Our primary use case is IPS and IDS.
Director of Information Technology at Slice
Effective for threat detection and remediation
Pros and Cons
- "The most valuable features are the complete IPS and IDS."
- "Forensic controls have room for improvement."
What is our primary use case?
How has it helped my organization?
CrowdStrike Falcon is extensively used by all 2,000 employees.
What is most valuable?
The most valuable features are the complete IPS and IDS. Both the feature provide good measures for threat detection and prevent network intrusions.
What needs improvement?
Forensic controls have room for improvement, and CrowdStrike Falcon can add more features here.
Another improvement could be the support for this product could be cheaper.
Buyer's Guide
CrowdStrike Falcon
December 2024
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years. We are using version 6.5.1.
What do I think about the stability of the solution?
It is a stable solution. I would rate it a nine out of ten.
What do I think about the scalability of the solution?
The scalability of CrowdStrike Falcon is quite good. There are around 2,000 users in our organization. I would rate it an eight out of ten. There are a few things, such as the forensic part and the investigation, that can be improved.
Which solution did I use previously and why did I switch?
I have worked on many other IDS solutions, but I found CrowdStrike Falcon to be the best.
How was the initial setup?
The setup is pretty straightforward. The deployment took some time because we didn't have an NBM solution. We installed it two years ago. But now it's clear, and we don't need much time to deploy it.
What about the implementation team?
The tech support is good but can be expensive when it goes out of the subscription.
What was our ROI?
I have seen a good return on investment.
What's my experience with pricing, setup cost, and licensing?
There is a license-based model. We use the yearly license. I would rate pricing a seven out of ten, where one is cheap, and ten is very expensive.
What other advice do I have?
I highly recommend people use CrowdStrike Falcon. Overall, I rate it a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Principal at Trifecta Cloud Security Solutions
A highly stable solution that is primarily used for its EDR and XDR capabilities
Pros and Cons
- "Regarding features, I appreciate its integration capabilities with identity providers...Stability-wise, I rate the solution a ten out of ten."
- "CrowdStrike needs to quit making up stuff about its features and functionality to bash its competition."
What is our primary use case?
The solution is primarily utilized for EDR and XDR capabilities, with some identity management features integrated through Falcon. In essence, it is employed like other endpoint protection platforms.
How has it helped my organization?
CrowdStrike Falcon no longer stands out compared to other endpoint protection platforms like Carbon Black or Microsoft Defender. Therefore, neither is superior to the other when used in our organization.
What is most valuable?
Regarding features, I appreciate its integration capabilities with identity providers, but it would have been better if they had their own identity product. The documentation is well-done in the solution.
What needs improvement?
CrowdStrike needs to quit making up stuff about its features and functionality to bash its competition.
I would like to see CrowdStrike become closer to an agentless solution where I wouldn't have to deploy software and maintain the version of the solution.
For how long have I used the solution?
I have been using CrowdStrike Falcon for a year. Also, I am using the solution's latest version.
What do I think about the stability of the solution?
There is no doubt about the stability of the solution. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
The solution has been successfully deployed in thousands of enterprises, so it is proven to be scalable. Major customers are using it, indicating that scalability is not a concern.
How are customer service and support?
There are two numbers to reach out to the technical support team. Considering the time taken to reach out to them with a request and get a response, I rate them a ten. Based on the technical skills of the customer support team to solve a problem, I rate them between a six and seven.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup process of the solution was straightforward. However, it is important to note that I was only setting up the solution in a POC (Proof of Concept) environment and not in a production one.
What was our ROI?
That's a difficult question to answer because CrowdStrike Falcon was implemented to replace a previous solution. While it was cheaper than the previous solution, the only initial return on investment was cost savings, as we have not yet developed key performance indicators to measure the security benefits of using CrowdStrike Falcon.
The effectiveness of a solution is not always easily measurable by simply avoiding a hack on a given day. Instead, it often requires analyzing reporting data to determine its environmental impact. This data must then be used to calculate the return on investment and compare it to the cost of ownership. In my experience, the only clear return on investment has been in the initial deployment of the solution. The solution's price has typically been lower than that of previous solutions.
What's my experience with pricing, setup cost, and licensing?
In my opinion, the pricing of CrowdStrike Falcon seems aggressive.
What other advice do I have?
I recommend anyone planning to use CrowdStrike Falcon to ensure that they have an integration team. This is because the solution does not have many built-in features, and it relies on partnership integration with other significant players, such as identity and network vulnerability solutions. Consequently, when deploying CrowdStrike, hiring additional personnel is necessary to comprehend the integration process. If CrowdStrike is ranked number one, then Microsoft is above CrowdStrike due to its fully integrated features. If Microsoft ever got details of incorrect licenses, it would run CrowdStrike out of business. Overall, I rate the product eight point nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
CrowdStrike Falcon
December 2024
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
Security Systems Analyst at a retailer with 5,001-10,000 employees
Allows us to sleep better at night
Pros and Cons
- "I value the overall behavior analysis of CrowdStrike. The engine of this product is what drew us to this solution."
- "I would also like to see the endpoint firewall component produce some level of logging and feedback."
What is our primary use case?
CrowdStrike is a malware protection solution that is deployed on a private cloud across all areas of our organization. We have deployed the solution to 10,000 users. Roles-based it's the security team.
We recently upgraded to a new feature that is set to roll out. CrowdStrike is a requirement, it's our standard. If you have a new OS deployed or a new server deployed, this is a required component. It has been automated as we grow and as we add more systems.
How has it helped my organization?
CrowdStrike allows us to sleep better at night.
What is most valuable?
I value the overall behavior analysis of CrowdStrike. The engine of this product is what drew us to this solution.
What needs improvement?
This solution lacks basic functionality, such as being able to perform on-demand scanning. This presents a challenge when it comes to the payment card industry, PCI which has that as built-in requirements for the PCI DSS standard.
I would also like to see the endpoint firewall component produce some level of logging and feedback.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
CrowdStrike is very stable, we've had very few technical issues. The false positive rate is average. It has been very easy to manage and to determine where issues are.
What do I think about the scalability of the solution?
This solution is very scalable. It is easy to roll out more agents and is fairly automated. We have it deployed in multiple environments such as hybrid versus cloud versus private.
How are customer service and support?
We have had very positive interactions with not only our manage service provider, but the vendor directly. They've offered good support when we've had some questions and concerns. Their documentation is fairly extensive.
Which solution did I use previously and why did I switch?
We follow trends to make sure we have the best product for our organizations. The one we were using fell behind a bit. We wanted something that was completely cloud-based so that the infrastructure wasn't on-prem and we wouldn't be required to manage the upgrades of servers and applications.
How was the initial setup?
The initial setup was moderate. There is a lot to think about and a lot to plan out, however once that is done the actual deployment is straightforward. We used a tiered deployment, deploying the product in a learning mode or logging mode only. We also did a tiered deployment by division and then enabled features by division to make sure that if there was an impact, we could at least contain it to one area and revert back as quickly as possible.
What about the implementation team?
We deployed with an integrator. They were very knowledgeable and knew what they were doing. They involved the vendor when required. We use half of an FTE to maintain the solution. We also have a managed service provided that also integrated the log files from this product into our SIM. We are pointing all the logs to a log reporting utility that allows us to react to alerts.
What was our ROI?
Because we are information security, we come with a price tag, unfortunately. When we look at it as a whole, we are able to sleep at night, we have a good solution and it is protecting us from the zero-days and the latest malware. I don't know what you put the cost of breach prevention at. We feel we are using a product that is at the top of the industry. We are doing as much as we can to protect our organization, so there is the return on investment that way.
What's my experience with pricing, setup cost, and licensing?
We pay yearly for the solution. It makes it easier for budgeting purposes. We did incur additional costs when we implemented their firewall solution, calling it the endpoint firewall.
Which other solutions did I evaluate?
We're constantly looking for other options the industry's top solutions and where the industry is going next. In cybersecurity, we ensure we are protected today but also make sure that we are thinking towards the future and analyzing other solutions to see if they are better, or potentially better in the future.
What other advice do I have?
If you are looking at CrowdStrike, plan appropriately. Make sure you have planned it out and do your testing. We found that it was legacy-friendly. We have a lot of legacy applications and we were concerned about that. We ran into some minor issues but we did find that it was friendly, however, there were some newer applications that the product did not interact with as well as we expected. They were easy fixes, but you should do your due diligence so you run into fewer surprises.
I would rate CrowdStrike a 9 out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Information Security Officer at a hospitality company with 5,001-10,000 employees
Stable and easy to set up, and has reduced our need to re-image machines
Pros and Cons
- "The most valuable feature is that we don't need to re-image machines as much as we had to."
- "They need to strengthen the forensic capabilities of this product, for e-discovery."
What is our primary use case?
We have various use cases. We are protecting servers and endpoints that are utilizing this product to focus on advanced, persistent threats, with the goal of reducing the overhead on the endpoint for early detection.
Right now, we have not put enforcement, and we're moving to the next level of detection.
How has it helped my organization?
Using this solution has reduced my need for imaging. We can mitigate the issue and address it immediately, for people both on and off of the network.
What is most valuable?
The most valuable feature is that we don't need to re-image machines as much as we had to.
What needs improvement?
They need to strengthen the forensic capabilities of this product, for e-discovery.
For how long have I used the solution?
We started testing and deploying CrowdStrike Falcon about a year and a half ago, in the early part of 2019.
What do I think about the stability of the solution?
In terms of stability, it's a great tool.
What do I think about the scalability of the solution?
At this time, we have between 5,000 and 6,000 endpoints.
How are customer service and technical support?
We have been in touch with CrowdStrike technical support and they have been very supportive.
Which solution did I use previously and why did I switch?
Prior to CrowdSrike, we used a signature-based solution from Symantec.
How was the initial setup?
The initial setup was very straightforward and very easy. We've been bringing stuff into the SWOT platform and getting that data. It has been pretty good.
What about the implementation team?
The implementation was done in-house. We had, in part, help from a strategic partner, EY.
Which other solutions did I evaluate?
CrowdStrike is what we did for the time and for the moment. It is number two when you look at the magic quadrant, and we have implemented that for the time being. When we selected it, that was right for us to get away from a Symantec signature-based environment for endpoint detection response.
We have moved over to CrowdStrike for now. When you look at the quadrant, the number one is Microsoft. With Defender built into the operating system, there is less overhead on the endpoint. We will eventually, most likely, migrate to that.
I have experience with Cylance, as well. They gave that the advanced persistent threat leader title, at one point in the market. I implemented that for one client and now, being in this CISO role, I went with CrowdStrike over Cyberreason and Cylance/Blackberry. The main reason for CrowdStrike is the Falcon technologies and what they do with their strategy.
We're moving to Office 365, and it will make sense for me to adopt Microsoft Defender because it's integrated into the platform. One of the differences between Defender versus CrowdStrike or any other of them is that they have to sit outside. Microsoft Defender can go deep down into the kernel, and that's a good thing for the endpoint. You can do a lot and detect a lot, which makes it far safer against advanced persistent threats.
What other advice do I have?
Overall, this product has been pretty good and I recommend it.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director Of Information Technology at DLZ Construction Svs.
Very good for endpoint security; we've remained infection free without any downtime
Pros and Cons
- "We haven't had any infections or down time."
- "Too many false positives."
What is our primary use case?
We use CrowdStrike for our endpoint security and we're about to tie it into vScaler. It's on every endpoint in the company and is used by everyone in the organization. It's anti-virus security software, so we'll continue to put it on every machine whether our company grows or shrinks.I'm the director of information technology in our company and we're a customer of CrowdStrike.
What is most valuable?
We rely on our environmental security and we haven't had any infections so that's valuable for us. It means we haven't lost any time due to the system being down from ransomware or anything like that, so it's quite positive.
What needs improvement?
Improvement could be made in the number of false positives we get, there are more than there needs to be. Typical Windows functions sometimes get stopped by CrowdStrike. In general, I'd rather err on the side of safety but some of these are really straightforward functions that should get through.
For the future, I think they need to keep building on their extensibility, the capability to be extended, so that it's not lost and we can utilize the knowledge that we're gaining from the endpoints.
For how long have I used the solution?
I've been using this solution for a little over a year.
What do I think about the stability of the solution?
This is a stable solution, I'm unaware of any failures.
What do I think about the scalability of the solution?
Scalability is expensive but it works. We've installed it on more than 900 machines in the corporation and it covers every role from civil engineers, architects, HR people, office workers and the server. Maintenance takes the equivalent of one full-time position but it's a shared responsibility among the IT team.
How are customer service and technical support?
The technical support do a good job.
How was the initial setup?
The initial setup occurred before I began working here although I believe it is quite straightforward. The install process for machines is pretty good. If we want to de-install it's not so great, but overall it's tolerable.
What's my experience with pricing, setup cost, and licensing?
I believe that we pay about US$ 65,000 annually which covers 900 machines in the company. There are no other costs but there are additional features that can be purchased but we haven't done that.
What other advice do I have?
CrowdStrike do their job well and can be compared to other solutions on the market such as SentinelOne and Huntress. They do need to be more extensible because right now they don't play well with others and it's a bit of a challenge on the management side.
I would rate this solution an eight out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security Operations Security Specialist at a insurance company with 1,001-5,000 employees
Good reporting capabilities and helps track machines much better
Pros and Cons
- "The solution's reporting console is phenomenal, and I can get a lot of data out of it."
- "The solution should have included remote wipe capability out of the box."
What is our primary use case?
We use the solution for end-user devices.
What is most valuable?
The reporting console is phenomenal, and I can get a lot of data out of it. The reporting capabilities are much better than anything I've used before. With CrowdStrike Falcon, we can track machines much better.
What needs improvement?
One of the things that we built and used quite regularly is a remote wipe capability within CrowdStrike Falcon. The solution should have included remote wipe capability out of the box.
If we have a compromised or stolen machine, we can quarantine it within the CrowdStrike console. However, it doesn't include a feature that enables you to remotely wipe that machine via the console. We had to build that in separately.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
We haven’t faced any issues with the solution’s stability.
What do I think about the scalability of the solution?
The solution's scalability has been amazing. We started by deploying it to 30 users, and over three months, we expanded to 5,000 users with no issues.
How are customer service and support?
For technical support, I open a ticket with the MSP, and they deal with it. Our MSP is excellent at resolving support tickets.
Which solution did I use previously and why did I switch?
We previously used Symantec Endpoint Protection. We switched to CrowdStrike Falcon because it was a new vendor with new technology.
How was the initial setup?
The solution's initial setup was very easy because we did an SCCM push for deployment.
What about the implementation team?
Our MSP did a lot of the deployment work for us. The solution was deployed by a small team in three months. It took four of us to deploy the tool to 5,000 users.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is great for us.
What other advice do I have?
It took us about three months to adjust to the new client and switch from a file-level scanner to an AI-based CrowdStrike scanner to see where we felt the differences. CrowdStrike Falcon is deployed on the cloud in our organization. From an end-user perspective, the solution does not require any maintenance after deployment.
New users should be prepared for unexpected alerts. CrowdStrike Falcon views things very differently than many conventional antivirus tools.
Overall, I rate the solution a nine out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Aug 4, 2024
Flag as inappropriateSecurity Analyst at a tech services company with 501-1,000 employees
Offers robust protection and excellent visibility in a highly scalable solution with great technical support
Pros and Cons
- "The feature I like the most is the solution's detection."
- "The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool."
What is our primary use case?
We use CrowdStrike Falcon to detect and alert us to any malware in our system. In our organization, we integrated CrowdStrike with a SIEM tool, which does the alerting. If the solution detects malware and issues an EDR alert, it notifies us and begins gathering data about the detection, including the hostname, user name, the hash value of the downloaded file, and the file's reputation. Then, we can ask the user the delete the file from the PC and drives, such as USB drives, if necessary. Following removing any malicious files, we can use CrowdStrike to run an AV scan on the affected device or devices.
How has it helped my organization?
We use the solution's Horizon module to protect multi-cloud work environments and integrate with SIEM tools. Detections in CrowdStrike trigger a response from the SIEM tool, allowing us to face threats via a coordinated approach.
Horizon simplifies security management of multi-cloud environments, and the improvement has been significant. Integration with a SIEM tool makes alerting and detection very rapid, which significantly helped.
To give an example, one of our employees mistakenly downloaded a malicious phishing video. The solution quarantined the file, protecting our organization from attack.
What is most valuable?
The feature I like the most is the solution's detection.
The fact that CrowdStrike Falcon is a cloud-native solution provides us with a lot of flexibility and always-on protection. This is very important to us because it enables automatic detection and quarantining of malicious files, and that's one of the features we like most about working with the tool.
The visibility provided by the solution in multi-cloud environments is excellent; it's one of the best features.
What needs improvement?
The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool.
For how long have I used the solution?
I've been using the solution for about three years.
What do I think about the stability of the solution?
The product's stability is good.
What do I think about the scalability of the solution?
The scalability is excellent; top tier. There are about 15 end users in our company, and they are members of the security team. We plan to increase our usage of the solution.
How was the initial setup?
It isn't challenging to deploy the solution's sensor to endpoints, and it becomes even more straightforward with some experience and understanding of the tool.
The deployment is relatively quick, though it takes a little longer than other products.
What about the implementation team?
We implemented via an in-house team as we had a lot of experience with the solution.
What's my experience with pricing, setup cost, and licensing?
The solution isn't very costly; it's affordable.
Which other solutions did I evaluate?
We evaluated a McAfee solution, and CrowdStrike has a lot more automation.
What other advice do I have?
I rate the product nine out of ten.
CrowdStrike is excellent at preventing breaches, and our security operations are more robust as a result. The automatic quarantining of malicious downloads keeps our system safe and our information out of the hands of attackers.
The solution reduces our security risk significantly; it's an advanced tool.
We learned about the solution when some of our employees saw a promotion campaign.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Lead Engg. Information Assurance at ACPL Systems Pvt Ltd
Simple initial setup, excellent support, and free upgrades
Pros and Cons
- "One of the most valuable features of CrowdStrike Falcon is when there are upgrades there are no additional fees."
- "CrowdStrike Falcon could improve by adding manual scanning or serverless scanning. It is not available at this time."
What is our primary use case?
I am using CrowdStrike Falcon to protect my endpoints from new zero-day threats.
What is most valuable?
One of the most valuable features of CrowdStrike Falcon is when there are upgrades there are no additional fees.
What needs improvement?
CrowdStrike Falcon could improve by adding manual scanning or serverless scanning. It is not available at this time.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two and a half years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable enough for our needs.
We have approximately 250 people using this solution in my organization.
How are customer service and support?
We have used the technical support for investigations, but not for installation or anything else.
I rate the support CrowdStrike Falcon a five out of five.
Which solution did I use previously and why did I switch?
I previously used McAfee but zero-day threats are not being protected. We evaluate CrowdStrike Falcon and when compared to McAfee, it was far better.
How was the initial setup?
The initial setup of CrowdStrike Falcon is easy.
What about the implementation team?
Our administrator of this solution had to configure the policy for the best detection.
What's my experience with pricing, setup cost, and licensing?
There is no license required to use this solution.
What other advice do I have?
My advice to others is this is a good solution that does not require a lot of attention. You can install it and it runs silently in the background.
I rate CrowdStrike Falcon a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Endpoint Detection and Response (EDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Identity Management (IM) Threat Intelligence Platforms Active Directory Management Extended Detection and Response (XDR) Attack Surface Management (ASM) Ransomware Protection Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
Microsoft Defender for Endpoint
Fortinet FortiEDR
Cisco Secure Endpoint
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
Check Point Harmony Endpoint
Trend Vision One
VMware Carbon Black Endpoint
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?