We use CrowdStrike Falcon for intrusion prevention management.
CrowdStrike Falcon Identity Protection
CrowdStrikeExternal reviews
External reviews are not included in the AWS star rating for the product.
Proactively blocks threats, provides insights, and integrates seamlessly
What is our primary use case?
How has it helped my organization?
CrowdStrike Falcon proactively blocks threats and provides us with insights.
CrowdStrike Falcon integration is seamless.
What is most valuable?
The endpoint and server management are the most valuable features of CrowdStrike Falcon.
What needs improvement?
CrowdStrike Falcon's GUI requires improvement for user-friendliness. The console's available options are unclear, making it difficult to understand and extract details. Additionally, correlating information within the console and reports proves challenging.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
CrowdStrike Falcon had some initial stability issues in our environment, likely due to its new integration. However, it appears to have matured and is now functioning reliably.
What do I think about the scalability of the solution?
Being cloud-based, CrowdStrike Falcon offers easy scalability. Adding licenses through procurement increases resources without the need for additional hardware, making scaling straightforward.
How are customer service and support?
While the technical support meets all response time commitments outlined in our Service Level Agreement, some users believe they should strive for a higher standard – a Security Level Target. This means responding to security incidents immediately, not just within SLA windows. Security tools are crucial for our environment's protection, and their use shouldn't be limited by SLA constraints.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
After using Symantec, Trend Micro, McAfee, and VMware Carbon Black, we migrated to CrowdStrike Falcon due to a lack of support from the previous vendors and their shortcomings in comprehensive threat detection.
What other advice do I have?
I would rate CrowdStrike Falcon eight out of ten.
The maintenance required is reasonable.
We have 6,000 endpoints in our environment.
CrowdStrike Falcon shines with its user-friendliness, providing clear insights into the endpoint environment. Proactive features are a major plus, offering actionable items and valuable attack path simulations that empower better decision-making.
The agents are deployed on every workstation, so policy changes can be enforced on all of them
What is our primary use case?
We use Falcon to check the login attempts of the users. We can see who has logged in and when. We can see which workstation is assigned to each user. CrowdStrike helps us enforce policies, such as USB policies and users recycling passwords.
How has it helped my organization?
CrowdStrike is deployed on every workstation, so policy changes can be enforced on all of them. It lowers the manual work on each of the workstations. It has helped us manage device usage in our environment.
What is most valuable?
I like CrowdStrike's policies. The integration is easy to do. I can remember once when Falcon prevented a security breach occurred because someone clicked on a phishing link, and their credential was compromised. We used threat tracking to isolate the device from networks.
For how long have I used the solution?
I have used Falcon for two years.
What do I think about the stability of the solution?
I rate Falcon nine out of 10 for stability.
What do I think about the scalability of the solution?
I rate Falcon eight out of 10 for scalability.
What other advice do I have?
I rate CrowdStrike Falcon nine out of 10.
Integrates well and identifies and responds to threats much faster
What is our primary use case?
Due to compliance requirements, our organization utilizes CrowdStrike Falcon as our Endpoint Detection and Response solution. This decision was particularly driven by the need to address a surge of ransomware attacks within our environment, experiencing between ten and 15 incidents at the time. The implementation of an EDR solution became crucial for effectively responding to these threats.
Our existing system lacked real-time monitoring and visibility, causing detection delays of even several minutes. CrowdStrike addressed this by offering near-instantaneous detection across the entire system. Furthermore, it allows for manual or automated response actions, significantly improving our overall incident response speed.
How has it helped my organization?
Integrating CrowdStrike Falcon with other solutions such as our SIEM was easy.
What is most valuable?
The key aspect of CrowdStrike Falcon is its behavioral detection approach. Unlike traditional signature-based platforms that rely on pre-defined patterns, Falcon analyzes an application's behavior to identify and respond to threats much faster. This makes it lightweight and minimizes impact on system performance. The sandbox feature is also valuable, while it incurs an additional cost, it can be valuable for deeper investigation.
What needs improvement?
The UI is not efficient. We are required to dig down to get more information, jumping from screen to screen.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three and a half years.
What do I think about the stability of the solution?
CrowdStrike Falcon generally ran smoothly with minimal lag.
What do I think about the scalability of the solution?
CrowdStrike Falcon meets our scaling needs. To increase usage we simply add more agents.
How are customer service and support?
Frustrated by CrowdStrike's slow and inconsistent technical support, we ended up having more success researching and resolving the issue ourselves.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
It is the 1st EDR we selected, after testing different solutions.
How was the initial setup?
Leveraging the cloud platform, the initial deployment was straightforward. We simply needed to activate and deploy the agents. While configuration for a seasoned professional only took one to two hours, the entire deployment process typically takes a couple of days.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon can be more expensive than some competitors, and its base price doesn't cover every feature. For instance, adding sandboxing for advanced malware analysis incurs an extra cost.
Which other solutions did I evaluate?
We evaluated CrowdStrike and SentinelOne. However, since we bought the CrowdStrike, we did not move forward with SentinelOne.
CrowdStrike stands out for its superior threat detection speed, lightweight agents that don't impact system performance, and its helpful recommendations for responding to threats. This combination allows us to swiftly stop even unknown threats in their tracks.
What other advice do I have?
I would rate CrowdStrike Falcon eight out of ten.
Two engineers max are required for maintenance.
We have 5,000 CrowdStrike Falcon users within our organization.
CrowdStrike Falcon utilizes a behavioral approach to security, proactively identifying threats based on their actions rather than relying on pre-defined signatures. This allows for faster response times compared to traditional signature-based systems.
Helps protect our data, is stable, and reasonably priced
What is our primary use case?
A popular choice for Data Loss Prevention is CrowdStrike Falcon. This is the primary function our clients leverage it for, as it offers industry-leading DLP capabilities.
How has it helped my organization?
CrowdStrike Falcon has helped our customers secure their confidential data.
What is most valuable?
The DLP is the most valuable feature of CrowdStrike Falcon. Additionally, the scanning is good and the deployment is easy.
What needs improvement?
The console is not user-friendly or visually appealing and has room for improvement. I would like a single pane of glass dashboard.
For how long have I used the solution?
I have been an integrator of CrowdStrike Falcon for one day.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
Which solution did I use previously and why did I switch?
I have also worked with Trend Micro and Panda.
How was the initial setup?
The initial deployment is straightforward. I would rate the ease of setup nine out of ten.
Two people are required for the deployment.
I need to upgrade the software occasionally but it doesn't require continuous maintenance.
While the specific deployment time varies depending on each client's individual environment, on average the process can be completed in a couple of days.
What was our ROI?
I only deploy the solution for clients, I don't calculate their ROI.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon's pricing is reasonable. We can customize features and that affects the pricing.
We pay 40,000 dirhams per 100 users.
What other advice do I have?
I would rate CrowdStrike Falcon nine out of ten.
Our clientele ranges from small to enterprise-level businesses.
I recommend CrowdStrike Falcon as it provides all the features of an EDR.
Easy to deploy and manage with many helpful features
What is our primary use case?
We use the product for cloud security. We use it for prevention, to watch for gaps in security. We work with customers seeking prevention for advanced apps.
How has it helped my organization?
Sometimes a customer has multiple solutions that come at a higher cost. They have to pay for all of these other security features. With CrowdStrike, customers get one agent for all system operations. It offers more security for remote work and clients gain access to the latest protections.
What is most valuable?
The solution offers good features. The prevention and device control are useful. It offers helpful firewall management and identity protection.
They've reduced the complexity and provide better security outcomes. Customers tend to prefer CrowdStrike.
It's easy to deploy and manage.
What needs improvement?
The solution isn't known in my market. The brand isn't as recognizable. Their shortcomings are more on the marketing side. Everyone knows Microsoft Defender. Customers need to hear more about CrowdStrike and all the advantages and features on offer.
For how long have I used the solution?
We've used the solution for three to four months.
What do I think about the stability of the solution?
I haven't had any issues with bugs or glitches. I haven't had a problem with stability so far.
What do I think about the scalability of the solution?
The capability to scale so far has been good.
How are customer service and support?
Technical support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I'm also familiar with Microsoft Defender. However, Defender works best with Microsoft and not necessarily other legacy applications. With CrowdStrike, you can secure all system operations and versions. It's easier to deploy and operate.
How was the initial setup?
The deployment is seamless and users get immediate protection. It's lightweight. There's one agent deployed to endpoints in minutes. The product offers consistent coverage. There's no complex integrations and it doesn't need fine-tuning. In comparison, Defender can be more complex.
CrowdStrike can be deployed on any operating system, not just Microsoft.
There isn't really maintenance, it's set and forget. The agent updates automatically and receives continuous security updates, enabling immediate enforcement across endpoints.
What was our ROI?
The solution is well worth the cost.
What's my experience with pricing, setup cost, and licensing?
The costs are predictable. There are no surprises.
In Chile, there are not a lot of CrowdStrike partners of the managed service; therefore, it's a little more expensive than Microsoft, as there are so many more managed partners for Microsoft. That said, if you look at the total cost of ownership, CrowStrike is better than Microsoft.
What other advice do I have?
We're a reseller. We're still new to CrowdStrike.
I'd rate the solution eight out of ten. The cost is good and they offer better tech support. Also, the protection is wonderful.
Is user-friendly, maintenance-free, and stable
What is our primary use case?
We are a CrowdStrike Falcon distributor that helps clients monitor their environments for malicious activity coming from the internet.
How has it helped my organization?
Both users and administrators find CrowdStrike Falcon easy to use.
What is most valuable?
I like the vulnerability assessment and proactive hunting features of CrowdStrike Falcon.
What needs improvement?
To simplify the budgeting process for our clients, CrowdStrike should consider offering bundled packages that include essential features. The separate model pricing structure can make it challenging for clients to gain approval for their security needs.
CrowdStrike could consider regional pricing models to better reflect the economic realities of different markets.
For how long have I used the solution?
I have been using CrowdStrike Falcon for 2 years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable.
Which solution did I use previously and why did I switch?
We have also used Sophos. CrowdStrike Falcon is a better solution but Sophos is more affordable.
How was the initial setup?
The deployment is straightforward.
What's my experience with pricing, setup cost, and licensing?
The cost of CrowdStrike Falcon in Latin America seems high relative to the economic conditions in the region.
What other advice do I have?
I would rate CrowdStrike Falcon 9 out of 10.
To realize the benefits of CrowdStrike Falcon, it's recommended to conduct a proof of concept first. You should then start to see the advantages within a few months.
No maintenance is required from our end.
To ensure the successful implementation of CrowdStrike Falcon, it's essential to have a complete network map and inventory of all resources and devices.
Excels at identifying suspicious activity, helps mitigate potential security breaches, and is easy to use
What is our primary use case?
We use CrowdStrike Falcon to investigate security detections for malicious activities in our environment.
CrowdStrike utilizes machine learning algorithms and detection rules to generate alerts for suspicious activity within our environment. We then investigate these detections individually, analyzing the details of each event.
In addition to automated detection, CrowdStrike allows for custom queries. For instance, if we need to investigate a specific host, we can leverage a cloud security language to examine its activity. Similarly, we can use CrowdStrike to search for activity related to particular users or hosts.
How has it helped my organization?
CrowdStrike Falcon provides significant additional value. It excels at identifying suspicious activity the moment an application appears in the environment, immediately bringing these incidents to the attention of our response team. Upon receiving an alert, our team can investigate and take appropriate action if anything malicious is found. In essence, CrowdStrike Falcon acts as a strong barrier against attackers.
In the past 3 years, we have encountered many scenarios where CrowdStrike Falcon has helped mitigate potential security breaches.
What is most valuable?
The detection and response console is the most valuable feature.
What needs improvement?
We encounter occasional issues, such as when disabling network access for a host that uses CrowdStrike. In these cases, the access disable process can be quite slow.
I'm using CrowdStrike Query Language, and I've noticed an issue with event backups. Searches exceeding a certain event threshold aren't capturing all results. For instance, if I run a search that returns 10,000 events in a single day, only 2,000 events are backed up. This limitation with CrowdStrike Query Language needs to be investigated.
For how long have I used the solution?
I have been using CrowdStrike Falcon for over 3 years.
What do I think about the stability of the solution?
CrowdStrike Falcon is generally stable, although event searches may occasionally experience slow performance.
What do I think about the scalability of the solution?
CrowdStrike Falcon's scalability is dependent on the license acquired.
How are customer service and support?
The technical support live chat can experience long wait times. Submitting a ticket may result in a quicker response.
Which solution did I use previously and why did I switch?
The company was using Carbon Black before I joined. When I came on board, they decided to switch to CrowdStrike.
What other advice do I have?
I would rate CrowdStrike Falcon 9 out of 10.
CrowdStrike Falcon is deployed across multiple end-user systems and locations.
I recommend CrowdStrike Falcon. It's a wonderful security platform that's easy to use and requires minimal effort to maintain.
Blocks suspicious activities and protects endpoints and servers from attacks
What is our primary use case?
A lot of customers face ransomware and malware attacks. The solution helps protect endpoints and servers from ransomware and malware attacks.
How has it helped my organization?
The solution has multiple layers of security, including web security. We can monitor endpoints, conduct root cause analysis, and find geolocations. If the tool finds any suspicious activity, it blocks and remediates it.
What is most valuable?
The solution makes our security operations easier. After an incident, we get complete reports and insights. The product provides good monitoring features. The product also has teams that help customers find suspicious activities. The team calls and asks us to check the updates and remediate issues. If the system can remediate it, the team does it through the system. The detection and response are in real-time. There are no security breaches. Resolving issues doesn’t take much time.
What needs improvement?
The tool is more expensive than other products in the market.
For how long have I used the solution?
I have been using the solution for more than 3 years.
What do I think about the stability of the solution?
I did not have any stability issues.
What do I think about the scalability of the solution?
It is easy to scale up. We just need to add the licenses. The product is suitable for small, medium, and large businesses. We must buy a minimum of 50 licenses.
How are customer service and support?
The support is excellent. We rarely need support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is pretty simple and clear. The time taken for deployment depends on the endpoints. It's a cloud solution. We can use Active Directory or the group policies to deploy it.
What was our ROI?
The product has a lot of use cases. There are companies that need to run their operations 24/7. It will be a big challenge if their server or infrastructure goes down. They cannot afford downtime. They need to choose the right solution for their needs.
What's my experience with pricing, setup cost, and licensing?
The price depends on the kind of service we need. If we need excellent service, we must pay a reasonable price. We can choose any pricing model if we do not want excellent service. The product is excellent. We need to pay a premium price for the tool.
Which other solutions did I evaluate?
Microsoft Defender Threat Intelligence, IBM, and Cisco are some competitors. CrowdStrike entered the market with a USP to protect endpoint servers. It has a different approach. Malwarebytes has a similar setup. I prefer CrowdStrike, though.
What other advice do I have?
I will recommend the tool to others depending on their budget. If customers have a good budget and need a premium product, they can choose CrowdStrike. No product is perfect. Overall, I rate the tool an 8 out of 10.
Is user-friendly, improves performance, and protects our end users
What is our primary use case?
We use CrowdStrike Falcon for endpoint protection and cybersecurity.
We implemented CrowdStrike Falcon to ensure our systems were secure and there were no infiltrations to our system.
We deploy CrowdStrike Falcon across a variety of platforms, including cloud and edge environments. We ensure it meets rigorous security standards, is properly certified, and adheres to our data management policy.
How has it helped my organization?
We integrated CrowdStrike Falcon with our end-user systems and servers.
Since implementing CrowdStrike Falcon, we haven't experienced any serious threats, and we've seen a decrease in phishing and ransomware emails. This suggests it's been very effective in mitigating those threats.
The UI is easy to use and comprehensive.
CrowdStrike Falcon's performance has improved our user productivity.
What is most valuable?
CrowdStrike Falcon offers a comprehensive dashboard that is highly effective in protecting against and blocking external infiltration attempts.
What needs improvement?
The pricing structure should allow for some flexibility.
For how long have I used the solution?
I have been using CrowdStrike Falcon for almost 3 years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon 8 out of 10.
How are customer service and support?
The technical support is good. We have not had any issues with them.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment was straightforward. The deployment doesn't take more than one day. Those involved with the deployment are system engineers, IT analysts, and software engineers.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The price is fixed with no room for negotiation.
What other advice do I have?
I would rate CrowdStrike Falcon 8 out of 10.
We have deployed CrowdStrike Falcon in multiple departments, locations, and satellite offices.
CrowdStrike Falcon doesn't require maintenance from our end other than the updates.
I recommend CrowdStrike Falcon to others.
Falcon Identity protection review
as it uses Zero Trust security for risk analytics
it has so many features which make this easy first one GUI