I tend to focus on SIEM implementations, so using CrowdStrike Falcon Insight XDR involves getting that agent out there, using it to collect telemetry, and feeding that into a SIEM.
CrowdStrike Falcon Insight XDR provides adversary-driven detection and response across endpoints and beyond. It combines AI-powered endpoint detection and response with integrated threat intelligence and expert context to deliver high-quality, context-rich detections that help security teams identify and prioritize sophisticated threats.

Automated leads and Charlotte AI, combined with attack-path visibility, adversary context and MITRE ATT&CK mappings, help analysts investigate incidents faster. Real Time Response and Falcon Fusion SOAR support direct and automated remediation at scale. Extend investigations with critical context from identity, cloud, mobile and data protection, while incorporating third-party data in the same console.
What are the key features of CrowdStrike Falcon?
What benefits and reported outcomes can organizations achieve?
In technology sectors, CrowdStrike Falcon commonly supports endpoint protection and threat response initiatives, allowing companies to replace traditional antivirus systems with more advanced solutions. In finance, it secures sensitive data across multiple platforms, ensuring compliance. In healthcare, real-time security analysis protects patient data on critical devices like servers and laptops, utilizing AI to enhance cybersecurity defenses.
| Author info | Rating | Review Summary |
|---|---|---|
| Senior Manager at a consultancy with 11-50 employees | 4.5 | CrowdStrike Falcon Insight XDR provides high-quality telemetry and correlation, significantly reducing my mean time to detect and respond. It's a stable, scalable, cloud-native solution with easy deployment and good support, though I'd like more built-in integrations. I highly recommend it. |
| Senior Sales Engineer at a tech services company with 11-50 employees | 5.0 | I leverage CrowdStrike Falcon Insight XDR for rapid incident investigation, real-time response, and robust attack detection. Though impactful and stable, I'd prefer clearer guides, improved UI, and more accessible licensing support, but rate it highly overall. |
| IT Director at a construction company with 201-500 employees | 5.0 | CrowdStrike Falcon Insight XDR gives me peace of mind, enhancing my small company's security effectiveness. It's stable, scalable, has amazing support, and offers tremendous value, allowing me to trust and love this great product. |
I tend to focus on SIEM implementations, so using CrowdStrike Falcon Insight XDR involves getting that agent out there, using it to collect telemetry, and feeding that into a SIEM.
The improvements I have observed in my process for detecting and investigating sophisticated attacks since adopting CrowdStrike Falcon Insight XDR is the quality of the telemetry that it collects. It collects all the right information you need to be able to detect threats and conduct threat hunting.
The value I get from correlating activity across endpoints and other security domains with CrowdStrike Falcon Insight XDR ensures that I am actually getting value out of my full security tooling stack, bringing everything together into one spot. Every product has its own blind spots, but when you bring them all together, you get a better picture of what is going on.
The detection capabilities of CrowdStrike Falcon Insight XDR have influenced my approach to identifying and addressing sophisticated threats by focusing on the correlation aspects and utilizing multiple data sources to detect those threats rather than having individual detections that utilize only one source. CrowdStrike Falcon Insight XDR has definitely reduced my mean time to detect and mean time to respond, though I could not give exact figures.
The impact that CrowdStrike Falcon Insight XDR has had on alert volume and analyst investigation time is definitely reducing the volume of alerts by correlating data sources. Anytime you do that, you are speeding up or reducing the amount of work an analyst does and speeding up the time for them to do things.
My experience with CrowdStrike Falcon Insight XDR's behavioral detections and Indicators of Attack has been good overall. I think it is hitting many of the points I have already mentioned in terms of correlating those data sources, making it easier to detect things and easier to investigate them.
These detection methods integrate into my current security operations workflows by generally forming the centerpiece. I am actually a consultant, so I do not have a specific workflow myself, but I work with multiple clients, many of them using CrowdStrike Falcon Insight XDR, and it brings in a lot of information and stitches it all together.
CrowdStrike Falcon Insight XDR can be improved by expanding the number of built-in integrations. It has a lot included out of the box, but you still run into outliers and things that are not available yet, so the more they build on that, the better it will get. I cannot think of any additional features that should be included in the next release at this time.
I have been working in my current field for approximately 10 years.
I assess the stability and reliability of CrowdStrike Falcon Insight XDR as pretty good. There was obviously a well-documented issue about two years ago, but they have gotten past that and implemented new configurations that can help organizations avoid that.
What happened two years ago was when CrowdStrike brought down half the internet due to an update and a glitch. However, it has not happened since, and they have implemented configurations that allow you to control how those things flow down to your endpoints.
CrowdStrike Falcon Insight XDR scales with the growing needs of my organization so far. Being a SaaS product, it just grows as I need it, so I have not seen any performance issues until we were playing the Survivor games, which apparently put too many people in one instance. Outside of that at Black Hat, it has been good.
I have expanded usage, and as a consultant doing client sales, we are always expanding and doing new installations. It seems pretty straightforward to increase and grow, onboarding new data sources, and so forth.
I would evaluate customer service and technical support as good on both parts. Compared to other vendors out there that can leave you hanging, I always get good, speedy responses.
Prior to adopting CrowdStrike Falcon Insight XDR, I was using Splunk to address similar needs.
The factors that led me to consider a change were seeing how XDR has matured over the last few years. It is becoming a product that is a lot easier to implement, turn on, and hand over to a client and a lot easier to maintain. The capabilities that most differentiate CrowdStrike Falcon Insight XDR from competing endpoint or XDR solutions, for me, is the cloud-native technology. I mentioned before that agents can self-update, and that has been a huge time saver for some clients compared to the manual effort involved in other vendors.
I would describe my experience with deploying CrowdStrike Falcon Insight XDR as easy and fast.
What made it easy for me is that it just seems incredibly easy to get the agent out there, turned on, and collecting data. I do not seem to be running into any massive roadblocks that I often do with other products.
What worked well in the deployment was probably just the ability to navigate the number of endpoints to reach in an environment that does not appreciate change. It turned out to be pretty easy, so we were able to get through it.
CrowdStrike Falcon Insight XDR has positively affected the productivity and effectiveness of my SOC. Without a doubt, it is making their lives easier. Some of my clients do not necessarily run a full SOC per se, but it is part of the individual's day job and it just makes it a bit easier for them so they can get on and do other things.
The impact that the Falcon sensor has on endpoint performance compared with solutions I previously used has been fine from a performance perspective. I think its ability to self-update is probably one of the best things about it compared to some other products where there is a lot of manual effort involved in updating.
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon Insight XDR.
The advice I would give to other organizations considering CrowdStrike Falcon Insight XDR is to just try it out. It is easy enough to put in there and try, and you do not have to throw away your existing toolset. I give this product a review rating of 9.
My main use case for CrowdStrike Falcon Insight XDR is to investigate incidents with the process tree and use their real-time response.
I always start by understanding what user is related to the incident, also the workstation or server related to the incident so I can open the host management group and understand more about that server. If we have some IOC or IOA involved, I try to place some Next-Gen SIEM workflow.
As a sales engineer, I am looking to understand my customer's objectives and I really try to design the best XDR way to work, so I'm trying to put some additional retention so we can correlate more incidents and understand the attack in a holistic point of view, unifying other products the customer may have.
CrowdStrike Falcon Insight XDR offers the fast way to investigate incidents, the easy integrations with Next-Gen SIEM and SOAR workflows, Fusion SOAR, the real-time response which is really useful, and also the commands and the whole engine and telemetry that we can use through the Falcon sensor.
Fusion SOAR helps to apply some scripts that we are building in PowerShell or other languages, allowing us to create templates, send them to the platform, and start to have better use cases to apply to our customers. The real-time response is for critical incidents that we have to address hands-on, and we are equipped for it. We know a lot of PowerShell scripts, we also know Linux well, so we are good with those resources, and it's really helpful.
CrowdStrike Falcon Insight XDR has positively impacted my organization by allowing us to understand behaviors and how our customers are suffering attacks, enabling us to anticipate those breaches. This is really useful as we start to become a real consultative partner to our customers. We can solve problems and suggest better processes, tools, or hiring a new service like MDR. Defense Security provides MDR to our customers, positively impacting the organization because we are not just selling CrowdStrike Falcon Insight XDR but our services as well.
CrowdStrike Falcon Insight XDR should have a manual guide or a user guide, as everything I have learned required me to put my hands on it, start a lab, and read the whole documentation. We can automate many processes through AI, which would be useful for us as partners to understand not just CrowdStrike Falcon Insight XDR but all CrowdStrike products more quickly so we can go to market and sell these products swiftly.
CrowdStrike Falcon Insight XDR is amazing, but I have heard that Palo Alto has a better UI interface, so maybe it is time to see what else can be improved regarding UX.
My experience with pricing, setup cost, and licensing could be better. I feel there is a lack of materials to assist sales engineers and account executives. Though we have to learn independently, it would help if the CrowdStrike LATAM team could be more accessible, as information often feels obfuscated. I have studied on my own and developed a method to license correctly and understand the need for additional ingestion or retention.
The scalability of CrowdStrike Falcon Insight XDR is good, though the process to apply it could be better. This is something we need to work on with our account executives from CrowdStrike.
I believe CrowdStrike Falcon Insight XDR's governance and security related to its AI capabilities are positive, although I need to understand it in a deeper way. As a matter of fact, we are doing such a great job, which is why we now have an ADR product and this partnership with NVIDIA.
I believe the accuracy and reliability of output from CrowdStrike Falcon Insight XDR's AI capabilities is fair, with responses that do not seem to exhibit hallucinations or drift, so I feel we are doing a great job.
CrowdStrike Falcon Insight XDR is deployed in my organization both on-premises and in the public cloud.
CrowdStrike Falcon Insight XDR is deployed in my organization both on-premises and in the public cloud.
I did not purchase CrowdStrike Falcon Insight XDR through the AWS Marketplace.
We are cutting off our MTTD metrics with CrowdStrike Falcon Insight XDR because we are combining this solution with Next-Gen SIEM, and we are answering to attacks and avoiding breaches faster, which is reflected in our MTTR metrics receiving very good numbers through CrowdStrike Falcon Insight XDR.
I have an example of return on investment regarding cost of a breach. The customer, protected by Abnormal Security implemented by Defense Security, showed during the POV with CrowdStrike Falcon Insight XDR that an attack was stopped. It was a business email compromise involving a fake invoice for $4 million.
My experience with pricing, setup cost, and licensing could be better. I feel there is a lack of materials to assist sales engineers and account executives. Though we have to learn independently, it would help if the CrowdStrike LATAM team could be more accessible, as information often feels obfuscated. I have studied on my own and developed a method to license correctly and understand the need for additional ingestion or retention.
I evaluated SentinelOne before choosing CrowdStrike Falcon Insight XDR.
I work with a wide range of solutions, including SentinelOne, Sophos, and Symantec, which informs my perspective as a sales engineer. It is not about why I switched but which solution fits my customer's needs, and CrowdStrike Falcon Insight XDR is leading this.
The capabilities that most differentiate CrowdStrike Falcon Insight XDR from other endpoint or XDR solutions are related to the anatomy of the attack, which I believe CrowdStrike Falcon Insight XDR accomplishes with perfection.
Since adopting CrowdStrike Falcon Insight XDR, I always try to position the adversary over what we have for our endpoint, which really helps us as threat hunters to understand the attack faster, including whether it is a nation-state attack or a script kiddie.
The value I get from correlating activity across endpoints and other security domains with CrowdStrike Falcon Insight XDR is substantial. The Next-Gen Identity Security integration is quite excellent and allows us to understand the attack context because we are unifying the endpoint plus the identity. I believe the detection capabilities of CrowdStrike Falcon Insight XDR are the best I have tried since we understand the full context of the attack rather than just relying on an IOC or a hash.
CrowdStrike Falcon Insight XDR reduces alert volume and analyst investigation time significantly. At Defense, we are one step ahead, working with Foundry and putting intelligence inside the Falcon Fusion workflow to improve processes, and CrowdStrike Falcon Insight XDR was just the beginning.
I use the MITRE ATT&CK framework, always trying to understand the attack point of view. Understanding initial access, persistence, and credential attacks with respect to this framework helps us to understand the attack faster and apply the necessary protections.
The impact of the Falcon sensor on endpoint performance compared to solutions I previously used is negligible. I have never received complaints or concerns about the sensor from my customers, as it is really lightweight.
CrowdStrike Falcon Insight XDR has affected the productivity and effectiveness of my SOC since we are applying AI-driven intelligence relying on traffic models, which allows us to work with other solutions. For example, customers at Google wanting to move to CrowdStrike benefit from the intelligence enhancements we have implemented after winning Mandiant.
To others looking into using CrowdStrike Falcon Insight XDR, I advise understanding the architecture and the FPP platform first, learning about the tools, the prevent feature such as NGAV, firewall management, device control, IOCs, IOAs, beacons, and so forth. After grasping this, it is crucial to understand how an attack works and how CrowdStrike analyzes behavior, as this will help illustrate the product's quality. I give this product a rating of ten out of ten.

I do not recommend using this review at all.
One of the best features that CrowdStrike Falcon Insight XDR offers is that it lets me sleep at night because I have faith that my environment is being watched and it really lets me focus on my end users and teaching them better habits, so I do not have to stress about the day-to-day.
As a small company, we do not have the bandwidth to give security the focus it needs, which is just a true fact about how it works. CrowdStrike Falcon Insight XDR gives us the overhead in terms of resources to make the most of what we have, and anytime I can free up myself to help my end users is a win.
CrowdStrike Falcon Insight XDR has positively impacted my organization by providing peace of mind knowing that we have oversight.
Having that oversight has affected my day-to-day work and the company overall. Every time I had a user who clicked the wrong thing, it gave me such relief to know that we had someone else looking out for us.
CrowdStrike Falcon Insight XDR has affected the productivity and effectiveness of our SOC or our security operations by making us incredibly effective because our time is utilized better.
CrowdStrike Falcon Insight XDR can be improved with a little more positive press about how good you are.
I have been using CrowdStrike Falcon Insight XDR for five years.
CrowdStrike Falcon Insight XDR is incredibly stable.
CrowdStrike Falcon Insight XDR has very good scalability.
CrowdStrike Falcon Insight XDR support is amazing, and I really am thankful for it.
CrowdStrike Falcon Insight XDR customer support is phenomenal.
We did not have a different solution previously.
We have not had to increase our staff, so fewer employees did not need to be added.
My experience with pricing, setup cost, and licensing for CrowdStrike Falcon Insight XDR is that it is very manageable and you get tremendous value for what you are purchasing.
I did not evaluate other options before choosing CrowdStrike Falcon Insight XDR.
I think it is a great product and if you have an environment, it is probably worth adding to it.
Regarding CrowdStrike Falcon Insight XDR's AI capabilities, I think it is a very good start and I believe they will continue to improve it.
I observe improvements in our processes for detecting and investigating because we use Falcon Complete, so I do not have to investigate.
My advice for others looking into using CrowdStrike Falcon Insight XDR is to invest in professional services, as having people guide you through setups is well worth it.
I rate CrowdStrike Falcon Insight XDR a 10 because I trust and love it.