My main use case for this platform is that it is strictly EDR.
Chief Information Security Officer at a energy/utilities company with 501-1,000 employees
Centralized security monitoring has reduced investigations and simplified multi-tool integrations
Pros and Cons
- "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by giving my team a single source outside of our SIEM to be able to quickly and easily drill into the incident and understand what the alert from our SIEM actually means."
- "Although after the CrowdStrike outage and blue screens, we have had to put in place additional controls to ensure that we have phased rollouts."
What is our primary use case?
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by giving my team a single source outside of our SIEM to be able to quickly and easily drill into the incident and understand what the alert from our SIEM actually means. It gives us a good spot to put integrations all in one location for our other platforms that we use, to bring everything into that single pane of glass and make it easy to use.
The benefits I have seen from having multiple security capabilities on a single CrowdStrike Falcon platform is that it is a good way to collapse down a bunch of disparate vendors and move everything into that single pane of glass. I do not have a lot of additional complexity in managing a bunch of separate vendors. Different capabilities, even if a separate vendor may have a slight edge, we will still likely consider rolling that into CrowdStrike.
CrowdStrike Falcon has affected the workload and productivity of my security team by allowing us to spend less time on our investigations because we have a single pane of glass, and that frees them up to work on our actual project work and other things that are probably higher value.
What needs improvement?
In my opinion, CrowdStrike Falcon platform can be improved by adding the improvements, functionality, or features that we would to see, which have actually been announced already, and that is the Guardian platform for AI. Using it to monitor agents now because it is going to be built into the endpoint, built into the sensor itself, being able to understand prompts, and then be able to see what agents are doing and how they are affecting identity usage. All of that is what we had on our wish list. We could look at a third party, but I would really prefer it be built into CrowdStrike.
The impact that the CrowdStrike Falcon sensor has had on endpoint performance and our ability to deploy security at scale is that the only noticeable impact was the CrowdStrike outage. On a day-to-day use case, I do not think we have ever found the CrowdStrike client to actually cause any sort of real major impact.
For how long have I used the solution?
Since my initial deployment, my use of CrowdStrike Falcon platform has not expanded, but I think it will be expanding with some of the announcements from Fal.Con.
Buyer's Guide
CrowdStrike Falcon
September 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,788 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon and its agent as being great. With the exception of the CrowdStrike outage, it has not been one of our platforms that has required a lot of additional care and feeding. Although after the CrowdStrike outage and blue screens, we have had to put in place additional controls to ensure that we have phased rollouts. It would be nice if we could more easily or more automatically have a little more granularity and control to get rid of some of my board processes and governance that I have had to set up around that. Outside of that, it is a very stable platform.
What do I think about the scalability of the solution?
I am not planning to expand the number of deployments, but I will expand the feature set and use cases.
How are customer service and support?
I would evaluate CrowdStrike's technical and customer support as excellent. We have never had a problem. At the enterprise level, we are probably a very large account, and so I have access to anybody that I need to talk to. There are no issues. We have never had any issues where we have had a question that was not able to get resolved.
Which solution did I use previously and why did I switch?
The other security tools I have used or evaluated include Microsoft Defender, McAfee, and Carbon Black. Those are the main ones that I have looked at.
How was the initial setup?
My experience with deploying CrowdStrike Falcon is that I was not around for the deployment, but I have never heard of anybody complaining about how the deployment went.
What was our ROI?
I would say I have not seen a return on my investment with CrowdStrike Falcon, but that is only because it is not really something that we were looking for a return on. We were solving a problem. There was not a financial bet. The return would be freeing up my team, so maybe from a time perspective, that would be where I would put it. It would be difficult to quantify. The fact that it is easier to manage than the competitors is valuable. We also have Trellix in our environment just because that is the only thing that the vendors that we have to deploy it to support. That is a very small subset of infrastructure, and my team has to spend more time messing around with that than we have to spend on CrowdStrike.
What's my experience with pricing, setup cost, and licensing?
In terms of my experience with pricing, set up costs, and licensing, I do not have any feedback that is under my purview. The only feedback that I would have there is it would be amazing if we could get a much better breakdown of all the SKUs and our entitlements, current entitlements, and costs for additional entitlements. There is a lot of opportunity there, but that is not specific to CrowdStrike. That is most places in the enterprise world.
Which other solutions did I evaluate?
What differentiates CrowdStrike Falcon platform from other cybersecurity platforms I have used or evaluated is that the biggest differentiator is the super lightweight client. The other differentiator is probably the breadth of functionality that is available if we wanted to buy it. Having it all in that one spot versus Trellix, Microsoft Defender, or something else, I would still have to buy a bunch of other third-party vendor products to fill in the holes in those spaces. It is nice to have that all-in-one, very lightweight client that is easy for my team to use.
What other advice do I have?
A security incident where CrowdStrike Falcon helped my team detect or stop a threat is that we have very few of those. We have a lot of false positives. We run a very conservative point of view on our alerting and so we want to see everything. We have not had a really a true positive. To be clear, this is in our business servers and our OT environments, not our endpoints. Somebody else handles our endpoints with CrowdStrike. There are true positives in there, but since we do not really have true positives in our business environment, it gives us a good way to very quickly rule out those false positives.
I have plugged in six or seven other platforms into CrowdStrike Falcon platform.
The value I see from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is really not having to go into all of our other platforms to see that data.
On an individual incident, I estimate it probably saves each individual analyst 15 or 20 minutes.
I handle probably 10 to 15 incidents in a day.
My advice to someone who is evaluating this platform based on my experience with it is to run demos. It is pretty easy to get set up. It is easy to run. Ensure that it integrates with all of your platforms. Make sure you get really close with your account team. I would rate this platform a 9 out of 10 based on my overall experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriateManager, Information Security at a leisure / travel company with 1,001-5,000 employees
Consolidated endpoint protection has improved threat prevention and streamlined investigations
Pros and Cons
- "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because we feel a lot more secure as it is very good at stopping threats."
- "I would assess the stability and reliability of CrowdStrike Falcon as being awesome, other than the great CrowdStriking. I have experienced downtime, crashes, or performance issues."
What is our primary use case?
My main use cases for CrowdStrike Falcon involve protecting all our endpoints and all our servers. CrowdStrike Falcon has allowed me to consolidate or replace other security tools.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because we feel a lot more secure as it is very good at stopping threats. It makes it very easy to investigate what happened and what triggered the event. Our response time is a little better when we have to actually dig into something.
The benefits I have seen from having multiple security capabilities on a single platform include that it makes it much easier to get to what I need quickly instead of trying to switch platforms. Sometimes switching between modules, the interface is not always the same and does not feel the same. However, largely it is usually very together and it works well.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that if we do have to open up other security tools, sometimes we can leverage what CrowdStrike Falcon sees to quickly get to what is another security tool because it exposes that information.
Using CrowdStrike Falcon has affected the workload or productivity of my security team because in a lot of ways it has actually lowered the workload as it does such a good job of preventing the threats. If something triggers on another system but CrowdStrike Falcon is not triggering it, we are automatically suspect whether it is a real problem.
What needs improvement?
I have not yet used AI within CrowdStrike Falcon. I cannot think of a way that CrowdStrike Falcon itself can be improved. I do not have any suggestions for additional features that should be included in the next release for CrowdStrike Falcon as it does a very good job by itself.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about six years.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as being awesome, other than the great CrowdStriking. I have experienced downtime, crashes, or performance issues.
The detail I can provide about the performance issues involves the same traumatic thing everyone has gone through, which is the great CrowdStriking. It was bad; I am a casino, so this was on a weekend, overnight.
What do I think about the scalability of the solution?
I have not noticed any impact on performance from the CrowdStrike Falcon sensor regarding endpoint performance and my ability to deploy security at scale.
How are customer service and support?
I would evaluate customer service and technical support by saying that every time I have had to access it, they have been very good.
Which solution did I use previously and why did I switch?
We used to use Bitdefender and it was not awesome, so we replaced it. We also have replaced some SIEM and some other detective systems with CrowdStrike Falcon.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as very easy. We have Active Directory, so we just deploy with Active Directory and it works very well. What worked well during the deployment was that it just worked, so there were not really a lot of challenges. It was configure this in Active Directory, deploy it, and it works.
What about the implementation team?
My use of CrowdStrike Falcon has expanded since the initial deployment as we started off with just workstations and now it is deployed to every surface we can get it on.
What was our ROI?
I believe I have seen a return on investment with CrowdStrike Falcon as I honestly believe it has saved us money and stopped threats.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is that everybody complains about pricing. I am not going to be that much different, but they are not outrageous, and I have dealt with companies that are outrageous. On a scale of one to 10, one being really super affordable and 10 being Palo Alto, I would say it is a seven or an eight.
Which other solutions did I evaluate?
What differentiates CrowdStrike Falcon from the other cybersecurity platforms I have used or evaluated is that the biggest differentiator is that it does not, to me, at the time when we got it, rely on knowing what the bad threat is. It sees the action of the threat and relies on that, so there are no signatures required and that is a pretty big deal.
What other advice do I have?
My advice for other organizations considering CrowdStrike Falcon is that it is worthwhile to test drive and compare it to other systems. I give this review a rating of 9.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriateBuyer's Guide
CrowdStrike Falcon
September 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,788 professionals have used our research since 2012.
Manager at Azuria Water Solutions
Unified security platform has reduced workload and has stopped ransomware attempts quickly
Pros and Cons
- "CrowdStrike Falcon has drastically reduced the workload and increased the productivity of my security team."
- "CrowdStrike Falcon can be improved by continuing to adapt to everything that is going on with AI and other developments in the world."
What is our primary use case?
My main use cases for CrowdStrike Falcon involve everything security. In more detail, we use Falcon Complete to ensure our users are completely covered.
What is most valuable?
The benefits I have seen from having multiple security capabilities on a single platform are significant because we do not have to go to different types of portals to get any kind of access; it is all in one. CrowdStrike is actually taking care of everything on the back end, so we do not have to worry about trying to go from one thing to another to figure out what is going on within our environment.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same Falcon platform is significant because it is a one-stop shop that eliminates the need to go from one to another; it is all in one console.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because we use Falcon Complete, which means the majority of it is that we do not have to constantly monitor everything that is going on. Falcon Complete actually monitors that for us, and when things do pop up, we are literally just reaching out to our users and following up after the fact of everything that Falcon Complete has done to remediate the issues.
CrowdStrike Falcon has drastically reduced the workload and increased the productivity of my security team.
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is zero; it is very easy with no impact whatsoever since it is very lightweight.
What needs improvement?
CrowdStrike Falcon can be improved by continuing to adapt to everything that is going on with AI and other developments in the world.
The one improvement I would suggest for the future is to make the console side of CrowdStrike Falcon more user-friendly, but as explained, most of those details are not things we need to worry about because those are things that Falcon Complete takes care of; overall, it is all good.
For how long have I used the solution?
I have been using CrowdStrike Falcon for four years.
What do I think about the stability of the solution?
Outside of the blue screen week, I have experienced really no downtime, crashes, or performance issues; the security factor of it all is top-notch.
I would assess the stability and reliability of CrowdStrike Falcon as really, really top-notch.
What do I think about the scalability of the solution?
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is zero; it is very easy with no impact whatsoever since it is very lightweight.
How are customer service and support?
I would evaluate customer service and technical support as still top-notch.
Which solution did I use previously and why did I switch?
The tools I used previously included Trend Micro, and we were also using Proofpoint for a lot of things; much of that has been able to be consolidated into CrowdStrike Falcon, allowing us not to use those products anymore, making it feel like one console to do two things.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that we used Trend Micro before, and their team was nowhere near as experienced or available to us, nor were they collaborative to ensure that anything that happened was at zero trust. We were able to get most attacks handled within the first few minutes before anything abruptly took place.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy, super easy.
What about the implementation team?
What worked during deployment was literally zero challenges; the biggest thing was when we went from Trend to CrowdStrike Falcon, where CrowdStrike Falcon did not care if Trend was installed, and they just took over management of everything. After that, it was just up to us to get rid of Trend Micro from all the machines that had it installed.
What was our ROI?
I have seen return on investment with CrowdStrike Falcon absolutely.
The data points or examples I can share are the many times we have almost had ransom attacks on our systems, and all of them have been stopped.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing has been very good and very easy.
Which other solutions did I evaluate?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools, and that is all we have been using.
What other advice do I have?
The advice I would give to other organizations considering CrowdStrike Falcon is that if you are really worried about the cost of it, it is worth it.
I am using AI within CrowdStrike Falcon for deep security issues, but to be honest, we do not use it completely; we really depend on Falcon Complete to do most of the work.
I really cannot think of how my use of CrowdStrike Falcon has expanded since my initial deployment.
My review rating for CrowdStrike Falcon is a 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriateCo-Owner at a manufacturing company with 1,001-5,000 employees
Automated endpoint protection has saved my team time and simplifies threat remediation
Pros and Cons
- "My advice to others looking into using CrowdStrike Falcon is to not look at anything else and to use it instead."
What is our primary use case?
My main use case for CrowdStrike Falcon is endpoint protection. I use CrowdStrike Falcon for general endpoint remediation if users happen to click on malicious content.
What is most valuable?
The automated task set is excellent. The best features CrowdStrike Falcon offers include automated tasks that remove the need for me to go in and manually remediate threats.
CrowdStrike Falcon has positively impacted my organization by removing task work that the tech would normally have to complete by using the automation processes. It has definitely saved time for my team's workload.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats as it usually detects threats and remediates them before we even have to take any action, definitely saving us a lot of time.
The benefits from having multiple security capabilities on a single platform include that it is easier to manage from a single pane of glass. CrowdStrike Falcon has allowed us to look into consolidating or replacing other security tools, and we are actually looking into that currently.
In a recent security incident, we noticed a few times where CrowdStrike Falcon stopped potential malware from running and removed it before it could establish a foothold. CrowdStrike Falcon sensor has positively impacted endpoint performance by keeping the systems clean and running optimal, aiding our ability to deploy security at scale.
What needs improvement?
We heard that the newest features coming soon are a major improvement that we would definitely be interested in. We have seen the announcement for the Red Team, Blue Team features, and they sound excellent. We are planning to use AI within CrowdStrike Falcon in the future.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about six years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
So far, there have been no issues with CrowdStrike Falcon's scalability.
How are customer service and support?
The customer support for CrowdStrike Falcon has been excellent. I would rate the customer support a 10 on a scale of 1 to 10.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been that so far, it is very easy to work with licensing and setup.
Which other solutions did I evaluate?
Before choosing CrowdStrike Falcon, we evaluated other options and currently overlap with Darktrace, but Darktrace's cost is making us look elsewhere.
What other advice do I have?
CrowdStrike Falcon is deployed in my organization using a hybrid cloud setup. What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that so far, it is a well-recognized name with good performance and a good overall reputation. I love it. My advice to others looking into using CrowdStrike Falcon is to not look at anything else and to use it instead. It works and it works great. I would rate this product a 10 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 1, 2026
Flag as inappropriateIT Security Engineer at a financial services firm with 10,001+ employees
Unified security telemetry has transformed how my teams detect, hunt, and respond to threats
Pros and Cons
- "CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by providing more advanced telemetry, faster response times, and better intelligence to identify anomalies in the ever-evolving cybersecurity landscape."
- "CrowdStrike has been a good partner, but there are times when we need to escalate support faster."
What is our primary use case?
As an infrastructure organization, we are using CrowdStrike Falcon to enable the tooling for our response, intel, and hunting teams. Currently, we are not using AI within CrowdStrike Falcon platform; our interest is outside the platform where we can access multiple telemetry streams through our SIEM. Although I think there is a use case within the platform itself, we have made the decision as a firm that it is probably better to use that aggregation of telemetry outside of the platform.
What is most valuable?
CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by providing more advanced telemetry, faster response times, and better intelligence to identify anomalies in the ever-evolving cybersecurity landscape.
The value we have seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform allows other teams with expertise in those cross-domains to communicate more effectively and efficiently amongst the response, intel, and hunting teams.
CrowdStrike Falcon has affected the workload and productivity of my security team by making us more effective and efficient in what we are doing. The work has exploded, but it helps us do more.
What needs improvement?
CrowdStrike has been a good partner, but there are times when we need to escalate support faster. With any large security organization, it takes a little bit of time to get to the right place, and if we can speed up the support model, that would always be better.
When we get our issues escalated properly, the right teams from CrowdStrike are on board to help me understand the problem in depth and resolve it quickly, but it takes a while to reach that escalation point.
When we open a case, it often takes some time to get it routed to the experts since there are basic questions that do not directly address what we are asking. If our support teams could take a step back and correctly route our queries faster, it would improve the experience.
For how long have I used the solution?
I have been using CrowdStrike Falcon for approximately six years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as very stable, providing us great telemetry. However, I think that there probably could be more done with networking telemetry.
Other than July 19th of 2024, there has been perfect performance with CrowdStrike Falcon, and that specific date has become notable for everyone.
What do I think about the scalability of the solution?
CrowdStrike Falcon sensor allows us to deploy security at scale with a lightweight sensor, which is one of the reasons why we were interested in CrowdStrike Falcon to begin with.
How are customer service and support?
CrowdStrike has been a good partner, but there are times when we need to escalate support faster. With any large security organization, it takes a little bit of time to get to the right place, and if we can speed up the support model, that would always be better.
When we get our issues escalated properly, the right teams from CrowdStrike are on board to help me understand the problem in depth and resolve it quickly, but it takes a while to reach that escalation point.
When we open a case, it often takes some time to get it routed to the experts since there are basic questions that do not directly address what we are asking. If our support teams could take a step back and correctly route our queries faster, it would improve the experience.
Which solution did I use previously and why did I switch?
Our experience with deploying CrowdStrike Falcon was when we switched from a competitor that was not advanced. We were approved to finish the project in about 18 to 24 months but were asked to complete it within three months, and we significantly reduced our time for deployment, accomplishing it in record time with a small number of resources.
How was the initial setup?
What worked well was our familiarity with the products, but we faced challenges as we were significantly expanding our response team, which was basically non-existent. This allowed us the opportunity to move into hunting and expand that and intel.
What about the implementation team?
My use of CrowdStrike Falcon platform has expanded since the initial deployment, as we have added several modules and now have better correlation across different security domains.
What was our ROI?
We have seen return on investment with CrowdStrike Falcon. We deployed CrowdStrike Falcon Identity module and immediately started seeing detections that turned out to be true positives, which we were able to mitigate and resolve very quickly. We realized that adding modules provides immediate returns on investment.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon pricing, setup costs, and licensing are on the expensive side, but we highly value what you provide. The value proposition yields amazing returns but comes at a cost commensurate with the platform's sophistication.
What other advice do I have?
On a scale from one to ten, I would rate CrowdStrike Falcon as a nine; you are great, but I cannot give a perfect score. My advice for other organizations considering CrowdStrike Falcon is that with the right plan and the right support from CrowdStrike, it is possible to deploy CrowdStrike Falcon endpoint very quickly and efficiently in a way that is safe and reliable. I provided this review with an overall rating of nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriateNetwork Security Engineers at Silver State Schools Credit Union
Integrated security platform has transformed incident response and reduced investigation time
Pros and Cons
- "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by improving the flow with the detections and the alerting."
- "For customer service and technical support, it can be spotty at times."
What is our primary use case?
My main use case for CrowdStrike Falcon is incident response.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by improving the flow with the detections and the alerting. One of the things I also have is the MDR, so that also helps with mitigating a lot of the problems as well.
The benefits I have seen from having multiple security capabilities on a single platform include just the time to remediate and to stop the threat.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that you understand what you know and what you don't know. Having all the telemetry data feed into one main system actually helps in quickly detecting threats and also seeing trends, patterns, or connections.
CrowdStrike Falcon has greatly affected the workload and productivity of my security team, which is me, by reducing the time I spend in the platform. With some workflows and creating some automation around it, it has improved my work-life balance because many tasks that I ended up doing multiple times daily are now automated, allowing me to focus on other things that need to be addressed.
What needs improvement?
I think CrowdStrike Falcon can be improved by making the menu a little bit more intuitive. I know some people like how every menu looks the same, but I don't prefer it because it makes me forget where I am or where I'm going or how to get to some place.
For the next release, I would like to see UI improvements, and also to have it where I don't need to drill into a device's alerting or submenus to just hit contain. If I bring up a device, I want a quick button there to contain it because if I'm clicking on that device, there's something I'm looking into and most likely I've been alerted of something, so I should probably contain it first and then ask questions later.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as pretty solid; it's perfect.
I have experienced no downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
Since my initial deployment, my use of CrowdStrike Falcon hasn't expanded; I think we got rid of some portions. We still have Falcon Complete, but we used to have Falcon Recon, which we got rid of. Now, we are looking back into it because of the Guardian and new steps announced with Recon today. It seems we lowered our use primarily from a customer-facing and interaction standpoint, not due to the technology itself.
How are customer service and support?
For customer service and technical support, it can be spotty at times. With CrowdStrike Recon, we got rid of it due to customer service problems; however, since then, customer reps have been in touch, quite active, vocal, and checking in on us. The support has gotten better since the initial experience.
Which solution did I use previously and why did I switch?
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used is the experience with SentinelOne for EDR and using InsightVM for vulnerability management. I used Adaptive Shield, which is now Falcon Shield, but I would say in the case of Adaptive Shield, it only got worse, mainly from a UI perspective. When it was integrated into CrowdStrike Falcon, it lost its methodical structure, making it hard to navigate. In terms of EDR, I think SentinelOne has an advantage because if I drill into a host or endpoint, I can quickly perform a bunch of actions from the initial click while I already have received the alert and a high confidence rating from CrowdStrike Falcon.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as easy because I use NinjaOne, which automatically does it. It's great, buy NinjaOne.
What about the implementation team?
What worked well for me was NinjaOne, and I faced honestly zero challenges. The API was easy to set up on both sides within CrowdStrike Falcon and NinjaOne, allowing us to see detections and other things as soon as we were in there. One challenge I faced was on NinjaOne's side, not CrowdStrike Falcon's side, and I would like to see integrations where we have more choice with our third-party vendors.
What was our ROI?
I can say I've seen a return on investment with CrowdStrike Falcon in terms of time and energy spent gathering information about events, but since I'm not the one spending the money, I can't really say more.
Which other solutions did I evaluate?
CrowdStrike Falcon hasn't helped me consolidate other tools, but with the announcement of Guardian and using it, it has begun the process of talking about consolidating things because right now, I use InsightIDR as my SIEM and am looking to move to the next-gen SIEM and create more workflows from there.
We haven't yet consolidated, but the impact would be that all the telemetry and plugins and everything I do, especially the workflows, would happen from CrowdStrike Falcon and not third-party. The other impact would be that I can actually integrate more because with Rapid7, I struggle with integrations from a lot of our other partners.
What other advice do I have?
My advice to other organizations considering CrowdStrike Falcon is to take a look at their third-party integrations and see what opportunities exist within CrowdStrike Falcon before making a final purchase. This way, they know which portions of CrowdStrike Falcon they actually need or want, especially since some features tie in deeply with tools like NinjaOne, making daily tasks, deployments, and implementations much easier and more manageable. I would rate this product a 9 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriateCISO at a financial services firm with 1,001-5,000 employees
Unified security platform has transformed threat hunting and accelerated incident response
Pros and Cons
- "Since using CrowdStrike Falcon, I have seen a lot faster incident response actions, containment, and it helps me mitigate many threats automatically that I previously handled manually."
What is our primary use case?
My main use case for CrowdStrike Falcon is protecting endpoints and cloud security. For endpoint or cloud security, I do a lot of threat hunting inside my environment using all the telemetry that CrowdStrike Falcon provides, and I tackle incidents by quarantining, deleting, and investigating remotely, among other actions. I have a lot of old software and operating systems, and CrowdStrike Falcon helps me protect all the boundaries of those systems.
What is most valuable?
In my opinion, the best features CrowdStrike Falcon offers are the Threat Graph, the investigation page, and the telemetry. The Threat Graph and the telemetry help my team day-to-day by providing insights during my threat hunting process on what's running, what's happening, what rules I can build, and what TTPs may be under the radar, with the Threat Graph being useful for new joiners and day-to-day incident response actions.
CrowdStrike Falcon positively impacts my organization by helping to protect us, providing us with a lot of visibility, and helping to show my board how my protection status is currently. Since using CrowdStrike Falcon, I have seen a lot faster incident response actions, containment, and it helps me mitigate many threats automatically that I previously handled manually.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by bringing a lot faster incident response times, including the MTTR and MTDR key indicators. Having multiple security capabilities on a single platform like CrowdStrike Falcon is helpful because my team does not need to change a lot of interfaces or consoles, and working within just one console is more helpful, which I believe brings more value to my team's time spent on the platform.
CrowdStrike Falcon lowers the workload and augments the productivity of my security team.
What needs improvement?
I think that bringing more AI and insights into anomalies could be helpful for CrowdStrike Falcon. I would also appreciate having CrowdStrike Falcon on legacy systems such as IBM AIX. Currently, I am not using AI within CrowdStrike Falcon, but I plan to do so.
For how long have I used the solution?
I have been working in my current field for at least fifteen years.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
What do I think about the scalability of the solution?
I just plug in more licenses and agents for scalability, and there is no complexity involved.
How are customer service and support?
The customer support is excellent, as I receive a lot of help from customer support and also from my technical and sales partner.
Which solution did I use previously and why did I switch?
I replaced Trend Micro with CrowdStrike Falcon, which brings more value with more precise detection and more automated responses. I previously used Trend Micro Vision One, and I switched because it was impacting me with many false positives and causing production disruptions.
How was the initial setup?
CrowdStrike Falcon was not purchased through the AWS Marketplace; it was purchased with a sales partner.
What was our ROI?
I have seen money saved and time saved, as I have augmented the capacity of my current team without needing to hire more people.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was good, as I received a lot of help from CrowdStrike Falcon itself and my sales partner Stelltech, making it a great experience.
Which other solutions did I evaluate?
I have evaluated other options, such as Microsoft, before choosing CrowdStrike Falcon.
What other advice do I have?
CrowdStrike Falcon differentiates itself from other cybersecurity platforms I have used or evaluated by having a lower learning curve compared to its competitors, as well as better accuracy and widely recognized superior telemetry. My advice to others looking into using CrowdStrike Falcon is to conduct a POC, as I believe the product proves itself during the POC.
CrowdStrike Falcon is unique in its ability to deploy security at scale quickly, as I do not see other vendors providing such options. I do not see any impact on endpoint performance, and CrowdStrike Falcon is unique in its ability to deploy security at scale quickly, as I do not see other vendors providing such options.
The alerts and capabilities of CrowdStrike Falcon are very precise, and with the AI built in, it brings more value and is becoming more powerful in recent months. I rate this review ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriateSenior Software Security Engineer at MGM Resorts International
Unified visibility has improved identity investigations but correlating data still needs work
Pros and Cons
- "CrowdStrike Falcon has affected the workload or productivity of my security team considerably better, because now I have visibility of what is happening within the organization from an identity perspective and a security perspective."
- "The only part that I get frustrated by is how many repetitions that they have across each part."
What is our primary use case?
My main use cases for CrowdStrike Falcon are broad. I mostly work in identity and access management, and I like to have a source of third-party truth module for various activities that we do. I rely on CrowdStrike Falcon to track most of the activities, and I try to use the user login information of various users.
Just because a user has access does not essentially mean they are using that access. In order to find out what sort of access is being used, I know which systems use what groups, but whether they have logged into those systems is something that I can pull in from CrowdStrike Falcon.
My use of CrowdStrike Falcon has expanded since my initial deployment because I learned a lot. I became aware of CrowdStrike Falcon, and then the incident happened, and then I started mostly using it.
What is most valuable?
The benefits I have seen from having multiple security capabilities on a single platform are substantial, as I appreciate the fact that they have a lot of metadata about metadata logs and about various activities that are happening within the organization. The only part that I get frustrated by is how many repetitions that they have across each part.
When I want to correlate multiple data and create a singularized dashboard, it becomes a nightmare and sometimes even impossible. For example, if you have the assets and you give me the users who logged into those assets, I can get a tabular view of that information. But if I want to create a dashboard out of it and create notifications with it, that is where my pain point comes in.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because I mostly try to create a couple of dashboards and KPI metrics in CrowdStrike Falcon customs, and that helps me to identify any odd usage of accounts. As an IAM team member, I know which accounts are used by whom and at what point in time they are being used. We can make a considerable guess, and we try to create rules around that and create notifications based on those activities.
CrowdStrike Falcon has affected the workload or productivity of my security team considerably better, because now I have visibility of what is happening within the organization from an identity perspective and a security perspective. Having visibility of all the servers, servers come and go when the organization is big. Having visibility of when the servers are created and who has logged into servers helps us better remediate the accesses and stick to the least access principle and least privilege principles.
What needs improvement?
I cannot talk about return on investment because I do not know how much it is or how much was invested, but regarding return on effort with CrowdStrike Falcon, I find it really good because with a small amount of effort, I can decipher a lot of information. I would say it is good. What worked well and what challenges I faced include understanding a couple of tables, the headers that you give to the tables, and no flexibility in writing the table headers or the data extraction in the individual tables. There are a couple of columns that I can siphon out, but from an overall perspective, I cannot do much customization around it.
I believe CrowdStrike Falcon can be improved regarding the cross; you have all the information in a kind of a bucket, but when I want to correlate all this information into a singularized view is when I am having issues.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three or four years, probably.
What do I think about the stability of the solution?
I would assess the stability and reliability of CrowdStrike Falcon as a ten, because I have never seen it go down. Reliability is also ten, because inconsistency of data is something that I never found. Filters probably rate a five.
I have experienced no downtime, crashes, or performance issues.
How was the initial setup?
I would describe my experience with deploying CrowdStrike Falcon as five or six, because I am still in a learning stage.
What other advice do I have?
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that it is more in the sense that instead of having one hundred tools, you have a single tool that performs those one hundred activities.
A security incident where CrowdStrike Falcon helped my team detect or stop a threat is not overall team related, but I mostly use it for investigation purposes from my own. Out of ten, five or six is how much it helps me.
My advice to other organizations considering CrowdStrike Falcon is that it is good to have and gives unified visibility across the organization. With whatever seminars I have been to and a couple of meetings I have attended, I would say a lot of interesting things are happening, so it is worth checking out. I rate this review a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriateVice President, Information & Security at a tech vendor with 201-500 employees
Unified security platform has transformed threat detection and accelerated incident response
Pros and Cons
- "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because it is much easier to use than any tool I have used before."
- "CrowdStrike Falcon can be improved in that the UI takes a little bit to understand where to go and how to get there."
What is our primary use case?
My main use cases for CrowdStrike Falcon are endpoint security, intrusion detection and response, and a SIM tool.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because it is much easier to use than any tool I have used before. It feels more like a partnership than just a vendor. CrowdStrike seems to be very quick to adopt new technology.
CrowdStrike Falcon sensor has had an impact on endpoint performance and my ability to deploy security at scale by making it extremely easy to deploy security at a large scale. I have zero issues with performance on my endpoints.
The benefits I have seen from having multiple security capabilities on a single platform are that it is easier to use. Ease of use is paramount. Nobody wants to have to jump into twenty different systems in the event of an emergency.
The value I have seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that in the event of an emergency, nobody wants to run to an article or a how-to runbook and dig through the specific scenario in order to know which tool to access. Having everything under a single pane of glass makes it much easier to address issues.
CrowdStrike Falcon has allowed me to consolidate or replace security tools. CrowdStrike Falcon is very much a platform and not a single use tool. I have been able to do a lot of vendor consolidation by bringing on CrowdStrike Falcon.
The impact of consolidating tools is having the ability to do the tasks of multiple vendors in one single pane of glass. That is what has really impressed us.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that it is such a large company that is the top line for pretty much every aspect of their tool. When new technology emerges, they are the first to embrace it, the first to adapt to it, and the first to release updates.
My use of CrowdStrike Falcon has expanded since my initial deployment. I initially deployed it just for endpoint management and then realized all of the things that CrowdStrike Falcon can do, including Overwatch. Now I have a team actually watching over all the anomalies that pop up in my system.
What needs improvement?
CrowdStrike Falcon can be improved in that the UI takes a little bit to understand where to go and how to get there. With every new release, I see a change in the user interface that makes it much easier to follow.
An additional feature that should be included in the next release is free AI.
For how long have I used the solution?
I have been using CrowdStrike Falcon for four years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as excellent, as we have never had an issue. We are a Mac shop, so we were not part of the outage.
I have not experienced any downtime, crashes, or performance issues. I realize that this is unique, but we are a Mac shop.
How are customer service and support?
I evaluate customer service and technical support as extreme and top of the line.
What about the implementation team?
My experience with deploying CrowdStrike Falcon is that I have had all the support in the world from CrowdStrike to help me navigate any changes. It is very easy to deploy through my MDMs.
What worked well in my deployment is that their online resources were extremely easy and their staff are very quick to respond. Challenges I faced are the same as with any new app in that it is hard to navigate a new user interface. CrowdStrike's UI is a little complicated and takes a while to get used to.
What was our ROI?
I have seen return on investment for CrowdStrike Falcon by the nature of vendor consolidation and lack of downtime.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is great. They work with all of my vendors and resellers, or I could buy directly through the AWS marketplace. The purchasing process is extremely easy.
What other advice do I have?
A security incident where CrowdStrike Falcon helped my team detect or stop a threat involved a contractor who came on who may not have actually been a human. CrowdStrike Falcon helped us discover malicious activity and we were able to remediate without losing anything.
CrowdStrike Falcon has affected the workload and productivity of my security team because it is so easy to use. We have been extremely productive and proactive. CrowdStrike is also the first to tell us about emerging technologies, so we know about it before the general marketplace.
We are using AI within CrowdStrike Falcon in that it is everywhere. AI is a tool to translate extremely complicated technical jargon into very easy to follow runbooks, words, verbiage, how-tos, and automations. That is how we are using it.
The impact AI has had on my security operations is that it allows computers to do computer things, so we do not have to have human interaction when it comes to security frameworks.
The advice I would give to other organizations considering CrowdStrike Falcon is to just implement it. I rate this product a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriateSenior Vice President, Director of Information Security at a financial services firm with 201-500 employees
Security platform has unified threat visibility and enabled faster incident response for small teams
Pros and Cons
- "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making our response time much quicker and giving me confidence in the alerts and information we receive."
What is our primary use case?
My main use cases for CrowdStrike Falcon are incident response to attacks, alerting, and threat intelligence.
What is most valuable?
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making our response time much quicker and giving me confidence in the alerts and information we receive.
Having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is much easier to manage since it all comes in through one platform, eliminating the need for cross-checking and making things much more efficient.
I have seen benefits from having multiple security capabilities on a single platform, particularly in identifying potential false positives or true positives where one system did not pick it up, and CrowdStrike Falcon did, ensuring our security.
CrowdStrike Falcon has definitely affected the workload and productivity of my security team by making us much more efficient, especially since we have a small team of only two people, which allows us to work much easier.
What needs improvement?
I believe CrowdStrike Falcon can be improved by continuing to keep up the good work, staying informed about global developments, and keeping us updated.
I would like to see additional features in the next release, such as SafeMind and further advancements in how AI is used to attack, react, and build defenses, which I think is terrific.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three and a half years.
What do I think about the stability of the solution?
I assess the stability and reliability of CrowdStrike Falcon as terrific since we have not had any issues; it is always running, with only occasional minor issues related to specific hardware.
I have experienced one instance of downtime where we had an update to a sensor that caused an issue with Microsoft, but we resolved it quickly.
What do I think about the scalability of the solution?
The impact of the CrowdStrike Falcon sensor on endpoint performance and my ability to deploy security at scale has been great, with only one issue regarding a few machines where the sensor would not update, but for the most part, it has been great with very few issues.
How are customer service and support?
I would evaluate customer service and technical support as great, with my current account representative being very responsive and no issues encountered.
Which solution did I use previously and why did I switch?
Previously, we were using Microsoft Defender, which had some tuning issues and was harder to configure, but CrowdStrike Falcon has helped clean up some issues that we did not identify right away.
How was the initial setup?
My experience with deploying CrowdStrike Falcon has been easy overall; every place I have used it has been fairly simple and quick, without any issues.
What about the implementation team?
My experience regarding what worked well and the challenges I faced was more related to resources and getting other teams involved in the deployment rather than issues with CrowdStrike Falcon itself.
What was our ROI?
I have definitely seen a return on investment with CrowdStrike Falcon, making it easier for me to sleep at night, especially as we are a small organization that does not operate 24/7.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing has been simple and without any issues.
Which other solutions did I evaluate?
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is its much easier usability compared to the past security platforms.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools, providing a secondary look at our current systems and a second set of eyes that verifies what I see, thus cutting down the need for additional security.
What other advice do I have?
CrowdStrike Falcon has allowed me to consolidate or replace other security tools, providing a secondary look at our current systems and a second set of eyes that verifies what I see, thus cutting down the need for additional security. I have given this review a rating of 9.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriateBuyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
IBM Security QRadar
Elastic Security
Huntress Managed EDR
Trellix Endpoint Security Platform
TrendAI Vision One
WatchGuard Firebox
HP Wolf Security
Microsoft Defender XDR
Symantec Endpoint Security
Check Point Harmony Endpoint
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?
















