Provides effective real-time threat detection with potential for cost optimization
What is our primary use case?
We are protecting our endpoints, workstations, servers, and cloud workloads. This includes effective use of antivirus and detection and response capabilities.
I am working at Arab Open University, and we are using CrowdStrike Falcon as our security product.
What is most valuable?
The most beneficial part is the active response capability of the product. Being an EDR solution, it helps us identify attacks in real-time. The product runs in the background 24/7. The most interesting aspect is the behavior analysis functionality, which analyzes the behavior of any suspicious activity.
It identifies threats efficiently due to its built-in intelligence and AI capabilities, which has been extremely helpful for our organization.
What needs improvement?
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product.
We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
For how long have I used the solution?
We have been using the solution for almost four years.
What was my experience with deployment of the solution?
It is a straightforward plug-and-play deployment.
What do I think about the stability of the solution?
Sometimes there are minor glitches, approximately 1% of the time. The biggest issue occurred when every computer worldwide experienced a blue screen. However, they solved the problems and introduced a new feature for channel updates. This has been much more beneficial, and while human errors can occur in any product, we cannot solely blame CrowdStrike Falcon for such incidents.
How are customer service and support?
The customer service is good and efficient in terms of responding. They could improve by initiating calls for high-priority cases instead of just opening tickets. When we open a support ticket, they should call to discuss what happened and listen to our concerns.
How would you rate customer service and support?
How was the initial setup?
The setup is straightforward, and most of our integration is within the package. However, for the integration part, we need to purchase additional modules from CrowdStrike Falcon. If this functionality was included as a free standalone feature within the built-in solution, it would be more market competitive. Competitors such as SentinelOne and Microsoft Defender provide this functionality out of the box without additional charges.
What was our ROI?
We have not calculated the ROI extensively, as we typically only calculate it when there is dissatisfaction. On a scale of one to ten, the ROI would be five, which translates to approximately 60%.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit expensive.
Which other solutions did I evaluate?
We are using
Darktrace as an email security solution, not as an EDR.
What other advice do I have?
I would rate CrowdStrike Falcon a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Very good product
What do you like best about the product?
Falcon Identity Protection is a comprehensive identity protection service that offers several features and benefits, including:
1. Identity Monitoring: It continuously monitors various data sources to detect any signs of identity theft or fraud, such as unauthorized use of your personal information.
2. Credit Monitoring: It keeps an eye on your credit reports and alerts you to any significant changes, helping you catch potential issues early.
3. Dark Web Monitoring: Falcon Identity Protection scans the dark web for your personal information, helping you stay informed if your data appears in suspicious places.
4. Identity Theft Resolution: If you become a victim of identity theft, the service provides assistance and support to help you resolve the situation and restore your identity.
5. Insurance Coverage: Some identity protection services offer insurance coverage to help cover expenses related to identity theft, such as legal fees or lost wages.
6. Customer Support: Many services have dedicated customer support teams to assist you with any questions or concerns you may have.
Please note that the specific features and benefits may vary depending on the identity protection service provider. It's essential to research and choose a service that best suits your needs and preferences.
What do you dislike about the product?
While Falcon Identity Protection and similar services offer valuable benefits, they also have some potential disadvantages:
1. Cost: These services typically come with a monthly or annual fee, which can add up over time.
2. Limited Coverage: Identity protection services can't guarantee complete protection against all forms of identity theft or fraud. They may focus on specific areas like credit monitoring or dark web scans, leaving some vulnerabilities unaddressed.
3. False Alarms: Sometimes, these services can generate false alerts, causing unnecessary concern or inconvenience.
4. Data Privacy: You need to share personal information with the service, which raises concerns about data privacy and security. Ensure you trust the provider and understand their data handling practices.
5. DIY Alternatives: Some of the features offered by identity protection services, like monitoring your credit reports, can be done independently for free. It may be more cost-effective to manage these tasks yourself.
6. No Preventative Measures: These services can help you detect identity theft, but they don't proactively prevent it.
7. Complexity: Depending on the service, there can be a learning curve in understanding how to use all of its features effectively.
Before choosing an identity protection service, carefully evaluate the pros and cons to determine if it's the right solution for your needs. Additionally, consider alternatives, such as monitoring your credit reports independently and implementing strong security practices to protect your identity.
What problems is the product solving and how is that benefiting you?
Falcon Identity Protection, like other identity protection services, aims to address several common problems related to identity theft and fraud. These problems include:
1. **Identity Theft Detection**: Falcon Identity Protection helps detect signs of identity theft early, such as unauthorized use of your personal information. This can prevent more significant financial and personal losses.
2. **Credit Monitoring**: By monitoring your credit reports, it can alert you to any suspicious activity or unauthorized credit inquiries, allowing you to take action promptly.
3. **Dark Web Monitoring**: The service scans the dark web for your personal information, which can help you become aware if your data is being traded or used illegally.
4. **Resolution Assistance**: In the unfortunate event of identity theft, the service offers support in resolving the issues, which can be a complex and time-consuming process on your own.
5. **Peace of Mind**: Knowing that your identity is being actively monitored can provide peace of mind, reducing stress related to identity theft concerns.
6. **Insurance Coverage**: Some identity protection services offer insurance coverage to help cover the costs associated with identity theft, providing financial protection.
The benefits of Falcon Identity Protection and similar services are that they provide a layer of security and support in an increasingly digital world where identity theft is a prevalent concern. They can save you time and effort in monitoring your personal information and provide guidance in case of a security breach. However, it's essential to weigh these benefits against the cost and potential limitations of the service to determine if it's a worthwhile investment for your specific situation.
Falcon Identity Protection - Good for End user behaviour analytics
What do you like best about the product?
1. It gives visibility into end-user behavior analytics like privileged users, risky events, and stale endpoints.
2. Good threat hunting of user authentication events.
3. Offers good connectivity to Windows domain controllers with a single-agent deployment.
What do you dislike about the product?
It generates too many informational alerts and events which are actually genuine in nature.
What problems is the product solving and how is that benefiting you?
It solves the problem of logging user behavior events and generates analytics since most of the attacks originate from end-user authentication anomalies.
A review about left out identity management tool
What do you like best about the product?
Falcon identity protection previously known as preemt is a identity protection tool, it has a use friendly dashboard , and the most useful feature is advance threat hunting using different query to find threat regarding all identity
What do you dislike about the product?
Sometimes there are many redundant data and in appropriate data is shown in the dashboard because of syncing issue . If new updates version are coming then I believe this issue can easily be resolved
What problems is the product solving and how is that benefiting you?
Its advance threat hunting feature is really useful to find threats in your organisation