We are using CrowdStrike Falcon Complete for fileless attacks, ransomware, and zero-day attacks.
IT Operations at AkshayaPatra
Light on resources, minimal maintenance, and scales well
Pros and Cons
- "The most valuable feature of CrowdStrike Falcon Complete is the lightweight design, easily manageable portal, and minimal IT maintenance required."
- "If you use this solution your environment will be safe."
- "CrowdStrike Falcon Complete could improve by having advanced features, such as SOC, and HDR. There would have been a lot of processes involved."
What is our primary use case?
What is most valuable?
The most valuable feature of CrowdStrike Falcon Complete is the lightweight design, easily manageable portal, and minimal IT maintenance required.
What needs improvement?
CrowdStrike Falcon Complete could improve by having advanced features, such as SOC, and HDR. There would have been a lot of processes involved.
For how long have I used the solution?
I have been using CrowdStrike Falcon Complete for approximately three years.
Buyer's Guide
CrowdStrike Falcon Complete MDR
August 2026
Learn what your peers think about CrowdStrike Falcon Complete MDR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,564 professionals have used our research since 2012.
What do I think about the stability of the solution?
CrowdStrike Falcon Complete is a stable solution.
What do I think about the scalability of the solution?
The scalability of rowdStrike Falcon Complete is good.
We have approximately 500 computers using the solution. We have approximately 1,200 people using the solution.
How are customer service and support?
I have not contacted the technical support from CrowdStrike Falcon Complete.
How was the initial setup?
The initial setup of CrowdStrike Falcon Complete is easy. The time it took for the deployment was approximate one week for 500 computers.
What about the implementation team?
We did the deployment of CrowdStrike Falcon Complete in-house.
What's my experience with pricing, setup cost, and licensing?
There is a license needed to use the solution. The price of the solution is fair.
Which other solutions did I evaluate?
We evaluated McAfee and Symantec before choosing CrowdStrike Falcon Complete.
Symantec is complicated and it did not have as many features when compared to CrowdStrike Falcon Complete. McAfee is also a very complicated solution.
What other advice do I have?
If you use this solution your environment will be safe.
I rate CrowdStrike Falcon Complete an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at a computer software company with 10,001+ employees
Intuitive capabilities, scalable, and beneficial cloud implementation
Pros and Cons
- "The most valuable features of CrowdStrike Falcon Complete are the modern and intuitive capabilities, and because it is cloud-based it is much easier to adopt and roll out to the environment."
- "The support is good from CrowdStrike Falcon Complete. We call them and we have a response immediately. They could improve by increasing their knowledge."
What is most valuable?
The most valuable features of CrowdStrike Falcon Complete are the modern and intuitive capabilities, and because it is cloud-based it is much easier to adopt and roll out to the environment.
For how long have I used the solution?
I have been using CrowdStrike Falcon Complete for approximately one year.
What do I think about the stability of the solution?
CrowdStrike Falcon Complete is a stable solution.
What do I think about the scalability of the solution?
The scalability of CrowdStrike Falcon Complete is good.
We have approximately 1,000 users using this solution in my company. We have plans to increase our usage.
How are customer service and support?
The support is good from CrowdStrike Falcon Complete. We call them and we have a response immediately. They could improve by increasing their knowledge.
I rate the support from CrowdStrike Falcon Complete a four out of five.
Which solution did I use previously and why did I switch?
Previously used Symantec Endpoint Protection. We switched to CrowdStrike Falcon Complete because we had a lot of real threats that passed through the antivirus and at the same time, we were not getting the right technical support from Symantec.
How was the initial setup?
The setup of CrowdStrike Falcon Complete was easy. We have not yet completed the full implementation, it is still ongoing and we hope to finish it in two to three months.
We had some initial proof of concept and did it on test PCs and test servers. We are moving it into production. We are doing small steps every week.
What about the implementation team?
We had support from CrowdStrike Falcon Complete available during the implementation.
What other advice do I have?
I rate CrowdStrike Falcon Complete an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
CrowdStrike Falcon Complete MDR
August 2026
Learn what your peers think about CrowdStrike Falcon Complete MDR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,564 professionals have used our research since 2012.
Security, Risk and Compliance Officer at a tech services company with 51-200 employees
Fully managed, super stable, and incredibly powerful from a compliance point of view
Pros and Cons
- "The most valuable feature of Falcon Complete is that it is a full security operations center (SOC) as well as a SIEM solution, and it is fully managed. Their security teams are working 24/7 and analyzing everything happening on all endpoints. They also take care of the instant response, which includes disconnecting endpoints, taking over the endpoints and fixing them, and ransomware protection. All of these things are most valuable because it is very difficult to get all the resources in-house to do all of that yourself. So, if you can leverage the experience of a global corporation with the best reputation in the market, and it is fully managed, that's the best."
- "The most valuable feature of Falcon Complete is that it is a full security operations center (SOC) as well as a SIEM solution, and it is fully managed."
- "It would be good if they fleshed it out a bit more, possibly with additional areas such as security awareness training. They could build that in. They're leveraging the same endpoint base that they have the security software on, but then they could offer a centralized portal or hub whereby someone like me could leverage it to track and put out security awareness training for people on all the common topics. I could have a centralized hub for everyone's results from that training and for the evidence that training occurred. It would be relatively straightforward, but it would add a lot for people in the compliance area. It would be a great expansion."
- "Occasionally, navigating it to try to find what you want can be challenging because there is so much information there."
What is most valuable?
The most valuable feature of Falcon Complete is that it is a full security operations center (SOC) as well as a SIEM solution, and it is fully managed. Their security teams are working 24/7 and analyzing everything happening on all endpoints. They also take care of the instant response, which includes disconnecting endpoints, taking over the endpoints and fixing them, and ransomware protection. All of these things are most valuable because it is very difficult to get all the resources in-house to do all of that yourself. So, if you can leverage the experience of a global corporation with the best reputation in the market, and it is fully managed, that's the best.
They're incredibly transparent. They give full access to all the information and dashboards that they work off themselves. So, you can look in and investigate any incident you wish. It is incredibly powerful from a compliance point of view because you have evidence that all of this is happening, and you're doing it correctly, and you take it seriously.
What needs improvement?
It is already wonderful. The dashboards they have are great, but they can always improve it in terms of general interfaces and searching and presenting the information. Occasionally, navigating it to try to find what you want can be challenging because there is so much information there. It is so rich, and it has everything you could ever want. The challenge with anything like that, and any website, is how to build the user journey so that it is user-friendly, but at the same time, it is incredibly dense with information. It is difficult to achieve that balance between these things. They've done a wonderful job, but everything can be improved. So, it could be even better. If I was to focus on one thing, that's what I'd tell them to focus on. The same is with Azure. There is just so much functionality there. How can you make it easy when it is just so vast? It is a tough one.
It would be good if they fleshed it out a bit more, possibly with additional areas such as security awareness training. They could build that in. They're leveraging the same endpoint base that they have the security software on, but then they could offer a centralized portal or hub whereby someone like me could leverage it to track and put out security awareness training for people on all the common topics. I could have a centralized hub for everyone's results from that training and for the evidence that training occurred. It would be relatively straightforward, but it would add a lot for people in the compliance area. It would be a great expansion. It won't improve the actual technical protection, but it would improve the user protection. Educating the users to be more aware increases security. So, if they branched out into that, it would be a great bonus. If I was speaking to them, that's what I'd tell them to do.
For how long have I used the solution?
I have been using this solution for a couple of years.
What do I think about the stability of the solution?
It is super stable. I would rate it a ten out of ten in terms of stability.
What do I think about the scalability of the solution?
It is scalable. It is for endpoint protection. It is a cloud-based platform. So, it can scale to whatever amount of endpoints you want. You can scale it any way you want.
The endpoint deployment is relatively straightforward. The only constraint is licensing. The more you scale, the more you pay. That's it.
We have less than 200 users of this solution.
How are customer service and support?
It is a fully managed service, So, we have 24/7 support. It is not technical support. It is a dedicated team, and they're there to answer any queries or questions. So, no technical support was required because nothing went wrong, but when we have questions, they're incredibly responsive. They get back super quick. I have no complaints at all. I would rate them a five out of five.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had another solution previously, and we just replaced it with CrowdStrike. Based on all available information, we just decided it was the best, and we don't regret that. It has been very good.
How was the initial setup?
Its initial setup is simple. It is very well designed.
All our endpoints are managed by mobile device management. We have centralized device management, deployment, and installation with Intune. We can install anything we want on any of the computers with Intune.
What's my experience with pricing, setup cost, and licensing?
It is not cheap, and it is not overpriced. It positions itself in the upper half of pricing in the market. You can find a product that claims to do the same and is super cheap, but it'll be not at all good. You can find something that says it does everything in the world, and it is the best thing since sliced bread, but it would be incredibly expensive. Falcon Complete is neither of those. It is always best to go somewhere in the middle, but it is not in the middle. It is in the upper half. So, it is by no means cheap, but it is worth it. Its pricing is well fixed. Given what you get in return, you wouldn't feel bad paying for it.
They have a great licensing model. You can add extra bells and whistles if you want. There is that ability to reduce the price by turning off certain features if you wish. I wouldn't necessarily recommend it, but they do cater to everyone in that sense.
Which other solutions did I evaluate?
We compared it to all other vendors, and then we decided on it because it is the best in class and in the Gartner Magic Quadrant. It is the best in the market.
What other advice do I have?
I would highly recommend it. So far, my experience has been nothing but positive.
I would rate it a 10 out of 10. It is in the top five. It ticks all the boxes that I have for it. You got to manage your expectations, and given my expectations, it exceeds my expectations. Now, if you were to ask me what is my expectation for the software next year, I'd want it to be better, but at this exact moment in time, it is doing a fantastic job, and I hope they keep it up and improve. If they don't, then my grade will drop.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Consultant - Applications & Technology at Select Home Health Services
Great next-generation antivirus with breach warranty and good intrusion protection
Pros and Cons
- "One unique thing that they offer is a breach warranty. We basically have a warranty of up to $100,000 should there be any breach that they're not able to manage."
- "One differentiator of CrowdStrike is that it's nearly what I would call zero-touch on the workstation."
- "The downside is that if you are using a device offline, not connected to the internet, you will potentially have exposure."
What is our primary use case?
We wanted a very high level of endpoint protection and intrusion detection. Based on all the reviews, you have a bunch of products out there to choose from. One differentiator of CrowdStrike is that it's nearly what I would call zero-touch on the workstation. You don't have to worry about upgrades and all that. Then, when something suspicious is detected, the CrowdStrike team investigates that for us. It's part of the service that we purchased from them. Basically, we use the solution for security.
How has it helped my organization?
Basically, from an overall management perspective of the devices, you really only install the sensor once, and then you set up policies on the portal to say, okay, we want to stay on the N minus one version of the sensor. If there's an update that's required, the portal pushes it to the workstation. It makes everything very easy and doesn't require any touch.
What is most valuable?
It's mainly the next-generation antivirus that we are leveraging.
In the traditional antivirus, like McAfee, for example, you'd have to maintain signature files and all that on the workstation. We don't have to do that. On top of that, the footprint on the workstation is nearly zero.
One unique thing that they offer is a breach warranty. We basically have a warranty of up to $100,000 should there be any breach that they're not able to manage.
What needs improvement?
The downside is that if you are using a device offline, not connected to the internet, you will potentially have exposure. Intrusion detection and endpoint protection is all driven using the internet. You have to be connected. If you're not connected, basically, unlike some antivirus software packages, if you introduce something, let's say through a USB port, and you are not online, you have potential exposure.
I'd like to see a capability where the solution can do offline intrusion detection if needed. For example, if you have offline workstations or devices, then there's new data introduced into the device using, I guess, portable data devices. If there was a way to detect that while the device was not connected, that would be great.
It's not a major concern for us since 100% of the time, our devices are connected to the internet because most of our business applications are using cloud-based applications.
The pricing can look expensive.
For how long have I used the solution?
We started using the solution in April or May of this year. It's only been a few months.
What do I think about the stability of the solution?
It's stable. So far, so good. I've not had any issues around it in terms of impacting usage, et cetera. It's pretty transparent to us.
What do I think about the scalability of the solution?
It's pretty scalable. I've talked to some users from huge companies, Fortune 500 companies, so I know that it's scalable.
We don't really have any users for it. It's pretty much myself and one other person who just monitors the portal, and that's about it. In terms of devices, we have 100 to 150 devices.
We intend to explore the other capabilities of what the sensor can provide us. However, right now, we're just focused on antivirus and intrusion detection. That's about it.
The intent is obviously to deploy. Every time we have new devices, et cetera, we just deploy this and go.
How are customer service and support?
Support is pretty transparent for me. We've had probably five or six incidents, and they were minor, however, then those are handled by the CrowdStrike team.
They would notify me if I needed to take action on my side. So far, they are good. I haven't needed to take any drastic action, like shutting down the device and all that.
Which solution did I use previously and why did I switch?
We had decentralized solutions. They were mainly workstation-based and was McAfee. We went to a centralized solution so that it can be centrally managed.
How was the initial setup?
The setup is pretty straightforward. We started out with a lot of effort since we didn't have managed devices when we installed it. We didn't have a device management system in place for Windows, so we had to install it at each workstation.
The deployment probably took us a week. We had to install the sensors manually. However, the installation process is very straightforward. It takes less than five minutes.
In terms of maintenance, it's all maintained on the CrowdStrike side.
What about the implementation team?
We did the initial setup ourselves in-house.
What was our ROI?
There's potentially really no ROI. It addresses an area of risk. That is all. You're putting the investment in the service as a kind of insurance against cyber attacks, data breaches, et cetera.
What's my experience with pricing, setup cost, and licensing?
We have a subscription.
The cost, the overall cost of the service, is something that could be improved. If you compare it to other antivirus systems, it'll seem more expensive as there's one piece that people overlook - you have a technical team monitoring for you behind the scenes.
The cost is approximately $35,000 to $40,000 a year. It covers up to 300 devices and 300 Windows or Mac OS devices, and about 150 mobile devices. There are no additional costs beyond the main fee. It's all paid on an annual lease.
Which other solutions did I evaluate?
We looked at Microsoft Defender, McAfee, Norton, and two other solutions, however, this one came up on top. The only downside is the overall cost when you compare it to the competition.
What other advice do I have?
We are customers and end-users.
I'm not sure which version of the solution we're using. Typically, we set ourselves to N minus one. We're typically one version behind the most current.
I'd warn potential new users that they have to look at the total cost of ownership. One item that's overlooked is when you get an antivirus or a security product, you will need experts to manage and maintain it. CrowdStrike basically provides you with the software solution and the technical support behind it. If you basically add up all those things, it'll probably be on a total cost basis; it'll be reasonable.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head Of Information Security at a financial services firm with 501-1,000 employees
Easy to set up, has multiple dashboards, and offers competitive pricing
Pros and Cons
- "What I found most valuable in CrowdStrike Falcon Complete is that it has a lot of monitoring dashboards and use cases, and I saw that it's a very good product, but my company has only tested it, so it's not been used for real use cases. My company hasn't tested the complete license for CrowdStrike Falcon Complete, so the team hasn't checked the open fiber rooms for zero-day attacks, IOAs and IOCs, or any indicators of fraudulent activities. I was also amazed at the solution and its licensing. My company did a competitive analysis of many EDR solutions, but it went with CrowdStrike Falcon Complete. It's one of the top-rated solutions on CyberRatings as well."
- "At the moment, nothing is missing in CrowdStrike Falcon Complete. I'm amazed by it. It's perfect and I'm not aware of any other vendors that provide its features, but it would also depend on the configuration and policy management of the solution, for example, I can bring you an EDR solution and configure it badly, so it won't do anything. It also depends on the people, not just the technology you're obtaining, so this is the most important thing to do for all solutions, even for firewalls. You can obtain a firewall and if you permit everyone to go through it, then it's useless. What could be improved in CrowdStrike Falcon Complete is its management console. Currently, that console is on the cloud, so if the cloud is compromised, then the management console would also be compromised, and that's quite risky."
- "What could be improved in CrowdStrike Falcon Complete is its management console. Currently, that console is on the cloud, so if the cloud is compromised, then the management console would also be compromised, and that's quite risky."
What is our primary use case?
We use CrowdStrike Falcon Complete internally and externally according to the MITRE ATT&CK framework. MITRE ATT&CK describes most of the TTPs and explains them, including the default use cases and deployed policies. Our internal use case for the solution is specifically for internal fraud cases to use in our internal forensics team.
How has it helped my organization?
CrowdStrike Falcon Complete has helped in improving my company in terms of achieving strategies and executing frameworks.
What is most valuable?
What I found most valuable in CrowdStrike Falcon Complete is that it has a lot of monitoring dashboards and use cases, and I saw that it's a very good product, but my company has only tested it, so it's not been used for real use cases. My company hasn't tested the complete license for CrowdStrike Falcon Complete, so the team hasn't checked the open fiber rooms for zero-day attacks, IOAs and IOCs, or any indicators of fraudulent activities.
I was also amazed at the solution and its licensing. My company did a competitive analysis of many EDR solutions, but it went with CrowdStrike Falcon Complete. It's one of the top-rated solutions on CyberRatings as well.
What needs improvement?
At the moment, nothing is missing in CrowdStrike Falcon Complete. I'm amazed by it. It's perfect and I'm not aware of any other vendors that provide its features, but it would also depend on the configuration and policy management of the solution, for example, I can bring you an EDR solution and configure it badly, so it won't do anything. It also depends on the people, not just the technology you're obtaining, so this is the most important thing to do for all solutions, even for firewalls. You can obtain a firewall and if you permit everyone to go through it, then it's useless.
What could be improved in CrowdStrike Falcon Complete is its management console. Currently, that console is on the cloud, so if the cloud is compromised, then the management console would also be compromised, and that's quite risky.
For how long have I used the solution?
I've been using CrowdStrike Falcon Complete for six months.
What do I think about the stability of the solution?
CrowdStrike Falcon Complete is too stable, but I still have to test it in a forensic case before I could comment on the stability of the solution.
What do I think about the scalability of the solution?
We usually follow TMMI, so in terms of the maturity and scalability of CrowdStrike Falcon Complete, it's fine, so far.
How are customer service and support?
Our only experience in terms of contacting the technical support team for CrowdStrike Falcon Complete was during implementation.
How was the initial setup?
Setting up CrowdStrike Falcon Complete was too easy because it's a cloud solution, so it was too easy to implement. There's nothing to do, for example, you just need to install the agent from the PCs on the endpoint.
In terms of the deployment time for CrowdStrike Falcon Complete, the infrastructure team implemented the endpoints which took one week, then there's the tuning of the policies, so overall, the deployment took one month.
What about the implementation team?
There's a third party or a partner either for implementation or support for CrowdStrike Falcon Complete, but my company did it in-house.
What was our ROI?
We haven't seen ROI from CrowdStrike Falcon Complete because we've just done a POV for the top management and there are limited attacks in our organization. We've done some use cases or POCs on a zero-day attack, changing the binaries, etc., and CrowdStrike Falcon Complete was perfect and detected all of the behaviors, isolated them, and did all the functions we expected it to do.
What's my experience with pricing, setup cost, and licensing?
The pricing for CrowdStrike Falcon Complete is competitive. It's a cheaper solution when you compare it with others, and on a scale of one to five, I'm rating its pricing a four. You also don't need to pay extra for its features. CrowdStrike Falcon Complete is perfect.
Which other solutions did I evaluate?
My company evaluated another solution that was also top-rated: FireEye (now called Trellix).
What other advice do I have?
CrowdStrike Falcon Complete currently has five thousand users in my company and the roles vary from top management to C-level to endpoint users to high privilege users, so a lot of people and a lot of money.
My company recommends CrowdStrike Falcon Complete for the financial, military, and oil and gas sectors. It's by sector, not by people. All the roads now move toward security and securing the business, and it also depends on the criticality of the assets you own and how you're securing the assets. Whenever or whoever has a critical asset should go for a strong security solution such as CrowdStrike Falcon Complete.
In terms of how extensively the solution is being used in my company, there's no 100% security, so my company is always developing security solutions that can handle new attacks, future attacks, and more sophisticated attacks, so I'm unable to give a percentage of the extent of usage of CrowdStrike Falcon Complete, but if I can just measure this from a governance perspective, it's 80%, specifically from a compliance perspective.
At the moment, I'm unable to give my advice to others looking into implementing CrowdStrike Falcon Complete because I need to use the solution on a real test or real compromise first.
I'm rating CrowdStrike Falcon Complete eight out of ten because of its management console being on the cloud. My company doesn't prefer this setup, even if it has an NDA with the vendor because if the cloud itself was compromised, the management is also compromised, and all users will be isolated, so this isn't good from a risk perspective.
My company is a customer of CrowdStrike Falcon Complete.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Vice President at a financial services firm with 10,001+ employees
Identifies malicious activity, light on the system, and has helpful technical support
Pros and Cons
- "There's less workload on the endpoint."
- "The capabilities of CrowdStrike as a tool are fantastic."
- "The initial setup was slightly complex although it's an easier solution."
What is our primary use case?
When work-from-home scenarios started in March 2020, during the pandemic, in the month of April, we were actually going through some POCs and had one ransomware attack on one of the client sites. We had to deploy the solution immediately, which actually helped us find out or not how it worked. Proactively, we could identify some threats in the environment and act on them. We were virtually identifying items and getting notifications, as well as seeing the availability of the intra. That was very helpful for the entire team.
What is most valuable?
The solution is very nice. It's got multiple products for multiple features and enabled multiple settings, which helped my team and the organization is also in a way better way. Since it was lockdown the last two years, when the entire organization went to working from a remote location, the earlier solutions, what we had, were of no use. We were most concerned about security over the cloud. Carbon Black has helped us handle that.
Before we used to support multiple clients. We had to have some connectivity to the client's environment via Citrix or something. To access any of our solutions was a challenge when most of them were on-prem. Those were challenges for all of us. Now, most of the world has gone to the cloud. That actually helped us. Obviously, CrowdStrike was a different experience altogether.
I personally work on advanced threat hunting and identifying possible malicious activity or the possible threat in our environment which is getting easier earlier. Symantec Engine Protection, for example, gives you known reactive reports where you get stuff from either SIM or some soft team to help us on finding out probably the path for the attack. However, CrowdStrike is better at hunting threats and catching them early.
There's less workload on the Endpoint. After moving to CrowdStrike we never have this issue of systems getting overutilized by any of the security tools. That was one of the biggest advantages for it.
What needs improvement?
CrowdStrike has multiple parameters of components in the same console, which includes your vulnerability scanning. It has access to, or rather, we can integrate with, our existing SIM technology or SIM tool. The information that gets passed on the SIM control, the soft tool data site or any other tool is very limited. I had to actually provide the control access to my soft team so that they could drill down if needed.
The information was get passed on from Falcon control to CrowdStrike and it was very limited. It was acting as more of an alert only. For any further deep-dive analysis, we had to log in on the console itself.
CrowdStrike has multiple parameters. For example, my vulnerability scanning team is a separate team who works on different tools altogether. If I need to give them access to my console I just need to provide them read-only access or kind of an admin access for VA scanning.
I had to make some customized access that can be provided to different teams on the same console. As a VA team member, if I login to the console with my credential I should be able to see the things which I am working upon. I don't need to see all other tile stack tabs. I should be able to provide some kind of customized access or other kind of access control for the console.
Microsoft Defender has one good option which is called the ASR rule. It basically allows the machines to be onboarded to different consoles, which analyzes the process of it and summarizes it in a single console. Obviously, the number of incidents of the event are very huge. It takes about a month or so to evaluate. However, after the evaluation completes, you can actually fine-tune what should not be present in your automation. Which you can set up and get rid of it. It would be nice if this product had something similar.
For how long have I used the solution?
I've used the solution for two years.
What do I think about the stability of the solution?
The stability is very good. It does not have any kind of payload on the endpoint, and we don't need to compromise with system performance. The legacy tools used to have this agent needed to be deployed and consumed a lot of system resources. In terms of performance, this tool was an improvement on the legacy. The capabilities of CrowdStrike as a tool are fantastic.
What do I think about the scalability of the solution?
We are working with about 18,000 endpoints and about 2,000 servers.
The scalability was really good. It covers most of the recent operating systems I would say in India, although most of our customers are using Microsoft operating systems only. In terms of my international clients who have different operating systems, including Mac, Linux, or Unix, this works. CrowdStrike has the maximum availability for all possible and the latest operating systems. With other tools. we didn't have that level of flexibility.
How are customer service and support?
Technical support was fantastic, however, frankly speaking, we barely had a chance to get in touch with the technical support as CrowdStrike has a fantastic health portal within that console. There were a couple of scenarios where we went to them as some kind of alert that CrowdStrike was publishing it to the customer only. They had some specific name for those alerts. Those used to get sent to the customer's end only. Being automation as security, CrowdStrike has a policy to provide the information only to the registered customers only. Obviously, the licenses are issued to the customer. However, the licensing policy was limited in that we were kind of a vendor, or rather, a mediator between the customer and the OEM and we fell through the cracks.
I would say in my earlier solution, we used to just provide the license number. If the license number were verified, we would get all types of support.
Overall, the support team was really good. They are more capable of understanding the other challenges and would then provide the solution.
Mostly, we were providing all the technical support to the customer. The licenses were installed with the customer's name. We were slightly lacking as the details that OEM was providing were direct to the customer and we were being skipped. At the same time, we used to struggle to get the details and updates or more input from the OEM from CrowdStrike.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We moved from Symantec Endpoint to CrowdStrike.
How was the initial setup?
The initial setup was slightly complex although it's an easier solution. It took us about a month to understand the entire process of the console.
Within a month we were able to train our members to a certain level and within a six-month span, all members actually became familiar for the technology.
We had some challenges from the client environment as well. That was expected as we were ruling out Symantec as well at the time. Concurrently, we were moving out of Symantec and deploying through the CrowdStrike agent. We were also doing the policy fine-tuning, which took a slightly longer time as the customer had their own developed applications and tools for finding their hashes. We added features like device control, app control. Those parts took slightly longer, however, it was still quicker than the legacy solution.
We have two people available to handle maintenance.
What about the implementation team?
The deployment was handled by my technical team only. Internally, we had eight team members deploying it. They were using a big fix as a deployment tool to deploy this agent on all the clients. I was leading the admin part of CrowdStrike. We had to involve the patch management team who could push a particular script on all the endpoints to onboard them. Most of the endpoints were working remotely and luckily we fixed everything there in the cloud which was making our life easier for onboarding scripts on the client.
What other advice do I have?
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of technology at Commtel
The solution integrates well and allows our customers to automate their site intelligence.
Pros and Cons
- "Falcon's threat intel is strong, and the solution allows our customers to automate their site intelligence. We can integrate Falcon X with the other platforms we use, like FireEye, Insight, Cybertech, and Kaspersky."
- "I would love for the threat intelligence part to be more globalized to provide a tailored response to types of malware and ransomware that are trending in other regions. For example, they can add a feature to tell us that there are separate attacks in South Asia or East Asia occurring at these times, so we can supply those things to our environment and protect ourselves."
- "In the CrowdStrike, you have some sort of limited information and for the in-depth information you need to take it, Carbon Black provides that particular thing on the first view."
What is our primary use case?
Falcon is a threat intelligence platform. In cybersecurity, there's always a chance you'll get breached and gaps that need to be addressed, but you'll never know unless there is a threat seeking to exploit that particular weakness. Most use cases for Falcon will be directly ingested into our Siemens server. The total number of users on the solution is around 1,500.
What is most valuable?
Falcon's threat intel is strong, and the solution allows our customers to automate their site intelligence. We can integrate Falcon X with the other platforms we use, like FireEye, Insight, Cybertech, and Kaspersky.
The threat intelligence comes from Falcon X and goes directly into the SIEM and SOAR. That provides us valuable feedback for the use cases being used. If my analyst wants to check suspicious or malicious activities, they get the maximum information from Falcon X about URLs, IPs, domains, hashes, etc.
What needs improvement?
I would love for the threat intelligence part to be more globalized to provide a tailored response to types of malware and ransomware that are trending in other regions.
For example, they can add a feature to tell us that there are separate attacks in South Asia or East Asia occurring at these times, so we can supply those things to our environment and protect ourselves.
For how long have I used the solution?
We've been using Crowdstrike Falcon Complete for almost a year.
What do I think about the scalability of the solution?
Falcon is easy to scale.
How are customer service and support?
I rate CrowdStrike support eight out of 10. Overall, the customer service is excellent, and the backend teams are highly responsive. We have a good relationship with CrowdStrike. The sales, technical, backend, and R&D teams work closely with the customers.
How would you rate customer service and support?
Positive
How was the initial setup?
Falcon X is a cloud-based subscription model, so you just need an account from CrowdStrike. You can log in and set it up in 5 to 10 minutes. It ultimately on how well you understand the technology. If you're familiar with the technology, it's straightforward, but you might find it complicated if this is your first time using it.
There's a lot of information and options in front of you. If you don't know where you have to go for specific information, you'll think it's complicated. The amount of maintenance depends on whether there's a particular update or batch on the back end.
What's my experience with pricing, setup cost, and licensing?
The licenses for both Carbon Black and Crowdstrike are expensive, but it depends on how the vendors scale the price and negotiate with the customer. So if you have a customer with 7,000 users, the vendor will offer them a low price per user to get them on board. If you have a few hundred users, the price will be a little bit more.
There's a huge price difference at various scales. I was surprised that the license for a hundred users went as high as $120 per user, whereas the same product might cost $30 for 6,000 users.
Which other solutions did I evaluate?
I haven't worked on the backend part of Carbon Black, so it's hard for me to compare both products. We're using the EDR for Carbon Black with CrowdStrike's threat intelligence.
Carbon Black is an impressive tool for analysis because it provides in-depth information and a complete triage file for the analysts. In the CrowdStrike, you have some sort of limited information and for the in-depth information you need to take it, Carbon Black provides that particular thing on the first view.
What other advice do I have?
I rate CrowdStrike Falcon Complete nine out of 10. Before you deploy the product, you need to do research, understand the capabilities, and assess your requirements. You should know what you need before you purchase something. It's not like buying jeans, where you can get another pair if you're not satisfied. You should be certain that it fits your requirement.
Budgets are always a challenge in the security field because every CEO or company owner thinks IT security is a burden. It doesn't generate profit, and the company needs to spend money on products and services. You might not go for the best product if you have budgetary constraints.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Director at a computer software company with 51-200 employees
Helps reduce the efforts of our SOC team, simplifies the response process, and remediates cyber threats
Pros and Cons
- "The overwatch module is the most valuable feature of CrowdStrike Falcon."
- "CrowdStrike Falcon Complete MDR offers an optional module that might not be cost-effective for all organizations."
What is our primary use case?
CrowdStrike Falcon Complete is an XDR solution that we use for our endpoint protection.
We currently don't have a complete CrowdStrike Falcon bundle; instead, we have an enterprise bundle in place. For this bundle, agents are installed on all endpoints, and we define security rules to ensure automated workflows are executed through multiple cells using pre-defined playbooks.
How has it helped my organization?
CrowdStrike Falcon's detailed dashboard simplifies the process to respond to and remediate cyber threats.
CrowdStrike Falcon Complete's AI-powered analytics have demonstrated good performance and accuracy in real-world scenarios.
CrowdStrike Falcon has helped reduce the efforts of our SOC team by remediating most of the alerts, directly allowing us to manage things more efficiently.
We realized the benefits of CrowdStrike Falcon Complete within the first year.
CrowdStrike Falcon Complete highlights any endpoint vulnerabilities it detects directly on the dashboard, making it easier for our IT staff to address them and improve our overall security posture.
What is most valuable?
The overwatch module is the most valuable feature of CrowdStrike Falcon.
What needs improvement?
CrowdStrike Falcon Complete MDR offers an optional module that might not be cost-effective for all organizations.
For how long have I used the solution?
I have been using CrowdStrike Falcon Complete for almost two years.
What do I think about the stability of the solution?
We frequently encounter situations where endpoint agents go offline for unknown reasons, necessitating a service restart on affected machines to restore connectivity.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon Complete an eight out of ten.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
As part of the integration team, I manage the entire transaction process. While the initial deployment presented a challenge due to the need to contact all end users, it was a one-time effort necessary to implement the solution. The deployment itself took four months to complete and required eight people.
We implemented a hybrid work model, allowing employees to work both from home and in the office. As a part of this model, we empowered end users to deploy the agents themselves. We carefully monitored the entire process through a designated dashboard, assigning agents to their respective groups and ensuring timely policy implementations based on individual agent online status. This approach granted us ultimate control over the process.
What about the implementation team?
We used an integrator in the middle of the deployment.
What was our ROI?
We have seen a return on investment with CrowdStrike Falcon Complete.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon Complete is expensive.
What other advice do I have?
I would rate CrowdStrike Falcon Complete a nine out of ten.
CrowdStrike Falcon Complete is deployed across our entire organization.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Infrastructure Manager (Region 2 IT Manager) at a transportation company with 201-500 employees
A stable tool that protects the core environment of its users while being able to detect viruses quickly
Pros and Cons
- "It's a stable application. It is one of the most stable out of all the other market applications, especially if you're talking about within the EDR platform."
- "The simplicity of CrowdStrike Falcon Complete's content control and firewall management should be improved."
What is our primary use case?
Comparing CrowdStrike Falcon Complete with Bitdefender, I would say that Bitdefender was comparatively easier to use, deploy and maintain, especially for my technical resources.
How has it helped my organization?
CrowdStrike Falcon Complete is the same as any other EDR program. It provided full antivirus protection. Also, it provided a little bit of the ransomware and other protections you would see within the Bitdefender field. The content control wasn't as intuitive and easy to use as Bitdefender.
What is most valuable?
The most valuable thing in the solution was the analytical AI to detect viruses faster than Bitdefender.
What needs improvement?
The simplicity of CrowdStrike Falcon Complete's content control and firewall management should be improved. Ransomware protection of the solution needs to be improved.
For how long have I used the solution?
I have been using CrowdStrike Falcon Complete for six months before switching to Bitdefender, which is easier to maintain.
What do I think about the stability of the solution?
It's a stable application. It is one of the most stable out of all the other market applications, especially if you're talking about within the EDR platform.
What do I think about the scalability of the solution?
If you don't watch the training videos for CrowdStrike Falcon Complete, it's not as intuitive as Bitdefender.
How are customer service and support?
I have had a very limited experience with the customer support team. So, their response time was far worse than any of the other vendors. So that was probably one of the driving factors and the reason why the adoption process didn't go so well, which is because of their onboarding process, during which they used to take a day to get back to assist you. I would have understood if they had taken a couple of hours to help us, but waiting for a day wasn't acceptable.
How was the initial setup?
I rate the initial setup a four on a scale from one to ten, where one is very difficult.
What was our ROI?
One can see a return on investment because it does protect one's core environment.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon Complete is very expensive in comparison to Bitdefender.
What other advice do I have?
CrowdStrike Falcon Complete is probably one of the best software out there if you're looking at it. But if you're on a budget and you want to get something within the same price level, I would look at Bitdefender. Then if I added a worst-case scenario, I would go to Sophos or SentinelOne. In my industry, the cost is a huge variable. Though it's a good product, it's not easy and intuitive. I have to remember that my technical resources to offload my work are in the Philippines. So I need to have something that's very simplistic. I have helped desks in the Philippines, Malaysia, Mexico, and Singapore. When I choose an application, I have to consider the intuitiveness of that application and also the multiple language barriers. So, that is where prospects fail, which is during the adoption process.
I rate the overall solution a seven or eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Engineer / Security Consultant at M.E. Services
It is very scalable and has good AI-based features
Pros and Cons
- "It is a stable solution."
- "Its reporting feature could be user-friendly."
What is our primary use case?
We use the solution for endpoint detection and response features.
What is most valuable?
The solution's most valuable feature is AI engine. It helps us automatically block the execution of suspicious activity.
What needs improvement?
The machines require several resets during the solution's deployment process. They should improve this particular area. Also, the reporting feature could be user-friendly. The reports need to be explained in simpler words instead of technical terms.
For how long have I used the solution?
We have been using the solution for six years.
What do I think about the stability of the solution?
I rate the solution's stability as a ten.
What do I think about the scalability of the solution?
We have 1000 solution users. It is very scalable. I rate its scalability as a ten.
How was the initial setup?
I rate the solution's initial setup process as nine. It takes a month to complete. We first deploy the pilot group in a passive mode and then move to active mode. Meanwhile, we also remove the old antivirus platform from the network. Once the pilot is active, we deploy it to the rest of the platform.
What's my experience with pricing, setup cost, and licensing?
The solution's licenses are expensive for small-scale companies. They cost around $120. There are no additional costs. But sometimes, we need to outsource some skills to access good security understanding. Thus, we have to pay extra for it apart from the licenses. I rate its pricing as a nine.
What other advice do I have?
I highly recommend the product and rate it as a nine. It is exceptional, but there are competitive products in the market with better pricing.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. consultant
Buyer's Guide
Download our free CrowdStrike Falcon Complete MDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Managed Detection and Response (MDR)Popular Comparisons
IBM Security QRadar
Huntress Managed EDR
Intercept X Endpoint
SentinelOne Wayfinder Threat Detection and Response
Arctic Wolf Managed Detection and Response
Adlumin Security Operations
Secureworks Taegis Managed XDR / MDR
CompassOne by Blackpoint Cyber
ConnectWise SIEM
Fidelis Elevate
Alert Logic MDR
Binary Defense MDR
Buyer's Guide
Download our free CrowdStrike Falcon Complete MDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How do you estimate ROI of a Managed Detection and Response (MDR) solution?
- When evaluating Managed Detection and Response (MDR), what aspect do you think is the most important to look for?
- Which solution do you prefer: Optiv Managed Security Services or eSentire?
- Why is Managed Detection and Response (MDR) important for companies?



















