Try our new research platform with insights from 80,000+ expert users
reviewer2564352 - PeerSpot reviewer
IT Specialist at a consultancy with 1-10 employees
Real User
Top 20
Remote investigations with enhanced visibility and easy to use
Pros and Cons
  • "The ability to remote into other devices for investigation and the way it presents a graphical representation of the detection, like the parent-child process, are valuable features."
  • "The new interface, the UI, seems a bit messy."

What is our primary use case?

CrowdStrike Falcon is used for incident response.

How has it helped my organization?

It is very easy to hunt a threat in the organization. It keeps logs, making it very easy to investigate any kind of incident using CrowdStrike by looking at the processes that are running on a machine. There's more visibility over the endpoint through CrowdStrike.

What is most valuable?

The ability to remote into other devices for investigation and the way it presents a graphical representation of the detection, like the parent-child process, are valuable features.

What needs improvement?

The new interface, the UI, seems a bit messy. The previous one was quite clear. It might be because of my adaptation to it. That's what I see as needing improvement.

Buyer's Guide
CrowdStrike Falcon
January 2025
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.

For how long have I used the solution?

I have been using CrowdStrike Falcon for more than three years, around three and a half years.

What do I think about the stability of the solution?

It is quite stable. I would rate it eight or nine out of ten.

How are customer service and support?

I would rate customer service and support a ten. I am very satisfied with the support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used antiviruses like Symantec before. Compared to all of that, I found CrowdStrike quite striking. Even compared to Defender, I find CrowdStrike more appealing.

What was our ROI?

On the terms of investigating, I find it's quite easy to investigate an event and have a broader look at the event using CrowdStrike. I would rate the time saved around eight, nine, or even ten out of ten. Compared to Defender, it makes it faster to investigate.

What's my experience with pricing, setup cost, and licensing?

I think the pricing is quite reasonable with the services they provide.

What other advice do I have?

For an incident investigator, it's quite easy to use, and it provides great visibility over the processes.

I'd rate the solution ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
reviewer2322486 - PeerSpot reviewer
Security Analyst at a insurance company with 1,001-5,000 employees
Real User
Top 20
Used few system resources, can easily isolate infected machines, and add modules
Pros and Cons
  • "I like the feature called RTC, the remote time connector."
  • "I have worked with their technical support on several problems that were never fully resolved."

What is our primary use case?

We use CrowdStrike Falcon for endpoint security and response, and Horizon to manage and protect our data.

Following a 2021 security incident, the general response team recommended implementing CrowdStrike. We adopted their suggestion and found its network threat detection and prevention capabilities invaluable.

What is most valuable?

I like the feature called RTC, the remote time connector. It allows us to connect to a computer via the command line and execute commands for various functions and investigations. This eliminates the need for any additional programs. We can launch the connection and its subcommands from a single console.

The containment feature is another valuable tool. It allows us to isolate any machine exhibiting suspicious behavior or facing a detected threat. Once activated, containment immediately severs the machine's network connection and blocks user access.

What needs improvement?

Despite implementing tuning rules specifically designed to address them, we are still encountering a significant number of false positives. This issue persists even after collaborating with their support team to find a solution.

I have worked with their technical support on several problems that were never fully resolved.

For how long have I used the solution?

I have been using CrowdStrike Falcon for three years.

What do I think about the stability of the solution?

While we encountered some bugs with on-demand scanning, the overall performance and stability of the system are positive. CrowdStrike Falcon is less resource-intensive than our old McAfee solution, which often led to performance complaints due to its high memory consumption.

What do I think about the scalability of the solution?

CrowdStrike Falcon is scalable. Adding new features or licenses to CrowdStrike Falcon is seamless, with no disruption to our system's performance. Installing new modules is easy because it uses the same sensor.

How are customer service and support?

While I've found screen sharing helpful with other support teams, CrowdStrike's technical support has never proactively suggested it. Instead, they've always initiated contact by calling me back after I submitted a ticket. We recently offered to screen share, but it seems it's not their preferred method. The support is good but it is not the best I have used.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we utilized Carbon Black for our endpoint security needs. However, we transitioned to CrowdStrike for several compelling reasons. As a prominent market competitor with widespread adoption among organizations, CrowdStrike offered a robust platform capable of meeting our evolving security requirements.

The 2021 incident further underscored the importance of robust security tools. CrowdStrike's capabilities proved invaluable in navigating the aftermath and instilled confidence in its continued effectiveness for future challenges.

Beyond its proven track record, CrowdStrike seamlessly integrates with our existing security ecosystem. The platform's comprehensive feature set simplifies endpoint management from a centralized console. Additionally, its granular telemetry across various modules provides invaluable insights during incident detection, enabling us to gather holistic information from each affected machine.

Furthermore, CrowdStrike consolidates our security stack by encompassing next-generation firewalls, endpoint detection and response, and real-time endpoint scanning, eliminating the need for separate solutions like McAfee. This streamlined approach enhances operational efficiency and simplifies security management.

How was the initial setup?

The initial deployment presented some challenges due to the need to install the solution on all machines. This phase, requiring careful coordination among ten people over several weeks, involved connecting all the computers to the network. However, once this foundation was laid, the subsequent rollout proceeded smoothly.

What about the implementation team?

The implementation was completed in-house by our people.

What was our ROI?

The return on investment is evident in the enhanced security posture achieved through continuous monitoring and immediate isolation of compromised machines. This proactive approach not only mitigates risk but also provides significant peace of mind for our team, alleviating concerns and optimizing their performance.

What's my experience with pricing, setup cost, and licensing?

While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours.

What other advice do I have?

I would rate CrowdStrike Falcon a nine out of ten.

CrowdStrike Falcon is a great tool. Investing in proper training on the CrowdStrike Falcon platform is highly recommended for any organization seeking to maximize its potential and avoid navigation struggles within the console. However, it's important to note that effective utilization of Falcon without CrowdStrike's managed services necessitates the formation of a dedicated team responsible for managing the solution. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
CrowdStrike Falcon
January 2025
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Nakul Chopra - PeerSpot reviewer
Owner at IT Solution
Reseller
Good detection and performance and uses very few resources
Pros and Cons
  • "It is an easy product to deploy."
  • "We can't do scanning audits or device blocking or application control."

What is our primary use case?

We primarily use the product for the security of the endpoints to protect against viruses and malware. It protects our devices from infection. 

What is most valuable?

The solution offers a very low footprint and provides very good protection. 

The resources that it uses are much lower than any other EDR or antivirus solution. The amount of RAM that it uses and the CPU that it uses are much lower than the other antivirus solutions.

It is an easy product to deploy. 

We've found the product to be scalable. 

It is stable and reliable. 

What needs improvement?

We can't do scanning audits or device blocking or application control. There are traditional antivirus features missing in XDR, and that is an issue. 

For how long have I used the solution?

I've been using the solution for 15 months. 

What do I think about the stability of the solution?

It is a very stable solution. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

We have 55 people currently using the solution. 

This is a scalable product.

How are customer service and support?

We have yet to contact technical support. I can't speak to how their services are. 

Which solution did I use previously and why did I switch?

We were using another antivirus previously. However, it was heavier. We liked how this solution used much fewer resources and the fact that we didn't need to update our machines. 

How was the initial setup?

The solution is simple to set up and deploy. It's cloud-based, which makes everything easy. It is already configured; you just need to prepare it on the endpoint. 

You can deploy the solution within a day. 

What's my experience with pricing, setup cost, and licensing?

We are a partner and therefore get the solution for free. 

What other advice do I have?

We are Crowdstrike partners. 

I'm not sure which version of the solution I'm using; however, it is likely the latest. 

From the theoretical perspective, it's a good product. They just need more features. You can't just replace an antivirus with it; you first need to ensure it's covering all of your requirements.

I'd rate the product nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer: partner/customer
PeerSpot user
Sandeep Sehrawat - PeerSpot reviewer
Information Technology Security Consultant at Sify Technologies
Real User
Your dashboards will tell you the number of the endpoints being protected and the incidents.
Pros and Cons
  • "CrowdStrike Falcon is effortless to use, and it's a cloud-specific platform. You only need to deploy the light agents on the licensed endpoints, and you're ready to work. Your dashboards will tell you the number of the endpoints being protected and the incidents. There are also incident dashboards with alerts that will tell you about the details."
  • "CrowdStrike should provide better visibility in its reporting. There should be more forensic details about detected threats."

What is our primary use case?

CrowdStrike Falcon is an Endpoint Detection and Response system that uses agents deployed on each endpoint. It works on mobile or wired devices. The operator provides you real-time and online protection against the latest malware and wireless attacks.

What is most valuable?

CrowdStrike Falcon is effortless to use, and it's a cloud-specific platform. You only need to deploy the light agents on the licensed endpoints, and you're ready to work. Your dashboards will tell you the number of the endpoints being protected and the incidents. There are also incident dashboards with alerts that will tell you about the details.

What needs improvement?

CrowdStrike should provide better visibility in its reporting. There should be more forensic details about detected threats.

For how long have I used the solution?

I've been using CrowdStrike Falcon for two years. 

What do I think about the stability of the solution?

CrowdStrike is highly stable.

What do I think about the scalability of the solution?

CrowdStrike is a cloud-based solution, so it's always scalable. You can adjust your endpoint licenses at any time, so if your endpoint is decommissioned, you can reduce the licenses. If you want to add few more endpoints, you only need to deploy the agents. We have provided CrowdStrike Falcon EDR solutions for many clients, and the largest is about 2,000 licenses. 

How are customer service and support?

CrowdStrike support is great. Palo Alto and CrowdStrike both have outsourced support.

How was the initial setup?

Deploying CrowdStrike is straightforward. You can mass-deploy it using any management solution like WSS. It's a light agent that only requires 30 to 40 MB of space, so it's deployed in minutes.

One person is enough to manage the solution. A single admin can create a group based policy and deploy on hundreds of systems in a day if they are connected with their AD or WSS. If they are out of the network and out of the reach, then you need to do it manually, and that takes times for the endpoint availability.

What other advice do I have?

I rate CrowdStrike Falcon eight out of 10. I strongly recommend it. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
reviewer2131563 - PeerSpot reviewer
AVP of Tech at a insurance company with 201-500 employees
Real User
Top 5
Integrates well with Arctic Wolf, simple to set up, and offers excellent pricing
Pros and Cons
  • "Everything we've done with CrowdStrike is due to Arctic Wolf. We don't even need to get alerts from CrowdStrike anymore. It'll send those to Arctic Wolf, and then Arctic Wolf analyzes those and let us know if there's a major issue."
  • "They offered a white glove service that was extremely costly. When we got into it, we saw it was relatively easy. If I was being nitpicky, I'd say that I don't like being sold something that's unnecessary. That's the only downside I've seen to the solution."

What is our primary use case?

We use this product as an antivirus. We use it as an add-on for Arctic Wolf, which it integrates with. 

What is most valuable?

The solution integrates well with Arctic Wolf. 

Everything we've done with CrowdStrike is due to Arctic Wolf. We don't even need to get alerts from CrowdStrike anymore. It'll send those to Arctic Wolf, and then Arctic Wolf analyzes those and let us know if there's a major issue.

It's very scalable.

The stability is excellent.

I'm very impressed by its low pricing.

The initial setup was simple, and the deployment was fast.

What needs improvement?

I do not have any notes for improvement. It just works. 

They offered a white glove service that was extremely costly. When we got into it, we saw it was relatively easy. If I was being nitpicky, I'd say that I don't like being sold something that's unnecessary. That's the only downside I've seen to the solution. 

For how long have I used the solution?

I've been using the solution for five years. 

What do I think about the stability of the solution?

The product is rock solid. I've never had an issue with stability. It is reliable and the performance is good. There are no bugs or glitches and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The product is very scalable. You can extend it as needed.

We have between 220 and 300 users at this time. 

How are customer service and support?

I've never dealt with technical support. 

Which solution did I use previously and why did I switch?

We had multiple other antiviruses, including Norton, Avast, and Defender. We chose Falcon due to its Arctic Wolf integration. 

How was the initial setup?

The initial setup was very easy.

We did not need a lot of people to set it up. It took a couple of people and less than five hours to have everything up and running. 

No maintenance is required. 

What's my experience with pricing, setup cost, and licensing?

The licensing is very low. It's quite affordable. 

What other advice do I have?

The solution is excellent. I'd advise people that if they have Arctic Wolf, they'll have an easy time.

I'd rate the solution ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Chief Information Security Officer at a manufacturing company with 10,001+ employees
Real User
Good detection rates, nice dashboards, easy to manage, and the technical support is responsive
Pros and Cons
  • "I like the detection rates of mobile threats."
  • "The management reporting functionality needs to be improved."

What is our primary use case?

Our primary use for CrowdStrike is as an EDR system. We are protecting more then 9.000 devices.

How has it helped my organization?

What is most valuable?

I like the detection rates of mobile threats.

The policies allow us to define the level of protection.

The dashboards are good, as well as user management.

What needs improvement?

The management reporting functionality needs to be improved.

We would like to see more features for vulnerability management included.

For how long have I used the solution?

We have been using CrowdStrike Falcon since one year.

What do I think about the stability of the solution?

This is a stable product.

What do I think about the scalability of the solution?

We haven't had any problems with scalability and it expands with the company's needs.

We have 20,000 users and about 20 of them are administrators.

How are customer service and technical support?

We have been in touch with technical support for a few issues. They are quite good and the response is fast.

Which solution did I use previously and why did I switch?

We were using Cylance prior to CrowdStrike, and these two products overlapped for a time. We also use an on-premises solution called F-Secure.

CrowdStrike has a much lower rate of false positives than Cylance and the dashboard makes it easier to use.

How was the initial setup?

The initial setup is very simple. It took two months to deploy for 20,000 clients.

What about the implementation team?

Our in-house team handled the implementation and deployment. No maintenance is required.

What was our ROI?

What's my experience with pricing, setup cost, and licensing?

The pricing is good and there are no costs in addition to the standard licensing fees. It is similar to that of Cylance and our on-premises solution.

Which other solutions did I evaluate?

What other advice do I have?

This is a product that I absolutely recommend.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Dan Brunnquell - PeerSpot reviewer
Director Of Information Technology at a financial services firm with 11-50 employees
Real User
Provides instant visibility and protection across an organization
Pros and Cons
  • "It's given me a level of confidence that my network is secure."
  • "CrowdStrike Falcon by itself does not supply in-depth reporting."

What is our primary use case?

We use this solution for threat protection and endpoint security.

Recently, we added on CrowdStrike OverWatch and Insightsoftware for better reporting. OverWatch monitors East-West issues that CrowdStrike Protect doesn't see. New next-generation endpoint security doesn't scan your PC. It doesn't scan files nightly. People have to get past that, it's so old school. 

I have 50 end-users, one hundred endpoints, and workers of all types, both in-house and remote workers.

How has it helped my organization?

With the addition of Overwatch and the Insight tool, the reporting has gotten better and I've gained some quality insight that helps me remedy compliance issues and maintain security posture; however, in a year and a half, we haven't had an actual positive detection across a hundred endpoints. The reason for that is mostly due to our employee training and the way that our complete security stack is configured. I hope that the way that I've got it configured right now is the sole reason that we literally aren't letting things in.

If the solution sees some issues, it reports them. Even though they're false positives, in a different scenario, what it's reporting could be a threat. Usually, they're just executables that were downloaded and installed by me. That's to be fully expected and maybe they came from a vendor, but it wasn't signed. 

It's given me a level of confidence that my network is secure — the fact that it's not finding anything; however, I am not experiencing the issues that competitors are saying I should be experiencing. I literally have to test it manually to know it's working.

What is most valuable?

Falcon Protect looks at processes and issues in real-time.

What needs improvement?

CrowdStrike Falcon by itself does not supply in-depth reporting. 

Falcon Protect does what it does. It's endpoint security — nothing more, nothing less. 

What it does, It does well. However, if you need more information on what it found and how it got there (including board reporting and compliance reporting), that's not there. Some of the other solutions that are available give you that, right out of the box.

For how long have I used the solution?

I have been using CrowdStrike Falcon for the past year and a half.

What do I think about the stability of the solution?

We haven't experienced any issues regarding the stability of CrowdStrike Falcon.

What do I think about the scalability of the solution?

CrowdStrike Falcon is scalable. I've only got one hundred endpoints and I know companies that are hundreds of times bigger who use it.

How are customer service and technical support?

Trying to get somebody on the phone might not always be the easiest thing, but they usually respond in a fairly timely manner. I haven't had any issues where I've needed them to immediately fix things.

On a scale from one to ten, I would give their customer support a rating of nine.

Which solution did I use previously and why did I switch?

We had a Vipre solution, but it was an On-Prem solution. The server was aging out and the software was up for renewal. It wasn't working well with our remote workers; they're not literally connected to my network so updating them was always a pain-point without a cloud-based solution.

We were going to transition to "cloud" and Vipre just wasn't really up to the level of CrowdStrike at the time.

How was the initial setup?

The deployment literally took about 15 minutes across the wide area network. Regarding configuration, we took a look at it with their tech support and Implementation team. There's literally maybe a dozen settings and we basically maxed them out.

What's my experience with pricing, setup cost, and licensing?

The price of CrowdStrike Falcon is a little high, but it can be negotiated.

What other advice do I have?

If you're thinking about implementing this solution, I would suggest getting Overwatch and Insight along with it. Also, don't be afraid to try and negotiate for a better price.

On a scale from one to ten, I would give this solution a rating of nine.

The reporting is part of the Overwatch and Insight combination. It's doing what we want it to do and it's not causing a lot of overhead. Like I said earlier, maybe we're an anomaly. We don't have a lot of issues on our network.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager at a consultancy with 10,001+ employees
Real User
It has helped us with security and managing threats that we see currently in our environment
Pros and Cons
  • "Because it is security product and acts like an AIML smart product, not merely based on daily/weekly updates and signatures."
  • "Unfortunately, native applications are not supported."

What is our primary use case?

It's security-related product. A security environment based on AIML. It is not like the older stuff, which used to have signature-based updates.

How has it helped my organization?

It has helped us with security and managing threats that we see currently in our environment.

What is most valuable?

Because it is security product and acts like an AIML smart product, not merely based on daily/weekly updates and signatures.

What needs improvement?

Unfortunately, native applications are not supported.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

It manages around a few thousand endpoints and servers in our environment, and it is doing well so far.

What do I think about the scalability of the solution?

There are no issues in terms of scalability. 

How is customer service and technical support?

We can call the tech support, if needed. Then, they have a dedicated rep for us.

How was the initial setup?

It went well. We just installed an app on all the endpoints or devices. They have a good console which helps do this. So, it is as simple as that.

We are using this for endpoint security, so it doesn't need to integrate with anything else.

Which other solutions did I evaluate?

We evaluated three to four other vendors.

During the PoC, we figured out that this product is far better, and it met our requirements. That is why we went for CrowdStrike. With our PoC, they did a good job in explaining the product. So, the PoC went well, and we were able to achieve what we intended to with it.

What other advice do I have?

Do a thorough PoC. Don't go ever go by the sales team unless you have tested it and know it works for your environment, because every environment is unique. The sales guy will promise you the moon. Only unless you have tested, you know it delivers.

The product has met its purpose for us.

We use both the on-premise and AWS versions. They are both good products and very simple to move, install, and configure.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user996702 - PeerSpot reviewer
it_user996702Cloud Security Engineer at a manufacturing company with 1,001-5,000 employees
Real User

Hi,
What you mean please by not supporting native applications? could you please explain it more?
Thanks and regards,

Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.