What is our primary use case?
Most of the day-to-day, I look at the telemetry in terms of vulnerability findings within our environment, but I also get a more in-depth look at how to prioritize findings based on criticality.
In terms of prioritizing based on criticality, I often look at the Ex-PERT score within the dashboard, and that allows me to prioritize my time on actual findings that have a big impact and also likelihood of being exploitable in our environment. This really cuts out a lot of the guesswork in terms of where to start when approaching vulnerability management.
In terms of vulnerability management, from a day-to-day perspective, we usually look at custom dashboards and that allows us to prioritize what vulnerabilities to attack first. When we look at things like Ex-PERT rating or the amount of devices and assets that a vulnerability is present on, it allows us to consolidate our resources and attack what matters most.
I would say the vulnerability findings dashboard in CrowdStrike Falcon Exposure Management, especially when they are generated as an executive report from the Kestrel dashboard, are most relevant or useful to communicate risk to different stakeholders.
I would say it has allowed us to have a one-stop shop of reviewing vulnerabilities and then prioritizing them based on that telemetry with CrowdStrike Falcon Exposure Management. Whether it be from the start of seeing it within our environment to engineering a solution to remediate it or mitigate it, and then following up by validating it within the dashboard and ensuring that vulnerability has been removed from the environment.
How has it helped my organization?
There has definitely been quite a drastic change in the security posture of our organization in a positive way with CrowdStrike Falcon
Exposure Management. By being able to utilize the expert management tool, it has really allowed us to focus our team's efforts on remediating vulnerabilities, essentially prioritizing our compliance policies and making sure vulnerabilities are remediated in a timely fashion based on our SLA statuses.
It is hard to say how much faster our team is remediating vulnerabilities, but I will say it definitely is giving us telemetry much quicker than some other tools that were previously used. From a compliance perspective, we are able to meet our targets much quicker when we have the relevant information and a good idea on how to approach these vulnerabilities.
What is most valuable?
There are many features that I really enjoy in CrowdStrike Falcon
Exposure Management, but I appreciate how you can not only build your own dashboards, but adjust filters to show you the information you are looking for. You can filter by assets or CVEs and so on and so forth. This has been really crucial in eliminating some noise and just focusing on the more important matters at hand.
What needs improvement?
Off the top of my head, I cannot really think of many improvements needed in CrowdStrike Falcon Exposure Management. I personally think that the product is great and it really allows me to do my job better.
Automations is the one area where I would like to see even more innovation.
I think at times it does take away from that idea of a single pane of glass, but that is to be expected considering how in-depth the product is and how many offerings it has. Recently I have been exploring Kestrel which has made it much easier to visualize telemetry and data within the environment, and I would say that is one of the reasons why it is not a perfect ten.
For how long have I used the solution?
I have only personally been using CrowdStrike Falcon Exposure Management for about five months now, but it has been a night and day difference when seeing its capabilities in comparison to other competitors.
What do I think about the stability of the solution?
CrowdStrike Falcon Exposure Management is stable.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and support?
CrowdStrike Falcon Exposure Management's customer support is amazing.
Which solution did I use previously and why did I switch?
We previously used Arctic Wolf. I think part of why we switched was we found it was not working the best for our environment and what we were paying for did not seem to match what CrowdStrike offers as a whole.
How was the initial setup?
Unfortunately, I was not part of the integration or initial conversation regarding pricing, setup cost, and licensing, and therefore I do not have any experience with those aspects. From my understanding, it has been a no-brainer and it has been a tool that our company has gladly used over competitors and will continue to use in the future.
What was our ROI?
I cannot definitively say exactly regarding return on investment, but I would say there is less time spent based on the in-depth telemetry that the tool provides us with CrowdStrike Falcon Exposure Management, which really allows us to focus on our jobs in terms of engineering, workflows, or remediating these vulnerabilities.
What other advice do I have?
Currently our team mainly uses the exposure management product, and not so much our IT team. In essence, similar to my previous answers, it does allow us to prioritize much better based on a number of factors, whether it be telemetry or the Ex-PERT rating feature or additional granular filters we can enable on the dashboard.
I think the advantages themselves of having CrowdStrike Falcon Exposure Management capabilities integrated within the Falcon platform are endless. I cannot really think of any disadvantages as this tool has been critical to our team and our approach to vulnerability management.
I would say definitely do your due diligence and see what product might be best for your environment or your company's financials, but I think overall, getting into the product suite, testing out these different dashboards and seeing how they will better impact or improve your day-to-day is probably the best advice I can give. I would rate this product a nine out of ten.