What is our primary use case?
I have been using CrowdStrike Falcon AI Detection and Response (AIDR) for two months.
My main use case for CrowdStrike Falcon AI Detection and Response (AIDR) is finding shadow AI in the environment.
I can give a quick specific example of how I have used AIDR to find shadow AI in my environment. We deployed browser extensions as well as now with CrowdStrike sensor. We are now able to monitor everybody who uses GenAI and everything so that we can understand what kind of LLMs that we are using across the board.
What is most valuable?
The best features CrowdStrike Falcon AI Detection and Response (AIDR) offers are that it tells us the token usage and provides us the capability to protect it, such as any PII data, we can mask it, block it. We can do all that within the product.
The most valuable feature for my team has been the PII data because sensitive data leaving our company to the GenAIs is probably not acceptable. It gives us control.
CrowdStrike Falcon AI Detection and Response (AIDR) has positively impacted my organization by providing insight into all types of AI usage, LLMs, and everything under shadow AI, which allows us to protect our data and govern our policy.
It has improved compliance because we can now put controls around our company policy.
What needs improvement?
CrowdStrike Falcon AI Detection and Response (AIDR) can be improved as the Falcon sensor currently only does a read and cannot do any block yet. I hope in the near future they can add that capability. I also hope that a browser extension gets removed and everything is handled through that one agent, the Falcon sensor.
CrowdStrike Falcon AI Detection and Response (AIDR) is still evolving in the market and the AI world, and I do not think any other improvements are needed at this time.
What do I think about the stability of the solution?
CrowdStrike Falcon AI Detection and Response (AIDR) is stable.
What do I think about the scalability of the solution?
CrowdStrike Falcon AI Detection and Response (AIDR) has very good scalability, and I trust that CrowdStrike will support and enhance their product across the board.
How are customer service and support?
The customer support is very good.
I would rate the customer support a perfect ten.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
I have not seen a return on investment yet as we are only two months into it. We still need time to evaluate the whole product in order for ROI to be determined.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is an expensive proposition, but it is something that I definitely look forward to expanding on and seeing the value.
Which other solutions did I evaluate?
Before choosing CrowdStrike Falcon AI Detection and Response (AIDR), I did not evaluate other options.
What other advice do I have?
CrowdStrike Falcon AI Detection and Response (AIDR) is deployed in my organization across public cloud, private cloud, hybrid cloud, and on-premises environments.
We use AWS as our cloud provider.
We purchased CrowdStrike Falcon AI Detection and Response (AIDR) through the AWS Marketplace.
Generative or agentic AI is being used across my organization for day-to-day operations, workflows, and finding quick answers.
The new security challenges created for my organization involve privacy, specifically sensitive data leaving our company and being put into the LLMs.
Falcon AIDR has improved my visibility into the AI applications, models, or agents being used in my environment significantly. We have been surprised by some of the early results that we have seen regarding the kinds of LLMs that we are using.
AIDR has helped me discover unsanctioned or shadow AI usage that I previously could not see, such as finding that there are people using DeepSeek overseas and other LLMs, which gave us insight that we need to stop this.
The types of AI-specific threats or behaviors I am most concerned about include RAG, malicious RAGs, prompt injections, malicious indirect prompt injections, and agents leaving the box or the sandbox.
I do not have any AI-related security risk or incident that AIDR helped me identify or address currently, but we were able to block a lot of sensitive data leaving our company through LLMs and through prompts.
It is valuable to secure AI activity through the same platform I use for endpoint, identity, cloud, or data security.
AIDR has affected my organization's ability to adopt AI while maintaining security and governance by helping us enforce our regulatory compliant policies.
As my organization's use of AI agents grows, I expect AIDR to play a key role in my security strategy by first detecting what kind of agents are out there and then responding according to our policy.
AIDR has offered additional visibility or control measures such as detecting previously unseen shadow AI.
I would advise others looking into using CrowdStrike Falcon AI Detection and Response (AIDR) that CrowdStrike stands behind their product, always looking to enhance, which is something I really appreciate. I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
public cloud, private cloud, hybrid cloud, on-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?