What is our primary use case?
We use CrowdStrike Falcon as our EDR solution, including antivirus.
How has it helped my organization?
As Symantec ended its endpoint protection, we were able to roll out CrowdStrike.
It is important to us that CrowdStrike is cloud-based because the way I understand it, that's their main engine for their next-gen EDR solution. The fact that it's cloud-native, flexible, and offers always-on protection is important because we want to have 24-hour monitoring of our environment. It is important to us that we don't have to worry about upgrades.
This product has worked flawlessly to prevent breaches, and then it has allowed us to prevent any downtime.
It has minimized our footprint because having the ability to implement the prevention policies has allowed us to focus on other projects. The prevention policies are working for us.
What is most valuable?
The most valuable feature is the activity dashboard because it gives you a holistic view of your environment from a security standpoint.
What needs improvement?
We would like to be able to perform on-demand scanning, rather than relying on the scheduler. Right now, CrowdStrike does not have an on-demand scanner. They have the always-on, but we have found instances where artifacts are being blocked from running, but they're not being removed. With an on-demand scanner, we would have the ability to remove those artifacts from an end user's machine.
I would like to see the multi-site environment functionality added in the next release. Currently, we are working under a single-site environment, and on the roadmap, they mentioned having the ability to have a multi-site environment.
For how long have I used the solution?
We have been using CrowdStrike Falcon for approximately eight months.
What do I think about the stability of the solution?
Stability-wise, they are very advanced in the next-gen antivirus game. CrowdStrike Falcon is always available.
What do I think about the scalability of the solution?
We have approximately 5,000 machines that are being managed. As time moves on, this number will grow, but we don't expect it to get larger in the near future.
How are customer service and technical support?
I would rate the technical support that we received during the deployment, as well as post-deployment, very well. They were very knowledgeable and gave us all of the tools we needed to have a successful deployment.
Which solution did I use previously and why did I switch?
Prior to Falcon, we were using Symantec antivirus. It was out of date, which is why we replaced it.
How was the initial setup?
It is very easy to deploy the solution's sensor to our endpoints. We use an automated process.
Our deployment took between two and three months, with paperwork, communication, and roll-out timeframes. Our implementation strategy included using IBM's BigFix application to push to Windows machines, and then we used a solution for the Mac to push it out remotely as well.
What about the implementation team?
Our IT Services team deployed this solution, and they leveraged consultants from CrowdStirke to get the proper packages for the process.
I'm sure that there is administration and upgrades to do, as sensors need to be updated or policies need to be adjusted. We have a group of approximately five people who are security engineers, IT Services, and directors who use it.
What's my experience with pricing, setup cost, and licensing?
With respect to pricing, my suggestion to others is to evaluate the environment and purchase what you need.
Which other solutions did I evaluate?
We looked at different options, such as Carbon Black, as we were replacing Symantec as our EDR solution, and CrowdStrike was the top winner. CrowdStrike is always on, 24 hours. Analysis, with the prevention and the detection policies, as well as the USB policies, are all very beneficial. The one thing that CrowdStrike did not have is the on-demand scanner.
What other advice do I have?
My advice for anybody who is interested in implementing CrowdStrike Falcon is to review and evaluate your environment and compare their EDR solutions.
I would rate this solution a ten out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: