CrowdStrike Falcon Next-Gen SIEM for AWS (pay-as-you-go)
Platform has unified threat visibility and delivers lightweight protection for every endpoint
What is our primary use case?
CrowdStrike Falcon is primarily used because we are a system integrator that sells a solution to our customers, so most of it is endpoint security.
We are not the one operating CrowdStrike Falcon, but when we do an implementation, once we install the agent and complete the implementation, we see what it has detected from day one of the implementation until the turnover to the operations team. The Falcon Complete dashboard is intuitive, especially OverWatch, which highlights every risk that we need to manage, and also the detection field and incident field where we can see the entire timeline and all the things that happened. There is also a network map where you can see, for example, if there is one detection on a workstation, which other users or other devices it communicated with.
We are primarily utilizing Charlotte AI within CrowdStrike Falcon platform. We use it extensively on CrowdStrike Falcon EDR, plus also NG-SIEM, because with Charlotte, it can help us create queries without doing it manually.
What is most valuable?
One of the key advantages of CrowdStrike Falcon is its lightweight sensor, so it is easy to deploy compared to other security solutions.
CrowdStrike Falcon provides results because, until now, no customer of ours has gotten ransomware or been infected.
The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of the companies that I mentioned earlier had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.
There is no impact on endpoint performance. On some of the other products that I compared CrowdStrike Falcon with, some of them cause high utilization. We have not experienced that with CrowdStrike Falcon.
For me as the one who implements CrowdStrike Falcon, it has a real impact because it is easy to deploy. Even though the customer does not have software deployment tools, you can deploy CrowdStrike Falcon by having a simple GPO, a Group Policy Object, load it there, and then you can install it easily.
For endpoint performance, it is great because it is very lightweight. It is not the traditional antivirus from before where when you do a scan and install it, the CPU and memory will spike up and the user cannot do anything about it. CrowdStrike Falcon is very lightweight. With that, users do not need to balance between usability and security because with CrowdStrike Falcon, you can have both.
What needs improvement?
CrowdStrike Falcon can improve their supportability of legacy devices. This is where CrowdStrike Falcon has been edged out by other cybersecurity vendors because some of them support legacy operating systems, unlike CrowdStrike Falcon that primarily uses one level higher of operating system than others.
For how long have I used the solution?
In the cybersecurity field, I have been working for more than ten years. We have been working with CrowdStrike Falcon since 2022 to now.
What do I think about the stability of the solution?
In terms of reliability, ever since I used CrowdStrike Falcon platform, I think it is still okay because the GUI, the dashboard, and the console are easy to use because all of their solutions are in one platform, so you will not get lost. They have OverWatch and a detection incident where all the detection is already consolidated there. Once you click it, you are going to see all the details.
What do I think about the scalability of the solution?
The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of those companies that I mentioned had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.
How are customer service and support?
When we had an issue, for example, on an agent installation because of one legacy device or when we were installing it with another endpoint application, we had CrowdStrike Falcon support come in with us. They are very helpful because they were able to resolve our issue.
Which solution did I use previously and why did I switch?
We had one experience with one of our customers where at first, they were not a CrowdStrike Falcon user. They had a ransomware with a different solution, not CrowdStrike Falcon. After that, we asked them to try CrowdStrike Falcon and install it, then we could see other detections that their previous vendor or solution did not see. After we were able to help them clean their environment, they transitioned to CrowdStrike Falcon with Falcon Complete, with the managed detection and response of CrowdStrike Falcon.
The most common solution right now in my country is NG-SIEM. Before, they used a different SIEM, like Splunk, Rapid7, Exabeam, or QRadar, but now that they see the value of CrowdStrike Falcon XDR and they want it to work together, most of them are trying to move to NG-SIEM so that you can have your XDR and your SIEM in one platform, plus the telemetry that CrowdStrike Falcon endpoint provides. This will really help them secure their environment.
What other advice do I have?
I think it is very great that we have a solution as CrowdStrike Falcon which has many different security functionalities because threats are evolving. As the defender, we need to evolve as well. We are fortunate to have CrowdStrike Falcon that is continuing to evolve, even now in the AI era because threats are more complex than before. Before you just needed to worry about the zero-day and the signature. Now it is different with AI. We are fortunate we have CrowdStrike Falcon with us.
I am confident that CrowdStrike Falcon is up to par to protect you and your customers from AI threats.
Most of our customers in my country use CrowdStrike Falcon, and ever since then, they do not have serious incidents, such as a ransomware that has taken effect on all their critical infrastructures, including servers.
One value or benefit that customers can have from CrowdStrike Falcon is not having their solutions in silos. If it works in silos, it is going to be hard to keep track of threats, especially now that AI is moving at AI speed. If we are working in silos or have different solutions, it is going to be hard to catch up. Did they get anything on the identity solution? Did they get anything on the cloud solution? With CrowdStrike Falcon, it is all in a single sensor and a single platform. Customers are going to have a single pane of glass that they can look at.
The impact of AI features such as Charlotte AI on our security operations makes our lives easier, not only for us but also for our customers. Before, when they were going to do a query, they needed to drill down multiple times before they got to the one event that they wanted to see. Now, if you ask Charlotte, it is one click of a button and enter, and Charlotte will give you everything. It is much faster than drilling down to all the events and all the reports.
Customers usually get Falcon EDR first, Falcon Pro. After that, they expand to Falcon Complete, meaning adding the MDR services, and now they are trying to go to NG-SIEM plus the identity. Now that they have heard about Falcon Guardian, they might look into that as well.
If I were to give advice for someone who is evaluating or considering CrowdStrike Falcon platform, I think they need to try it so they can feel the experience and the protection and the security that CrowdStrike Falcon provides. I rate this solution a ten out of ten.
Advanced endpoint protection has secured our servers and now reduces analyst investigation time
What is our primary use case?
My main use case for CrowdStrike Falcon is to monitor endpoint and end devices, find any anomalies, detect them, and provide a resolution to secure our endpoint devices.
I use CrowdStrike Falcon to examine different network traces and traffic around our Windows and Linux devices. CrowdStrike Falcon monitors how people are accessing our applications around those servers and logs, catching any blast radius such as a high volume of bombarding requests coming to a specific server or any unauthorized access to the server, whether internally or from disallowed external sources.
What is most valuable?
The best features CrowdStrike Falcon offers include endpoint device monitoring, protection from malware and external threats, and alerting on wrong policies being implemented or blocking such as an administrator applying certain policies, making CrowdStrike Falcon a great endpoint protection tool.
The feature I rely on most day to day is endpoint device protection, as CrowdStrike Falcon surpasses tools such as Symantec which do not have interactive monitoring or defensive methodology, allowing us to control and align policies across all servers in our organization.
CrowdStrike Falcon has positively impacted my organization by helping us to stay secure, resilient, and provide what our customers need all the time without impacting their data or disclosing their personal information.
I can share that CrowdStrike Falcon has prevented our end users from uploading malicious files to our applications on those servers, meaning our systems are well protected, and we avoid incidents or threats against our applications.
What needs improvement?
I chose nine out of ten because while CrowdStrike Falcon has the capabilities and features I want, the pricing for each different functionality or feature we want to add raises my concern about potentially having a compound or overall pricing increase.
For how long have I used the solution?
I have been using CrowdStrike Falcon for five years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable, and I have not witnessed any performance impact on our endpoints due to the Falcon sensor as they are running smoothly without issues. The sensor is deployed through our imaging tool quickly to all endpoints.
What do I think about the scalability of the solution?
CrowdStrike Falcon's scalability is excellent because it is software as a service, allowing us to deploy more agents without experiencing performance lags or issues.
How are customer service and support?
The customer support is excellent. We receive reliable enterprise support when we have issues, and they provide all the guidance we need.
Which solution did I use previously and why did I switch?
We previously used Symantec and Norton for some time before switching five or six years ago because they became obsolete and failed to keep pace with market advancements.
How was the initial setup?
Using CrowdStrike Falcon has significantly helped our security team by allowing them to get alerts and perform blast radius detection in a straightforward manner, making the process more automated without the need to look through logs.
Since our initial deployment, our use of CrowdStrike Falcon has expanded significantly, starting with the basic Falcon sensor and then gradually including more capabilities around AIDR and other tools.
What about the implementation team?
We utilize Charlotte AI within CrowdStrike Falcon to investigate endpoints and understand what certain actors did, allowing us to retrieve user and machine information quickly without manually browsing through CrowdStrike Falcon.
What was our ROI?
We have seen a return on investment with CrowdStrike Falcon as our security team has been optimized and scaled, allowing them to conduct more analyses around different security postures because CrowdStrike Falcon handles most of the groundwork.
What's my experience with pricing, setup cost, and licensing?
I am not very knowledgeable about pricing, but I am aware it is quite expensive.
Which other solutions did I evaluate?
We did not evaluate other options before choosing CrowdStrike Falcon.
What other advice do I have?
CrowdStrike Falcon has already improved significantly with its AI capability, Charlotte, and I am quite happy with what is being offered.
CrowdStrike Falcon's AI capabilities are remarkable, and I trust CrowdStrike to maintain governance, security, and data privacy with the tools they provide.
Regarding the AI capabilities, I have used Charlotte AI a couple of times, and I find it quite accurate, providing the right resiliency and detection during any investigation I perform.
Having multiple security capabilities on a single platform is excellent as it eliminates the need to navigate different tools to find anomalies or detect and analyze root causes, thereby saving time for analysts whenever security breaches or vulnerabilities are identified.
CrowdStrike Falcon helped our team detect a security incident where someone attempted a SQL injection on one of our secured Drupal-based application servers. CrowdStrike Falcon alerted our team, allowing us to block access and patch the vulnerability to avoid any future incidents.
CrowdStrike Falcon has significantly helped my security team reduce their efforts and time spent analyzing vulnerable resources or security mishaps and setting up enterprise policies across the organization.
My advice to others considering CrowdStrike Falcon is that it is a great product that reduces analyst time while providing greater security posture to meet industry standards. I gave this product a rating of nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Platform has transformed threat detection speed and reduced false positives for my team
What is our primary use case?
My main use cases for CrowdStrike Falcon include detecting malicious behavior and identifying user trends.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making it faster and easier to respond to advanced threats.
In a security incident, CrowdStrike Falcon helps my team detect or stop threats by assisting in detecting unauthorized use of local binaries, such as those that are natively installed including PowerShell and scheduled tasks.
What is most valuable?
The benefits I have seen from multiple security capabilities on a single platform include solid control over consolidated information that can be accessed quickly.
I believe the value of having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform lies in the correlation of these different data sources, which is essential to identifying and disrupting advanced threats.
CrowdStrike Falcon has massively affected the workload and productivity of my security team, leading to significant improvements. These improvements result from having fewer false positives, which means more time spent working on real, high-impact work.
CrowdStrike Falcon makes every analyst much more effective and informed than they would have been otherwise.
What needs improvement?
CrowdStrike Falcon can be improved by continuing to listen to customer feedback.
I believe that more integrations and support for Mac products should be included in the next release.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as reliable ever since the massive incident occurred.
I have not experienced any downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is none; it is a force accelerator.
How are customer service and support?
I evaluate customer service and technical support as excellent.
Which solution did I use previously and why did I switch?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools. The tools I replaced were those provided by legacy vendors, which operated for the sole purpose of one or two functions, and they were able to be replaced through the flexible approaches that CrowdStrike Falcon provides.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy and effective. What worked well includes the solid deployment process, though communication with lay users is always a challenge, which I would say resulted in limited to no issues.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon.
What other advice do I have?
I would rate CrowdStrike Falcon an eight on a scale from one to ten, as nothing is perfect. My advice to other organizations considering CrowdStrike Falcon is to adopt now or adopt later. I provided an overall review rating of eight.
Integrated security platform has transformed incident response and reduced investigation time
What is our primary use case?
My main use case for CrowdStrike Falcon is incident response.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by improving the flow with the detections and the alerting. One of the things I also have is the MDR, so that also helps with mitigating a lot of the problems as well.
The benefits I have seen from having multiple security capabilities on a single platform include just the time to remediate and to stop the threat.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that you understand what you know and what you don't know. Having all the telemetry data feed into one main system actually helps in quickly detecting threats and also seeing trends, patterns, or connections.
CrowdStrike Falcon has greatly affected the workload and productivity of my security team, which is me, by reducing the time I spend in the platform. With some workflows and creating some automation around it, it has improved my work-life balance because many tasks that I ended up doing multiple times daily are now automated, allowing me to focus on other things that need to be addressed.
What needs improvement?
I think CrowdStrike Falcon can be improved by making the menu a little bit more intuitive. I know some people like how every menu looks the same, but I don't prefer it because it makes me forget where I am or where I'm going or how to get to some place.
For the next release, I would like to see UI improvements, and also to have it where I don't need to drill into a device's alerting or submenus to just hit contain. If I bring up a device, I want a quick button there to contain it because if I'm clicking on that device, there's something I'm looking into and most likely I've been alerted of something, so I should probably contain it first and then ask questions later.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as pretty solid; it's perfect.
I have experienced no downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
Since my initial deployment, my use of CrowdStrike Falcon hasn't expanded; I think we got rid of some portions. We still have Falcon Complete, but we used to have Falcon Recon, which we got rid of. Now, we are looking back into it because of the Guardian and new steps announced with Recon today. It seems we lowered our use primarily from a customer-facing and interaction standpoint, not due to the technology itself.
How are customer service and support?
For customer service and technical support, it can be spotty at times. With CrowdStrike Recon, we got rid of it due to customer service problems; however, since then, customer reps have been in touch, quite active, vocal, and checking in on us. The support has gotten better since the initial experience.
Which solution did I use previously and why did I switch?
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used is the experience with SentinelOne for EDR and using InsightVM for vulnerability management. I used Adaptive Shield, which is now Falcon Shield, but I would say in the case of Adaptive Shield, it only got worse, mainly from a UI perspective. When it was integrated into CrowdStrike Falcon, it lost its methodical structure, making it hard to navigate. In terms of EDR, I think SentinelOne has an advantage because if I drill into a host or endpoint, I can quickly perform a bunch of actions from the initial click while I already have received the alert and a high confidence rating from CrowdStrike Falcon.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy because I use NinjaOne, which automatically does it. It's great, buy NinjaOne.
What about the implementation team?
What worked well for me was NinjaOne, and I faced honestly zero challenges. The API was easy to set up on both sides within CrowdStrike Falcon and NinjaOne, allowing us to see detections and other things as soon as we were in there. One challenge I faced was on NinjaOne's side, not CrowdStrike Falcon's side, and I would like to see integrations where we have more choice with our third-party vendors.
What was our ROI?
I can say I've seen a return on investment with CrowdStrike Falcon in terms of time and energy spent gathering information about events, but since I'm not the one spending the money, I can't really say more.
Which other solutions did I evaluate?
CrowdStrike Falcon hasn't helped me consolidate other tools, but with the announcement of Guardian and using it, it has begun the process of talking about consolidating things because right now, I use InsightIDR as my SIEM and am looking to move to the next-gen SIEM and create more workflows from there.
We haven't yet consolidated, but the impact would be that all the telemetry and plugins and everything I do, especially the workflows, would happen from CrowdStrike Falcon and not third-party. The other impact would be that I can actually integrate more because with Rapid7, I struggle with integrations from a lot of our other partners.
What other advice do I have?
My advice to other organizations considering CrowdStrike Falcon is to take a look at their third-party integrations and see what opportunities exist within CrowdStrike Falcon before making a final purchase. This way, they know which portions of CrowdStrike Falcon they actually need or want, especially since some features tie in deeply with tools like NinjaOne, making daily tasks, deployments, and implementations much easier and more manageable. I would rate this product a 9 out of 10.
Consolidated endpoint protection has improved threat prevention and streamlined investigations
What is our primary use case?
My main use cases for CrowdStrike Falcon involve protecting all our endpoints and all our servers. CrowdStrike Falcon has allowed me to consolidate or replace other security tools.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because we feel a lot more secure as it is very good at stopping threats. It makes it very easy to investigate what happened and what triggered the event. Our response time is a little better when we have to actually dig into something.
The benefits I have seen from having multiple security capabilities on a single platform include that it makes it much easier to get to what I need quickly instead of trying to switch platforms. Sometimes switching between modules, the interface is not always the same and does not feel the same. However, largely it is usually very together and it works well.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that if we do have to open up other security tools, sometimes we can leverage what CrowdStrike Falcon sees to quickly get to what is another security tool because it exposes that information.
Using CrowdStrike Falcon has affected the workload or productivity of my security team because in a lot of ways it has actually lowered the workload as it does such a good job of preventing the threats. If something triggers on another system but CrowdStrike Falcon is not triggering it, we are automatically suspect whether it is a real problem.
What needs improvement?
I have not yet used AI within CrowdStrike Falcon. I cannot think of a way that CrowdStrike Falcon itself can be improved. I do not have any suggestions for additional features that should be included in the next release for CrowdStrike Falcon as it does a very good job by itself.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about six years.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as being awesome, other than the great CrowdStriking. I have experienced downtime, crashes, or performance issues.
The detail I can provide about the performance issues involves the same traumatic thing everyone has gone through, which is the great CrowdStriking. It was bad; I am a casino, so this was on a weekend, overnight.
What do I think about the scalability of the solution?
I have not noticed any impact on performance from the CrowdStrike Falcon sensor regarding endpoint performance and my ability to deploy security at scale.
How are customer service and support?
I would evaluate customer service and technical support by saying that every time I have had to access it, they have been very good.
Which solution did I use previously and why did I switch?
We used to use Bitdefender and it was not awesome, so we replaced it. We also have replaced some SIEM and some other detective systems with CrowdStrike Falcon.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as very easy. We have Active Directory, so we just deploy with Active Directory and it works very well. What worked well during the deployment was that it just worked, so there were not really a lot of challenges. It was configure this in Active Directory, deploy it, and it works.
What about the implementation team?
My use of CrowdStrike Falcon has expanded since the initial deployment as we started off with just workstations and now it is deployed to every surface we can get it on.
What was our ROI?
I believe I have seen a return on investment with CrowdStrike Falcon as I honestly believe it has saved us money and stopped threats.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is that everybody complains about pricing. I am not going to be that much different, but they are not outrageous, and I have dealt with companies that are outrageous. On a scale of one to 10, one being really super affordable and 10 being Palo Alto, I would say it is a seven or an eight.
Which other solutions did I evaluate?
What differentiates CrowdStrike Falcon from the other cybersecurity platforms I have used or evaluated is that the biggest differentiator is that it does not, to me, at the time when we got it, rely on knowing what the bad threat is. It sees the action of the threat and relies on that, so there are no signatures required and that is a pretty big deal.
What other advice do I have?
My advice for other organizations considering CrowdStrike Falcon is that it is worthwhile to test drive and compare it to other systems. I give this review a rating of 9.
Rapid threat response has improved investigations and simplified unified security operations
What is our primary use case?
My main use cases for CrowdStrike Falcon are MDR, SIEM, and incident response.
I can describe a security incident where CrowdStrike Falcon helped my team detect or stop a threat. We had a stolen session token that somebody had phished and reused. We were able to respond on CrowdStrike Falcon within three minutes. It was really fast. We were able to find what we needed, figure out it was malicious, and then we revoked the tokens within three minutes. It was really quick and probably the fastest reaction we ever had.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats. We are a lot faster than we were previously. The investigations are easier. I can do forensics a lot faster and easier than what our last vendor had for us, which was Arctic Wolf.
The benefits I have seen from having multiple security capabilities on a single platform include having all the data in one place, which makes it easy. It makes it a lot faster for me to find what I need and to correlate that data as well, so it helps a lot.
Having endpoint, identity, cloud, and other security telemetry in CrowdStrike Falcon benefits us because we can correlate a lot more data from different places where we could not before. We had to copy and paste session ID numbers and UUIDs from one place to the other.
What needs improvement?
I did not think much about how CrowdStrike Falcon can be improved. For additional features that should be included in the next release, I would suggest the ability to save my queries, which would make it a lot easier. The only other thing I can think of is to make the query buttons, such as the save and load query buttons, a little bit bigger and easier to access.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about a year now.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as very stable and very reliable. We have not had it give us a lot of false positives.
I have not experienced any downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
CrowdStrike Falcon sensor has had an impact on endpoint performance and my ability to deploy security at scale. The sensor itself on some of the machines had a little bit of a learning curve and some growing pains when we installed it at first. We had some users complain that CrowdStrike Falcon was blocking their application, but as soon as we got the necessary exclusions in place, everything was fine. It was a little bit of a learning curve for some of our developers.
How are customer service and support?
I would evaluate customer service and technical support as great. I have only had to call customer support once and they were great.
What was great about my experience with technical support is that they were responsive and called me back.
Which solution did I use previously and why did I switch?
I replaced Arctic Wolf because Arctic Wolf did our vulnerability management and our SIEM. CrowdStrike Falcon replaced that. We were also using ESET and Bitdefender, and CrowdStrike Falcon also replaced those for our endpoint.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that I have used many cybersecurity tools, and CrowdStrike Falcon is on the cutting edge of cybersecurity. You have more features, your detections are better, and they are more reliable. I prefer CrowdStrike Falcon much better than all the tools I have used. I used to work for a competitor, so I worked for LogRhythm a long time ago, and LogRhythm is still stuck in the past.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as really easy to deploy. We set it up in NinjaOne and pushed it out and used a GPO for the rest.
What worked well was the installation, which went really well. We did not have any major issues getting it installed. The only challenges we had were that it started blocking things right away before we could get the exclusions in place.
What about the implementation team?
My use of CrowdStrike Falcon has expanded since my initial deployment. We are still in the process of expanding to other things. We are about to start using the AIDR feature, which we were not using previously. We had not rolled out VM management until very recently. We were still using Arctic Wolf for that, and we just started using CrowdStrike Falcon for that as well. We are still expanding it and turning on features that we did not have before.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon. Whatever it costs, it was worth it.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing was easy. I cannot provide data points or examples because I do not know what we paid for it.
Which other solutions did I evaluate?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools.
What other advice do I have?
The advice I would give to other organizations considering CrowdStrike Falcon is to deploy it on the endpoints. However, do not install it until you are ready and have the exclusions in place. A good feature that could be added would be a monitoring mode when you first install it, so it does not start blocking things right away. I give CrowdStrike Falcon a rating of ten out of ten.
Security team has transformed threat detection and response and gains proactive SaaS visibility
What is our primary use case?
Our main use cases for CrowdStrike Falcon include sensor updates, prevention policies, policy sensor, and firewall.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats in an excellent way that enables us to see threats ahead of time and provides us with reports so we are able to see how we are lagging behind.
CrowdStrike Falcon has reduced the workload and productivity demands on my security team dramatically.
The Falcon sensor has positively affected endpoint performance and our ability to deploy security at scale because it helped us scale at a faster rate since we do not have to always focus on identifying minor issues here and there. We have been able to address threats ahead of time, and we are able to mitigate ahead of time as well.
CrowdStrike Falcon has allowed us to consolidate or replace security tools, and right now we are trying to look at SSPM, which will give us more visibility into Salesforce. We are hoping to gain much more visibility into SaaS applications.
What needs improvement?
Improving CrowdStrike Falcon could involve slowing down the release of sensor updates and prevention policies, as I appreciate how they release them, but if they could slow down the release, that would help us catch up. I do not have any additional features that should be included in the next release.
For how long have I used the solution?
I have been using CrowdStrike Falcon for five years.
What do I think about the stability of the solution?
I have experienced downtime, crashes, or performance issues only once, which happened during the overall worldwide incident in July. Apart from that, everything is functioning properly.
What do I think about the scalability of the solution?
Since our initial deployment, our use of CrowdStrike Falcon is expanding as we look to integrate more, and I hope it will keep expanding since you keep bringing on more.
How are customer service and support?
I think the support team is excellent and able to push our tickets through efficiently. I evaluate customer service and technical support as excellent.
Which solution did I use previously and why did I switch?
I have not experienced any other cybersecurity platforms since I joined the firm as it has been CrowdStrike, so I do not know if there are any that the organization had in the past.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy. It is straightforward and easy to navigate.
What was our ROI?
I have not seen a return on investment with CrowdStrike Falcon.
What other advice do I have?
My advice to other organizations considering CrowdStrike Falcon is to give it a try if it works for them. I know there are many tools out there, but you should look for a tool that works for your organization. I would rate CrowdStrike Falcon overall a 10 on a scale from 1 to 10.
Unified visibility has improved identity investigations but correlating data still needs work
What is our primary use case?
My main use cases for CrowdStrike Falcon are broad. I mostly work in identity and access management, and I like to have a source of third-party truth module for various activities that we do. I rely on CrowdStrike Falcon to track most of the activities, and I try to use the user login information of various users.
Just because a user has access does not essentially mean they are using that access. In order to find out what sort of access is being used, I know which systems use what groups, but whether they have logged into those systems is something that I can pull in from CrowdStrike Falcon.
My use of CrowdStrike Falcon has expanded since my initial deployment because I learned a lot. I became aware of CrowdStrike Falcon, and then the incident happened, and then I started mostly using it.
What is most valuable?
The benefits I have seen from having multiple security capabilities on a single platform are substantial, as I appreciate the fact that they have a lot of metadata about metadata logs and about various activities that are happening within the organization. The only part that I get frustrated by is how many repetitions that they have across each part.
When I want to correlate multiple data and create a singularized dashboard, it becomes a nightmare and sometimes even impossible. For example, if you have the assets and you give me the users who logged into those assets, I can get a tabular view of that information. But if I want to create a dashboard out of it and create notifications with it, that is where my pain point comes in.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because I mostly try to create a couple of dashboards and KPI metrics in CrowdStrike Falcon customs, and that helps me to identify any odd usage of accounts. As an IAM team member, I know which accounts are used by whom and at what point in time they are being used. We can make a considerable guess, and we try to create rules around that and create notifications based on those activities.
CrowdStrike Falcon has affected the workload or productivity of my security team considerably better, because now I have visibility of what is happening within the organization from an identity perspective and a security perspective. Having visibility of all the servers, servers come and go when the organization is big. Having visibility of when the servers are created and who has logged into servers helps us better remediate the accesses and stick to the least access principle and least privilege principles.
What needs improvement?
I cannot talk about return on investment because I do not know how much it is or how much was invested, but regarding return on effort with CrowdStrike Falcon, I find it really good because with a small amount of effort, I can decipher a lot of information. I would say it is good. What worked well and what challenges I faced include understanding a couple of tables, the headers that you give to the tables, and no flexibility in writing the table headers or the data extraction in the individual tables. There are a couple of columns that I can siphon out, but from an overall perspective, I cannot do much customization around it.
I believe CrowdStrike Falcon can be improved regarding the cross; you have all the information in a kind of a bucket, but when I want to correlate all this information into a singularized view is when I am having issues.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three or four years, probably.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as a ten, because I have never seen it go down. Reliability is also ten, because inconsistency of data is something that I never found. Filters probably rate a five.
I have experienced no downtime, crashes, or performance issues.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as five or six, because I am still in a learning stage.
What other advice do I have?
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that it is more in the sense that instead of having one hundred tools, you have a single tool that performs those one hundred activities.
A security incident where CrowdStrike Falcon helped my team detect or stop a threat is not overall team related, but I mostly use it for investigation purposes from my own. Out of ten, five or six is how much it helps me.
My advice to other organizations considering CrowdStrike Falcon is that it is good to have and gives unified visibility across the organization. With whatever seminars I have been to and a couple of meetings I have attended, I would say a lot of interesting things are happening, so it is worth checking out. I rate this review a seven out of ten.
Centralized endpoint protection has strengthened compliance and accelerated incident response
What is our primary use case?
My main use case for CrowdStrike Falcon is endpoint detection and response. We use CrowdStrike Falcon for our antivirus across our entire organization, as well as insight and investigation to event data, telemetry data, and a plethora of other use cases and visibility.
What is most valuable?
Their early warning detections, their ransomware protections, their endpoint detection and response capabilities, and the telemetry data that allows us deeper insight into identifying threats as well as utilizing that for troubleshooting purposes are the best features CrowdStrike Falcon offers. It is pretty useful to glean a lot of details of what's happening within a process when you're trying to figure out something in a more technical aspect of the problem.
Positively, we have been able to successfully maintain compliance within all of our security obligations within our industry. We have had next to zero downtime outside of larger widespread problems, which has allowed us to remain secure on all of our endpoints and be able to conduct business with a lot less worry. We have also been able to improve our response speed to potential threats and infiltrations into the firm, as well as hardening those areas and offering faster and more effective remediation methods based on the data found from CrowdStrike Falcon.
What needs improvement?
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think.
Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
For how long have I used the solution?
I have been using CrowdStrike Falcon since 2014.
What do I think about the scalability of the solution?
We have put CrowdStrike Falcon at the top of our detection list, meaning we are now getting what we feel to be higher efficacy alerts and prevention capabilities to our entire fleet. That has helped speed up our response capabilities as well as improve our CIS benchmarking for different areas and different teams.
It has increased the speed in which we are able to address incidences and it has increased the deployment capabilities of our security solutions that we are subscribing to within CrowdStrike Falcon.
How are customer service and support?
I feel CrowdStrike Falcon's AI capabilities are a lot better than they were even six months ago and after a lot of the sessions that I've sat in this week, I am optimistic that they are getting their heads wrapped around what is most important, obviously starting with discovery. Initially as AI was this budding landscape and budding technology, CrowdStrike Falcon was just there and it was a little easy to read through the marketing fluff. However, they really seem to have figured it out. They understand already because CrowdStrike Falcon is a great company. They've already gotten a head start in understanding the nuances and difficulties around security and staying on the bleeding edge. In terms of AI, I think that they really are defending the right areas to gain that appropriate visibility and then put the appropriate guardrails in place. I also appreciate how CrowdStrike Falcon is on the forefront of governance and actually helping define that across the industries to ensure that there is safe usage of AI and that education is disseminating out from them.
As with any AI output, I am a little hesitant to believe it outright as I do think that it still hallucinates quite a bit. I have not had the opportunity to play too much with the AI outside of the support AI, which again I already mentioned is not good and in my opinion is more a chatbot than anything else. The Charlotte AI, initially, and again, I have not tried it in the last year or so, but the Charlotte AI, I felt initially was more a glorified search engine. As the LLM models are maturing and becoming more efficient, I would still trust the output, but I would still validate whatever it would tell me and I would do that for anything. As I've worked with AI now for the last several years, all models suffer from the same problem and I don't think it is unique to CrowdStrike Falcon. I think it is something that as usage increases, so will the efficacy and capabilities of the models to be able to trust them even more. We get into that situation when should we do a full trust and will we ever? Living in a zero trust environment or mindset, we should never. We should still have some sort of checks and balances and controls in place with a human or another agent or multiple agents to do validation where needed.
Which solution did I use previously and why did I switch?
I wasn't involved too much with the earlier methods prior to CrowdStrike Falcon's deployment, so I don't have the baseline of where we were prior. However, I can speak to the overall supportability of the tool and the software, ensuring that we are able to quickly update our versioning across a large number of endpoints much more efficiently and effectively than in the past. Our overall deployment and replacement of our previous EDR solution and AV was a much more painless and seamless process to actually be able to deploy within just a matter of weeks, as opposed to older, more legacy software where that might take months. We've also been able to systematically improve our versioning updates. Initially we were doing regular updates that would take several months to ensure that we were continually pushing forward and maintaining those updates and those updated versions. But now with more automation and capabilities to remain as vigilant and compliant as possible, we're now down to automating those updates and are able to complete that within a matter of hours.
How was the initial setup?
We started with EDR and AV and have brought on multiple modules since then. We brought in device control, Falcon Complete, and Overwatch. We have a lot of the prevention and ransomware features enabled and we are eyeballing other features such as AIDR.
What was our ROI?
CrowdStrike Falcon is a cloud-based deployment that is faster to update and has higher efficacy in terms of their detection capabilities.
What's my experience with pricing, setup cost, and licensing?
Don't get sticker shocked by the price. It does a lot for the money; it's a lot of bang for the buck. Build off of lower tiered offerings and as you mature your organization, see what capabilities and features you have to turn on. It makes it very easy to enable new features. Keep that in mind as you're evaluating products.
What other advice do I have?
CrowdStrike Falcon is the industry leader and continues to maintain that leading the charge of all of this. Having these multiple security products in the same tool is helpful because we already have that peace of mind that they are able to do that proper security. Everything is under a single pane of glass, so we're able to take a look and we can scale, or we only have to offer access via roles and responsibilities via CrowdStrike Falcon platform. We can control everything in one spot, which is also very helpful. The downside of having everything on one platform is if it goes down, then everything is down. We want to really be a bit cautious about how we do that. I would rate this product an 8 out of 10 overall.
Unified security telemetry has transformed how my teams detect, hunt, and respond to threats
What is our primary use case?
As an infrastructure organization, we are using CrowdStrike Falcon to enable the tooling for our response, intel, and hunting teams. Currently, we are not using AI within CrowdStrike Falcon platform; our interest is outside the platform where we can access multiple telemetry streams through our SIEM. Although I think there is a use case within the platform itself, we have made the decision as a firm that it is probably better to use that aggregation of telemetry outside of the platform.
What is most valuable?
CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by providing more advanced telemetry, faster response times, and better intelligence to identify anomalies in the ever-evolving cybersecurity landscape.
The value we have seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform allows other teams with expertise in those cross-domains to communicate more effectively and efficiently amongst the response, intel, and hunting teams.
CrowdStrike Falcon has affected the workload and productivity of my security team by making us more effective and efficient in what we are doing. The work has exploded, but it helps us do more.
What needs improvement?
CrowdStrike has been a good partner, but there are times when we need to escalate support faster. With any large security organization, it takes a little bit of time to get to the right place, and if we can speed up the support model, that would always be better.
When we get our issues escalated properly, the right teams from CrowdStrike are on board to help me understand the problem in depth and resolve it quickly, but it takes a while to reach that escalation point.
When we open a case, it often takes some time to get it routed to the experts since there are basic questions that do not directly address what we are asking. If our support teams could take a step back and correctly route our queries faster, it would improve the experience.
For how long have I used the solution?
I have been using CrowdStrike Falcon for approximately six years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as very stable, providing us great telemetry. However, I think that there probably could be more done with networking telemetry.
Other than July 19th of 2024, there has been perfect performance with CrowdStrike Falcon, and that specific date has become notable for everyone.
What do I think about the scalability of the solution?
CrowdStrike Falcon sensor allows us to deploy security at scale with a lightweight sensor, which is one of the reasons why we were interested in CrowdStrike Falcon to begin with.
How are customer service and support?
CrowdStrike has been a good partner, but there are times when we need to escalate support faster. With any large security organization, it takes a little bit of time to get to the right place, and if we can speed up the support model, that would always be better.
When we get our issues escalated properly, the right teams from CrowdStrike are on board to help me understand the problem in depth and resolve it quickly, but it takes a while to reach that escalation point.
When we open a case, it often takes some time to get it routed to the experts since there are basic questions that do not directly address what we are asking. If our support teams could take a step back and correctly route our queries faster, it would improve the experience.
Which solution did I use previously and why did I switch?
Our experience with deploying CrowdStrike Falcon was when we switched from a competitor that was not advanced. We were approved to finish the project in about 18 to 24 months but were asked to complete it within three months, and we significantly reduced our time for deployment, accomplishing it in record time with a small number of resources.
How was the initial setup?
What worked well was our familiarity with the products, but we faced challenges as we were significantly expanding our response team, which was basically non-existent. This allowed us the opportunity to move into hunting and expand that and intel.
What about the implementation team?
My use of CrowdStrike Falcon platform has expanded since the initial deployment, as we have added several modules and now have better correlation across different security domains.
What was our ROI?
We have seen return on investment with CrowdStrike Falcon. We deployed CrowdStrike Falcon Identity module and immediately started seeing detections that turned out to be true positives, which we were able to mitigate and resolve very quickly. We realized that adding modules provides immediate returns on investment.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon pricing, setup costs, and licensing are on the expensive side, but we highly value what you provide. The value proposition yields amazing returns but comes at a cost commensurate with the platform's sophistication.
What other advice do I have?
On a scale from one to ten, I would rate CrowdStrike Falcon as a nine; you are great, but I cannot give a perfect score. My advice for other organizations considering CrowdStrike Falcon is that with the right plan and the right support from CrowdStrike, it is possible to deploy CrowdStrike Falcon endpoint very quickly and efficiently in a way that is safe and reliable. I provided this review with an overall rating of nine out of ten.