CrowdStrike Falcon Platform
Falcon Endpoint Protection
Comprehensive Protection, Easy Management
Helpful Policy Creation and Asset Monitoring
Strong USB Protection, Effortless Setup
Platform has unified threat visibility and delivers lightweight protection for every endpoint
What is our primary use case?
CrowdStrike Falcon is primarily used because we are a system integrator that sells a solution to our customers, so most of it is endpoint security.
We are not the one operating CrowdStrike Falcon, but when we do an implementation, once we install the agent and complete the implementation, we see what it has detected from day one of the implementation until the turnover to the operations team. The Falcon Complete dashboard is intuitive, especially OverWatch, which highlights every risk that we need to manage, and also the detection field and incident field where we can see the entire timeline and all the things that happened. There is also a network map where you can see, for example, if there is one detection on a workstation, which other users or other devices it communicated with.
We are primarily utilizing Charlotte AI within CrowdStrike Falcon platform. We use it extensively on CrowdStrike Falcon EDR, plus also NG-SIEM, because with Charlotte, it can help us create queries without doing it manually.
What is most valuable?
One of the key advantages of CrowdStrike Falcon is its lightweight sensor, so it is easy to deploy compared to other security solutions.
CrowdStrike Falcon provides results because, until now, no customer of ours has gotten ransomware or been infected.
The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of the companies that I mentioned earlier had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.
There is no impact on endpoint performance. On some of the other products that I compared CrowdStrike Falcon with, some of them cause high utilization. We have not experienced that with CrowdStrike Falcon.
For me as the one who implements CrowdStrike Falcon, it has a real impact because it is easy to deploy. Even though the customer does not have software deployment tools, you can deploy CrowdStrike Falcon by having a simple GPO, a Group Policy Object, load it there, and then you can install it easily.
For endpoint performance, it is great because it is very lightweight. It is not the traditional antivirus from before where when you do a scan and install it, the CPU and memory will spike up and the user cannot do anything about it. CrowdStrike Falcon is very lightweight. With that, users do not need to balance between usability and security because with CrowdStrike Falcon, you can have both.
What needs improvement?
CrowdStrike Falcon can improve their supportability of legacy devices. This is where CrowdStrike Falcon has been edged out by other cybersecurity vendors because some of them support legacy operating systems, unlike CrowdStrike Falcon that primarily uses one level higher of operating system than others.
For how long have I used the solution?
In the cybersecurity field, I have been working for more than ten years. We have been working with CrowdStrike Falcon since 2022 to now.
What do I think about the stability of the solution?
In terms of reliability, ever since I used CrowdStrike Falcon platform, I think it is still okay because the GUI, the dashboard, and the console are easy to use because all of their solutions are in one platform, so you will not get lost. They have OverWatch and a detection incident where all the detection is already consolidated there. Once you click it, you are going to see all the details.
What do I think about the scalability of the solution?
The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of those companies that I mentioned had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.
How are customer service and support?
When we had an issue, for example, on an agent installation because of one legacy device or when we were installing it with another endpoint application, we had CrowdStrike Falcon support come in with us. They are very helpful because they were able to resolve our issue.
Which solution did I use previously and why did I switch?
We had one experience with one of our customers where at first, they were not a CrowdStrike Falcon user. They had a ransomware with a different solution, not CrowdStrike Falcon. After that, we asked them to try CrowdStrike Falcon and install it, then we could see other detections that their previous vendor or solution did not see. After we were able to help them clean their environment, they transitioned to CrowdStrike Falcon with Falcon Complete, with the managed detection and response of CrowdStrike Falcon.
The most common solution right now in my country is NG-SIEM. Before, they used a different SIEM, like Splunk, Rapid7, Exabeam, or QRadar, but now that they see the value of CrowdStrike Falcon XDR and they want it to work together, most of them are trying to move to NG-SIEM so that you can have your XDR and your SIEM in one platform, plus the telemetry that CrowdStrike Falcon endpoint provides. This will really help them secure their environment.
What other advice do I have?
I think it is very great that we have a solution as CrowdStrike Falcon which has many different security functionalities because threats are evolving. As the defender, we need to evolve as well. We are fortunate to have CrowdStrike Falcon that is continuing to evolve, even now in the AI era because threats are more complex than before. Before you just needed to worry about the zero-day and the signature. Now it is different with AI. We are fortunate we have CrowdStrike Falcon with us.
I am confident that CrowdStrike Falcon is up to par to protect you and your customers from AI threats.
Most of our customers in my country use CrowdStrike Falcon, and ever since then, they do not have serious incidents, such as a ransomware that has taken effect on all their critical infrastructures, including servers.
One value or benefit that customers can have from CrowdStrike Falcon is not having their solutions in silos. If it works in silos, it is going to be hard to keep track of threats, especially now that AI is moving at AI speed. If we are working in silos or have different solutions, it is going to be hard to catch up. Did they get anything on the identity solution? Did they get anything on the cloud solution? With CrowdStrike Falcon, it is all in a single sensor and a single platform. Customers are going to have a single pane of glass that they can look at.
The impact of AI features such as Charlotte AI on our security operations makes our lives easier, not only for us but also for our customers. Before, when they were going to do a query, they needed to drill down multiple times before they got to the one event that they wanted to see. Now, if you ask Charlotte, it is one click of a button and enter, and Charlotte will give you everything. It is much faster than drilling down to all the events and all the reports.
Customers usually get Falcon EDR first, Falcon Pro. After that, they expand to Falcon Complete, meaning adding the MDR services, and now they are trying to go to NG-SIEM plus the identity. Now that they have heard about Falcon Guardian, they might look into that as well.
If I were to give advice for someone who is evaluating or considering CrowdStrike Falcon platform, I think they need to try it so they can feel the experience and the protection and the security that CrowdStrike Falcon provides. I rate this solution a ten out of ten.
Advanced endpoint protection has secured our servers and now reduces analyst investigation time
What is our primary use case?
My main use case for CrowdStrike Falcon is to monitor endpoint and end devices, find any anomalies, detect them, and provide a resolution to secure our endpoint devices.
I use CrowdStrike Falcon to examine different network traces and traffic around our Windows and Linux devices. CrowdStrike Falcon monitors how people are accessing our applications around those servers and logs, catching any blast radius such as a high volume of bombarding requests coming to a specific server or any unauthorized access to the server, whether internally or from disallowed external sources.
What is most valuable?
The best features CrowdStrike Falcon offers include endpoint device monitoring, protection from malware and external threats, and alerting on wrong policies being implemented or blocking such as an administrator applying certain policies, making CrowdStrike Falcon a great endpoint protection tool.
The feature I rely on most day to day is endpoint device protection, as CrowdStrike Falcon surpasses tools such as Symantec which do not have interactive monitoring or defensive methodology, allowing us to control and align policies across all servers in our organization.
CrowdStrike Falcon has positively impacted my organization by helping us to stay secure, resilient, and provide what our customers need all the time without impacting their data or disclosing their personal information.
I can share that CrowdStrike Falcon has prevented our end users from uploading malicious files to our applications on those servers, meaning our systems are well protected, and we avoid incidents or threats against our applications.
What needs improvement?
I chose nine out of ten because while CrowdStrike Falcon has the capabilities and features I want, the pricing for each different functionality or feature we want to add raises my concern about potentially having a compound or overall pricing increase.
For how long have I used the solution?
I have been using CrowdStrike Falcon for five years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable, and I have not witnessed any performance impact on our endpoints due to the Falcon sensor as they are running smoothly without issues. The sensor is deployed through our imaging tool quickly to all endpoints.
What do I think about the scalability of the solution?
CrowdStrike Falcon's scalability is excellent because it is software as a service, allowing us to deploy more agents without experiencing performance lags or issues.
How are customer service and support?
The customer support is excellent. We receive reliable enterprise support when we have issues, and they provide all the guidance we need.
Which solution did I use previously and why did I switch?
We previously used Symantec and Norton for some time before switching five or six years ago because they became obsolete and failed to keep pace with market advancements.
How was the initial setup?
Using CrowdStrike Falcon has significantly helped our security team by allowing them to get alerts and perform blast radius detection in a straightforward manner, making the process more automated without the need to look through logs.
Since our initial deployment, our use of CrowdStrike Falcon has expanded significantly, starting with the basic Falcon sensor and then gradually including more capabilities around AIDR and other tools.
What about the implementation team?
We utilize Charlotte AI within CrowdStrike Falcon to investigate endpoints and understand what certain actors did, allowing us to retrieve user and machine information quickly without manually browsing through CrowdStrike Falcon.
What was our ROI?
We have seen a return on investment with CrowdStrike Falcon as our security team has been optimized and scaled, allowing them to conduct more analyses around different security postures because CrowdStrike Falcon handles most of the groundwork.
What's my experience with pricing, setup cost, and licensing?
I am not very knowledgeable about pricing, but I am aware it is quite expensive.
Which other solutions did I evaluate?
We did not evaluate other options before choosing CrowdStrike Falcon.
What other advice do I have?
CrowdStrike Falcon has already improved significantly with its AI capability, Charlotte, and I am quite happy with what is being offered.
CrowdStrike Falcon's AI capabilities are remarkable, and I trust CrowdStrike to maintain governance, security, and data privacy with the tools they provide.
Regarding the AI capabilities, I have used Charlotte AI a couple of times, and I find it quite accurate, providing the right resiliency and detection during any investigation I perform.
Having multiple security capabilities on a single platform is excellent as it eliminates the need to navigate different tools to find anomalies or detect and analyze root causes, thereby saving time for analysts whenever security breaches or vulnerabilities are identified.
CrowdStrike Falcon helped our team detect a security incident where someone attempted a SQL injection on one of our secured Drupal-based application servers. CrowdStrike Falcon alerted our team, allowing us to block access and patch the vulnerability to avoid any future incidents.
CrowdStrike Falcon has significantly helped my security team reduce their efforts and time spent analyzing vulnerable resources or security mishaps and setting up enterprise policies across the organization.
My advice to others considering CrowdStrike Falcon is that it is a great product that reduces analyst time while providing greater security posture to meet industry standards. I gave this product a rating of nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Platform has transformed threat detection speed and reduced false positives for my team
What is our primary use case?
My main use cases for CrowdStrike Falcon include detecting malicious behavior and identifying user trends.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making it faster and easier to respond to advanced threats.
In a security incident, CrowdStrike Falcon helps my team detect or stop threats by assisting in detecting unauthorized use of local binaries, such as those that are natively installed including PowerShell and scheduled tasks.
What is most valuable?
The benefits I have seen from multiple security capabilities on a single platform include solid control over consolidated information that can be accessed quickly.
I believe the value of having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform lies in the correlation of these different data sources, which is essential to identifying and disrupting advanced threats.
CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements. These improvements result from having fewer false positives, which means more time spent working on real, high-impact work.
CrowdStrike Falcon makes every analyst much more effective and informed than they would have been otherwise.
What needs improvement?
CrowdStrike Falcon can be improved by continuing to listen to customer feedback.
I believe that more integrations and support for Mac products should be included in the next release.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as reliable ever since the massive incident occurred.
I have not experienced any downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is none; it is a force accelerator.
How are customer service and support?
I evaluate customer service and technical support as excellent.
Which solution did I use previously and why did I switch?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools. The tools I replaced were those provided by legacy vendors, which operated for the sole purpose of one or two functions, and they were able to be replaced through the flexible approaches that CrowdStrike Falcon provides.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy and effective. What worked well includes the solid deployment process, though communication with lay users is always a challenge, which I would say resulted in limited to no issues.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon.
What other advice do I have?
I would rate CrowdStrike Falcon an eight on a scale from one to ten, as nothing is perfect. My advice to other organizations considering CrowdStrike Falcon is to adopt now or adopt later. I provided an overall review rating of eight.