The most valuable feature of CrowdStrike Falcon is its accuracy.
Head of IT at Alantra
Accurate, good technical support, and reliable
Pros and Cons
- "The most valuable feature of CrowdStrike Falcon is its accuracy."
- "CrowdStrike Falcon could improve the logs by making them free to the API."
What is most valuable?
What needs improvement?
CrowdStrike Falcon could improve the logs by making them free to the API.
For how long have I used the solution?
I have used CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
The solution is stable.
Buyer's Guide
CrowdStrike Falcon
April 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
848,207 professionals have used our research since 2012.
What do I think about the scalability of the solution?
CrowdStrike Falcon is a scalable solution.
We have approximately 800 people using this solution in my organization.
How are customer service and support?
CrowdStrike Falcon technical support has been fine in my experience.
Which solution did I use previously and why did I switch?
I have used other solutions before CrowdStrike Falcon, such as Symantec.
Symantec does not have any advantage over CrowdStrike.
How was the initial setup?
The initial setup of CrowdStrike Falcon is easy.
What's my experience with pricing, setup cost, and licensing?
The price of CrowdStrike Falcon is reasonable.
What other advice do I have?
I rate CrowdStrike Falcon a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Product Manager at Softcell Technologies Limited
Prevent unauthorized access or identity theft from external sites
Pros and Cons
- "It helps to prevent unauthorized access or identity theft from external sites. If your identity is stolen, you can ban it."
- "One thing that is not yet available is attack simulation."
What is our primary use case?
It also helps you with access, like we have dark web monitoring and admin protection management. So, the use cases can vary from organization to organization, but every organization has different value in it.
What is most valuable?
It helps to prevent unauthorized access or identity theft from external sites. If your identity is stolen, you can ban it.
Real-time monitoring is important because it runs multiple things on a single platform, like IDA, EDR, XDR, and SIM solutions. It captures all technology with one agent, which makes it easier for us to fix customer issues.
Having a single console is helpful, especially when customers have multiple vendors for their products. It's easier to manage one partner. In this case, CrowdStrike Falcon helps.
What needs improvement?
One thing that is not yet available is attack simulation. For example, if someone tries to attack your Active Directory on inactive accounts, a cyber attacker could hack those accounts and try to get into your company. This could be a feature to add. It would give a fake reply each time someone tries to hack it. Multiple companies that I know of would like that.
For how long have I used the solution?
I have been using it for two years.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. It's a scalable solution that is very easy to deploy.
It is suitable for every kind of business, including small, medium, or enterprise businesses.
How are customer service and support?
Technical support depends on a system integrator.
CrowdStrike technical support regarding Identity Protection has a team, but if there's no issue with the agent, you can work it out yourself.
The support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy. We only have one option available right now: on the cloud. It gets applied to endpoints, but it's cloud-based.
It is very easy to integrate this product into our existing environment.
What's my experience with pricing, setup cost, and licensing?
It's a premium product.
What other advice do I have?
From my end, it works. But it can be recommended or viewed by a personal customer. We are not the sole user of CrowdStrike Falcon. It's the end user.
I would recommend using it. For me, it is the best product ever. Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Last updated: Jul 30, 2024
Flag as inappropriateBuyer's Guide
CrowdStrike Falcon
April 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
848,207 professionals have used our research since 2012.
Chief Technology Officer at a manufacturing company with 1,001-5,000 employees
Is user-friendly, improves performance, and protects our end users
Pros and Cons
- "CrowdStrike Falcon offers a comprehensive dashboard that is highly effective in protecting against and blocking external infiltration attempts."
- "The pricing structure should allow for some flexibility."
What is our primary use case?
We use CrowdStrike Falcon for endpoint protection and cybersecurity.
We implemented CrowdStrike Falcon to ensure our systems were secure and there were no infiltrations to our system.
We deploy CrowdStrike Falcon across a variety of platforms, including cloud and edge environments. We ensure it meets rigorous security standards, is properly certified, and adheres to our data management policy.
How has it helped my organization?
We integrated CrowdStrike Falcon with our end-user systems and servers.
Since implementing CrowdStrike Falcon, we haven't experienced any serious threats, and we've seen a decrease in phishing and ransomware emails. This suggests it's been very effective in mitigating those threats.
The UI is easy to use and comprehensive.
CrowdStrike Falcon's performance has improved our user productivity.
What is most valuable?
CrowdStrike Falcon offers a comprehensive dashboard that is highly effective in protecting against and blocking external infiltration attempts.
What needs improvement?
The pricing structure should allow for some flexibility.
For how long have I used the solution?
I have been using CrowdStrike Falcon for almost 3 years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon 8 out of 10.
How are customer service and support?
The technical support is good. We have not had any issues with them.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment was straightforward. The deployment doesn't take more than one day. Those involved with the deployment are system engineers, IT analysts, and software engineers.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The price is fixed with no room for negotiation.
What other advice do I have?
I would rate CrowdStrike Falcon 8 out of 10.
We have deployed CrowdStrike Falcon in multiple departments, locations, and satellite offices.
CrowdStrike Falcon doesn't require maintenance from our end other than the updates.
I recommend CrowdStrike Falcon to others.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Manager at a healthcare company with 10,001+ employees
Provides great protection and can crosscheck environments. Helpful in investigating any alerts
Pros and Cons
- "It provides very good protection and the ability to crosscheck environments."
- "Falcon could include more integrative features."
What is our primary use case?
We use the EDR feature.
What is most valuable?
This is unlike any other EDR solution that I am familiar with. It provides very good protection and the ability to crosscheck environments. It's really helpful in investigating any alerts and is easy to use. You can use some of the Splunk language to search.
What needs improvement?
We've tried some integrations with solutions, closing off false positives and things like that. Falcon could include more features in that area. In addition, some features are modularized and we're unable to buy them as we're in the healthcare field and limited in the amount we can invest.
For how long have I used the solution?
I've been using this product for close to 18 months.
What do I think about the stability of the solution?
We haven't had any stability issues.
What do I think about the scalability of the solution?
The solution is very scalable but we had issues with some groups, that manage their own devices and wanted to have access to self-manage them. We weren't able to do that, unfortunately.
How are customer service and support?
My team has interacted with tech support and I believe the issues were resolved in a timely manner.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used other solutions such as Setinel One.
How was the initial setup?
The initial setup was very straightforward and smooth.
What's my experience with pricing, setup cost, and licensing?
Falcon is more expensive than every other solution on the market. That said, they do have a better product than anyone else.
What other advice do I have?
Some of the default settings are set to 'easy' which isn't sufficient. We had some conversations around this and the recommendation was to change some of these settings to more aggressive ones on the policy side. I know some organizations have had issues automatically updating CrowdStrike to the latest version. I recommend going through the change process but saving it at minus one for a while to avoid all the negative downtimes where you might need to roll back to the previous update.
When we switched to CrowdStrike, we didn't expect it to find anything that was already on the computer because the primary reason we swapped was because of EDR. But it did find things that were dormant as well as other things.
I rate this solution nine out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director Of Information Technology at TollPlus LLC.
An AI-driven solution that self-activates to find issues and provide alerts
Pros and Cons
- "The solution is silent and sits on your system as one single agent."
- "Technical support could be better than what is currently offered."
What is our primary use case?
Our company's line of business includes financial transactions with an insurance policy that requires EDR protection. Compliance is part of our policy and agreement with customers.
We currently have 1,100 users of the solution.
What is most valuable?
The solution is silent and sits on your system as one single agent.
Only one or two MB of memory are consumed which is much less than other products.
The solution is AI-driven so it self-activates to find issues and provide alerts or notifications rather than running all the time.
The portal is very user-friendly so it is not difficult to manage.
The solution doesn't require system restarts. That is one disadvantage of Symantec or Kaspersky because they require restarts when you uninstall or reinstall.
What needs improvement?
Technical support could be better than what is currently offered.
For how long have I used the solution?
I have been using the solution for three months.
What do I think about the stability of the solution?
The solution is stable with no issues.
We have only used the solution for three months so will continue to monitor stability for the next several months.
I rate stability an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. We do not yet have the requirement to take an in-depth look at scalability.
I rate scalability an eight out of ten.
How are customer service and support?
Technical support could be better because there are ownership issues.
For example, when you raise a support case there is not much communication between the account manager and support. The account manager is supposed to own the case but instead is disconnected from it.
I rate support a six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used Symantec and Kaspersky.
How was the initial setup?
The setup is pretty easy to walk through without much trouble.
I rate setup an eight out of ten.
What about the implementation team?
We utilized a third-party for implementation. They helped us with the admin console, training, and the pilot setup that we eventually took over. Our internal team included two security staff and four support staff.
We were moving from Symantec and Kaspersky. We targeted our servers first because Symantec is difficult to uninstall and there is an interim process for removal. Once completed, we installed the solution.
It took about two months to complete implementation across all systems.
What was our ROI?
We did our homework in advance for cost or other things to calculate ROI. The solution met our expectations so ROI is rated a seven out of ten.
What's my experience with pricing, setup cost, and licensing?
The pricing is competitive and includes all features and support.
I rate pricing an eight out of ten.
Which other solutions did I evaluate?
We evaluated Microsoft Defender, Sophos, Symantec, and Trend Micro before choosing CrowdStrike Falcon.
What other advice do I have?
I recommend using the solution and rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at a tech services company with 501-1,000 employees
Offers robust protection and excellent visibility in a highly scalable solution with great technical support
Pros and Cons
- "The feature I like the most is the solution's detection."
- "The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool."
What is our primary use case?
We use CrowdStrike Falcon to detect and alert us to any malware in our system. In our organization, we integrated CrowdStrike with a SIEM tool, which does the alerting. If the solution detects malware and issues an EDR alert, it notifies us and begins gathering data about the detection, including the hostname, user name, the hash value of the downloaded file, and the file's reputation. Then, we can ask the user the delete the file from the PC and drives, such as USB drives, if necessary. Following removing any malicious files, we can use CrowdStrike to run an AV scan on the affected device or devices.
How has it helped my organization?
We use the solution's Horizon module to protect multi-cloud work environments and integrate with SIEM tools. Detections in CrowdStrike trigger a response from the SIEM tool, allowing us to face threats via a coordinated approach.
Horizon simplifies security management of multi-cloud environments, and the improvement has been significant. Integration with a SIEM tool makes alerting and detection very rapid, which significantly helped.
To give an example, one of our employees mistakenly downloaded a malicious phishing video. The solution quarantined the file, protecting our organization from attack.
What is most valuable?
The feature I like the most is the solution's detection.
The fact that CrowdStrike Falcon is a cloud-native solution provides us with a lot of flexibility and always-on protection. This is very important to us because it enables automatic detection and quarantining of malicious files, and that's one of the features we like most about working with the tool.
The visibility provided by the solution in multi-cloud environments is excellent; it's one of the best features.
What needs improvement?
The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool.
For how long have I used the solution?
I've been using the solution for about three years.
What do I think about the stability of the solution?
The product's stability is good.
What do I think about the scalability of the solution?
The scalability is excellent; top tier. There are about 15 end users in our company, and they are members of the security team. We plan to increase our usage of the solution.
How was the initial setup?
It isn't challenging to deploy the solution's sensor to endpoints, and it becomes even more straightforward with some experience and understanding of the tool.
The deployment is relatively quick, though it takes a little longer than other products.
What about the implementation team?
We implemented via an in-house team as we had a lot of experience with the solution.
What's my experience with pricing, setup cost, and licensing?
The solution isn't very costly; it's affordable.
Which other solutions did I evaluate?
We evaluated a McAfee solution, and CrowdStrike has a lot more automation.
What other advice do I have?
I rate the product nine out of ten.
CrowdStrike is excellent at preventing breaches, and our security operations are more robust as a result. The automatic quarantining of malicious downloads keeps our system safe and our information out of the hands of attackers.
The solution reduces our security risk significantly; it's an advanced tool.
We learned about the solution when some of our employees saw a promotion campaign.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Dy General Manager at a real estate/law firm with 501-1,000 employees
Great user experience, very little maintenance required, and easy to set up
Pros and Cons
- "There's almost no maintenance required. It's very low if there's any at all."
- "The solution needs to have integration with on-premises security devices and security facilities. That means all the security products, including the perimeter firewall, the DMZ."
What is our primary use case?
The solution is primarily being used at our endpoint, which includes roaming users with laptops. It is being used in all of our servers at our data center. Our security team can monitor everything centrally using the Falcon dashboard. If there is an incident, our team can actually go to the root cause of the incident to try to solve it there.
What is most valuable?
The overall user experience is good. As of today, there have been no incidents that we've had to deal with and we've been using it for years.
The solution has a very good graphical interface. It makes it easy to use. The central monitoring is excellent.
There's almost no maintenance required. It's very low if there's any at all.
The solution is an AI and ML-enabled tool for protecting our endpoints. We're still able to use Symantec as an endpoint as well.
What needs improvement?
The solution needs to have integration with on-premises security devices and security facilities. That means all the security products, including the perimeter firewall, the DMZ.
I'd really like to have a complete solution. Right now most of the incidents happen on our endpoints. It is visible at the endpoint, the end server. If this can have a correlation tool that could actually give us a comprehensive dashboard, that would be useful. It could give us top-down visibility and could be from the firewall or any kind of security protection tool. It could be part of the DNS protection suite. However, that's why it's so important to have better integration capabilities.
If this endpoint is trying to get at this particular website and it is identified as DNS level protection, that also comes to this dashboard. Around 80% to 90% view of whatever it is happening with this endpoint, whatever action it is doing, can be inspected on the dashboard.
If the endpoint is protected by CrowdStrike. I am only to access this application through a CrowdStrike protected device.
For how long have I used the solution?
We have been using CrowdStrike as a tool now for the last three months.
What do I think about the stability of the solution?
The stability may be too early to judge, as we are still in a POC. However, when we see the product, it is very, very stable.
What do I think about the scalability of the solution?
We didn't go with the Basic version. We went with Superior. Even the insurance companies are also sold on this product.
We find that the solution is very, very scalable as a tool and it can completely manage and protect the endpoint. It offers around 99.99% of your protection and assurance and can scale up however much you like.
We have implemented it for approximately 200 users as a POC. We are ready to have a contract with CrowdStrike and we will be implementing it for 700 users in the end, so we will scale it from the POC when we begin to officially use it.
How are customer service and technical support?
Due to the fact that we are still running a POC, we have direct access to the principal on the contract. They have given us a lot of confidence in the product and they are always available alongside the system integrator. We basically have two layers of support.
At this initial stage, if there is any troubleshooting needed, or any type of support is required, the system integrator will provide this to us. If we need to escalate to support for some reason, we have agreed to have CrowdStrike themselves look into any issues.
So far, it's been an effective system and we are satisfied with the level of support we've received.
Which solution did I use previously and why did I switch?
We were using Symantec products, which were Symantec EndPoint Four and Five. We found that the latest modules needed additional tools to protect us. There were multiple tools needed at various levels. There was complexity in increasing users on this platform. It also took a more traditional approach to security, and we were looking for something more advanced that had advanced AI and ML capability.
We evaluated CrowdStrike and we found it satisfactory in our environment. Therefore, we decided to change to it from Symantec.
How was the initial setup?
The initial setup is very, very straightforward, and very easy to use. So far, we've found it very easy to drill down to the root cause.
This is a new area and product for us, so we decided to start using it as a POC. We started in March, or the end of February, of this year, and we have done a POC for some of our users. We'll be going forward with a full implementation and increasing our usage.
In terms of maintenance, I don't find there's much of a requirement for it. It is very easy to maintain. For monitoring and reporting purpose, we have access to a dashboard. Our security can take a look at everything themselves. We also have team members that are capable of configuring this product. That will help us to reduce the requirement of manpower in the long run.
What about the implementation team?
We had a system integrator partner that assisted us with the POC.
What's my experience with pricing, setup cost, and licensing?
I'm not sure what the exact cost of the solution is.
What other advice do I have?
We're a customer. We don't have a business partnership with this solution.
I'm not sure which version of the solution we're using right now. It is the latest, as far as I know. We're currently running a POC with it.
In today's environment, it's very crucial to protect a company from ransomware, and malware. We focus mainly on avoiding these types of attacks. We're always interested in the latest tools that have the latest techniques and are effective in our environment.
On top of that. we've noticed during the pandemic, there are even more threats happening. We need to focus most of our energy on the endpoints which are basically connected to an unprotected network.
The focus on the endpoints has to be increased at this point in time to ensure we have maximum protection. We prefer to have a cloud-based product rather than an on-premise-based product to protect our data and our endpoints. Therefore, we may need to move to a cloud-based protection suite. Other companies should also consider this. Whether they choose a product like CrowdStrike, Cortex, or Cylance is up to them.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Cyber Security Analyst at Securonix
Fast, easy to use, and integrates easily with any OS
Pros and Cons
- "Its integration capability is valuable. It integrates easily with any OS."
- "In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it."
What is our primary use case?
We use it for threat detection and threat hunting.
How has it helped my organization?
We are an MSP. We have deployed this in our customer environment, and we use it to detect threats in their environment. It is beneficial for customers to find cybersecurity-related threats on the endpoints.
The out-of-the-box configurations and threat intelligence provided by CrowdStrike are better than other vendors and competitors in this field. It improves our security strategy because we are building threat intelligence on top of CrowdStrike-provided detection.
We are building SIEM use cases on top of the data provided by CrowdStrike. There is reliability, and the response that we get from it is very fast. If any incident happens on the endpoint, it immediately detects that and sends that to our SIEM.
Endpoint security is a very crucial aspect of cybersecurity. Integrating CrowdStrike helps a lot to identify and dig deeper into the threats.
What is most valuable?
Its integration capability is valuable. It integrates easily with any OS.
What needs improvement?
They are good at what they are doing, but they can add more use cases. They can improve their documentation. It is a very big aspect where they are lacking. They have documentation, but it is behind the wall of authentication. It is not available publicly.
In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it. If they can add more information about an event, it will be beneficial for us and everyone else who is using CrowdStrike.
For how long have I used the solution?
I have been using this solution for four years. I have had hands-on experience with it for about two to three years.
What do I think about the stability of the solution?
It is a stable product.
How are customer service and support?
I have not interacted with their support team. It is not a part of my job.
Which solution did I use previously and why did I switch?
I work with multiple vendors, not only CrowdStrike, in the endpoint space, and the CrowdStrike UI is better than others. The response of CrowdStrike is better than other vendors.
How was the initial setup?
It is deployed on the cloud. Its deployment is of moderate complexity. It is not easy, and it is also not difficult. Overall, it is easy to deploy and manage CrowdStrike Falcon across the organization.
What other advice do I have?
I would definitely recommend CrowdStrike Falcon. It is better than other solutions, such as VMware Carbon Black. CrowdStrike is doing better in this space.
If you are using CrowdStrike Falcon for the first time, it will be easy for you. You can definitely use it.
Overall, I would rate CrowdStrike Falcon an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Endpoint Detection and Response (EDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Identity Management (IM) Threat Intelligence Platforms Active Directory Management Extended Detection and Response (XDR) Attack Surface Management (ASM) Ransomware Protection Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity Platforms Continuous Threat Exposure Management (CTEM)Popular Comparisons
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Cisco Secure Endpoint
Elastic Security
HP Wolf Security
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
Intercept X Endpoint
Trend Vision One
Check Point Harmony Endpoint
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?