What is our primary use case?
I use the capability of Charlotte AI that allows me to analyze logs most often. I give it a bunch of logs, and Charlotte AI is able to compare the logs from my network team into something that makes sense. It tells me which device is impacted by that log and which device is not, and which device I should take action on. Overall, it makes working with the network team seamless because now I don't have to second-guess what they see and what I see in my endpoints. It all checks out.
Charlotte AI has changed the way my security team investigates and responds to threats by making us faster than a speeding bullet. Instead of going through pages and pages of logs trying to figure out what is what, we can just upload it, say go look at our setup, and see what you can find out.
Charlotte AI's natural language capabilities are extremely useful for analysts with different levels of security expertise. Even if you are a beginner, you cannot go wrong in uploading the log and learning about what it says about that product. I am actually learning while using the product. Every day, I am not going to upload everything because the next time I will know, for example, I already know what this does. Let me upload something different. I keep learning as I keep using it.
What is most valuable?
Charlotte AI helps my analysts understand and prioritize security findings very much. Once we use Charlotte AI for log purposes, if we find out that a device has an outdated agent, we decide to go ahead and update that agent. If the agent is not up to date, everything else will be wonky. So we update the agent, and then the analyst is able to do the task before relying on Charlotte AI to just provide a false positive potentially.
Charlotte AI fits into my team's existing CrowdStrike Falcon workflows extremely well. It is a member of one of our teams. We count on it to do well for us.
Charlotte AI has affected analyst productivity and my team's ability to handle a large volume of security activity positively. Every time we use it, we feel a co-worker. We rely on it to give us some metrics that we couldn't otherwise get, an explanation, and a summary to our network team. That way, they understand why our response is the way it is because we now have something we can trust. We are not comparing a regular third-party Copilot or AI to tell us that. We are not uploading our data anywhere; it is all in-house.
I have 100% confidence in the responses and recommendations that Charlotte AI provides. It can see the endpoints, the agent, and everything that is going on. If we don't have confidence in that, there is nothing else we are going to have confidence in. So we have very great confidence.
I validate Charlotte AI's responses and recommendations by checking them against what I tell it to give me in the summary. I can go into a couple of endpoints to make sure that the reading is the same, that the device has been online or what it says has been online. Overall, we can compare that result. We also have other competitors, in this case, Defender, and basically, I can say, Charlotte AI says this; what about this Defender? Defender is, I see what Charlotte AI says is right. This is true; this is what we got going on.
There are particular security use cases where Charlotte AI has been especially valuable for me. Pretty much anytime we get an incident with unknown things going on or unknown traffic patterns, we rely on Charlotte AI first to get the log from our network people, to provide the information, and then we upload that log. Then we are going to get a transcription of what that says, so we can make a summary, do some more research, and then send out that nice email to our corporate people, so they know what we find, what we think is going to be happening, and what we are going to need to do to improve security in the future.
Charlotte AI has positively affected the experience and learning curve for less-experienced members of my security team. The ability to get an explanation of why a certain thing happened is invaluable because when something happens, I don't want to guess at it, especially in security. I want to know what that means, why it happened, who scanned, and whether it is a software backup or just a random scan. Is there an anomaly? Charlotte AI tells us, this has been going on. It is a periodic thing that occurs every night when there is a backup running. So that means we are no longer guessing; we are now also understanding something we didn't even know was happening every day. We are learning from it.
What needs improvement?
Charlotte AI could be improved by allowing us to upload a nice report from PowerPoint or Excel, just as other AI models do. The details they give us are so good, but right now it is all text-based, and I have to copy it and format it. I would like it to be formatted into an executive-level review or initial review, so we don't have to spend additional time formatting it. It would just be easier to present the output and what we found out without spending another hour improving how the report looks because it is not clean right now when it outputs it.
For how long have I used the solution?
I have been using Charlotte AI about since it was released.
What do I think about the stability of the solution?
I assess the stability and reliability of Charlotte AI as very reliable. We could probably use more understanding of how many tokens we are using so we know how much we have remaining, ensuring we are not going crazy on it and then limiting all our token usage to one incident.
I have not experienced any downtime, crashes, or performance issues with Charlotte AI.
What do I think about the scalability of the solution?
Charlotte AI scales with the growing needs of my organization extremely well. We are in education, and we get a lot of unusual traffic patterns from students. So, this thing is basically able to analyze, learn, and predict what is normal. I think it is a perfect companion.
How are customer service and support?
I evaluate customer service and technical support as easy. We have Falcon Complete, so we just call them, and they help us out, which makes it easy to do what we need to do.
Which solution did I use previously and why did I switch?
Prior to adopting Charlotte AI, I was using another solution to address similar needs. We were putting some things to Copilot. The difference is that Copilot cannot see our endpoints. So it doesn't know. It tells us what it thinks happened, but it is never 100% confident because it is just guessing. It doesn't know what that endpoint's regular pattern is. So it just tells us we think this is good, but I never know because it is based on general industry data, but it doesn't consider what is normal or abnormal for our environment.
How was the initial setup?
I would describe my experience deploying Charlotte AI as easy. It is already there; it is just more about prompting really. If I prompt it correctly, it does what it needs to do, especially if my prompt and the log I am trying to parse are effective. So it does all the work for us.
What was our ROI?
I have seen a return on investment with Charlotte AI, especially when we have a limited team. Every time those logs are disproved in terms of what is an incident and what is not, it shows us that it is worth having a tool that can overlook both sides. Maybe the network team has a legitimate concern for something. We put this tool there, and it is the final judge to confirm whether this is a true incident or not because the server is fine.
Which other solutions did I evaluate?
The other solutions I considered before selecting Charlotte AI were minimal. I am one of the people that didn't even consider it because I knew if it doesn't integrate with everything, it is not going to be good. That is basically how it goes. Even if I use Cloud or Copilot, they cannot see what Charlotte AI can see because it can see the endpoint data. So because of that, it is an easy choice to choose whatever can see the data.
In my evaluation process comparing these options, the positive aspects that stood out are when something can see everything, it gives me faster results. I am not waiting for it to load because it can see the devices and also provide close to accurate information as possible, given I have everything up to date. The negative aspects, however, are that sometimes the reporting is not as great as I want it to be. But if that can improve, then it is all positive.
What other advice do I have?
The advice I would give to other organizations considering Charlotte AI is that they need to be open-minded. They must be able to use it efficiently, input logs, and try different methods. Every organization is different, but the biggest thing is you have to be able to figure out what works for you. So I would say an organization needs to think of it as a companion rather than a threat to their job, using it to help them do their job faster and better.
What worked for us is that pretty much everything we have tried so far works well. I am not saying that we will not face challenges in the future, but right now, initially, we haven't had anything that did not work well.
I have not expanded usage yet, but I want to learn more about the credits—how we can get more and what we are going to get charged. That is the only uncertainty we have because once we know that, we can expand its use more on a daily basis without the fear of running out of credits.
I would rate this review a 9 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other