewer2895060 - PeerSpot reviewer
      Senior DevSecOps Engineer at a tech vendor with 1,001-5,000 employees
      Real User
      Top 20
      Sep 2, 2026
      Endpoint investigations have become faster and have prevented recurring malware incidents
      Pros and Cons
      • "Where previous incidents that CrowdStrike Falcon has now stopped used to take anywhere from two to five hours to get contained and remediated, now they are prevented."
      • "Training is the biggest thing that could be improved; there is not a lot of training, and it is not that accessible."

      What is our primary use case?

      My main use case for CrowdStrike Falcon is endpoint detection and response.

      What is most valuable?

      The best features CrowdStrike Falcon offers are the ease of use and accessibility in the console, making it a very easy-to-use tool from an analyst's perspective.

      The way that everything is laid out and the way that the detections are formatted, giving you the different types of process graphs and process tree details, especially with Charlotte AI, really helps smooth everything out.

      Having all of the data correlated in the same spot makes an investigation really easy.

      It makes investigations a lot easier; anything that is on the endpoints and reaches up to the cloud, you can find that very easily.

      What needs improvement?

      Training is the biggest thing that could be improved; there is not a lot of training, and it is not that accessible.

      The ability to implement profile groups requires SCIM to be configured. SCIM is not in the documentation. SCIM is required if you want to do just-in-time access provisioning for profile groups for new users, and that is not in the documentation. It took a lot of communication with support to figure that out.

      The AI detections on anything about a severity five or lower could be improved; many of those are more on the informational side. There have not been too many with a severity of five or lower, detection-wise, that have actually been useful as an analyst.

      For how long have I used the solution?

      I have been using CrowdStrike Falcon since 2021.

      What do I think about the scalability of the solution?

      We have had no issues with how it scales.

      How are customer service and support?

      Customer support in our government environment is quite fast, but customer support in the commercial or non-government environment is slow and not necessarily the most knowledgeable until you get higher up and the ticket gets escalated higher up.

      Which solution did I use previously and why did I switch?

      It has not necessarily changed anything because we have been using CrowdStrike Falcon since the formation of our team; we have almost always had CrowdStrike Falcon. There was not anything coming before that, but it definitely makes the flow a lot easier with how our team is set up.

      How was the initial setup?

      The endpoint agent for the commercial endpoints, Windows and Mac, has been very easy; the rollout has not caused any issues, but the deployment in the various clouds has caused some difficulty due to deployments not being standardized across all three major cloud platforms.

      What was our ROI?

      We definitely have had time saved; where previous incidents that CrowdStrike Falcon has now stopped used to take anywhere from two to five hours to get contained and remediated, now they are prevented.

      Which other solutions did I evaluate?

      We evaluated at least 15 different options, and CrowdStrike Falcon by far was the best.

      What other advice do I have?

      I monitor our endpoints across Windows, Mac, and Linux, and I identify any malicious software or unapproved software that comes up and is blocked by the platform.

      I also use CrowdStrike Falcon for a rudimentary asset inventory and checking out what types of shadow IT and applications are installed across my network.

      CrowdStrike Falcon has stopped a lot of malware from being executed on user devices.

      I estimate we have had about 20 incidents over the past year that were prevented by CrowdStrike Falcon.

      The workload has not necessarily gone down; the detections that are created are reviewed now, but there is almost nothing that needs to be done other than having the device wiped.

      I am using Charlotte AI to help craft better queries for Falcon Fusion.

      We have purchased at least five different add-ons to increase the overall insight into everything in the company. Using Falcon for IT, we have been able to identify and assess different application-based risks on our user endpoints.

      I would advise anyone to dive in and get comfortable with the console; there is a lot of information in there that you need to figure out, and it is pretty easy to figure out. I would rate this product a 9 out of 10.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 2, 2026
      Flag as inappropriate
      PeerSpot user
      Ashutosh Jha - PeerSpot reviewer
      Project Engineer at IT Solution
      Real User
      Top 5Leaderboard
      Mar 14, 2026
      Endpoint protection has blocked ransomware and malware and gives me real-time control
      Pros and Cons
      • "CrowdStrike Falcon features are robust and reliable."
      • "As of now, CrowdStrike Falcon does not have application control and web control."

      What is our primary use case?

      I am using CrowdStrike Falcon because I want to secure my end-user devices.

      What is most valuable?

      I am using CrowdStrike Falcon because it works on signature-based and signature-less technology, which will prevent me from outside attackers and outside malware.

      CrowdStrike Falcon will protect me from ransomware, and after the installation of CrowdStrike Falcon, I get full control on my endpoints and I am secure from outsiders.

      CrowdStrike Falcon features are robust and reliable.

      There are multiple features including real-time detection, real-time prevention, ATP, and IPS.

      CrowdStrike Falcon makes my job easier because it will prevent me from outsider attacks and outsider detection; for example, if I want to stop any types of pen drive block or allow, it will prevent me from that as well.

      It will impact my organization positively because if anybody wants to try to hit something, wants to take access, wants to perform CNC attacks, wants to do DOS attacks, CrowdStrike Falcon will protect me regarding real-time protection, PUA detection, scanning, and scheduler scanning.

      I have seen on my portal, as the owner, that last week there were some detections about Trojan malware and some detections about CryptoGuard crypto malware. There are many detections, and I have seen that Trojans and malware have been blocked by CrowdStrike Falcon.

      What needs improvement?

      As of now, CrowdStrike Falcon does not have application control and web control. If CrowdStrike Falcon applies those types of features, it will be more reliable and stronger than any other antivirus or next-gen antivirus in the world or in the industries.

      For how long have I used the solution?

      I am using CrowdStrike Falcon from last two years.

      What do I think about the stability of the solution?

      CrowdStrike Falcon is stable right now.

      What do I think about the scalability of the solution?

      It is good; I can increase it any time.

      How are customer service and support?

      Customer support is good for CrowdStrike Falcon; they have the best support.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I have used Seqrite, but I have switched because Seqrite does not have signature-less technology.

      What was our ROI?

      CrowdStrike Falcon has saved me money because if any attacker attacks, they can borrow money to decrypt the file, so it is the money saved and time saved.

      What's my experience with pricing, setup cost, and licensing?

      Pricing, setup cost, and licensing is very good for CrowdStrike Falcon based on what I have seen.

      Which other solutions did I evaluate?

      I have evaluated Sophos.

      What other advice do I have?

      As of now, I think CrowdStrike Falcon is better and it is working fine. I rate it 10 out of 10 because it is lightweight, it has real-time detection, and it has the more powerful signature-based and signature-less technology. I can advise others that if there are any opportunities, they should use CrowdStrike Falcon because it is a very lightweight agent with signature-based and signature-less technology. CrowdStrike Falcon has real-time scanning, real-time prevention, and multiple other features. My overall rating for this product is 10 out of 10.

      Which deployment model are you using for this solution?

      Private Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Mar 14, 2026
      Flag as inappropriate
      PeerSpot user
      Pré-vendas da área de segurança at a tech services company with 11-50 employees
      Real User
      Top 20
      Sep 2, 2026
      Integrated cloud security has transformed our threat response and reduced monitoring workload
      Pros and Cons
      • "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by changing the response time and reducing the number of employees needed for monitoring."
      • "I think CrowdStrike Falcon could be improved by making the interface more modern and simpler."

      What is our primary use case?

      My main use case for CrowdStrike Falcon is protection for containers and protection for the cloud in general.

      I protect my entire modern AWS environment with CrowdStrike Falcon for containers, and for the cloud part, I use CrowdStrike's CSPM visibility, the CNAPP, and also the identity component.

      Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by changing the response time and reducing the number of employees needed for monitoring.

      The benefits of having multiple security capabilities integrated into a single platform include using just one agent, which makes our lives much easier, and having a single administration interface that correlates logs.

      I replaced traditional CSPMs with CrowdStrike Falcon, and that was the main advantage: providing real-time protection.

      A security incident where CrowdStrike Falcon helped my team detect or prevent a threat involved a case with a secretary where someone tried social engineering to install an Ndesk, and we saw it—OverWatch intervened.

      What is most valuable?

      In my opinion, the best feature that CrowdStrike Falcon offers is adversary exploration.

      The adversary exploration feature has helped my team on a day-to-day basis by enabling us to anticipate attacks and be more effective in our response, mainly through the use of OverWatch.

      CrowdStrike Falcon has had a positive impact on my organization by making our lives easier through reducing the time we spend worrying, allowing us to sleep more peacefully today.

      After adopting CrowdStrike Falcon, the response time changed positively, and the care CrowdStrike provides through OverWatch feels like having an extended arm of our organization; it reduces the time and the number of incidents, as well as the number of people needed to monitor things all the time.

      What needs improvement?

      I think CrowdStrike Falcon could be improved by making the interface more modern and simpler.

      For how long have I used the solution?

      I have been using CrowdStrike Falcon for three years.

      What do I think about the stability of the solution?

      CrowdStrike Falcon is very stable.

      What do I think about the scalability of the solution?

      The scalability of CrowdStrike Falcon is very smooth since it uses only one agent.

      How are customer service and support?

      Customer support for CrowdStrike Falcon is perfect, and I have never had any problems.

      I would rate customer support a ten on a scale of one to ten.

      Which solution did I use previously and why did I switch?

      I previously used Trend Micro, and I switched because the support was terrible.

      What was our ROI?

      I have definitely seen a return on investment; even though the cost is higher, the reduction in staff needed for monitoring offsets the cost.

      What's my experience with pricing, setup cost, and licensing?

      My experience with pricing, setup costs, and licensing reveals that the price is a bit higher than competitors, but the delivery is greater.

      Which other solutions did I evaluate?

      Before choosing CrowdStrike Falcon, I did not evaluate other options.

      What other advice do I have?

      I would rate CrowdStrike Falcon a nine on a scale of one to ten.

      I rate it a nine because, for it to be a ten, the interface needs improvement.

      My advice to others who are thinking about using CrowdStrike Falcon is to do a PoC because they will definitely end up buying it.

      My overall review rating for CrowdStrike Falcon is nine.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      Last updated: Sep 2, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2894877 - PeerSpot reviewer
      Senior IT Engineer at a healthcare company with 201-500 employees
      Real User
      Top 20
      Sep 2, 2026
      Endpoint protection has reduced incidents and now enables rapid threat detection and response
      Pros and Cons
      • "The best features CrowdStrike Falcon offers are the speed that it detects anomalies at and allows me to respond quickly."
      • "CrowdStrike Falcon can be improved by integrating with other platforms I utilize like InTune, ScreenConnect, and TeamViewer."

      What is our primary use case?

      My main use case for CrowdStrike Falcon is for endpoint detection. CrowdStrike Falcon endpoint is installed on all workstations, and I use it to detect threats and to assist with vulnerability remediation in my day-to-day work.

      What is most valuable?

      The best features CrowdStrike Falcon offers are the speed that it detects anomalies at and allows me to respond quickly. That speed and quick response help my team by reducing incident response time and helping us react quickly and efficiently. CrowdStrike Falcon has positively impacted my organization by stopping threats before they became an issue on multiple occasions. One specific incident where it stopped a threat before it became an issue involved an engineer with admin rights attempting to install software, and CrowdStrike Falcon detected that it was not software we wanted in our environment, blocking the installation before the malicious software could spread.

      What needs improvement?

      CrowdStrike Falcon can be improved by integrating with other platforms I utilize like InTune, ScreenConnect, and TeamViewer.

      For how long have I used the solution?

      I have been working in my current field for 12 years.

      What do I think about the stability of the solution?

      CrowdStrike Falcon is stable.

      What do I think about the scalability of the solution?

      Its scalability is good; I have no issues with scalability, as I've installed it on all of my machines, and it has not affected performance at all.

      How are customer service and support?

      Customer support is terrific; we are in regular contact with our support crew, and they are always helpful and available when we need them.

      Which solution did I use previously and why did I switch?

      I did not previously use a different solution.

      How was the initial setup?

      My experience with pricing, setup cost, and licensing is that the product setup cost and licensing were all handled by the CISO of the organization, who reports that it was an easy process and we had no issues.

      What about the implementation team?

      Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by allowing us to integrate with our vulnerability remediation team to use the data from both platforms effectively.

      From having multiple security capabilities on a single platform, we benefit by being able to validate threats on multiple platforms, proving that they are accurate, and it gives us additional information to be able to start the remediation process.

      CrowdStrike Falcon has affected the workload and productivity of my security team positively by allowing my team to be more productive because they have instant access to the telemetry data.

      What was our ROI?

      I have seen a return on investment by needing fewer employees; I give access to CrowdStrike Falcon to my MSP, and they are able to manage the environment with a smaller team than they previously had.

      Which other solutions did I evaluate?

      Before choosing CrowdStrike Falcon, I did not evaluate other options.

      What other advice do I have?

      My advice for others looking into using CrowdStrike Falcon is to set up a small pilot environment to get used to it and speak to an existing customer for any quirks related to their specific environment. I gave this review a rating of 10.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 2, 2026
      Flag as inappropriate
      PeerSpot user
      Section Head at Galaxy Chemicals Egypt
      Real User
      Top 5
      Sep 2, 2025
      Provides comprehensive threat protection and seamless integration with third-party tools
      Pros and Cons
      • "CrowdStrike Falcon has positively impacted my organization by providing good protection, logs, and reports, which I find very good."
      • "One area for improvement in CrowdStrike Falcon could be the user interface and reports; it requires some improvements to be easily handled."

      What is our primary use case?

      I am a customer of CrowdStrike Falcon through a consultant, and our company is headquartered in India, while our consultant is a sister company also located in India.

      We use CrowdStrike Falcon internally in our company.

      I am using CrowdStrike Falcon for its purpose, which is to save the company from any attacks, viruses, or whatever threats are available.

      What is most valuable?

      The most useful feature of CrowdStrike Falcon is protection, though it cannot be described in one word.

      Protection is the main purpose of CrowdStrike Falcon.

      CrowdStrike Falcon has positively impacted my organization by providing good protection, logs, and reports, which I find very good.

      What needs improvement?

      One area for improvement in CrowdStrike Falcon could be the user interface and reports; it requires some improvements to be easily handled.

      For the reporting in CrowdStrike Falcon, I need specific data because in most reports, some of the data is not with that importance for the collector, so the reports need to be more specific for each purpose.

      For how long have I used the solution?

      I have been working with CrowdStrike Falcon for around three years.

      What do I think about the stability of the solution?

      Regarding stability and reliability, I find CrowdStrike Falcon to be stable; nothing has happened since we installed it, and there are no bugs or issues from the software.

      What do I think about the scalability of the solution?

      I can say that CrowdStrike Falcon is sufficient in terms of scalability from my point of view; it is capable of working with our current infrastructure or setup, and I believe it's sufficient.

      How are customer service and support?

      My interaction with technical support for CrowdStrike Falcon was fine; they supported me and provided a solution for my issue.

      Based on my experience, I would rate the technical support for CrowdStrike Falcon an eight.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      Before CrowdStrike Falcon, I used an application called Kaspersky, but not for the same purposes.

      Which other solutions did I evaluate?

      I did not evaluate other options before choosing CrowdStrike Falcon because it was a forced decision from our headquarters, from the mother company.

      What other advice do I have?

      Currently, I do not remember exactly what version of CrowdStrike Falcon we are using because I'm managing the team, but I can check the right version later.

      We are using the latest version of CrowdStrike Falcon.

      CrowdStrike Falcon has not helped me predict and prevent potential breaches by itself, but with support from other applications such as Splunk and Windows Defender, it has contributed.

      I integrate CrowdStrike Falcon with third-party tools.

      I have to integrate CrowdStrike Falcon with other applications to get the most protection, and the integration is smooth and everything works well.

      I am using the lightweight agent.

      For the system performance, the lightweight agent is fine; it has not affected performance too much, and generally it's acceptable.

      I rate CrowdStrike Falcon eight out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      reviewer2895198 - PeerSpot reviewer
      System Administrator III at a government with 501-1,000 employees
      Real User
      Top 20
      Sep 3, 2026
      Security workflows have become streamlined and investigations are resolved faster at scale
      Pros and Cons
      • "CrowdStrike Falcon has positively impacted my organization by allowing fewer people to do more workloads, so it has saved us time, money, and effort."
      • "I feel the weakest thing about CrowdStrike Falcon is their documentation."

      What is our primary use case?

      My main use case for CrowdStrike Falcon is for security. We recently had some user credentials get lost in the shuffle, and I use CrowdStrike Falcon to figure out what had happened and correct the issue so it would not happen in the future.

      What is most valuable?

      The best feature that we appreciate about CrowdStrike Falcon is the ability to run APIs and manage things like UDP connections with non-licensed Microsoft accounts.

      The API functionality and managing UDP connections with non-licensed Microsoft accounts makes my work easier by giving us another MFA method for elevated accounts that are non-licensed.

      CrowdStrike Falcon has positively impacted my organization by allowing fewer people to do more workloads, so it has saved us time, money, and effort.

      From what I have used so far, CrowdStrike Falcon is very accurate, and the output gives a good overview. I think it does a good job.

      CrowdStrike Falcon is deployed in our organization in a hybrid cloud setup, and we install the sensor via Intune on each Autopiloted machine.

      What needs improvement?

      I feel the weakest thing about CrowdStrike Falcon is their documentation.

      For how long have I used the solution?

      I have been using CrowdStrike Falcon for a year and a half.

      What do I think about the scalability of the solution?

      CrowdStrike Falcon sensor has increased our security at scale, as before we had to do different updates, different policy fixes, and management one at a time.

      Which solution did I use previously and why did I switch?

      CrowdStrike Falcon has allowed us to replace Microsoft Defender, and the impact was a cost savings.

      Switching from Microsoft Defender to CrowdStrike Falcon improved detection and response time because it is all in one place. It gives you a cleaner reference for the incident.

      Which other solutions did I evaluate?

      What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is ease of access, cost, manageability, and customization.

      Using CrowdStrike Falcon platform has changed the way my security team detects, investigates, and responds to threats by giving us a broader range of the threat, more idea of what the issue is, and helping us with our solution. It has decreased our time and allowed us fewer employees to function at a faster pace.

      What other advice do I have?

      My advice to others looking into using CrowdStrike Falcon is to not get overwhelmed and to start small with a lot of data. We have not used the AI within CrowdStrike Falcon at this point. I would rate this product a 9.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 3, 2026
      Flag as inappropriate
      PeerSpot user
      Waleed Omar - PeerSpot reviewer
      Information Security Specialist at Arab Open University
      Real User
      Top 5Leaderboard
      May 21, 2025
      Provides effective real-time threat detection with potential for cost optimization
      Pros and Cons
      • "The most beneficial part is the active response capability of the product."
      • "The biggest issue occurred when every computer worldwide experienced a blue screen."

      What is our primary use case?

      We are protecting our endpoints, workstations, servers, and cloud workloads. This includes effective use of antivirus and detection and response capabilities.

      I am working at Arab Open University, and we are using CrowdStrike Falcon as our security product.

      What is most valuable?

      The most beneficial part is the active response capability of the product. Being an EDR solution, it helps us identify attacks in real-time. The product runs in the background 24/7. The most interesting aspect is the behavior analysis functionality, which analyzes the behavior of any suspicious activity.

      It identifies threats efficiently due to its built-in intelligence and AI capabilities, which has been extremely helpful for our organization.

      What needs improvement?

      Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product.

      We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.

      For how long have I used the solution?

      We have been using the solution for almost four years.

      What was my experience with deployment of the solution?

      It is a straightforward plug-and-play deployment.

      What do I think about the stability of the solution?

      Sometimes there are minor glitches, approximately 1% of the time. The biggest issue occurred when every computer worldwide experienced a blue screen. However, they solved the problems and introduced a new feature for channel updates. This has been much more beneficial, and while human errors can occur in any product, we cannot solely blame CrowdStrike Falcon for such incidents.

      How are customer service and support?

      The customer service is good and efficient in terms of responding. They could improve by initiating calls for high-priority cases instead of just opening tickets. When we open a support ticket, they should call to discuss what happened and listen to our concerns.

      How would you rate customer service and support?

      Neutral

      How was the initial setup?

      The setup is straightforward, and most of our integration is within the package. However, for the integration part, we need to purchase additional modules from CrowdStrike Falcon. If this functionality was included as a free standalone feature within the built-in solution, it would be more market competitive. Competitors such as SentinelOne and Microsoft Defender provide this functionality out of the box without additional charges.

      What was our ROI?

      We have not calculated the ROI extensively, as we typically only calculate it when there is dissatisfaction. On a scale of one to ten, the ROI would be five, which translates to approximately 60%.

      What's my experience with pricing, setup cost, and licensing?

      The solution is a bit expensive.

      Which other solutions did I evaluate?

      We are using Darktrace as an email security solution, not as an EDR.

      What other advice do I have?

      I would rate CrowdStrike Falcon a seven out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Sumanth Kandanuru - PeerSpot reviewer
      Security Analyst at NTT Ltd
      Real User
      Top 10
      Feb 16, 2025
      Enables direct remote investigations with comprehensive analysis features
      Pros and Cons
      • "CrowdStrike is a great solution."
      • "In CrowdStrike, with the variety of security tools available, learning the different query languages can be challenging."

      What is our primary use case?

      I am currently using CrowdStrike Falcon as an EDR, which is integrated with SIEM. We also work in a real-time environment with the product. As a Falconist, I perform investigation actions on it. There are three different kinds of alerts I deal with: one based purely on IOCs, another process-oriented IOA, and those based on machine learning alerts. This is what I work on, and it is actually a good tool. It has multiple features, including real-time connection to the RTR environment, allowing direct remote host connection through CrowdStrike. I have multiple options like host search and event search, enabling me to do everything I need. It's a comprehensive package. It's a challenging tool to explore, but once accustomed to it, it is quite excellent.

      What is most valuable?

      Obviously, when checking in the SIEM, not all logs are available. In CrowdStrike, unlike SIEM, actions are clearly defined. For example, a regular AV like Symantec might indicate a file was quarantined or failed to quarantine, but in CrowdStrike, I can verify the action. As an incident response analyst, I can use CrowdStrike to perform actions like directly wiping a file from a host if given access. I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections. Event search also allows for detailed investigations, showing accessed files and remote installations.

      What needs improvement?

      In CrowdStrike, with the variety of security tools available, learning the different query languages can be challenging. I use KQL queries with Sentinel and AQL with QRadar, and CrowdStrike's query language is different as well. This requires constant learning for security analysts. Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial. The event search tab in CrowdStrike is complex, though the host search is more straightforward and gets details from the past week. The querying system, similar to Splunk, could be made more user-friendly.

      For how long have I used the solution?

      I have been using it for the past two years.

      What do I think about the stability of the solution?

      The stability is always great. I have never seen instability in the CrowdStrike tool.

      What do I think about the scalability of the solution?

      When it comes to scalability, it is entirely based on premium models according to demand. Our log retention is low, but paying more increases it. Scalability is moderate, based on the charges paid to the CrowdStrike product service team. Offering good services, like better log retention at a lower price, would be excellent.

      How are customer service and support?

      The CrowdStrike team is very efficient; I would rate them ten out of ten. They respond quickly when it comes to providing services.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I have worked on Symantec ATP, advanced threat protection, but it is a legacy product. Many companies have moved away from Symantec, and they use legacy antivirus solutions. The integration with Symantec ATP was tough, and event or host searches were based entirely on raw logs.

      How was the initial setup?

      The current setup is easy, but it could be more natural and make drill-down searches simpler. With advancements in AI, integration could streamline responses further, but there is still room for making the process easier.

      What about the implementation team?

      The integration task should be done by engineers. I'm interested in the process and have learned something about integration, but we have not fully explored all integration aspects.

      What other advice do I have?

      CrowdStrike is a great solution. It's a hands-on tool. I have not seen other EDRs like it. Compared to Carbon Black, which is much more difficult with a different UI, CrowdStrike allows direct, detailed investigation with a PID generated for each process. It offers unique abilities not seen in other EDRs. Overall product rating: nine out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.
      Updated: September 2026
      Buyer's Guide
      Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.