We use CrowdStrike Falcon Cloud Security for our client's endpoint security in the manufacturing, banking, and IT industries.
CrowdStrike Falcon Cloud Security
CrowdStrikeExternal reviews
External reviews are not included in the AWS star rating for the product.
Effective EDR for Large Infrastructure
Good experience
Crowd strike best could security tool
Boasts a wide range of features while remaining exceptionally lightweight and improves our security posture
What is our primary use case?
How has it helped my organization?
CrowdStrike Falcon Cloud Security has helped improve our security operations. When facing signatureless attacks, CrowdStrike's EDR solution, which also incorporates SOAR capabilities, can prevent attacks in real-time. The SOAR engine detects malicious activity and suspicious file or transaction behavior on the network. Based on this detection, CrowdStrike proactively prevents these attacks. Additionally, features like Spotlight, a valuable tool for vulnerability management, provide remediation actions. Spotlight identifies the specific patches or knowledge base (KB) articles needed to mitigate these types of attacks.
To experience the full value of CrowdStrike Falcon Cloud Security, we recommend deploying the Falcon Agent on at least 500 systems and monitoring their activity for 15 days to a month. This deployment will provide comprehensive visibility into whether CrowdStrike can detect suspicious activity that might be missed by other third-party antivirus solutions and firewalls.
What is most valuable?
The CrowdStrike platform boasts a wide range of features while remaining exceptionally lightweight. Compared to traditional antivirus software, its impact on system resources is minimal. In terms of specific figures, CPU utilization typically ranges from one to two percent, while memory usage falls between 12 and 15 MB. This translates to a very small footprint on our system.
CrowdStrike utilizes signatureless technology, eliminating the need for regular signature updates on endpoint systems. It provides protection based on processes and activity behavior observed on the endpoint. The platform collects raw telemetry data from the endpoint and leverages it to proactively offer prevention and EDR capabilities. This approach offers multiple benefits, including eliminating the need for manual scans and providing broader protection against both known and unknown threats.
What needs improvement?
Due to the time zone difference, we in India experience delays in accessing immediate support for L2 and production-related issues until engineers become available in their respective time zones.
The CrowdStrike dashboard currently lacks a username field. This creates a gap for customers who manage multiple systems under a single username, making it difficult to identify individual systems based on username alone. Adding a dedicated username column to the dashboard would greatly improve its functionality in this regard.
For how long have I used the solution?
I have been using CrowdStrike Falcon Cloud Security for five years.
What do I think about the stability of the solution?
I would rate the stability of CrowdStrike Falcon Cloud Security ten out of ten. We have not received any complaints from our multiple customers related to stability.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon Cloud Security ten out of ten.
How are customer service and support?
While there may be delays due to time zones, the technical support itself is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In collaboration with a security partner, we work with several other OEMs, including Symantec, McAfee, and Trend Micro.
How was the initial setup?
The initial deployment is straightforward.
We utilize several third-party deployment tools for our installations, including Microsoft GPO, SCCM, and solutions offered by other market OEMs. These tools allow us to deploy the CrowdStrike Falcon Agent across all endpoints. Before deployment, we confirm the absence of any existing antivirus software. If the customer is already employing legacy antivirus solutions, we typically configure Falcon prevention policies to operate in "monitor mode." This means Falcon will monitor for threats without actively interfering with the existing antivirus. We refrain from uninstalling the legacy software until it becomes necessary. Once uninstalled, the Falcon prevention mode is switched to "aggressive mode," enabling it to function as the primary antivirus on the endpoint. This approach ensures a smooth transition while safeguarding endpoint security.
What other advice do I have?
I would rate CrowdStrike Falcon Cloud Security ten out of ten.
CrowdStrike Falcon Cloud Security is deployed in multiple locations and departments.
No maintenance is required.
CrowdStrike Falcon Cloud Security offers flexible integration with various third-party security products, including SIEM and proxy solutions. This capability significantly enhances our organization's overall security posture by facilitating seamless integration with existing tools via its robust API functionality.
Worth the money and provides a lot of control and visibility
What is our primary use case?
We use it for EDR as well as cloud security posture management. We also use file integrity and vulnerability management.
How has it helped my organization?
By implementing CrowdStrike Falcon Cloud Security, we wanted a 360-degree view of the security landscape of our enterprise. We wanted the complete view in one single dashboard, and our requirement was almost met with this solution.
We gained a lot of control and visibility into our cloud infrastructure using CrowdStrike Falcon Cloud Security. Within 30 days of deployment, we started seeing its value.
What is most valuable?
Cloud security posture management (CSPM) is most valuable.
What needs improvement?
There should be cloud storage scanning. We would like to have cloud storage vulnerability and threat management on any cloud storage.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
It is stable. I would rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
It is scalable. I would rate it a nine out of ten for scalability.
In terms of our environment, we have multiple sites, multiple delivery centers, and multiple clouds. CrowdStrike Falcon Cloud Security is covering all aspects.
Which solution did I use previously and why did I switch?
We had McAfee, and we replaced McAfee with CrowdStrike because of the features such as EDR. We got multiple security features from a single vendor.
How was the initial setup?
It is deployed on the public cloud. We use AWS and Azure.
Its initial setup was straightforward. Its implementation took about 15 days.
We did the agent installation on a test bed or less critical devices. We monitored the performance, and we monitored the data coming into CrowdStrike from those deployments. Once we were satisfied, we followed a phased approach. Phase by phase, we covered all our resources under the CrowdStrike umbrella.
What about the implementation team?
We implemented it in-house. We had two senior engineers involved.
In terms of maintenance, it does not require any maintenance from our side.
What was our ROI?
It is worth the money.
What's my experience with pricing, setup cost, and licensing?
Its price is moderate.
What other advice do I have?
I would recommend trying its features, evaluating it, and seeing if it fits your requirements. Only then proceed with the purchase.
I would rate CrowdStrike Falcon Cloud Security a ten out of ten. It is good.