We use CrowdStrike for our endpoint security and we're about to tie it into vScaler. It's on every endpoint in the company and is used by everyone in the organization. It's anti-virus security software, so we'll continue to put it on every machine whether our company grows or shrinks.I'm the director of information technology in our company and we're a customer of CrowdStrike.
Director Of Information Technology at DLZ Construction Svs.
Very good for endpoint security; we've remained infection free without any downtime
Pros and Cons
- "We haven't had any infections or down time."
- "Too many false positives."
What is our primary use case?
What is most valuable?
We rely on our environmental security and we haven't had any infections so that's valuable for us. It means we haven't lost any time due to the system being down from ransomware or anything like that, so it's quite positive.
What needs improvement?
Improvement could be made in the number of false positives we get, there are more than there needs to be. Typical Windows functions sometimes get stopped by CrowdStrike. In general, I'd rather err on the side of safety but some of these are really straightforward functions that should get through.
For the future, I think they need to keep building on their extensibility, the capability to be extended, so that it's not lost and we can utilize the knowledge that we're gaining from the endpoints.
For how long have I used the solution?
I've been using this solution for a little over a year.
Buyer's Guide
CrowdStrike Falcon
February 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the stability of the solution?
This is a stable solution, I'm unaware of any failures.
What do I think about the scalability of the solution?
Scalability is expensive but it works. We've installed it on more than 900 machines in the corporation and it covers every role from civil engineers, architects, HR people, office workers and the server. Maintenance takes the equivalent of one full-time position but it's a shared responsibility among the IT team.
How are customer service and support?
The technical support do a good job.
How was the initial setup?
The initial setup occurred before I began working here although I believe it is quite straightforward. The install process for machines is pretty good. If we want to de-install it's not so great, but overall it's tolerable.
What's my experience with pricing, setup cost, and licensing?
I believe that we pay about US$ 65,000 annually which covers 900 machines in the company. There are no other costs but there are additional features that can be purchased but we haven't done that.
What other advice do I have?
CrowdStrike do their job well and can be compared to other solutions on the market such as SentinelOne and Huntress. They do need to be more extensible because right now they don't play well with others and it's a bit of a challenge on the management side.
I would rate this solution an eight out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

IT Specialist at a consultancy with 1-10 employees
Remote investigations with enhanced visibility and easy to use
Pros and Cons
- "The ability to remote into other devices for investigation and the way it presents a graphical representation of the detection, like the parent-child process, are valuable features."
- "The new interface, the UI, seems a bit messy."
What is our primary use case?
CrowdStrike Falcon is used for incident response.
How has it helped my organization?
It is very easy to hunt a threat in the organization. It keeps logs, making it very easy to investigate any kind of incident using CrowdStrike by looking at the processes that are running on a machine. There's more visibility over the endpoint through CrowdStrike.
What is most valuable?
The ability to remote into other devices for investigation and the way it presents a graphical representation of the detection, like the parent-child process, are valuable features.
What needs improvement?
The new interface, the UI, seems a bit messy. The previous one was quite clear. It might be because of my adaptation to it. That's what I see as needing improvement.
For how long have I used the solution?
I have been using CrowdStrike Falcon for more than three years, around three and a half years.
What do I think about the stability of the solution?
It is quite stable. I would rate it eight or nine out of ten.
How are customer service and support?
I would rate customer service and support a ten. I am very satisfied with the support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used antiviruses like Symantec before. Compared to all of that, I found CrowdStrike quite striking. Even compared to Defender, I find CrowdStrike more appealing.
What was our ROI?
On the terms of investigating, I find it's quite easy to investigate an event and have a broader look at the event using CrowdStrike. I would rate the time saved around eight, nine, or even ten out of ten. Compared to Defender, it makes it faster to investigate.
What's my experience with pricing, setup cost, and licensing?
I think the pricing is quite reasonable with the services they provide.
What other advice do I have?
For an incident investigator, it's quite easy to use, and it provides great visibility over the processes.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Oct 15, 2024
Flag as inappropriateBuyer's Guide
CrowdStrike Falcon
February 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Security Analyst at a insurance company with 1,001-5,000 employees
Used few system resources, can easily isolate infected machines, and add modules
Pros and Cons
- "I like the feature called RTC, the remote time connector."
- "I have worked with their technical support on several problems that were never fully resolved."
What is our primary use case?
We use CrowdStrike Falcon for endpoint security and response, and Horizon to manage and protect our data.
Following a 2021 security incident, the general response team recommended implementing CrowdStrike. We adopted their suggestion and found its network threat detection and prevention capabilities invaluable.
What is most valuable?
I like the feature called RTC, the remote time connector. It allows us to connect to a computer via the command line and execute commands for various functions and investigations. This eliminates the need for any additional programs. We can launch the connection and its subcommands from a single console.
The containment feature is another valuable tool. It allows us to isolate any machine exhibiting suspicious behavior or facing a detected threat. Once activated, containment immediately severs the machine's network connection and blocks user access.
What needs improvement?
Despite implementing tuning rules specifically designed to address them, we are still encountering a significant number of false positives. This issue persists even after collaborating with their support team to find a solution.
I have worked with their technical support on several problems that were never fully resolved.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
While we encountered some bugs with on-demand scanning, the overall performance and stability of the system are positive. CrowdStrike Falcon is less resource-intensive than our old McAfee solution, which often led to performance complaints due to its high memory consumption.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable. Adding new features or licenses to CrowdStrike Falcon is seamless, with no disruption to our system's performance. Installing new modules is easy because it uses the same sensor.
How are customer service and support?
While I've found screen sharing helpful with other support teams, CrowdStrike's technical support has never proactively suggested it. Instead, they've always initiated contact by calling me back after I submitted a ticket. We recently offered to screen share, but it seems it's not their preferred method. The support is good but it is not the best I have used.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we utilized Carbon Black for our endpoint security needs. However, we transitioned to CrowdStrike for several compelling reasons. As a prominent market competitor with widespread adoption among organizations, CrowdStrike offered a robust platform capable of meeting our evolving security requirements.
The 2021 incident further underscored the importance of robust security tools. CrowdStrike's capabilities proved invaluable in navigating the aftermath and instilled confidence in its continued effectiveness for future challenges.
Beyond its proven track record, CrowdStrike seamlessly integrates with our existing security ecosystem. The platform's comprehensive feature set simplifies endpoint management from a centralized console. Additionally, its granular telemetry across various modules provides invaluable insights during incident detection, enabling us to gather holistic information from each affected machine.
Furthermore, CrowdStrike consolidates our security stack by encompassing next-generation firewalls, endpoint detection and response, and real-time endpoint scanning, eliminating the need for separate solutions like McAfee. This streamlined approach enhances operational efficiency and simplifies security management.
How was the initial setup?
The initial deployment presented some challenges due to the need to install the solution on all machines. This phase, requiring careful coordination among ten people over several weeks, involved connecting all the computers to the network. However, once this foundation was laid, the subsequent rollout proceeded smoothly.
What about the implementation team?
The implementation was completed in-house by our people.
What was our ROI?
The return on investment is evident in the enhanced security posture achieved through continuous monitoring and immediate isolation of compromised machines. This proactive approach not only mitigates risk but also provides significant peace of mind for our team, alleviating concerns and optimizing their performance.
What's my experience with pricing, setup cost, and licensing?
While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours.
What other advice do I have?
I would rate CrowdStrike Falcon a nine out of ten.
CrowdStrike Falcon is a great tool. Investing in proper training on the CrowdStrike Falcon platform is highly recommended for any organization seeking to maximize its potential and avoid navigation struggles within the console. However, it's important to note that effective utilization of Falcon without CrowdStrike's managed services necessitates the formation of a dedicated team responsible for managing the solution.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Owner at IT Solution
Good detection and performance and uses very few resources
Pros and Cons
- "It is an easy product to deploy."
- "We can't do scanning audits or device blocking or application control."
What is our primary use case?
We primarily use the product for the security of the endpoints to protect against viruses and malware. It protects our devices from infection.
What is most valuable?
The solution offers a very low footprint and provides very good protection.
The resources that it uses are much lower than any other EDR or antivirus solution. The amount of RAM that it uses and the CPU that it uses are much lower than the other antivirus solutions.
It is an easy product to deploy.
We've found the product to be scalable.
It is stable and reliable.
What needs improvement?
We can't do scanning audits or device blocking or application control. There are traditional antivirus features missing in XDR, and that is an issue.
For how long have I used the solution?
I've been using the solution for 15 months.
What do I think about the stability of the solution?
It is a very stable solution. There are no bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
We have 55 people currently using the solution.
This is a scalable product.
How are customer service and support?
We have yet to contact technical support. I can't speak to how their services are.
Which solution did I use previously and why did I switch?
We were using another antivirus previously. However, it was heavier. We liked how this solution used much fewer resources and the fact that we didn't need to update our machines.
How was the initial setup?
The solution is simple to set up and deploy. It's cloud-based, which makes everything easy. It is already configured; you just need to prepare it on the endpoint.
You can deploy the solution within a day.
What's my experience with pricing, setup cost, and licensing?
We are a partner and therefore get the solution for free.
What other advice do I have?
We are Crowdstrike partners.
I'm not sure which version of the solution I'm using; however, it is likely the latest.
From the theoretical perspective, it's a good product. They just need more features. You can't just replace an antivirus with it; you first need to ensure it's covering all of your requirements.
I'd rate the product nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: partner/customer
Information Technology Security Consultant at Sify Technologies
Your dashboards will tell you the number of the endpoints being protected and the incidents.
Pros and Cons
- "CrowdStrike Falcon is effortless to use, and it's a cloud-specific platform. You only need to deploy the light agents on the licensed endpoints, and you're ready to work. Your dashboards will tell you the number of the endpoints being protected and the incidents. There are also incident dashboards with alerts that will tell you about the details."
- "CrowdStrike should provide better visibility in its reporting. There should be more forensic details about detected threats."
What is our primary use case?
CrowdStrike Falcon is an Endpoint Detection and Response system that uses agents deployed on each endpoint. It works on mobile or wired devices. The operator provides you real-time and online protection against the latest malware and wireless attacks.
What is most valuable?
CrowdStrike Falcon is effortless to use, and it's a cloud-specific platform. You only need to deploy the light agents on the licensed endpoints, and you're ready to work. Your dashboards will tell you the number of the endpoints being protected and the incidents. There are also incident dashboards with alerts that will tell you about the details.
What needs improvement?
CrowdStrike should provide better visibility in its reporting. There should be more forensic details about detected threats.
For how long have I used the solution?
I've been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
CrowdStrike is highly stable.
What do I think about the scalability of the solution?
CrowdStrike is a cloud-based solution, so it's always scalable. You can adjust your endpoint licenses at any time, so if your endpoint is decommissioned, you can reduce the licenses. If you want to add few more endpoints, you only need to deploy the agents. We have provided CrowdStrike Falcon EDR solutions for many clients, and the largest is about 2,000 licenses.
How are customer service and support?
CrowdStrike support is great. Palo Alto and CrowdStrike both have outsourced support.
How was the initial setup?
Deploying CrowdStrike is straightforward. You can mass-deploy it using any management solution like WSS. It's a light agent that only requires 30 to 40 MB of space, so it's deployed in minutes.
One person is enough to manage the solution. A single admin can create a group based policy and deploy on hundreds of systems in a day if they are connected with their AD or WSS. If they are out of the network and out of the reach, then you need to do it manually, and that takes times for the endpoint availability.
What other advice do I have?
I rate CrowdStrike Falcon eight out of 10. I strongly recommend it.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
AVP of Tech at a insurance company with 201-500 employees
Integrates well with Arctic Wolf, simple to set up, and offers excellent pricing
Pros and Cons
- "Everything we've done with CrowdStrike is due to Arctic Wolf. We don't even need to get alerts from CrowdStrike anymore. It'll send those to Arctic Wolf, and then Arctic Wolf analyzes those and let us know if there's a major issue."
- "They offered a white glove service that was extremely costly. When we got into it, we saw it was relatively easy. If I was being nitpicky, I'd say that I don't like being sold something that's unnecessary. That's the only downside I've seen to the solution."
What is our primary use case?
We use this product as an antivirus. We use it as an add-on for Arctic Wolf, which it integrates with.
What is most valuable?
The solution integrates well with Arctic Wolf.
Everything we've done with CrowdStrike is due to Arctic Wolf. We don't even need to get alerts from CrowdStrike anymore. It'll send those to Arctic Wolf, and then Arctic Wolf analyzes those and let us know if there's a major issue.
It's very scalable.
The stability is excellent.
I'm very impressed by its low pricing.
The initial setup was simple, and the deployment was fast.
What needs improvement?
I do not have any notes for improvement. It just works.
They offered a white glove service that was extremely costly. When we got into it, we saw it was relatively easy. If I was being nitpicky, I'd say that I don't like being sold something that's unnecessary. That's the only downside I've seen to the solution.
For how long have I used the solution?
I've been using the solution for five years.
What do I think about the stability of the solution?
The product is rock solid. I've never had an issue with stability. It is reliable and the performance is good. There are no bugs or glitches and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The product is very scalable. You can extend it as needed.
We have between 220 and 300 users at this time.
How are customer service and support?
I've never dealt with technical support.
Which solution did I use previously and why did I switch?
We had multiple other antiviruses, including Norton, Avast, and Defender. We chose Falcon due to its Arctic Wolf integration.
How was the initial setup?
The initial setup was very easy.
We did not need a lot of people to set it up. It took a couple of people and less than five hours to have everything up and running.
No maintenance is required.
What's my experience with pricing, setup cost, and licensing?
The licensing is very low. It's quite affordable.
What other advice do I have?
The solution is excellent. I'd advise people that if they have Arctic Wolf, they'll have an easy time.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Systems Analyst at a retailer with 5,001-10,000 employees
Allows us to sleep better at night
Pros and Cons
- "I value the overall behavior analysis of CrowdStrike. The engine of this product is what drew us to this solution."
- "I would also like to see the endpoint firewall component produce some level of logging and feedback."
What is our primary use case?
CrowdStrike is a malware protection solution that is deployed on a private cloud across all areas of our organization. We have deployed the solution to 10,000 users. Roles-based it's the security team.
We recently upgraded to a new feature that is set to roll out. CrowdStrike is a requirement, it's our standard. If you have a new OS deployed or a new server deployed, this is a required component. It has been automated as we grow and as we add more systems.
How has it helped my organization?
CrowdStrike allows us to sleep better at night.
What is most valuable?
I value the overall behavior analysis of CrowdStrike. The engine of this product is what drew us to this solution.
What needs improvement?
This solution lacks basic functionality, such as being able to perform on-demand scanning. This presents a challenge when it comes to the payment card industry, PCI which has that as built-in requirements for the PCI DSS standard.
I would also like to see the endpoint firewall component produce some level of logging and feedback.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
CrowdStrike is very stable, we've had very few technical issues. The false positive rate is average. It has been very easy to manage and to determine where issues are.
What do I think about the scalability of the solution?
This solution is very scalable. It is easy to roll out more agents and is fairly automated. We have it deployed in multiple environments such as hybrid versus cloud versus private.
How are customer service and support?
We have had very positive interactions with not only our manage service provider, but the vendor directly. They've offered good support when we've had some questions and concerns. Their documentation is fairly extensive.
Which solution did I use previously and why did I switch?
We follow trends to make sure we have the best product for our organizations. The one we were using fell behind a bit. We wanted something that was completely cloud-based so that the infrastructure wasn't on-prem and we wouldn't be required to manage the upgrades of servers and applications.
How was the initial setup?
The initial setup was moderate. There is a lot to think about and a lot to plan out, however once that is done the actual deployment is straightforward. We used a tiered deployment, deploying the product in a learning mode or logging mode only. We also did a tiered deployment by division and then enabled features by division to make sure that if there was an impact, we could at least contain it to one area and revert back as quickly as possible.
What about the implementation team?
We deployed with an integrator. They were very knowledgeable and knew what they were doing. They involved the vendor when required. We use half of an FTE to maintain the solution. We also have a managed service provided that also integrated the log files from this product into our SIM. We are pointing all the logs to a log reporting utility that allows us to react to alerts.
What was our ROI?
Because we are information security, we come with a price tag, unfortunately. When we look at it as a whole, we are able to sleep at night, we have a good solution and it is protecting us from the zero-days and the latest malware. I don't know what you put the cost of breach prevention at. We feel we are using a product that is at the top of the industry. We are doing as much as we can to protect our organization, so there is the return on investment that way.
What's my experience with pricing, setup cost, and licensing?
We pay yearly for the solution. It makes it easier for budgeting purposes. We did incur additional costs when we implemented their firewall solution, calling it the endpoint firewall.
Which other solutions did I evaluate?
We're constantly looking for other options the industry's top solutions and where the industry is going next. In cybersecurity, we ensure we are protected today but also make sure that we are thinking towards the future and analyzing other solutions to see if they are better, or potentially better in the future.
What other advice do I have?
If you are looking at CrowdStrike, plan appropriately. Make sure you have planned it out and do your testing. We found that it was legacy-friendly. We have a lot of legacy applications and we were concerned about that. We ran into some minor issues but we did find that it was friendly, however, there were some newer applications that the product did not interact with as well as we expected. They were easy fixes, but you should do your due diligence so you run into fewer surprises.
I would rate CrowdStrike a 9 out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Information Security Officer at a manufacturing company with 10,001+ employees
Good detection rates, nice dashboards, easy to manage, and the technical support is responsive
Pros and Cons
- "I like the detection rates of mobile threats."
- "The management reporting functionality needs to be improved."
What is our primary use case?
Our primary use for CrowdStrike is as an EDR system. We are protecting more then 9.000 devices.
How has it helped my organization?
What is most valuable?
I like the detection rates of mobile threats.
The policies allow us to define the level of protection.
The dashboards are good, as well as user management.
What needs improvement?
The management reporting functionality needs to be improved.
We would like to see more features for vulnerability management included.
For how long have I used the solution?
We have been using CrowdStrike Falcon since one year.
What do I think about the stability of the solution?
This is a stable product.
What do I think about the scalability of the solution?
We haven't had any problems with scalability and it expands with the company's needs.
We have 20,000 users and about 20 of them are administrators.
How are customer service and technical support?
We have been in touch with technical support for a few issues. They are quite good and the response is fast.
Which solution did I use previously and why did I switch?
We were using Cylance prior to CrowdStrike, and these two products overlapped for a time. We also use an on-premises solution called F-Secure.
CrowdStrike has a much lower rate of false positives than Cylance and the dashboard makes it easier to use.
How was the initial setup?
The initial setup is very simple. It took two months to deploy for 20,000 clients.
What about the implementation team?
Our in-house team handled the implementation and deployment. No maintenance is required.
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
The pricing is good and there are no costs in addition to the standard licensing fees. It is similar to that of Cylance and our on-premises solution.
Which other solutions did I evaluate?
What other advice do I have?
This is a product that I absolutely recommend.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Detection and Response (EDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Identity Management (IM) Threat Intelligence Platforms Active Directory Management Extended Detection and Response (XDR) Attack Surface Management (ASM) Ransomware Protection Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Cisco Secure Endpoint
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
Check Point Harmony Endpoint
Trend Vision One
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?