What is our primary use case?
My main use case for CrowdStrike Falcon is endpoint detection for the most part.
The other part would be all the other capabilities that we use it for, such as identity, detection, policies, response, RTR, and forensics.
What is most valuable?
The benefits I've seen from having multiple security capabilities on a single platform include a single pane of glass, the ability to contain, and eradicate threats easier.
The value I've seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform makes it easy to use one path to focus on specific threats and be able to correlate them together, especially with advanced search and using the graph.
CrowdStrike Falcon has definitely decreased the workload and increased the productivity of my security team compared to if we were to use something else.
The Falcon sensor's impact on endpoint performance is that it does not necessarily affect it in a negative way; the agent does not. From a security perspective, it has a very high impact with ensuring things are secure.
What needs improvement?
The only downside is trying to figure out all the agents or all of the machines that do not have CrowdStrike Falcon on them, unlike SentinelOne which has a feature for that, along with a feature where you can roll back to detect ransomware if you ever get ransomware.
CrowdStrike Falcon can be improved by having the ability to scan the network to determine what machines do not have CrowdStrike Falcon on, which is a big one, and having the ability to roll back from the volume image if you get encrypted. Other than that, it is pretty solid; you have a monopoly on the field as of now.
For how long have I used the solution?
I have been using CrowdStrike Falcon for seven or eight years.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as a 10 out of 10.
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.
What do I think about the scalability of the solution?
My use of CrowdStrike Falcon platform has expanded significantly since my initial deployment; I started with Falcon when I worked for the government and then moved to the private sector. As an incident responder, the majority of clients did not have Falcon, and that is when I got compromised. After we installed Falcon, it made life much easier for them. As times changed, Falcon has come a long way from where it first started; I believe you switched your query language to make it faster, as one of the complaints back then was that it was too slow. Now it is much faster and scales at a large scale, so there are definitely many improvements since the first time I ever used it.
How are customer service and support?
I would evaluate customer service and technical support as generally good, but we must mention 2024 because that was the issue with the blue screens; other than that, there were no other issues.
Which solution did I use previously and why did I switch?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools; we replaced a couple when we added specific features.
One of the tools I replaced was Wiz; some of the Wiz sensors we replaced with CrowdStrike cloud Falcon sensor because it was cheaper, and then another one with Falcon Forensics would have been Axiom or FTK. However, we have a retainer, so we do not really dive into Falcon Forensics extensively. The identity one, I had a POC but did not prefer it for whatever reason, so I did not replace anything there that I can think of now.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that, from an EDR perspective, it has a tight grip on everything; in some aspects, such as Falcon Forensics, I have used Axiom in the past, and Axiom is probably better. For identity, there are better identity solutions out there, and for host management, Spotlight is one that we replaced Tenable with; it is pretty solid for vulnerability management, especially because it does automatic scanning. One challenge is trying to convince auditors that this is the solution now because they cannot keep up with the times. Overall, CrowdStrike Falcon is pretty amazing.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as pretty easy to deploy; I have not deployed it in a minute, but when I did, I just hooked it up in whatever automation platform the company at the time used and went from there.
What about the implementation team?
In terms of deployment challenges, figuring out which machines do not have it is an issue I faced, while what worked well was being able to install it and having installers available for different operating systems, although legacy operating systems are difficult to get an installer for, such as 2008 and 2003.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon.
Return on investment would be most likely just being able to consolidate tools; Spotlight was a big one, and asset discovery is a big one.
What's my experience with pricing, setup cost, and licensing?
I do not deal with pricing, setup costs, and licensing, but I know that it is approximately 60 dollars per endpoint at MSRP, and they make deals based on that. Our sales reps are pretty good, so we just let the sales rep talk to us, and they sold us on it right there.
Which other solutions did I evaluate?
I would recommend CrowdStrike Falcon over Carbon Black, SentinelOne, Huntress, and any other main EDR solutions to another organization considering it.
What other advice do I have?
The impact of Charlotte AI on my security operations is high from the perspective of being able to find things quicker, but if you ask it to do complex tasks, it is not necessarily the best. I would rate this review an 8 out of 10 overall.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other