Sign in
Categories
Your Saved List Partners Sell in AWS Marketplace Amazon Web Services Home Help

CrowdStrike: Falcon Horizon CSPM

CrowdStrike, Inc. | 1

Reviews from AWS Marketplace

0 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

97 reviews
from G2

External reviews are not included in the AWS star rating for the product.


    Rhutuja T.

Very easy to protect system from any type of attack

  • June 24, 2021
  • Review provided by G2

What do you like best?
The best thing that I like about Crowdstrike tool is it gives us a complete picture about what all progress was executed which leads to detect the file as suspicious like it tell us attack pattern in case of true positive
What do you dislike?
Sometimes it becomes difficult to fetch event logs or we are unable to fetch list of incident we got in particular time frame
What problems are you solving with the product? What benefits have you realized?
The benefits of using crowdstrike is that it is able to detect any suspicious activity carried out on specific device where crowdstrike is installed


    Daniel O.

This is a must have for corporations that are fighting against cyber attacks

  • June 16, 2021
  • Review verified by G2

What do you like best?
Relatively easy to deploy and highly efficient, integration with other vendors is available using APIs.
What do you dislike?
I think reporting is something Crowdstrike could invest more.
What problems are you solving with the product? What benefits have you realized?
We are constantly fighting against cyber attacks, Crowdstrike is one of the top tools we have in our toolbox.
Recommendations to others considering the product:
I highly recommend Crowdstrike epp; you'll reduce the number of machines you reimage because of cyber incidents. If you also use Proofpoint, make sure you enable the Integration between them. Your email gateway will be able to use Crowdstrike infrastructure to decide about block attachments.


    Mahesh S.

Endpoint Detection and Response

  • June 09, 2021
  • Review verified by G2

What do you like best?
EDR Discover and spotlight is the best for the investigation
What do you dislike?
Device Control need to have good functionality
What problems are you solving with the product? What benefits have you realized?
I have gain lot of experience in falcon and got lot of benifits
Recommendations to others considering the product:
They need to have the proper solutions like crowdstrike need to migrate from legacy solution to NGAV


    Saibal B.

CrowdStrike Falcon, an EDR tool with compliance monitoring features embedded

  • June 08, 2021
  • Review verified by G2

What do you like best?
The UI is extremely User friendly and informative. apart from that the level of details that the tool captures for a particular incident is pretty impressive.

Especially the process tree that the tool creates for each detection triggered helps the analysts understand the context of an incident pretty seamlessly.

The Falcon Overwatch service is also one of the best managed defense service that I have ever witnessed. Their engineering teams are prompt to respond in case of an actual threat.
What do you dislike?
The RTR tool has limited functionality. Also one of the major things I have found to crib about is the fact that when you contain a machine using CS, the end user does not receives any notification for the same. Other competitor EDRs like FireEye publish it to user when a machine is contained.

Also, there is no way to remotely uninstall a crowdstrike sensor from a machine which no longer requires to be monitored using CS. This is something which could help a lot.
What problems are you solving with the product? What benefits have you realized?
The biggest advantage of having CS Falcon is being able to control real time and zero day exploits that do not get captured using traditional AV.

Also, having crowdstrike as the primary EDR, you essentially can perform compliance tracking for apps used in an environment and local admin usage.

CrowdStrike can also be used to essentially map your entire environment into separate departments and create custom policies for each department.
Recommendations to others considering the product:
Any organization that is looking for an EDR to deploy in their environment can go with CS Falcon without any second thoughts. It is rated the best EDR solution across multiple surveys and also has one of the fastest evolving technology landscapes.


    Consumer Services

I recommend the CrowdStrike to organizations to protect their endpoint devices from cyberattacks

  • June 05, 2021
  • Review provided by G2

What do you like best?
1. Dashboard Flexibility - we can get a clear picture of what's going in the network environment. Mainly, the incident and detections widgets are very important. The overall scoring of incidents will be crucial to understand how safe the network is. Additionally, the mitre tactics will be clearly displayed. The home screen search gives flexibility for the analysts to quickly check for IP/hostname/file details within seconds.

2. Incident Scoring - it will trigger with an indication of critically scoring out of 10. The incident details are, with flow-based and behavioral-based pre-analysis will be given. Each stage of flow will be represented with a full description, block action, and mitre attack mapping.

3. Detection Mechanism - mainly focuses on file-based detection, which comes with a lot of filters where we can filter will hostname, filename, mitre tactic, block action, severity, etc.

4. Event Search - All the Investigate search fields help to search each and every event.

5. Overwatch alerting - are a more important part of monitoring. The critical true positive incidents will trigger as overwatch. The probability of getting true positive incidents is very high.

6. Finally, the Support team of crowdstrike will also keeps eye on the critical things happening in our environment and notify us.
What do you dislike?
1. More focused on only file-based executions.

2. Machine Learning based detections throw more false positives. Unnecessary blocking of genuine executions will sometimes impact business.

3. For Endpoints protection, it can have the best alternatives with the best features like Microsoft ATP, Zscalar.
What problems are you solving with the product? What benefits have you realized?
1. File-based detections is the biggest positive in Crowdstrike.

2. Overwatch alerts will be the most probably true positive incidents. It will alarm in the CS console as well as in the mail.

3. We can see what all applications installed in the user's machine.

4. Almost 65% percent of work will be done by crowdstrike itself without analyst intervention.
Recommendations to others considering the product:
I strongly recommend the Crowstrike to organizations to protect their endpoint devices from cyberattacks. Almost all the major incidents can be mitigated with this Endpoint protection.


    Ankit M.

It is excellent cloud based NGAV with full proof protection..!!

  • June 05, 2021
  • Review provided by G2

What do you like best?
It is reaaly good in manageability and monitoring entire organization in single console with very less effort.
What do you dislike?
Crowdstrike Store must be more user friendly and product needs to display with full description with use case.
What problems are you solving with the product? What benefits have you realized?
It is work with less compute power and use unwanted disk operation. The endpoint works really well in terms of other peers competition.


    Balaji Ganesh M.

Compared to other Commercial Endpoint solutions Falcon has superior technology and it is hassle free

  • June 04, 2021
  • Review provided by G2

What do you like best?
features like Threat actors details, network quarantine capabilities, malware execution map & Dashboard
Threat actors database.
Dashboard filtering capabilities and eliminating falsepositives with just a click.
RBAC (role based access control) features enables high security towards authentication.
Email alerts is helpful for rapid threat response to aviod potential security incident.

Intergration capabilities with ITSM tools is an added advantage.
What do you dislike?
Initially, eliminating the false positives and purging them is time-consuming. Agent deployment for Windows flavored OS is easy. But for a Linux-based system, it is a tedious task.
Extracting logs or report for troubleshooting should be even more used readable. I liked the Dashboard, but Falcon can still improve a few automation to eradicate known false positives.

Main Disadvantage: Active endpoint scanning is not possible CrowdStrike only analysis the network traffice and behaviour with in the system. Falcon should introduce quick scan and full scan features to over come this disadvantage.

Duplicate alerts and related ITSM tickets are a problem with falcon, In my experience I have experienced Crowdstrike reporting multiple alerts for same issue. This results in huge number of ticket creation (If Intergrated with ITSM) or large amount of emails spamming your Inbox.
What problems are you solving with the product? What benefits have you realized?
I have mostly been a Security Analyst. I have investigated alerts reported by Falcon. In a nutshell, we used Crowdstrike for Managing all the endpoints used for business.

Benefits- Real-time status and statistics, since using dashboard one can control the agents so in terms of incident response one can network quarantine a system (if found with malware) with just a few clicks using central Dashboard.

This feature will surely help restrict ransomware from spreading across systems.
Recommendations to others considering the product:
The product is futuristic and will surely add multiple automation over the period. But for Endpoint Detection and Response (EDR). I would recommend CrowdStrike as the market's Pioneer.


    Rahul V.

It the best solution in market

  • June 02, 2021
  • Review provided by G2

What do you like best?
Capability of the tool and the performance of the tool and
What do you dislike?
Nothing there is that I dislike about crowdstrike
What problems are you solving with the product? What benefits have you realized?
Real time response is the best feature
Recommendations to others considering the product:
It's the best in market


    Consumer Services

One of the most advanced EDR available in the market

  • June 01, 2021
  • Review provided by G2

What do you like best?
The way alerts are triaged and broken up for easy understanding
What do you dislike?
Nothing. Everything is good in this EDR.
What problems are you solving with the product? What benefits have you realized?
Most of the threats to a organization are through the mistakes of the users which is directly monitored by CS Falcon
Recommendations to others considering the product:
Start using this in the organisation for better security


    Information Technology and Services

This is easy to manage

  • May 31, 2021
  • Review provided by G2

What do you like best?
Cloud console and kernel-level falcon sensor
What do you dislike?
Everyone should have internet access to connect cloud console.
What problems are you solving with the product? What benefits have you realized?
Endpoint protection with EDR features