Provides real-time response, helps reduce malware risk, and provides advanced investigation capabilities
What is our primary use case?
Our organization uses CrowdStrike Falcon for a variety of security tasks, including incident response, investigations, malware analysis, and threat hunting. This comprehensive platform excels at detecting malware across various technologies and endpoints within our environment.
CrowdStrike Falcon functions as a threat detection platform. It identifies malware based on pre-defined signatures and rules. Upon detection, it triggers a response and provides a dashboard for further analysis. This allows us to assess if the malware poses a risk to our organization or if it's a false positive. For confirmed threats, we can then delve deeper for a thorough investigation to uncover any underlying malicious intent.
Our primary goal is to prevent malware-related risks proactively. By leveraging CrowdStrike Falcon, a premium endpoint detection and response tool, we can safeguard our organization from malware exploitation attempts employed by hackers.
How has it helped my organization?
The primary advantage of CrowdStrike Falcon is twofold: reducing malware risk and providing advanced investigation capabilities. Traditional antivirus solutions struggle to keep pace with ever-evolving malware threats. CrowdStrike Falcon utilizes cutting-edge technology to proactively prevent these threats, minimizing the risk of infection. Falcon also features a threat intelligence platform that keeps us informed about the latest global malware threats and compromised tactics. This real-time awareness empowers us to proactively prevent threats before they impact our environment.
Recently CrowdStrike Falcon detected and mitigated malware that would have compromised several vulnerabilities in our environment.
Falcon's real-time response capability ensures we can quickly access any compromised host. This is a valuable advantage over other EDR tools.
What is most valuable?
The most valuable features of CrowdStrike Falcon include Falcon Fusion workflows and endpoint detection capabilities.
What needs improvement?
I've found that CrowdStrike's technical support could benefit from increased technical expertise. In my experience, their representatives haven't been able to resolve my issues as effectively as I would have liked.
For how long have I used the solution?
I have been using CrowdStrike Falcon for 1.5 years.
What do I think about the stability of the solution?
I would rate the stability of CrowdStrike Falcon nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon eight out of ten.
How are customer service and support?
I've found the technical support staff to be less knowledgeable than I'd expect. Ideally, they should have expertise in all CrowdStrike modules, as we utilize a wide range of them.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used security solutions from Symantec, Trend Micro, Trellix, and Mandiant. However, CrowdStrike Falcon stood out as a more premium offering. Its advanced capabilities and comprehensive approach to security ultimately led us to switch providers after careful consideration of several factors.
How was the initial setup?
The initial deployment was straightforward and took less than 15 days to complete.
There were between 30 to 40 people involved in the deployment.
What about the implementation team?
Our security engineering team implemented CrowdStrike Falcon entirely in-house. We also received some support from our internal desktop team and leveraged the expertise of an internal managed service provider team. No third-party vendors were involved in the deployment.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon is more expensive than other EDR solutions with similar features.
What other advice do I have?
I would rate CrowdStrike Falcon nine out of ten.
After deployment, there are some simple maintenance tasks to keep everything functioning well.
New users should learn about the different modules of CrowdStrike Falcon and their functionalities to work effectively with the tool.
Which deployment model are you using for this solution?
Hybrid Cloud
The integration is flexible, helps identify required patches, and excels in external media control
What is our primary use case?
CrowdStrike Falcon is our platform for IT security, encompassing endpoint security, cloud security, and EDR capabilities.
How has it helped my organization?
CrowdStrike protected us from a cyberattack. That's why I believe it's a very effective product. It's already prevented attacks on 2 occasions. It successfully quarantined suspicious files, essentially making our organization much safer.
We also leverage CrowdStrike Falcon Overwatch, a managed threat-hunting service offered by CrowdStrike. This service complements CrowdStrike's EDR functionality, which provides automated detection and response capabilities against external attacks. In our case, CrowdStrike successfully identified and automatically contained a cyberattack launched against our organization.
Our CrowdStrike Falcon integration with our SIEM is proving to be flexible.
What is most valuable?
The most valuable aspects of CrowdStrike Falcon for me are its device observability, identification, and software and OS recognition. It also excels in external media control, particularly USB access. The ability to disable USB access to flash drives significantly improves security.
Furthermore, Falcon helps identify patches needed for Windows, Mac, and other operating systems. This provides valuable reports and insights into our system vulnerabilities, allowing us to proactively address them.
What needs improvement?
If CrowdStrike can further expand its support for XDR compatibility, that would give it an edge over all the other competing new products.
For how long have I used the solution?
I have been using CrowdStrike Falcon for 2 years.
What do I think about the stability of the solution?
I would rate the stability of CrowdStrike Falcon 8 out of 10.
What do I think about the scalability of the solution?
We've deployed CrowdStrike Falcon across all 3,000 of our endpoints, and it has demonstrated excellent scalability. Therefore, scalability is not a concern for CrowdStrike in terms of performance or its ability to handle growth.
I would rate the scalability a 9 out of 10.
How was the initial setup?
The deployment was straightforward, taking 2 months for 3,000 endpoints. We implemented it directly where needed. The process was simple and easy. We believe this approach offers advantages due to its lower complexity compared to other methods. Careful planning was essential, and with a clear plan for sensor installation, we were able to execute the deployment successfully.
What about the implementation team?
While a third party handled the implementation, the OEM provided us with direct training on Falcon alongside CrowdStrike.
What was our ROI?
CrowdStrike Falcon has demonstrably provided a positive return on investment. We've already encountered two specific instances where, without CrowdStrike, the company would have faced millions in damages. In one case, we would have likely lost our entire SAP system.
What's my experience with pricing, setup cost, and licensing?
The pricing of CrowdStrike Falcon is competitive.
Which other solutions did I evaluate?
After evaluating SentinelOne, we found CrowdStrike to be a superior solution. CrowdStrike offers advantages in dashboard compatibility and a feature called Overwatch, which gives it a competitive edge.
What other advice do I have?
I would rate CrowdStrike Falcon 8 out of 10.
CrowdStrike Falcon is deployed in multiple branches across India.
No maintenance is required from our end.
I recommend CrowdStrike Falcon. It is not a solution we need to think twice about using.
Which deployment model are you using for this solution?
Hybrid Cloud
The threat score helps us prioritize remediation and cross-reference with other products
What is our primary use case?
We provide a service for our clients with CrowdStrike Falcon. Alerts come into the CrowdStrike Falcon dashboard, and we investigate them based on the process tree and commands running. We check everything for any infections in the host or internal connections. If a threat is confirmed, we place it into the containment section inside Falcon.
How has it helped my organization?
CrowdStrike improves our detection capabilities. We use multiple tools like Symantec and this one. CrowdStrike reports on the processes and services, allowing us to investigate forensically. We can conduct a deep analysis and identify the threat at the memory level. We can do more investigation of the process to see where it started and where it is going. We can see the commands running on the backend, CPU utilization, and memory consumption. All of that information is helpful.
What is most valuable?
CrowdStrike displays a threat score when it detects an infection. This is helpful because not all detections are the same. It will classify them as ransomware, malware, phishing, etc. This feature helps us prioritize and cross-check with other EDR tools.
It's integrated with multiple threat intelligence sources, such as the AbuseIPDB. That integration helps because we can easily cross-check between CrowdStrike and other solutions like an MDR or Azure AD. Hybrid analysis is integrated with CrowdStrike in our environment. There's also sandbox analysis. It's more informative. We perform a routine activity in our test environment where we simulate the process and file.
What needs improvement?
CrowdStrike Falcon sometimes wrongly flags things as malicious. Let's say a user is active on Chrome only. Sometimes, our cross-segmenting will fetch from the backend data and show that it is malicious because of memory or CPU utilization.
For how long have I used the solution?
I have used Falcon for more than two years.
What do I think about the stability of the solution?
CrowdStrike Falcon is a stable solution.
What do I think about the scalability of the solution?
CrowdStrike is scalable. We can query large amounts of data, and the solution responds well, whereas Splunk takes a longer time to perform a search operation.
How are customer service and support?
I rate CrowdStrike support 10 out of 10. They respond quickly and don't take much time to resolve all our issues.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have used Symantec and Rapid7.
How was the initial setup?
Falcon was already deployed when I started working. It requires some maintenance. We need to make some adjustments for some use cases, or we might need to implement upgrades that require downtime.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon is expensive because it's based on the number of services.
What other advice do I have?
I rate CrowdStrike Falcon 10 out of 10. It has delivered some good results.
Which deployment model are you using for this solution?
On-premises
Fast, easy to use, and integrates easily with any OS
What is our primary use case?
We use it for threat detection and threat hunting.
How has it helped my organization?
We are an MSP. We have deployed this in our customer environment, and we use it to detect threats in their environment. It is beneficial for customers to find cybersecurity-related threats on the endpoints.
The out-of-the-box configurations and threat intelligence provided by CrowdStrike are better than other vendors and competitors in this field. It improves our security strategy because we are building threat intelligence on top of CrowdStrike-provided detection.
We are building SIEM use cases on top of the data provided by CrowdStrike. There is reliability, and the response that we get from it is very fast. If any incident happens on the endpoint, it immediately detects that and sends that to our SIEM.
Endpoint security is a very crucial aspect of cybersecurity. Integrating CrowdStrike helps a lot to identify and dig deeper into the threats.
What is most valuable?
Its integration capability is valuable. It integrates easily with any OS.
What needs improvement?
They are good at what they are doing, but they can add more use cases. They can improve their documentation. It is a very big aspect where they are lacking. They have documentation, but it is behind the wall of authentication. It is not available publicly.
In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it. If they can add more information about an event, it will be beneficial for us and everyone else who is using CrowdStrike.
For how long have I used the solution?
I have been using this solution for four years. I have had hands-on experience with it for about two to three years.
What do I think about the stability of the solution?
How are customer service and support?
I have not interacted with their support team. It is not a part of my job.
Which solution did I use previously and why did I switch?
I work with multiple vendors, not only CrowdStrike, in the endpoint space, and the CrowdStrike UI is better than others. The response of CrowdStrike is better than other vendors.
How was the initial setup?
It is deployed on the cloud. Its deployment is of moderate complexity. It is not easy, and it is also not difficult. Overall, it is easy to deploy and manage CrowdStrike Falcon across the organization.
What other advice do I have?
I would definitely recommend CrowdStrike Falcon. It is better than other solutions, such as VMware Carbon Black. CrowdStrike is doing better in this space.
If you are using CrowdStrike Falcon for the first time, it will be easy for you. You can definitely use it.
Overall, I would rate CrowdStrike Falcon an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
I like the ease of use and its threat investigation features
What is our primary use case?
I'm a security analyst. We get alerts on the cloud side that appear in the CrowdStrike console and also in our email. We can consolidate them on the console and check the process tree. You can see the hostname, user details, and all the information on the right side. On the file part, we can see whether the malicious file has been executed and decode it to see where the hash appears.
How has it helped my organization?
I worked with an event-tracking tool before I started working at this company, and any insights that were triggered in that tool would be noted in the infrastructure certificate tool. The information we gather from CrowdStrike will be updated in Azure, so all the information, resolutions, etc. will be added to Azure. We can check the activity and whether the malicious file is being blocked, quarantined, or allowed.
What is most valuable?
I like Falcon's threat detection and endpoint investigation features. It's a user-friendly solution. We determine the root cause of an alert and contact the end user via our Slack channel if necessary to gather additional information to determine whether they know about the activity. We can download and investigate the malicious file in the sandbox to see what's happening. We check to see if it has been executed. We can easily delete it in the CrowdStrike console if it hasn't.
For how long have I used the solution?
I have used CrowdStrike for two years.
What do I think about the stability of the solution?
I rate CrowdStrike Falcon ten out of ten for stability.
What do I think about the scalability of the solution?
I rate CrowdStrike Falcon ten out of ten for scalability.
How are customer service and support?
I rate CrowdStrike support eight out of ten. They respond quickly on weekdays, but the weekend response times are slower.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I'm working on two projects. One is using CrowdStrike Falcon and the other is using Crowdstrike XDR, which is the advanced version.
How was the initial setup?
Falcon is a cloud-based platform so deployment is easy. You only need to deploy the agent to the endpoints, but the data is stored in CrowdStrike.
What other advice do I have?
I rate CrowdStrike Falcon ten out of ten. I would recommend Falcon to others.
Which deployment model are you using for this solution?
Public Cloud
The overall experience with Crowdstrike Falcon is highly positive, with seamless scalability, easy deployment, and exceptional stability once properly configured.
What is our primary use case?
We rely on CrowdStrike Falcon for comprehensive threat detection, prevention, and valuable insights. This robust solution also offers identity protection features. Our dedicated team of six professionals effectively manages the platform, ensuring its effectiveness across multiple locations, including our data centers and core facility.
How has it helped my organization?
CrowdStrike's advanced detection and prevention capabilities offer a superior level of protection against potential threats. Its unique feature of automated rules is designed to effectively confine threats at the device level. This automatic confinement of high alerts ensures that the device is secured immediately, buying crucial time for the dedicated response team to identify and neutralize the threat. This proactive strategy not only minimizes the potential impact of threats but also guarantees a rapid and efficient response to any security incidents, thereby enhancing the overall security posture.
What is most valuable?
We appreciate Falcon's network visibility feature as it allows us to monitor the evolution of threats on PCs and within the company network. The solution's real-time incident response is notably swift. Initially, we encountered numerous false positives during the project initiation phase. However, we managed to resolve most of them independently or with assistance from CrowdStrike support. Consequently, our security levels were significantly improved, and we elevated all parameters to their maximum. Currently, we seldom encounter false positives. Most of these were low-level alerts, while the high-level alerts were automatically quarantined.
What needs improvement?
While Falcon's advanced capabilities offer robust security solutions, it's worth noting that some of these features may come at a higher cost. This could potentially make it a less economical option for small to medium-sized businesses operating on tighter budgets. It's important for such companies to weigh the benefits of Falcon's comprehensive protection against their financial constraints to make an informed decision.
For how long have I used the solution?
We have been using CrowdStrike Falcon for nearly five years already.
What do I think about the stability of the solution?
Crowdstrike Falcon demonstrates exceptional stability once it has been properly configured with the appropriate settings. While there may be a period of adaptation and configuration required to ensure optimal performance, once the solution is in place, it operates with remarkable stability. Users can rely on Crowdstrike Falcon to consistently deliver reliable and secure protection without significant disruptions or instability.
What do I think about the scalability of the solution?
I would rate Crowdstrike Falcon a nine out of 10 for scalability. It offers seamless scalability, allowing easy expansion of the sensor deployment to accommodate growing needs. However, it's worth noting that the primary limitation one may encounter is the cost associated with deploying additional sensors.
How are customer service and support?
I rate CrowdStrike support nine out of 10. It's fantastic.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We made the switch from Symantec to Falcon because we required a solution that offered greater speed, reliability, and the ability to effectively handle the wide range of advanced threats present in the wild.
How was the initial setup?
The initial setup of Crowdstrike Falcon was straightforward and efficient. The cloud-based deployment process was seamless for most components, with the exception of the sensors. Deploying the sensors to PCs was automated and hassle-free, requiring just a few minutes per device. However, to ensure the highest level of protection and customization, we opted to manually install the sensors on our servers. This hands-on approach allowed us to have greater control and assurance over the server deployment, ensuring the best possible protection for our critical infrastructure.
What was our ROI?
We've seen an ROI in terms of time saved. It's probably around 5 percent.
What's my experience with pricing, setup cost, and licensing?
While Falcon's advanced capabilities offer robust security solutions, it's worth noting that some of these features may come at a higher cost. This could potentially make it a less economical option for small to medium-sized businesses operating on tighter budgets. It's important for such companies to weigh the benefits of Falcon's comprehensive protection against their financial constraints to make an informed decision.
Which other solutions did I evaluate?
Of course but I can't disclose this information.
What other advice do I have?
I rate Crowdstrike Falcon nine out of 10.
Automatically takes immediate action whenever it detects suspicious activity
What is our primary use case?
We use CrowdStrike Falcon for both our server and endpoint security, including our users' laptops and PCs.
How has it helped my organization?
CrowdStrike Falcon has made a significant difference for us, especially in mitigating ransomware and zero-day attacks. Its proactive and defensive response approach effectively isolates threats, setting it apart from other endpoint solutions.
Integrating CrowdStrike Falcon into our environment was seamless. Once we set the policy the software was activated immediately and distributed on all our endpoints.
The real-time response is highly effective. It automatically takes immediate action whenever it detects suspicious activity, alerting us to the problem and providing clear mitigation steps. In some cases, it even pushes through updates to resolve the issue proactively.
The usability and interface of CrowdStrike Falcon for daily operations are good.
What is most valuable?
The managed services are distinguished, responsive, dynamic, flexible, and assertive when taking action.
What needs improvement?
CrowdStrike Falcon could be enhanced by extending its security capabilities to include NDR and XDR.
The pricing has room for improvement.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
In the three years of using CrowdStrike Falcon, we have not encountered any stability issues.
What do I think about the scalability of the solution?
CrowdStrike Falcon scales well. We are using it in a large environment with no problems.
How are customer service and support?
The technical support is responsive.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used both Symantec Endpoint Detection and Response and Kaspersky Endpoint Detection and Response but found that they lacked the 24/7/365 monitoring and response offered by CrowdStrike Falcon. Additionally, their detection capabilities, particularly for ransomware and zero-day attacks, were not as effective.
How was the initial setup?
The initial deployment was straightforward and non-disruptive. The deployment took one week to complete.
We required two people from our organization for the deployment on-site and the CrowdStrike team worked remotely.
What about the implementation team?
The CrowdStrike team helped with the implementation.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon is one of the more expensive endpoint solutions on the market.
What other advice do I have?
I would rate CrowdStrike Falcon an eight out of ten.
We deployed CrowdStrike Falcon across all our locations, including subsidiaries and remote sites in various regions.
Maintaining CrowdStrike Falcon is simple because it only requires a client agent to be installed on the machine at the kernel level, below the operating system.
Helps protect against malware and the maintenance is straightforward, but there are a lot of false positives
What is our primary use case?
Our organization relies on CrowdStrike, a standalone endpoint security solution, to safeguard our bare-metal machines. CrowdStrike continuously monitors for threats on all endpoints. If it detects any suspicious activity, such as malware or malicious processes, it immediately alerts us for investigation.
What is most valuable?
The malware protection is the most valuable feature of CrowdStrike Falcon.
What needs improvement?
The current database schema presents challenges and has potential for improvement.
The technical support response time can be improved.
There are a lot of false positives reported.
For how long have I used the solution?
I have been using CrowdStrike Falcon for almost four years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable.
How are customer service and support?
The technical support is good but the response time can be improved.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used VMware Carbon Black Endpoint. CrowdStrike Falcon is more of an EDR solution.
What other advice do I have?
I would rate CrowdStrike Falcon a seven out of ten.
The maintenance is straightforward.
CrowdStrike Falcon is deployed independently in our environment and we have 30 users.
While CrowdStrike Falcon offers valuable security tools for larger organizations with extensive infrastructure, its complexity might not be ideal for smaller businesses with limited IT resources.
Which deployment model are you using for this solution?
Public Cloud
The sensor requires very little memory and doesn't slow down your computer
What is our primary use case?
I'm a tax lawyer, so the IRS requires me to have a security program.
What is most valuable?
Everything is automatic. I install the sensor and renew the service. Periodically, I get a notice that they've shut something down. It couldn't be less painful, and it couldn't be more reassuring. I never need to do anything with it. I don't tweak it or update it.
You place a sensor on your computers that requires a very small amount of memory. It's about 39k or so to run the sensor. It's not like other programs that slow down the computer. CrowdStrike is constantly scanning your computer from the cloud and responds in a millisecond when it detects anything.
What needs improvement?
The content-filtering features for children could be improved. We have young grandchildren aged 12 and 8. My daughter, their mother, wants to keep them from getting in trouble on the net. She looked at all these other solutions from Google, Microsoft, etc., and she couldn't figure out how to make any of those work. I told her that I bet CrowdStrike could handle this. Sure enough, CrowdStrike can do exactly that. It's the same solution that the Defense Department gets. It works, but it's a little complicated to implement. It could be simpler to set the policies.
For how long have I used the solution?
I have used CrowdStrike Falcon for three or four years.
How are customer service and support?
I rate CrowdStrike support 10 out of 10. It's an email-based procedure. You create a case, and they notify you when it's assigned. You get an email from the technician, and you correspond back and forth. I usually request a phone call. They respond quickly. It's usually within half an hour to an hour. The tech support is perfectly adequate and certainly helps with whatever you want. They're nice, and the people seem intelligent.
How would you rate customer service and support?
How was the initial setup?
Setting up CrowdStrike Falcon is easy. They give you this enormous knowledge base. I almost never use it, but it covers absolutely everything. They also do a lot of handholding for the installation. You can get somebody to call you and tell you that everything is in the right place and it's doing all the right stuff. You can also do it by yourself, and you'll get an email message saying your sensor has been installed on this endpoint.
It took me about half an hour to an hour to download and install the sensor, but I also think it was influenced by the level at which I use CrowdStrike. I am their most basic user. A more complicated environment like the Defense Department might take more time.
What was our ROI?
CrowdStrike Falcon offers a great value. I'm the smallest kind of customer they had. It's a big step up. I had a more robust subscription, but I found I didn't use any of it ever, so I just cut back to the same thing that I had to begin with. You hardly notice any difference.
What's my experience with pricing, setup cost, and licensing?
Crowdstrike Falcon is relatively cheap.
Which other solutions did I evaluate?
We also considered Palo Alto. It had a device, but once you got it, you had some technical issues to deal with. I don't know if Palo Alto's requirements were more or less onerous than CrowdStrike's, but it seemed a little more complicated.
The two products had similar pricing. Palo Alto was about $750 for the device and a small amount for maintenance and whatnot. The other one is $500 a shot. The fact that you can get some other form of security software for a tenth of that price doesn't matter. It's just not even worth thinking about.
What other advice do I have?
I rate CrowdStrike Falcon 10 out of 10. It's extraordinarily easy to implement and use. You can do some advanced things that require some expertise, but those levels of security would be more appropriate for larger enterprises.
Offers good centralization and access to remote sites with an easy setup
What is our primary use case?
We're installing the solution on some of our external servers. It has a cloud portal, and we can control everything through the cloud. It's good for remote sites.
What is most valuable?
I like that it has a centralized cloud, and all the agents provide visibility on our remote sites. It offers good central management. It can be accessed through external networks.
The management is taken care of. It's a complete solution that's taken care of by CrowdStrike. We don't have to do anything.
What needs improvement?
We'd like to see more integration capabilities.
We need more log storage as CrowdStrike will dump all logs to the centralized server.
For how long have I used the solution?
I've been using the solution for five years.
What do I think about the stability of the solution?
The solution is stable enough. We have not had any downtime. The only issue is if we have issues with the internet connectivity.
How are customer service and support?
We get support from their local vendors. We have a lot of local support. If they cannot handle the case, they directly forward the issue to CrowdStrike. The downside is that support asks for too many logs. We, of course, have to investigate first and try to solve the problem ourselves.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I've worked with Kaspersky. They are a similar solution. I've also used Microsoft Defender, which is also very similar. We do use a lot of Microsoft products, and Defender is readily available everywhere. They are the market leaders right now. Their software has very good integration across the whole Microsoft product offering. CrowdStrike, however, we have high trust with, as they are focused specifically on security, unlike Microsoft. CrowdStrike offers updates quicker than Microsoft or other services.
How was the initial setup?
The initial setup is a very fast process. Cloud solutions are fast to set up. They just give you access to their cloud and they have an API integration. It will be up and running within a few minutes.
What's my experience with pricing, setup cost, and licensing?
The tool is very expensive. It's similar to Microsoft Defender. That said, it's not overpriced. It's worth it for the level of security. We need it for our company.
What other advice do I have?
I'd rate the solution nine out of ten.