We use it for threat detection and threat hunting.
Senior Cyber Security Analyst at Securonix
Fast, easy to use, and integrates easily with any OS
Pros and Cons
- "Its integration capability is valuable. It integrates easily with any OS."
- "In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it."
What is our primary use case?
How has it helped my organization?
We are an MSP. We have deployed this in our customer environment, and we use it to detect threats in their environment. It is beneficial for customers to find cybersecurity-related threats on the endpoints.
The out-of-the-box configurations and threat intelligence provided by CrowdStrike are better than other vendors and competitors in this field. It improves our security strategy because we are building threat intelligence on top of CrowdStrike-provided detection.
We are building SIEM use cases on top of the data provided by CrowdStrike. There is reliability, and the response that we get from it is very fast. If any incident happens on the endpoint, it immediately detects that and sends that to our SIEM.
Endpoint security is a very crucial aspect of cybersecurity. Integrating CrowdStrike helps a lot to identify and dig deeper into the threats.
What is most valuable?
Its integration capability is valuable. It integrates easily with any OS.
What needs improvement?
They are good at what they are doing, but they can add more use cases. They can improve their documentation. It is a very big aspect where they are lacking. They have documentation, but it is behind the wall of authentication. It is not available publicly.
In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it. If they can add more information about an event, it will be beneficial for us and everyone else who is using CrowdStrike.
Buyer's Guide
CrowdStrike Falcon
February 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
For how long have I used the solution?
I have been using this solution for four years. I have had hands-on experience with it for about two to three years.
What do I think about the stability of the solution?
It is a stable product.
How are customer service and support?
I have not interacted with their support team. It is not a part of my job.
Which solution did I use previously and why did I switch?
I work with multiple vendors, not only CrowdStrike, in the endpoint space, and the CrowdStrike UI is better than others. The response of CrowdStrike is better than other vendors.
How was the initial setup?
It is deployed on the cloud. Its deployment is of moderate complexity. It is not easy, and it is also not difficult. Overall, it is easy to deploy and manage CrowdStrike Falcon across the organization.
What other advice do I have?
I would definitely recommend CrowdStrike Falcon. It is better than other solutions, such as VMware Carbon Black. CrowdStrike is doing better in this space.
If you are using CrowdStrike Falcon for the first time, it will be easy for you. You can definitely use it.
Overall, I would rate CrowdStrike Falcon an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Chief Information Security Officer at a hospitality company with 5,001-10,000 employees
Stable and easy to set up, and has reduced our need to re-image machines
Pros and Cons
- "The most valuable feature is that we don't need to re-image machines as much as we had to."
- "They need to strengthen the forensic capabilities of this product, for e-discovery."
What is our primary use case?
We have various use cases. We are protecting servers and endpoints that are utilizing this product to focus on advanced, persistent threats, with the goal of reducing the overhead on the endpoint for early detection.
Right now, we have not put enforcement, and we're moving to the next level of detection.
How has it helped my organization?
Using this solution has reduced my need for imaging. We can mitigate the issue and address it immediately, for people both on and off of the network.
What is most valuable?
The most valuable feature is that we don't need to re-image machines as much as we had to.
What needs improvement?
They need to strengthen the forensic capabilities of this product, for e-discovery.
For how long have I used the solution?
We started testing and deploying CrowdStrike Falcon about a year and a half ago, in the early part of 2019.
What do I think about the stability of the solution?
In terms of stability, it's a great tool.
What do I think about the scalability of the solution?
At this time, we have between 5,000 and 6,000 endpoints.
How are customer service and technical support?
We have been in touch with CrowdStrike technical support and they have been very supportive.
Which solution did I use previously and why did I switch?
Prior to CrowdSrike, we used a signature-based solution from Symantec.
How was the initial setup?
The initial setup was very straightforward and very easy. We've been bringing stuff into the SWOT platform and getting that data. It has been pretty good.
What about the implementation team?
The implementation was done in-house. We had, in part, help from a strategic partner, EY.
Which other solutions did I evaluate?
CrowdStrike is what we did for the time and for the moment. It is number two when you look at the magic quadrant, and we have implemented that for the time being. When we selected it, that was right for us to get away from a Symantec signature-based environment for endpoint detection response.
We have moved over to CrowdStrike for now. When you look at the quadrant, the number one is Microsoft. With Defender built into the operating system, there is less overhead on the endpoint. We will eventually, most likely, migrate to that.
I have experience with Cylance, as well. They gave that the advanced persistent threat leader title, at one point in the market. I implemented that for one client and now, being in this CISO role, I went with CrowdStrike over Cyberreason and Cylance/Blackberry. The main reason for CrowdStrike is the Falcon technologies and what they do with their strategy.
We're moving to Office 365, and it will make sense for me to adopt Microsoft Defender because it's integrated into the platform. One of the differences between Defender versus CrowdStrike or any other of them is that they have to sit outside. Microsoft Defender can go deep down into the kernel, and that's a good thing for the endpoint. You can do a lot and detect a lot, which makes it far safer against advanced persistent threats.
What other advice do I have?
Overall, this product has been pretty good and I recommend it.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
CrowdStrike Falcon
February 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
IT Security Operations Security Specialist at a insurance company with 1,001-5,000 employees
Good reporting capabilities and helps track machines much better
Pros and Cons
- "The solution's reporting console is phenomenal, and I can get a lot of data out of it."
- "The solution should have included remote wipe capability out of the box."
What is our primary use case?
We use the solution for end-user devices.
What is most valuable?
The reporting console is phenomenal, and I can get a lot of data out of it. The reporting capabilities are much better than anything I've used before. With CrowdStrike Falcon, we can track machines much better.
What needs improvement?
One of the things that we built and used quite regularly is a remote wipe capability within CrowdStrike Falcon. The solution should have included remote wipe capability out of the box.
If we have a compromised or stolen machine, we can quarantine it within the CrowdStrike console. However, it doesn't include a feature that enables you to remotely wipe that machine via the console. We had to build that in separately.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
We haven’t faced any issues with the solution’s stability.
What do I think about the scalability of the solution?
The solution's scalability has been amazing. We started by deploying it to 30 users, and over three months, we expanded to 5,000 users with no issues.
How are customer service and support?
For technical support, I open a ticket with the MSP, and they deal with it. Our MSP is excellent at resolving support tickets.
Which solution did I use previously and why did I switch?
We previously used Symantec Endpoint Protection. We switched to CrowdStrike Falcon because it was a new vendor with new technology.
How was the initial setup?
The solution's initial setup was very easy because we did an SCCM push for deployment.
What about the implementation team?
Our MSP did a lot of the deployment work for us. The solution was deployed by a small team in three months. It took four of us to deploy the tool to 5,000 users.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is great for us.
What other advice do I have?
It took us about three months to adjust to the new client and switch from a file-level scanner to an AI-based CrowdStrike scanner to see where we felt the differences. CrowdStrike Falcon is deployed on the cloud in our organization. From an end-user perspective, the solution does not require any maintenance after deployment.
New users should be prepared for unexpected alerts. CrowdStrike Falcon views things very differently than many conventional antivirus tools.
Overall, I rate the solution a nine out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Aug 4, 2024
Flag as inappropriateCIO & Information manager at Home Benelux
Works with Office 365 and helps to manage threats
Pros and Cons
- "The main feature we rely on is the product's intelligence. We appreciate the advice from the team during implementation. One of the main reasons we chose this product is its compatibility with Office 365."
- "Improvement is always possible. It's challenging to gauge how much future mitigation is provided, especially since we've only been using the product for about one and a half years. Every product faces this challenge because nothing is ever completely foolproof. So, besides relying on technology, we also focus on increasing our staff's awareness of security issues. Feedback from my colleagues suggests that the reporting and dashboarding of incidents could be improved."
What is our primary use case?
The tool helps to increase security because the threats we face keep changing, so we need better protection. In the past, we've faced some attacks on our network, and while we managed to deal with them, we realized we needed even stronger protection. That's why we decided to implement CrowdStrike Identity Protection.
What is most valuable?
The main feature we rely on is the product's intelligence. We appreciate the advice from the team during implementation. One of the main reasons we chose this product is its compatibility with Office 365.
What needs improvement?
Improvement is always possible. It's challenging to gauge how much future mitigation is provided, especially since we've only been using the product for about one and a half years. Every product faces this challenge because nothing is ever completely foolproof. So, besides relying on technology, we also focus on increasing our staff's awareness of security issues. Feedback from my colleagues suggests that the reporting and dashboarding of incidents could be improved.
For how long have I used the solution?
I have been working with the product for one and a half years.
What do I think about the stability of the solution?
I rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
Scalability isn't a problem for us. Many big multinational companies use CrowdStrike Identity Protection, so it's designed to handle environments like ours without any issues. My company has 500 users.
How was the initial setup?
The tool's deployment is easy. Thanks to the installation scripting we utilized, the technical rollout took about two weeks. Then, there was some additional time, around two to four weeks, for customization and configuration. After that, the systems were up and running. So, all in all, it took about three months to have our mitigation strategies in place. We have one engineer for maintenance.
What other advice do I have?
I rate the overall product an eight out of ten. I would recommend it to others. However, it's crucial to understand areas where the product might not provide coverage and how to mitigate those gaps. For example, it covers endpoints, networks, and Office 365 environments, but are there other areas in the attack surface that it doesn't address well? It's essential to be aware of any potential gaps upfront.
The solution helps in preventing incidents. However, it's challenging to quantify the exact impact because we don't know what would have happened without it. It's similar to having insurance for your house.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Jun 6, 2024
Flag as inappropriatePrinciple Consultant at Infosec Ventures
Light on resources, good performance, and useful administrator functions
Pros and Cons
- "CrowdStrike Falcon's most valuable features are the lightweight agent which has absolutely zero performance issues. There is no performance deterioration on the laptop on the network. It is a signature-less antivirus and anti-malware solution, it doesn't depend on signatures which better protects the systems."
- "The technical support could improve because I am in India and the support I receive is from the UK or Australia. It is difficult to manage the time difference. The service could be faster. However, when we do have the support they are knowledgeable."
What is most valuable?
CrowdStrike Falcon's most valuable features are the lightweight agent which has absolutely zero performance issues. There is no performance deterioration on the laptop on the network. It is a signature-less antivirus and anti-malware solution, it doesn't depend on signatures which better protects the systems.
The solution comes with many competitive modules, such as the Discover Module. It is helpful to us with regard to the application search. For example, which users are using which application, what is the application involved in, how many administrators and local users are there, and do the users have administrator privileges. It can give us a lot of information. Additionally, it can inform us if the user's password has changed. The solution is very useful for administrators and is overall easy to use and manage.
For how long have I used the solution?
I have been using CrowdStrike Falcon for seven months.
What do I think about the stability of the solution?
CrowdStrike Falcon is a highly stable solution. We have not had any performance or compatibility problems.
What do I think about the scalability of the solution?
The solution is scalable.
We have approximately 1,000 users using this solution in my organization. We plan to increase usage in the future.
How are customer service and support?
The technical support could improve because I am in India and the support I receive is from the UK or Australia. It is difficult to manage the time difference. The service could be faster. However, when we do have the support they are knowledgeable.
Which solution did I use previously and why did I switch?
We were previously using Symantec and we switched to CrowdStrike Falcon.
How was the initial setup?
The initial setup is straightforward. It took us approximately two weeks to implement.
What about the implementation team?
We have one person that does the implementation and support of CrowdStrike Falcon.
What's my experience with pricing, setup cost, and licensing?
The licensing model is straightforward. We choose the features we want and we then can download the package we want.
What other advice do I have?
I would highly recommend this solution to others.
I rate CrowdStrike Falcon a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Information Technology at SIT
Helps protect our data, is stable, and reasonably priced
Pros and Cons
- "The DLP is the most valuable feature of CrowdStrike Falcon."
- "The console is not user-friendly or visually appealing and has room for improvement."
What is our primary use case?
A popular choice for Data Loss Prevention is CrowdStrike Falcon. This is the primary function our clients leverage it for, as it offers industry-leading DLP capabilities.
How has it helped my organization?
CrowdStrike Falcon has helped our customers secure their confidential data.
What is most valuable?
The DLP is the most valuable feature of CrowdStrike Falcon. Additionally, the scanning is good and the deployment is easy.
What needs improvement?
The console is not user-friendly or visually appealing and has room for improvement. I would like a single pane of glass dashboard.
For how long have I used the solution?
I have been an integrator of CrowdStrike Falcon for one day.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
Which solution did I use previously and why did I switch?
I have also worked with Trend Micro and Panda.
How was the initial setup?
The initial deployment is straightforward. I would rate the ease of setup nine out of ten.
Two people are required for the deployment.
I need to upgrade the software occasionally but it doesn't require continuous maintenance.
While the specific deployment time varies depending on each client's individual environment, on average the process can be completed in a couple of days.
What was our ROI?
I only deploy the solution for clients, I don't calculate their ROI.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon's pricing is reasonable. We can customize features and that affects the pricing.
We pay 40,000 dirhams per 100 users.
What other advice do I have?
I would rate CrowdStrike Falcon nine out of ten.
Our clientele ranges from small to enterprise-level businesses.
I recommend CrowdStrike Falcon as it provides all the features of an EDR.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
IT Consultant at a comms service provider with 5,001-10,000 employees
Provides real-time monitoring and response to security incidents
Pros and Cons
- "The most valuable feature of CrowdStrike Falcon for me is its unified sensor, applicable across all models."
- "There is room for improvement in managing multiple customer IDs."
What is our primary use case?
We use CrowdStrike Falcon mostly for EDR.
How has it helped my organization?
We implemented CrowdStrike Falcon to gain better control over our endpoints, servers, and work sessions. Unlike traditional antivirus programs, Falcon's sophisticated features allow us to comprehensively manage and enhance security, providing a more robust solution for our specific needs.
In the past year, Falcon has significantly improved our organization's security by consolidating endpoint management. With a single call to Falcon, we can oversee all endpoints, eliminating the need for multiple platforms and streamlining our security operations for better efficiency and awareness.
What is most valuable?
The most valuable feature of CrowdStrike Falcon for me is its unified sensor, applicable across all models. This consistency simplifies operations, and while the analytics and server capabilities are significant, having a single sensor for all models stands out as the key advantage in managing security effectively.
What needs improvement?
There is room for improvement in managing multiple customer IDs. Enhancements in the console web for better control and customization of sensor features would be valuable to ensure a smoother experience in handling various customer IDs and installations.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about a year.
What do I think about the stability of the solution?
I have not had any stability issues with CrowdStrike Falcon.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon as a ten out of ten.
How are customer service and support?
The technical support is not very good. I would rate it as an eight out of ten. One improvement could be reducing the response time for cases, as waiting two or three days, even for less critical issues, can be a bit long. Additionally, a better feedback loop on submitted ideas would enhance the efficiency of communication with the product group, providing more clarity on whether proposed features or versions will be considered.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Falcon, we used Trellix. We switched to Falcon for enhanced security, moving beyond just antivirus protection. Falcon provides more advanced features and a comprehensive security solution.
How was the initial setup?
The deployment of Falcon was relatively easy, with no major issues except occasional misconfigurations on the filter. The process for individual work sessions is fast, taking around a few minutes, but for servers, it requires more time due to the need for antivirus removal and sensor replacement, involving server restarts. Overall, the deployment time depends on the scope, ranging from minutes for work sessions to more extended periods for servers.
What other advice do I have?
At the moment, we have around twenty thousand users in our environment. Our setup spans multiple locations, mainly in Portugal, and we operate on various operating systems, including Mac, Linux, and Windows.
Falcon, being a SaaS product, doesn't require maintenance on our end. Updates are needed for servers, but they can be easily managed through the web interface without causing any inconvenience for us.
I would recommend conducting a proof of concept with CrowdStrike Falcon before making a decision. While the product has strengths, I would advise new users to address questions and doubts directly with the product team, especially when seeking new features or improvements. Ensure there is a clear communication channel for feedback and inquiries. Overall, I would rate CrowdStrike Falcon as a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Director of Information Technology at Slice
Effective for threat detection and remediation
Pros and Cons
- "The most valuable features are the complete IPS and IDS."
- "Forensic controls have room for improvement."
What is our primary use case?
Our primary use case is IPS and IDS.
How has it helped my organization?
CrowdStrike Falcon is extensively used by all 2,000 employees.
What is most valuable?
The most valuable features are the complete IPS and IDS. Both the feature provide good measures for threat detection and prevent network intrusions.
What needs improvement?
Forensic controls have room for improvement, and CrowdStrike Falcon can add more features here.
Another improvement could be the support for this product could be cheaper.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years. We are using version 6.5.1.
What do I think about the stability of the solution?
It is a stable solution. I would rate it a nine out of ten.
What do I think about the scalability of the solution?
The scalability of CrowdStrike Falcon is quite good. There are around 2,000 users in our organization. I would rate it an eight out of ten. There are a few things, such as the forensic part and the investigation, that can be improved.
Which solution did I use previously and why did I switch?
I have worked on many other IDS solutions, but I found CrowdStrike Falcon to be the best.
How was the initial setup?
The setup is pretty straightforward. The deployment took some time because we didn't have an NBM solution. We installed it two years ago. But now it's clear, and we don't need much time to deploy it.
What about the implementation team?
The tech support is good but can be expensive when it goes out of the subscription.
What was our ROI?
I have seen a good return on investment.
What's my experience with pricing, setup cost, and licensing?
There is a license-based model. We use the yearly license. I would rate pricing a seven out of ten, where one is cheap, and ten is very expensive.
What other advice do I have?
I highly recommend people use CrowdStrike Falcon. Overall, I rate it a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Detection and Response (EDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Identity Management (IM) Threat Intelligence Platforms Active Directory Management Extended Detection and Response (XDR) Attack Surface Management (ASM) Ransomware Protection Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Cisco Secure Endpoint
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
Check Point Harmony Endpoint
Trend Vision One
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?