I use the solution in my company primarily for endpoint detection and response. Our company has multiple endpoints at different levels, and this is basically to detect anomalies. At the back end, we have a Splunk Data Lake, where all the data goes. We use the same for alerting and monitoring purposes, on the basis of which we take action. The tool is basically used in combination with Splunk and other tools that we have in our company.
CrowdStrike Falcon Cloud Security
CrowdStrikeExternal reviews
External reviews are not included in the AWS star rating for the product.
Helpful to detect anomalies in endpoints but needs to improve its integration capabilities
What is our primary use case?
What needs improvement?
I am not part of the current monitoring team, so I do not know how they feel about the tool. I am sharing information related to the tool based on the feedback and on my experience deploying it four to five years ago.
I would not say the tool's integration capabilities were straightforward because the complexity depends on the volume of the data. I am talking about petabytes of data, so sometimes, the integration part is not so straightforward. I would say we have had our own share of issues. All in all, we were able to manage it in the long run. I tried to integrate the issue with Splunk Enterprise Security and Splunk Data Lake, too. I am not a user of Splunk, but I have just implemented it to support my customers, who are the primary users of the data.
For how long have I used the solution?
I have been using CrowdStrike Falcon Cloud Security for four to five years.
What do I think about the scalability of the solution?
The scalability of the product has been great. My company started off with 1,50,000 endpoints, and now we are at 2,00,000, and I believe that it speaks volumes for itself. The tool's team has been super supportive when it comes to providing support, helping us out with upgrades, and letting us know how things could work. I believe the experience with the tool has been good.
How are customer service and support?
Nothing is perfect in this world. There will always be positive and negative aspects associated with the product. I have heard more positive things about the product than negative statements. As an enterprise, when you are dealing with a vendor, there are chances where, you know, there will be few misses and lots of hits.
Which solution did I use previously and why did I switch?
I have experience with FireEye. In 2019, my company migrated from FireEye to CrowdStrike Falcon Cloud Security.
How was the initial setup?
The product's initial setup phase is not really difficult, especially if you have managed the setup phase before. In our company, we migrated from Mandiant to FireEye and from FireEye to CrowdStrike, so it has been a journey for us over the last ten years. You get to learn as you go and embark on a journey. We were able to deal with challenges in the area of deployment that we were trying to perform, and there were not many from the vendor side. Still, at the enterprise level, you have endpoints that are across different landscapes, like if you have a cloud platform or an on-prem model, and then you have things that the vendors manage. If you are trying to deploy things at different levels with different scales, you may face some challenges, but nothing in particular with the vendor, I would say.
What was our ROI?
I have experienced an ROI from the use of the product, and it is definitely one of the biggest takeaways or the reasons that my company migrated from FireEye to CrowdStrike. The features that CrowdStrike offered our company were far more in-depth than those of FireEye. I am not saying that FireEye does not offer great features, but with the kind of landscape that we operate on, we felt that we would be better off with CrowdStrike than with FireEye. We have FireEye, and we saw that there were certain shortcomings. Getting down to the specifics, I am not part of the monitoring team, so I will not be able to give you very crisp data about it.
What other advice do I have?
CrowdStrike Falcon Cloud Security's features have proven to be the most effective for detecting and responding to threats. While I was involved in the deployment, I was not involved in the product's day-to-day activity, as I was not a part of the monitoring team. I was basically on the deployment team. I do not use it on a day-to-day basis.
Speaking about the integration of CrowdStrike Falcon Cloud Security within our existing infrastructure and with third-party solutions, I feel that everything has been okay, and it is something that we need to figure out as an enterprise. When you are trying to do things at a very large scale, consisting of more than 1,50,000 endpoints, that is the scale within the enterprise that we were dealing with in the past, and it has crossed 2,00,000 right now. When trying to integrate it with other applications, the likes of Splunk or other data lakes, if I have to say, but categorically and specifically Splunk in the current case, you have to see how that is going to work and ensure whether everything will be seamless or not, and it may not be something that is possible at the first instance, but you need to try things and see what works and what does not. You also got to get the vendors along, and that is basically what my company did. In our case, we got people from CrowdStrike speaking to people from Splunk, after which whatever integration issues we had were resolved.
I recommend the product to others who plan to use it.
Everything depends upon your use cases since not one size fits all templates. The use cases vary from organization to organization. In our case, CrowdStrike Falcon Cloud Security suited us the best, which is why we went with it and moved away from FireEye, which may or may not be the case for others. I know organizations that continue to use FireEye, and they are pretty happy with it because it suits their requirements. It just fits all the use cases that they have listed out.
Whether the product needs to increase your marketing strategy or not is something that depends on what the solution wants to achieve. As far as I know, CrowdSrike has a sizable base in the market, but it completely depends on what they want to do. I don't think I am the right person to suggest or tell CrowdStrike what they need to do because the product is managed by a set of stable and sane minds who would decide how they want to strategize things when it comes to sales.
I rate the tool a seven to eight out of ten.
Review
Best Cloud Security that I am used.
CrowdStrike Falcon Cloud Security
Offers reliable threat intelligence features with AI capabilities and excellent stability
What is our primary use case?
The solution is used for endpoint management and profiling. CrowdStrike Falcon Cloud Security offers protection against security threats or attacks.
What is most valuable?
The threat intelligence is the most vital feature of CrowdStrike Falcon Cloud Security.
What needs improvement?
Certain endpoint management features, such as encryption and extensive file integrity monitoring, should be added to the solution. The file integrity monitoring feature should be enhanced and offered more control. The functionality of DLP also needs to be enhanced.
For how long have I used the solution?
I have been using CrowdStrike Falcon Cloud Security for two years.
What do I think about the stability of the solution?
The solution exhibits impressive stability. I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
In our company, about 20 clients use CrowdStrike Falcon Cloud Security, and the total number of end-users combining all clients exceeds 1000. I would rate the scalability an eight out of ten.
How are customer service and support?
Support is provided based on the service level availed from CrowdStrike. I would rate the basic tech support a six out of ten. An advanced service contract with the vendor includes more available support members for rapid response, I would rate the advanced support from the vendor an eight out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have worked with Trend Micro, Symantec and McAfee. CrowdStrike Falcon Cloud Security is a more enhanced and cost-effective solution than Trend Micro.
How was the initial setup?
The solution can be easily deployed. If numerous endpoints are involved in the deployment, automation tools like SCM can push the packages, which then start communicating with the servers.
Our company offers security service management, therefore we manage the license renewals and facilitate the regular maintenance. One product manager from our company and a team of three professionals are needed to maintain CrowdStrike Falcon Cloud Security.
What's my experience with pricing, setup cost, and licensing?
It's an expensive product. The solution costs around $60 for a single user on a yearly basis. I would rate the pricing a four out of ten.
What other advice do I have?
The solution's threat intelligence features enhance endpoint detection and security to a great extent. The aforementioned feature quickly detects new malware based on behavior with the assistance of an AI learning model.
The solution acts as a single agent with multiple capabilities, but some features don't perform optimally, including DLP and file integrity monitoring, which aren't extensive enough.
The product enhances endpoint security and management of global threats. The solution's AI module learns from behavior and it's able to detect behavior inconsistencies, facilitating rapid threat detection and mitigation.
I would definitely recommend the product to other users. CrowdStrike Falcon Cloud Security is slightly more expensive than other competitor solutions. Every customer of our company can't afford CrowdStrike Falcon Cloud Security, and there isn't always a need for its high-end features, so we recommend a different solution. I would rate the product a nine out of ten. I believe some features are still missing from the solution.
Enhancing threat detection with CrowdStrike Falcon
The Machine Learning and AI platform leverages advanced machine learning algorithms and artificial intelligence to identify and prevent threats, even without relying solely on signatures.
CrowdStrike Falcon Cloud Security
Despite all of this, CrowdStrike Falcon continues to be popular for its overall effectiveness and excellent threat detection capabilities.
Crowdstrike falcon best EDR tool
Inbuilt Mitre attacks tactics to identify threats
Lightweight and has login features like multi factor authentication
What is our primary use case?
I use the solution for protection on the go for end-user computers, identity management, proactive awareness of devices on the network, and statistical collection on the devices.
What is most valuable?
The solution's most valuable feature is that the solution for IT security is not based on the on-premises solution; it is available on demand. It is lightweight and can be held on a mobile device. The solution has login features like multi factor authentication. The tool facilitates data collection of the equipment on the network, including solutions on whether to remove or keep some computers.
The solution interacts with the domain controller and gives an update on what specifics may be harmful to the environment so that we can tag it to the users before they actually contact the IT team for support.
What needs improvement?
While it may be able to show the user in the drill zone, it could have a listed column at a higher level. That way, it would help the IT team do targeted interventions rather than having to drill into the details. The tool could give us more templates so that people who are not updated with the platform can easily get acquainted with how to secure and utilize the product more.
The only thing I don't like about the application is when a computer name changes, the CrowdStrike app maintains the two devices. The name or the MAC address was different. I'm unsure if the solution can flush the database based on the similarities in the MAC address.
The solution lists the equipment but maintains the tool name on to something else. If we have renamed the equipment that joined the platform before, we just delete it manually. So, we know which one is now the new name.
For how long have I used the solution?
I have been using CrowdStrike Falcon Cloud Security for more than two years.
What do I think about the scalability of the solution?
We are confident that the solution should be able to scale well based on the current features and the modular programming that it appears to be doing. The idea of scalability is that it can handle volumes of data requests outside of what our environment is doing. We not only deploy the solution in one domain controller, but what we can see on the domain controller is based on our environment setup. Based on the hybrid point of view, I think the solution is very scalable.
We have around 500 users working with the solution in our environment. In my environment, we're testing to see if we need to increase usage. If not, the other solution would be mobile device management to handle the other exceptions we currently see.
I rate the solution’s scalability an eight out of ten.
How are customer service and support?
When we recently got the licenses, we were told to do something. When we observed that we didn't want to transfer where we were, they did something else to help with the solution. The technical team is not just technical; they're also human in that they're adaptable to customer needs and provide guidance.
How would you rate customer service and support?
Positive
How was the initial setup?
The team was awesome at implementing the tool. When we transferred to the paid version, the technician or engineer from CrowdStrike transferred to the new tenant without redeploying the endpoint, which was awesome for me.
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a nine out of ten.
What was our ROI?
I can't give you a percentage of the return on investment. The solution protects me from the cybersecurity threats, which is very good for me and my team. So, I'm giving you a qualitative response as opposed to a quantitative response.
What's my experience with pricing, setup cost, and licensing?
It's an expensive package but does what it says it will do. Specialists are usually not cheap, so you expect to have a great package. They help you customize it, so I think it is worth it. The solution's pricing is in the same range as FortiEDR's. We paid over five million dollars for our package based on the number of subscriptions and the other add-ons to the package bundle.
The licensing fee we pay for the solution doesn't include managed services because my technical team and I were able to handle the product. It's very easy to maneuver. There's no additional cost for us to use the product outside the bundle we've requested. We ask for the basics, and then we include add-ons for the identity and server management. That will be the only add-ons cost that is manageable.
I rate the solution’s pricing an eight out of ten.
What other advice do I have?
The dashboard gives an overview of the last login for somebody besides you. You know what is going on at a high level since you don't always have to have one operating system or environment. The suggestion and the data dictionary or the look of the threat environment are also helpful because they help us prepare against the threat landscape once it is known.
Based on how the organization is listed, you could classify the equipment according to an organizational unit to identify the component. That is helpful because if you're being attacked, you can see where the entry point comes from based on the response coming from the panel. This response can be emailed to the team.
The solution is deployed on the cloud. Before buying the solution, understand the technology gap so that you can look for the features you need. Any lightweight product that can be accessed on a mobile device on the go or outside the office is a great product for security specialists. The solution offers good availability and multi factor authentication. Some security concerns are built into the tool's security package.
It helps you understand the ecosystem of lurking threats waiting to come to your network or already on it. It is a great product for those who want inventory insight into their network. It gives you a lot of details that you probably wouldn't have captured if you didn't have great inventory management from an IT perspective.
The tool can also help you plan your next product or procurement of equipment to get better feedback on what's going on from your user experience. For me, the solution's statistics insight is great. The dashboard is awesome because you don't have to look for something. It can tell you exactly which computers are online and which haven't come online for a long time.
From a technological point of view, you can call and find out why equipment is not online to make a proactive decision.
I believe AI has always been a part of the package we've been using for a time. The proactive threat hunt based on statistics in the environment is a part of the AI search feature in the portal. From a cybersecurity point of view, if the product can detect a threat lurking in your network, it helps you sleep better at night because you don't have to look for it all the time.
The statistics provided via email or in the CrowdStrike environment point you in a direction so you can do something. If you don't want to do it yourself, the tool can be trained to do it automatically for you if you allow the settings.
Overall, I rate the solution a nine out of ten.