CrowdStrike Falcon Pros

Jeffrey-Anderson - PeerSpot reviewer
Security Analyst II at a healthcare company with 10,001+ employees
I like the dashboard nature of it. Everything is clickable, linkable, and information is easy to obtain and find. How it presents that information is probably the biggest win as far as the information correlation aspect. The presentation of it is very good.
View full review »
Erik Hart - PeerSpot reviewer
Chief Information Security Officer at a real estate/law firm with 10,001+ employees
As long as the machine is connected to the Internet, and CrowdStrike is running, then it will be on and we will have visibility; no VPNing in or making some type of network connection. CrowdStrike always there and running in the background; for us, that is big. We wanted something that could give us data as long as the machines connected to the Internet and be almost invisible to the employees.
View full review »
Jim McCartney - PeerSpot reviewer
Information Security Analyst at a insurance company with 1,001-5,000 employees
The 10 hours a week that we are freeing up from having to manage and monitor our AV solution has really allowed us to focus on other areas of the business. This has been a huge return on investment.
View full review »
Buyer's Guide
CrowdStrike Falcon
November 2022
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: November 2022.
653,522 professionals have used our research since 2012.
Michael Getz - PeerSpot reviewer
Enterprise Cybersecurity Architect at Swagelok Company
Probably the most valuable thing to me is the real-time response piece. The fact that I can connect to an endpoint as long as it is on the Internet, no matter where it is globally. I can remove files from the endpoint, drop files on the endpoint, stop processes, reboot it, run custom scripts, and deploy software. Pretty much no other tool can do all that.
View full review »
NormanCyman - PeerSpot reviewer
IT Security Analyst at U.S. Venture, Inc.
From what we have seen, it is very scalable. We have recently acquired a company where someone had a ransomware attack when we joined networks. Within the course of just a few days, we were able to easily get CrowdStrike rolled out to about 300 machines. That also included the removal of that company's legacy anti-malware tool.
View full review »
AT
Chief Security Officer at a financial services firm with 201-500 employees
The OverWatch is the most valuable feature to me. It's a 24x7 monitoring service, and when they see anything suspicious in my environment, they will investigate.
View full review »
Adam Shusterman - PeerSpot reviewer
Cyber Security Engineer at a legal firm with 501-1,000 employees
It has definitely minimized resources. When everything was on-prem, there was a lot more work maintaining it. One of the big value tickets: I don't have lists of hundreds of exceptions for certain applications that I have to maintain, add, delete, and move. The very nature of the product has lessened my workload considerably.
View full review »
Stephen Hand - PeerSpot reviewer
Director, IT & Systems Security at Tilson Technology Management
The Protect functionality on the laptops provides great visibility into what's occurring, and the cloud management of the platform is what we needed.
View full review »
JS
Director of IT at a tech services company with 51-200 employees
We have a small IT Team, and this allows us to get sleep at night, knowing that someone else is taking care of any incidents that occur.
View full review »
Syed Ubaid Ali Jafri - PeerSpot reviewer
Head of Cyber Defense & Offensive Security at Habib Bank Limited
The CS falcon agent is a lightweight agent compared with other agents of EDR products.
View full review »

CrowdStrike Falcon Cons

Jeffrey-Anderson - PeerSpot reviewer
Security Analyst II at a healthcare company with 10,001+ employees
I would like them to improve the correlation of data in the search algorithms. When we run an investigation, malware, phishing, etc., I want to look at multiple endpoints at once to correlate that data to see the likenesses, e.g., how are they not alike or what systems and processes are running across those systems? I don't want to have to run the same search in their Spotlight module five, 10, 15, or 100 times to get 100 different results, copy that data out, and then correlate it on my own. In a very simple way, I want to be able to load up a comma-delimited list giving me the spotlight data on these X amount of hosts, letting me search for it quickly. We have had to go back to CrowdStrike, and say, "Our search are taking far too long for even one host." They did bump up the cores and that did improve performance, but it is still kind of slow to get that Spotlight data. That is probably our biggest pain point. I think that needs some help. I understand this kind of information access is probably not the easiest thing to do. It is probably a big ask depending on how their back-end is setup.
View full review »
Erik Hart - PeerSpot reviewer
Chief Information Security Officer at a real estate/law firm with 10,001+ employees
I would love to see more investment in Insight because CrowdStrike have an opportunity to potentially displace some of the vulnerability management vendors with the visibility they can see over time. I want to see them continue to evolve, e.g., what other things can they disrupt which are operational things we have to continue to do as an organization.
View full review »
Jim McCartney - PeerSpot reviewer
Information Security Analyst at a insurance company with 1,001-5,000 employees
It would be nice if they did have some sort of Active Directory tie-in, whether that be Azure or on-prem. Sometimes, it is difficult for us to determine if we are missing any endpoints or servers in CrowdStrike. We honestly don't have a great inventory, but it would be nice if CrowdStrike had a way to say this is everything in your environment, Active Directory-wise, and this is what doesn't have sensors. They try to do that now with a function that they have built-in, but I have been unsuccessful in having it help us identify what needs a sensor. So, better visibility of what doesn't have a sensor in our environment would be helpful.
View full review »
Buyer's Guide
CrowdStrike Falcon
November 2022
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: November 2022.
653,522 professionals have used our research since 2012.
Michael Getz - PeerSpot reviewer
Enterprise Cybersecurity Architect at Swagelok Company
A year and a half ago or more, if you put in a support request by email, then it wasn't timely addressed. It could be a day to three days before you received a response, which was a bit frustrating. There was a lot of customer feedback around this issue, which has been greatly refined.
View full review »
NormanCyman - PeerSpot reviewer
IT Security Analyst at U.S. Venture, Inc.
I would like to see a little bit more in the offline scanning ability. This just comes from my background in what I have done in other positions. They only scan on demand, so I always have this fear that we sometimes maybe email out a dormant virus and can be held liable for that. That is something where I would like to see a little bit more robustness to the tool.
View full review »
AT
Chief Security Officer at a financial services firm with 201-500 employees
If we have a dashboard capability to uninstall agents, I think that would be great.
View full review »
Adam Shusterman - PeerSpot reviewer
Cyber Security Engineer at a legal firm with 501-1,000 employees
There are some aspects of the UI that could use some improvement, e.g., working in groups. I build a group, then I have to manually assign prevention policies, update policies, etc., but there is no function to copy that group. So, if I wanted to make a subgroup for troubleshooting or divide workstations into groups of laptops and desktops, then I have to manually build a brand new group. I can't just copy a build from one to another. Additionally, in order to do any work within a group, I have to first do the work on the respective prevention policy page or individual policy page, then remove the group if the group is assigned to a different prevention policy, remove the prevention policy, and then add the new one in. So, it can get a little hectic. It would be easier if I could add and remove things from the group page rather than having to go into the policy pages to do it.
View full review »
Stephen Hand - PeerSpot reviewer
Director, IT & Systems Security at Tilson Technology Management
The console is a little cluttered and at times, finding what you're looking for is not intuitive.
View full review »
JS
Director of IT at a tech services company with 51-200 employees
It would be nice if the dashboard had some more information upfront, and looked a little better.
View full review »
Syed Ubaid Ali Jafri - PeerSpot reviewer
Head of Cyber Defense & Offensive Security at Habib Bank Limited
CS Falcon sensing capabilities for non-domain machines should be enhanced since the agent doesn't detect the neighbor's IP Address and/or any anomaly which was identified in the network for the non-domain machine.
View full review »
Buyer's Guide
CrowdStrike Falcon
November 2022
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: November 2022.
653,522 professionals have used our research since 2012.