No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2895027 - PeerSpot reviewer
Security Operations at a financial services firm with 5,001-10,000 employees
Real User
Top 5
Sep 4, 2026
Platform has transformed threat detection speed and reduced false positives for my team
Pros and Cons
  • "CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements."

    What is our primary use case?

    My main use cases for CrowdStrike Falcon include detecting malicious behavior and identifying user trends.

    Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making it faster and easier to respond to advanced threats.

    In a security incident, CrowdStrike Falcon helps my team detect or stop threats by assisting in detecting unauthorized use of local binaries, such as those that are natively installed including PowerShell and scheduled tasks.

    What is most valuable?

    The benefits I have seen from multiple security capabilities on a single platform include solid control over consolidated information that can be accessed quickly.

    I believe the value of having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform lies in the correlation of these different data sources, which is essential to identifying and disrupting advanced threats.

    CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements. These improvements result from having fewer false positives, which means more time spent working on real, high-impact work.

    CrowdStrike Falcon makes every analyst much more effective and informed than they would have been otherwise.

    What needs improvement?

    CrowdStrike Falcon can be improved by continuing to listen to customer feedback.

    I believe that more integrations and support for Mac products should be included in the next release.

    For how long have I used the solution?

    I have been using CrowdStrike Falcon for three years.

    Buyer's Guide
    CrowdStrike Falcon
    October 2026
    Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: October 2026.
    916,197 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    I assess the stability and reliability of CrowdStrike Falcon as reliable ever since the massive incident occurred.

    I have not experienced any downtime, crashes, or performance issues.

    What do I think about the scalability of the solution?

    The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is none; it is a force accelerator.

    How are customer service and support?

    I evaluate customer service and technical support as excellent.

    Which solution did I use previously and why did I switch?

    CrowdStrike Falcon has allowed me to consolidate or replace other security tools. The tools I replaced were those provided by legacy vendors, which operated for the sole purpose of one or two functions, and they were able to be replaced through the flexible approaches that CrowdStrike Falcon provides.

    How was the initial setup?

    I would describe my experience with deploying CrowdStrike Falcon as easy and effective. What worked well includes the solid deployment process, though communication with lay users is always a challenge, which I would say resulted in limited to no issues.

    What was our ROI?

    I have seen return on investment with CrowdStrike Falcon.

    What other advice do I have?

    I would rate CrowdStrike Falcon an eight on a scale from one to ten, as nothing is perfect. My advice to other organizations considering CrowdStrike Falcon is to adopt now or adopt later. I provided an overall review rating of eight.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 4, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2895060 - PeerSpot reviewer
    Senior DevSecOps Engineer at a tech vendor with 1,001-5,000 employees
    Real User
    Top 20
    Sep 2, 2026
    Endpoint investigations have become faster and have prevented recurring malware incidents
    Pros and Cons
    • "Where previous incidents that CrowdStrike Falcon has now stopped used to take anywhere from two to five hours to get contained and remediated, now they are prevented."
    • "Training is the biggest thing that could be improved; there is not a lot of training, and it is not that accessible."

    What is our primary use case?

    My main use case for CrowdStrike Falcon is endpoint detection and response.

    What is most valuable?

    The best features CrowdStrike Falcon offers are the ease of use and accessibility in the console, making it a very easy-to-use tool from an analyst's perspective.

    The way that everything is laid out and the way that the detections are formatted, giving you the different types of process graphs and process tree details, especially with Charlotte AI, really helps smooth everything out.

    Having all of the data correlated in the same spot makes an investigation really easy.

    It makes investigations a lot easier; anything that is on the endpoints and reaches up to the cloud, you can find that very easily.

    What needs improvement?

    Training is the biggest thing that could be improved; there is not a lot of training, and it is not that accessible.

    The ability to implement profile groups requires SCIM to be configured. SCIM is not in the documentation. SCIM is required if you want to do just-in-time access provisioning for profile groups for new users, and that is not in the documentation. It took a lot of communication with support to figure that out.

    The AI detections on anything about a severity five or lower could be improved; many of those are more on the informational side. There have not been too many with a severity of five or lower, detection-wise, that have actually been useful as an analyst.

    For how long have I used the solution?

    I have been using CrowdStrike Falcon since 2021.

    What do I think about the scalability of the solution?

    We have had no issues with how it scales.

    How are customer service and support?

    Customer support in our government environment is quite fast, but customer support in the commercial or non-government environment is slow and not necessarily the most knowledgeable until you get higher up and the ticket gets escalated higher up.

    Which solution did I use previously and why did I switch?

    It has not necessarily changed anything because we have been using CrowdStrike Falcon since the formation of our team; we have almost always had CrowdStrike Falcon. There was not anything coming before that, but it definitely makes the flow a lot easier with how our team is set up.

    How was the initial setup?

    The endpoint agent for the commercial endpoints, Windows and Mac, has been very easy; the rollout has not caused any issues, but the deployment in the various clouds has caused some difficulty due to deployments not being standardized across all three major cloud platforms.

    What was our ROI?

    We definitely have had time saved; where previous incidents that CrowdStrike Falcon has now stopped used to take anywhere from two to five hours to get contained and remediated, now they are prevented.

    Which other solutions did I evaluate?

    We evaluated at least 15 different options, and CrowdStrike Falcon by far was the best.

    What other advice do I have?

    I monitor our endpoints across Windows, Mac, and Linux, and I identify any malicious software or unapproved software that comes up and is blocked by the platform.

    I also use CrowdStrike Falcon for a rudimentary asset inventory and checking out what types of shadow IT and applications are installed across my network.

    CrowdStrike Falcon has stopped a lot of malware from being executed on user devices.

    I estimate we have had about 20 incidents over the past year that were prevented by CrowdStrike Falcon.

    The workload has not necessarily gone down; the detections that are created are reviewed now, but there is almost nothing that needs to be done other than having the device wiped.

    I am using Charlotte AI to help craft better queries for Falcon Fusion.

    We have purchased at least five different add-ons to increase the overall insight into everything in the company. Using Falcon for IT, we have been able to identify and assess different application-based risks on our user endpoints.

    I would advise anyone to dive in and get comfortable with the console; there is a lot of information in there that you need to figure out, and it is pretty easy to figure out. I would rate this product a 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 2, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    CrowdStrike Falcon
    October 2026
    Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: October 2026.
    916,197 professionals have used our research since 2012.
    Ashutosh Jha - PeerSpot reviewer
    Project engineer at IT Solution india private limited
    Real User
    Top 5Leaderboard
    Mar 14, 2026
    Endpoint protection has blocked ransomware and malware and gives me real-time control
    Pros and Cons
    • "CrowdStrike Falcon features are robust and reliable."
    • "As of now, CrowdStrike Falcon does not have application control and web control."

    What is our primary use case?

    I am using CrowdStrike Falcon because I want to secure my end-user devices.

    What is most valuable?

    I am using CrowdStrike Falcon because it works on signature-based and signature-less technology, which will prevent me from outside attackers and outside malware.

    CrowdStrike Falcon will protect me from ransomware, and after the installation of CrowdStrike Falcon, I get full control on my endpoints and I am secure from outsiders.

    CrowdStrike Falcon features are robust and reliable.

    There are multiple features including real-time detection, real-time prevention, ATP, and IPS.

    CrowdStrike Falcon makes my job easier because it will prevent me from outsider attacks and outsider detection; for example, if I want to stop any types of pen drive block or allow, it will prevent me from that as well.

    It will impact my organization positively because if anybody wants to try to hit something, wants to take access, wants to perform CNC attacks, wants to do DOS attacks, CrowdStrike Falcon will protect me regarding real-time protection, PUA detection, scanning, and scheduler scanning.

    I have seen on my portal, as the owner, that last week there were some detections about Trojan malware and some detections about CryptoGuard crypto malware. There are many detections, and I have seen that Trojans and malware have been blocked by CrowdStrike Falcon.

    What needs improvement?

    As of now, CrowdStrike Falcon does not have application control and web control. If CrowdStrike Falcon applies those types of features, it will be more reliable and stronger than any other antivirus or next-gen antivirus in the world or in the industries.

    For how long have I used the solution?

    I am using CrowdStrike Falcon from last two years.

    What do I think about the stability of the solution?

    CrowdStrike Falcon is stable right now.

    What do I think about the scalability of the solution?

    It is good; I can increase it any time.

    How are customer service and support?

    Customer support is good for CrowdStrike Falcon; they have the best support.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have used Seqrite, but I have switched because Seqrite does not have signature-less technology.

    What was our ROI?

    CrowdStrike Falcon has saved me money because if any attacker attacks, they can borrow money to decrypt the file, so it is the money saved and time saved.

    What's my experience with pricing, setup cost, and licensing?

    Pricing, setup cost, and licensing is very good for CrowdStrike Falcon based on what I have seen.

    Which other solutions did I evaluate?

    I have evaluated Sophos.

    What other advice do I have?

    As of now, I think CrowdStrike Falcon is better and it is working fine. I rate it 10 out of 10 because it is lightweight, it has real-time detection, and it has the more powerful signature-based and signature-less technology. I can advise others that if there are any opportunities, they should use CrowdStrike Falcon because it is a very lightweight agent with signature-based and signature-less technology. CrowdStrike Falcon has real-time scanning, real-time prevention, and multiple other features. My overall rating for this product is 10 out of 10.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Mar 14, 2026
    Flag as inappropriate
    PeerSpot user
    Pré-vendas da área de segurança at a tech services company with 11-50 employees
    Real User
    Top 10
    Sep 2, 2026
    Integrated cloud security has transformed our threat response and reduced monitoring workload
    Pros and Cons
    • "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by changing the response time and reducing the number of employees needed for monitoring."
    • "I think CrowdStrike Falcon could be improved by making the interface more modern and simpler."

    What is our primary use case?

    My main use case for CrowdStrike Falcon is protection for containers and protection for the cloud in general.

    I protect my entire modern AWS environment with CrowdStrike Falcon for containers, and for the cloud part, I use CrowdStrike's CSPM visibility, the CNAPP, and also the identity component.

    Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by changing the response time and reducing the number of employees needed for monitoring.

    The benefits of having multiple security capabilities integrated into a single platform include using just one agent, which makes our lives much easier, and having a single administration interface that correlates logs.

    I replaced traditional CSPMs with CrowdStrike Falcon, and that was the main advantage: providing real-time protection.

    A security incident where CrowdStrike Falcon helped my team detect or prevent a threat involved a case with a secretary where someone tried social engineering to install an Ndesk, and we saw it—OverWatch intervened.

    What is most valuable?

    In my opinion, the best feature that CrowdStrike Falcon offers is adversary exploration.

    The adversary exploration feature has helped my team on a day-to-day basis by enabling us to anticipate attacks and be more effective in our response, mainly through the use of OverWatch.

    CrowdStrike Falcon has had a positive impact on my organization by making our lives easier through reducing the time we spend worrying, allowing us to sleep more peacefully today.

    After adopting CrowdStrike Falcon, the response time changed positively, and the care CrowdStrike provides through OverWatch feels like having an extended arm of our organization; it reduces the time and the number of incidents, as well as the number of people needed to monitor things all the time.

    What needs improvement?

    I think CrowdStrike Falcon could be improved by making the interface more modern and simpler.

    For how long have I used the solution?

    I have been using CrowdStrike Falcon for three years.

    What do I think about the stability of the solution?

    CrowdStrike Falcon is very stable.

    What do I think about the scalability of the solution?

    The scalability of CrowdStrike Falcon is very smooth since it uses only one agent.

    How are customer service and support?

    Customer support for CrowdStrike Falcon is perfect, and I have never had any problems.

    I would rate customer support a ten on a scale of one to ten.

    Which solution did I use previously and why did I switch?

    I previously used Trend Micro, and I switched because the support was terrible.

    What was our ROI?

    I have definitely seen a return on investment; even though the cost is higher, the reduction in staff needed for monitoring offsets the cost.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing reveals that the price is a bit higher than competitors, but the delivery is greater.

    Which other solutions did I evaluate?

    Before choosing CrowdStrike Falcon, I did not evaluate other options.

    What other advice do I have?

    I would rate CrowdStrike Falcon a nine on a scale of one to ten.

    I rate it a nine because, for it to be a ten, the interface needs improvement.

    My advice to others who are thinking about using CrowdStrike Falcon is to do a PoC because they will definitely end up buying it.

    My overall review rating for CrowdStrike Falcon is nine.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: Sep 2, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2894877 - PeerSpot reviewer
    Senior IT Engineer at a healthcare company with 201-500 employees
    Real User
    Top 20
    Sep 2, 2026
    Endpoint protection has reduced incidents and now enables rapid threat detection and response
    Pros and Cons
    • "The best features CrowdStrike Falcon offers are the speed that it detects anomalies at and allows me to respond quickly."
    • "CrowdStrike Falcon can be improved by integrating with other platforms I utilize like InTune, ScreenConnect, and TeamViewer."

    What is our primary use case?

    My main use case for CrowdStrike Falcon is for endpoint detection. CrowdStrike Falcon endpoint is installed on all workstations, and I use it to detect threats and to assist with vulnerability remediation in my day-to-day work.

    What is most valuable?

    The best features CrowdStrike Falcon offers are the speed that it detects anomalies at and allows me to respond quickly. That speed and quick response help my team by reducing incident response time and helping us react quickly and efficiently. CrowdStrike Falcon has positively impacted my organization by stopping threats before they became an issue on multiple occasions. One specific incident where it stopped a threat before it became an issue involved an engineer with admin rights attempting to install software, and CrowdStrike Falcon detected that it was not software we wanted in our environment, blocking the installation before the malicious software could spread.

    What needs improvement?

    CrowdStrike Falcon can be improved by integrating with other platforms I utilize like InTune, ScreenConnect, and TeamViewer.

    For how long have I used the solution?

    I have been working in my current field for 12 years.

    What do I think about the stability of the solution?

    CrowdStrike Falcon is stable.

    What do I think about the scalability of the solution?

    Its scalability is good; I have no issues with scalability, as I've installed it on all of my machines, and it has not affected performance at all.

    How are customer service and support?

    Customer support is terrific; we are in regular contact with our support crew, and they are always helpful and available when we need them.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is that the product setup cost and licensing were all handled by the CISO of the organization, who reports that it was an easy process and we had no issues.

    What about the implementation team?

    Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by allowing us to integrate with our vulnerability remediation team to use the data from both platforms effectively.

    From having multiple security capabilities on a single platform, we benefit by being able to validate threats on multiple platforms, proving that they are accurate, and it gives us additional information to be able to start the remediation process.

    CrowdStrike Falcon has affected the workload and productivity of my security team positively by allowing my team to be more productive because they have instant access to the telemetry data.

    What was our ROI?

    I have seen a return on investment by needing fewer employees; I give access to CrowdStrike Falcon to my MSP, and they are able to manage the environment with a smaller team than they previously had.

    Which other solutions did I evaluate?

    Before choosing CrowdStrike Falcon, I did not evaluate other options.

    What other advice do I have?

    My advice for others looking into using CrowdStrike Falcon is to set up a small pilot environment to get used to it and speak to an existing customer for any quirks related to their specific environment. I gave this review a rating of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 2, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2895198 - PeerSpot reviewer
    System Administrator III at a government with 501-1,000 employees
    Real User
    Top 20
    Sep 3, 2026
    Security workflows have become streamlined and investigations are resolved faster at scale
    Pros and Cons
    • "CrowdStrike Falcon has positively impacted my organization by allowing fewer people to do more workloads, so it has saved us time, money, and effort."
    • "I feel the weakest thing about CrowdStrike Falcon is their documentation."

    What is our primary use case?

    My main use case for CrowdStrike Falcon is for security. We recently had some user credentials get lost in the shuffle, and I use CrowdStrike Falcon to figure out what had happened and correct the issue so it would not happen in the future.

    What is most valuable?

    The best feature that we appreciate about CrowdStrike Falcon is the ability to run APIs and manage things like UDP connections with non-licensed Microsoft accounts.

    The API functionality and managing UDP connections with non-licensed Microsoft accounts makes my work easier by giving us another MFA method for elevated accounts that are non-licensed.

    CrowdStrike Falcon has positively impacted my organization by allowing fewer people to do more workloads, so it has saved us time, money, and effort.

    From what I have used so far, CrowdStrike Falcon is very accurate, and the output gives a good overview. I think it does a good job.

    CrowdStrike Falcon is deployed in our organization in a hybrid cloud setup, and we install the sensor via Intune on each Autopiloted machine.

    What needs improvement?

    I feel the weakest thing about CrowdStrike Falcon is their documentation.

    For how long have I used the solution?

    I have been using CrowdStrike Falcon for a year and a half.

    What do I think about the scalability of the solution?

    CrowdStrike Falcon sensor has increased our security at scale, as before we had to do different updates, different policy fixes, and management one at a time.

    Which solution did I use previously and why did I switch?

    CrowdStrike Falcon has allowed us to replace Microsoft Defender, and the impact was a cost savings.

    Switching from Microsoft Defender to CrowdStrike Falcon improved detection and response time because it is all in one place. It gives you a cleaner reference for the incident.

    Which other solutions did I evaluate?

    What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is ease of access, cost, manageability, and customization.

    Using CrowdStrike Falcon platform has changed the way my security team detects, investigates, and responds to threats by giving us a broader range of the threat, more idea of what the issue is, and helping us with our solution. It has decreased our time and allowed us fewer employees to function at a faster pace.

    What other advice do I have?

    My advice to others looking into using CrowdStrike Falcon is to not get overwhelmed and to start small with a lot of data. We have not used the AI within CrowdStrike Falcon at this point. I would rate this product a 9.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 3, 2026
    Flag as inappropriate
    PeerSpot user
    Waleed Omar - PeerSpot reviewer
    Information Security Specialist at Arab Open University
    Real User
    Top 5Leaderboard
    May 21, 2025
    Provides effective real-time threat detection with potential for cost optimization
    Pros and Cons
    • "The most beneficial part is the active response capability of the product."
    • "The biggest issue occurred when every computer worldwide experienced a blue screen."

    What is our primary use case?

    We are protecting our endpoints, workstations, servers, and cloud workloads. This includes effective use of antivirus and detection and response capabilities.

    I am working at Arab Open University, and we are using CrowdStrike Falcon as our security product.

    What is most valuable?

    The most beneficial part is the active response capability of the product. Being an EDR solution, it helps us identify attacks in real-time. The product runs in the background 24/7. The most interesting aspect is the behavior analysis functionality, which analyzes the behavior of any suspicious activity.

    It identifies threats efficiently due to its built-in intelligence and AI capabilities, which has been extremely helpful for our organization.

    What needs improvement?

    Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product.

    We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.

    For how long have I used the solution?

    We have been using the solution for almost four years.

    What was my experience with deployment of the solution?

    It is a straightforward plug-and-play deployment.

    What do I think about the stability of the solution?

    Sometimes there are minor glitches, approximately 1% of the time. The biggest issue occurred when every computer worldwide experienced a blue screen. However, they solved the problems and introduced a new feature for channel updates. This has been much more beneficial, and while human errors can occur in any product, we cannot solely blame CrowdStrike Falcon for such incidents.

    How are customer service and support?

    The customer service is good and efficient in terms of responding. They could improve by initiating calls for high-priority cases instead of just opening tickets. When we open a support ticket, they should call to discuss what happened and listen to our concerns.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    The setup is straightforward, and most of our integration is within the package. However, for the integration part, we need to purchase additional modules from CrowdStrike Falcon. If this functionality was included as a free standalone feature within the built-in solution, it would be more market competitive. Competitors such as SentinelOne and Microsoft Defender provide this functionality out of the box without additional charges.

    What was our ROI?

    We have not calculated the ROI extensively, as we typically only calculate it when there is dissatisfaction. On a scale of one to ten, the ROI would be five, which translates to approximately 60%.

    What's my experience with pricing, setup cost, and licensing?

    The solution is a bit expensive.

    Which other solutions did I evaluate?

    We are using Darktrace as an email security solution, not as an EDR.

    What other advice do I have?

    I would rate CrowdStrike Falcon a seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Sumanth Kandanuru - PeerSpot reviewer
    Security Analyst at NTT Ltd
    Real User
    Top 10
    Feb 16, 2025
    Enables direct remote investigations with comprehensive analysis features
    Pros and Cons
    • "CrowdStrike is a great solution."
    • "In CrowdStrike, with the variety of security tools available, learning the different query languages can be challenging."

    What is our primary use case?

    I am currently using CrowdStrike Falcon as an EDR, which is integrated with SIEM. We also work in a real-time environment with the product. As a Falconist, I perform investigation actions on it. There are three different kinds of alerts I deal with: one based purely on IOCs, another process-oriented IOA, and those based on machine learning alerts. This is what I work on, and it is actually a good tool. It has multiple features, including real-time connection to the RTR environment, allowing direct remote host connection through CrowdStrike. I have multiple options like host search and event search, enabling me to do everything I need. It's a comprehensive package. It's a challenging tool to explore, but once accustomed to it, it is quite excellent.

    What is most valuable?

    Obviously, when checking in the SIEM, not all logs are available. In CrowdStrike, unlike SIEM, actions are clearly defined. For example, a regular AV like Symantec might indicate a file was quarantined or failed to quarantine, but in CrowdStrike, I can verify the action. As an incident response analyst, I can use CrowdStrike to perform actions like directly wiping a file from a host if given access. I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections. Event search also allows for detailed investigations, showing accessed files and remote installations.

    What needs improvement?

    In CrowdStrike, with the variety of security tools available, learning the different query languages can be challenging. I use KQL queries with Sentinel and AQL with QRadar, and CrowdStrike's query language is different as well. This requires constant learning for security analysts. Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial. The event search tab in CrowdStrike is complex, though the host search is more straightforward and gets details from the past week. The querying system, similar to Splunk, could be made more user-friendly.

    For how long have I used the solution?

    I have been using it for the past two years.

    What do I think about the stability of the solution?

    The stability is always great. I have never seen instability in the CrowdStrike tool.

    What do I think about the scalability of the solution?

    When it comes to scalability, it is entirely based on premium models according to demand. Our log retention is low, but paying more increases it. Scalability is moderate, based on the charges paid to the CrowdStrike product service team. Offering good services, like better log retention at a lower price, would be excellent.

    How are customer service and support?

    The CrowdStrike team is very efficient; I would rate them ten out of ten. They respond quickly when it comes to providing services.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have worked on Symantec ATP, advanced threat protection, but it is a legacy product. Many companies have moved away from Symantec, and they use legacy antivirus solutions. The integration with Symantec ATP was tough, and event or host searches were based entirely on raw logs.

    How was the initial setup?

    The current setup is easy, but it could be more natural and make drill-down searches simpler. With advancements in AI, integration could streamline responses further, but there is still room for making the process easier.

    What about the implementation team?

    The integration task should be done by engineers. I'm interested in the process and have learned something about integration, but we have not fully explored all integration aspects.

    What other advice do I have?

    CrowdStrike is a great solution. It's a hands-on tool. I have not seen other EDRs like it. Compared to Carbon Black, which is much more difficult with a different UI, CrowdStrike allows direct, detailed investigation with a PID generated for each process. It offers unique abilities not seen in other EDRs. Overall product rating: nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Shubham Sinha. - PeerSpot reviewer
    Senior Principal Information Security Analyst at Veritas Technologies LLC
    Real User
    Top 20
    Feb 23, 2025
    Detects anomalies and helps with fast threat identification and response
    Pros and Cons
    • "The machine learning behavior for anomaly detection is a valuable feature. It helps identify any suspicious or unusual activities within the system."
    • "The best benefit of CrowdStrike Falcon is 99% MITRE coverage."
    • "Deployment in cloud environments is challenging. Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options."

    What is our primary use case?

    We are using it for endpoint protection, as well as for cloud security coverage. It includes monitoring all our critical servers and endpoint devices. We also design workflows for anomaly behavior detection using machine learning techniques for anything malicious or abnormal. We monitor everything suspicious. We either design the workflows or use CrowdStrike to monitor any new detections and anomaly behaviors, as well as do vulnerability management.

    How has it helped my organization?

    The best benefit of CrowdStrike Falcon is 99% MITRE coverage. It detects suspicious or undetected activities on the system and provides protection for zero-day vulnerabilities. If there is a sudden rise in CPU consumption or abnormal storage use, it helps us by creating a ticket, allowing us to investigate any abnormal behavior present. We can look into the machine and investigate. It reduces the false negatives common with other technologies.

    The real-time response helps with MTTR. We achieve faster detection and response times.

    It helped prevent breaches. In the past, there was abnormal consumption of RAM along with CPU on a server. It also started communicating with other subnets. CrowdStrike Falcon triggered an alert. We did our investigation and found that we had ransomware. We successfully mitigated it.

    What is most valuable?

    The machine learning behavior for anomaly detection is a valuable feature. It helps identify any suspicious or unusual activities within the system.

    Furthermore, it has impressive MITRE coverage. 

    What needs improvement?

    Deployment in cloud environments is challenging. Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options. After a year, options change or integrate with something else, which is challenging for me as it requires relearning. It is time-consuming.

    For how long have I used the solution?

    I started working on CrowdStrike in 2018. 

    What do I think about the stability of the solution?

    We are following N-1 versions across our environment, which is stable. Due to our requirements, we never switch to the N version; we always stick to N-1 and never face anything abnormal while using it.

    What do I think about the scalability of the solution?

    It has proven to be a good technology for me. It has adequate coverage and is easy to deploy. Its scalability is good.

    It is deployed across the globe.

    How are customer service and support?

    I would rate them a seven out of ten. They take a lot of time to come back to us.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I have used SentinelOne as well. SentinelOne was similar but had major challenges with workflow implementation. Workflow implementation is far easier in CrowdStrike compared to SentinelOne.

    How was the initial setup?

    We have it in the on-premises environment and cloud environments. For endpoint hosts, it is very easy, but in the cloud environment, there are challenges, especially if we have AWS technologies with Lambda functions, which are serverless.

    My implementation strategy was simple. I segregated servers based on criticality, then network, and finally OS level. Anything critical was based on my CMDB asset configuration. Following criticality was the network, determining internal versus public-facing. The last segmentation was on OS configuration. These three categorizations were primarily used in deploying agents across our environment.

    In terms of maintenance, there are patches or version upgrades. 

    What about the implementation team?

    We had a group of five people, which was enough to manage this.

    What was our ROI?

    It is worth the money.

    What's my experience with pricing, setup cost, and licensing?

    It is expensive compared to SentinelOne, but as the market leader, it is worth it.

    What other advice do I have?

    I would rate CrowdStrike Falcon an eight out of ten. They have some challenges with the cloud environment, which is a major drawback, especially with the serverless aspect. Their GUI also causes issues with regular changes.

    If anyone has worked with CrowdStrike, they would promote it. However, cloud security presents challenges. Moving from physical to cloud environments is difficult. I have raised 7-8 tickets to resolve cloud issues, especially with AWS.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Dipak M Gohil - PeerSpot reviewer
    IT Manager at Jord International Pty Ltd
    Real User
    Top 5
    Sep 3, 2025
    Efficient threat detection and seamless deployment improve overall security
    Pros and Cons
    • "CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions."
    • "I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does."

    What is our primary use case?

    We are using CrowdStrike Falcon because it has very low surface impact and minimal consumption of our resources, and we mainly use it for our endpoint protection.

    CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions.

    We find it very unique that CrowdStrike Falcon, which we deployed in many countries wherever our offices are, can be installed very quickly, maintained on a single console, single panel of console, and it's really easy to use and deploy. We primarily use it for endpoint protection.

    What is most valuable?

    The single panel console of CrowdStrike Falcon is very user-friendly, which is what we are looking for. Having multiple administrators between various offices with this single console gives us the ability to see all offices, branch offices, and partners, making it very useful to detect machines, identify machines, and check security risks. Everything in the single console is very useful.

    CrowdStrike Falcon has positively impacted our organization in terms of efficiency because it's very lightweight, easy to deploy, easy to manage, and works very efficiently. It quickly detects issues and doesn't have a signature-based system, so it works fast and takes immediate action.

    What needs improvement?

    I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does.

    For how long have I used the solution?

    We have been using CrowdStrike Falcon for the past seven years.

    What do I think about the stability of the solution?

    CrowdStrike Falcon is stable; I have not had any issues with reliability or downtime.

    What do I think about the scalability of the solution?

    For scalability, CrowdStrike Falcon deserves a perfect score of ten out of ten.

    How are customer service and support?

    Regarding customer support, our experience has been really positive as they are very quick to assist us.

    The customer support deserves a rating of ten out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We were previously using Symantec Endpoint because we were not getting proper quotations, pricing, or support, particularly in India, which is why we wanted to switch.

    What was our ROI?

    In terms of return on investment, we find that CrowdStrike Falcon has ROI covered because less manpower is required. It's very easy to deploy without many IT admins, saving time, and while I cannot specify the money saved, the time saved is money in terms of manpower. This makes it very useful, quick to run, quick to install, easy to manage, and easy to deploy.

    What's my experience with pricing, setup cost, and licensing?

    We do not find any price challenges or setup costs with CrowdStrike Falcon; everything is smooth.

    Which other solutions did I evaluate?

    We evaluated three products, which were Sophos, CrowdStrike Falcon, and Trend Micro, before choosing CrowdStrike Falcon.

    What other advice do I have?

    In some cases, we have Excel files with VBA code inside, and CrowdStrike Falcon detects that it's a bit risky for us. When people download EXE files that are threats to our organization, it detects them very quickly. It also detects threats under ZIP files and can show us the path from where it came and where it goes, allowing us to easily see where the infection is and where it has spread.

    My advice for others looking into using CrowdStrike Falcon is that as an endpoint protection solution, Falcon is always reliable, and I can recommend that this is the product you can deploy and forget all the worries.

    We are an end user customer of CrowdStrike Falcon; we are not a partner or reseller, and we are not receiving any gift card or incentive for this review. We are just sharing our experience as an end user and as an IT Manager.

    I rate CrowdStrike Falcon 9 out of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.
    Updated: October 2026
    Buyer's Guide
    Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.