No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2894955 - PeerSpot reviewer
data and cyber security manager at a construction company with 11-50 employees
Real User
Top 20
Sep 2, 2026
Unified security platform has simplified endpoint protection and strengthened continuous defense
Pros and Cons
  • "CrowdStrike Falcon helps my security team quickly respond to alerts escalated from the Falcon Complete team and has minimized the business impact of potential compromises."
  • "The main complaint that myself and leadership have about CrowdStrike Falcon is that the cost has become expensive compared to competitors."

What is our primary use case?

CrowdStrike Falcon serves as our main endpoint protection and vulnerability management solution, particularly for scanning. We deploy it across our environment using the MDR, endpoint protection, and SIM solution.

Due to our organization being very merger and acquisition heavy, one of our primary use cases is rapidly deploying CrowdStrike Falcon to all endpoints when we bring on a new organization.

What is most valuable?

The 24/7 monitoring through the MDR portion of CrowdStrike Falcon is very valuable, as my team is lean and cannot monitor all endpoints or alerts around the clock.

One of the best features that CrowdStrike Falcon offers is the Next-Gen SIM, which includes free daily ingest of up to 10 gigabytes per day. This feature stands out to me because it helps with costs and has helped me sell the product to leadership, since we were only adding an additional gigabyte for Falcon Complete to take over that portion of the SIM. The data that endpoints already feed back to the console is valuable in its own right.

I really appreciate the built-in connectors and dashboarding inside the console of CrowdStrike Falcon, which works very well when I need to send a report to leadership on sensor health. It is easy to use and straightforward to read.

CrowdStrike Falcon helps my security team quickly respond to alerts escalated from the Falcon Complete team and has minimized the business impact of potential compromises.

CrowdStrike Falcon has prevented many compromises in my organization, as there have been many detections on endpoints that Falcon has prevented from escalating.

The Falcon sensor has had a positive impact on endpoint performance and my ability to deploy security at scale.

What needs improvement?

The main complaint that myself and leadership have about CrowdStrike Falcon is that the cost has become expensive compared to competitors.

Cost is really the only significant area needing improvement for CrowdStrike Falcon. More direct connectors on the SIM side could be beneficial, but I am already quite satisfied with the current offerings, and I understand that some limitations depend on vendors rather than CrowdStrike, such as Fortinet.

I have not used many of the AI capabilities of CrowdStrike Falcon yet, though I have experimented with Charlotte to a limited extent.

From what I have seen of CrowdStrike Falcon, the AI capabilities seem to work fairly well in terms of accuracy and reliability of output.

The only factor preventing a perfect rating is the actual cost of the product, as it is expensive. It is best in market, but it is somewhat pricey compared to achieving a full ten.

For how long have I used the solution?

I have been using CrowdStrike Falcon for four years.

Buyer's Guide
CrowdStrike Falcon
September 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,517 professionals have used our research since 2012.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

Its scalability has worked well for us, as we use NinjaOne as our RMM and deploy it to our endpoints through that platform.

How are customer service and support?

The customer support for CrowdStrike Falcon has been fantastic.

I would rate the customer support for CrowdStrike Falcon as ten out of ten.

What was our ROI?

I have seen a return on investment with CrowdStrike Falcon.

What other advice do I have?

I benefit greatly from having multiple security capabilities on a single platform, as it is advantageous not to have numerous different agents installed on endpoints and to be able to leverage a single sensor.

CrowdStrike Falcon sensors are installed across all of our endpoints.

We use Microsoft Azure as our cloud provider.

The single sensor approach of CrowdStrike Falcon differentiates it from other cybersecurity platforms I have used or evaluated.

My use of CrowdStrike Falcon has expanded since the initial deployment, as we have added additional modules to the sensor, including Spotlight and Next-Gen SIM.

My experience with pricing, setup cost, and licensing for CrowdStrike Falcon is positive, but the licensing cost is somewhat expensive.

I would advise others looking to use CrowdStrike Falcon to fully leverage the solution and build into the Falcon stack, as it works exceptionally when you have the different modules deployed.

I would give CrowdStrike Falcon a nine on a scale of one to ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriate
PeerSpot user
Charles Martin - PeerSpot reviewer
Chief Information Officer at Tucker Freight Lines
Real User
Top 20
Sep 2, 2026
Unified security platform has improved threat detection and streamlined investigations
Pros and Cons
  • "What differentiates CrowdStrike Falcon from other security platforms I have used or evaluated is that it is much more comprehensive and it is a single platform for multiple vulnerabilities."
  • "So far, the benefits I have seen from having multiple security capabilities on a single platform have been limited, but based on the testing, we see that it is identifying threats and it has shown us proactive capabilities to shut down the threats."

What is our primary use case?

For my main use cases with CrowdStrike Falcon, we tested vulnerability assessment and we also tested threats, AI intrusion threats, and vulnerability detection.

What is most valuable?

Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats. Although we are too new to really change behavior, it has identified some behaviors that we need to correct.

For example, it has identified threats and user behavior, including user risk behavior.

So far, the benefits I have seen from having multiple security capabilities on a single platform have been limited, but based on the testing, we see that it is identifying threats and it has shown us proactive capabilities to shut down the threats.

I recognize that having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is going to make it very efficient for our team because previously, we had to search and diagnose threats from multiple locations and multiple issues from different locations.

I estimate that we will have time saved, and I think it will be hours where we would go in and track who the offending email was and where it came from. Having one platform for each incident will probably save us twenty minutes to a half hour per incident.

The impact that CrowdStrike Falcon sensor has had on endpoint performance and my ability to deploy security at scale is too new to assess.

So far, CrowdStrike Falcon has allowed me to replace Trend Micro right away with it.

What needs improvement?

CrowdStrike Falcon platform is too new to suggest ways it could be better or additional features that should be included in the next release.

For how long have I used the solution?

I have been using CrowdStrike Falcon for less than one week.

What do I think about the stability of the solution?

So far, I would assess the stability and reliability of CrowdStrike Falcon as too new to provide a comprehensive evaluation.

How are customer service and support?

I would evaluate CrowdStrike's customer and technical support as excellent in getting us where we are in the testing phase and closing sales.

The reason for my rating is the willingness to answer questions, the willingness to demonstrate, and the willingness to call up third-party references.

Which solution did I use previously and why did I switch?

The factors that impacted that change were that we did the testing and found out that it was not adequate to handle all the vulnerabilities that we had, and through testing, it identified more. We knew that this product would replace and extend our capabilities, so as opposed to keeping what we had and adding three other products, we wanted to consolidate everything in one platform.

What differentiates CrowdStrike Falcon from other security platforms I have used or evaluated is that it is much more comprehensive and it is a single platform for multiple vulnerabilities.

How was the initial setup?

So far, it has not had any impact on my security operations because we signed the contract Wednesday with a test deployment, and now we will get the official deployment when we return. Part of us testing and coming to CrowdStrike was part of the experimental process of getting it deployed and finding out what other people are using it for.

I have not deployed CrowdStrike Falcon into my production environment, but we have tested it.

What about the implementation team?

During my test, the experience with deploying CrowdStrike Falcon was very easy with the assistance of professional services or the implementation team, so we are ready. Their assistance has us ready to turn it on and to start right away. There is not a startup process; based on the testing, we are ready now to deploy.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing was a traditional business venture where you go back and forth and ask for what you want. The only surprising piece for me was that there is a third-party vendor who we purchased from. I thought we would be dealing directly with CrowdStrike, and we were dealing with a third party that offered financing and handled all the contracts, and that is who we paid. I was prepared to write a check to CrowdStrike and it is not that way. That was the surprising piece. I will not say it is negative or positive, but that was the surprising piece. I thought it would all be consolidated.

What other advice do I have?

If I would rate CrowdStrike Falcon on a scale of one to ten, I would give it a ten.

What would make it a ten for me is if everything was consolidated in one, where I did not have to deal with a third party and a go-between.

My advice to other companies considering CrowdStrike Falcon is to make sure you get references and make sure that you adequately do the vetting and testing.

I would rate this review overall as a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
CrowdStrike Falcon
September 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,517 professionals have used our research since 2012.
reviewer2894949 - PeerSpot reviewer
Security Analyst at a manufacturing company with 201-500 employees
Real User
Top 20
Sep 2, 2026
Endpoint defense has strengthened visibility and now supports faster compliant investigations
Pros and Cons
  • "CrowdStrike Falcon has positively impacted my organization by providing better visibility, host management, compliance, and real-time responses."
  • "The customer support for CrowdStrike Falcon on the commercial side is great, but the government side is not as strong."

What is our primary use case?

My main use case for CrowdStrike Falcon is EDR. For EDR, I use CrowdStrike Falcon for identity, endpoint management, and device control.

What is most valuable?

The best features CrowdStrike Falcon offers are endpoint and device control, identity threat protection, and AI-generic responses. What I appreciate about the endpoint and device control in CrowdStrike Falcon is that it allows me to lock down USBs for all hosts on the policies applied company-wide.

CrowdStrike Falcon has positively impacted my organization by providing better visibility, host management, compliance, and real-time responses. A specific example that demonstrates how CrowdStrike Falcon has improved visibility or compliance is response times and compliance with NIST 800-171 for CMMC, with an example of locking down mass storage and access controls.

What needs improvement?

One specific example of how CrowdStrike Falcon can be improved would be the ability to export the device control exceptions for auditability purposes, and perhaps a cleaner UI.

For how long have I used the solution?

I have been using CrowdStrike Falcon for one year.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

CrowdStrike Falcon's scalability is great, as long as I have the licenses for more sensors.

How are customer service and support?

The customer support for CrowdStrike Falcon on the commercial side is great, but the government side is not as strong.

How was the initial setup?

Since my initial deployment, my use of CrowdStrike Falcon has expanded, and I definitely feel better as a security analyst, more knowledgeable, and have better investigation processes.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that I was able to lower the price a bit by going from a one-year to a three-year contract, but it was still very expensive for the three-year commitment.

Which other solutions did I evaluate?

Before choosing CrowdStrike Falcon, I did not evaluate other options, as I was not part of that decision.

What other advice do I have?

I would rate CrowdStrike Falcon a nine on a scale of one to ten because I never give anything a perfect score, and it is almost a ten.

Regarding CrowdStrike Falcon's AI capabilities, I think its governance and security are great. Its accuracy and reliability of output seem reliable, but I have not used it enough, as I rely mostly on the Falcon Complete team and my own individual investigations.

CrowdStrike Falcon is now deployed in my organization on GovCloud due to the recent migration.

CrowdStrike Falcon has allowed me to consolidate or replace other security tools, as I actually got rid of some such as Exonius.

The benefits I have seen from having multiple security capabilities on a single platform are faster response time, quicker identification for investigations, and better overall security posture.

I can describe a security incident where CrowdStrike Falcon helped my team detect or stop a threat involving individuals getting fooled by malicious emails and links, and CrowdStrike Falcon stopping it and allowing me to use the sandbox to see what would have occurred and how it was stopped.

CrowdStrike Falcon has affected the workload or productivity of my security team by making response times faster and visibility quicker and more seamless.

The CrowdStrike Falcon sensor has had a lightweight effect on endpoint performance, is easy to roll out, and there is really no difference at all when it comes to response or processes, other than being faster than it was prior to having CrowdStrike Falcon sensors on my hosts.

What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that so far it is the best, but it is definitely the most expensive.

My advice for others looking into using CrowdStrike Falcon is to invest in it, as it is a good solution. I would rate CrowdStrike Falcon a nine out of ten overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriate
PeerSpot user
reviewer2895258 - PeerSpot reviewer
Security Engineer at a outsourcing company with 1,001-5,000 employees
Real User
Top 20
Sep 4, 2026
Rapid threat response has improved investigations and simplified unified security operations
Pros and Cons
  • "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats."
  • "CrowdStrike Falcon sensor has had an impact on endpoint performance and my ability to deploy security at scale."

What is our primary use case?

My main use cases for CrowdStrike Falcon are MDR, SIEM, and incident response.

I can describe a security incident where CrowdStrike Falcon helped my team detect or stop a threat. We had a stolen session token that somebody had phished and reused. We were able to respond on CrowdStrike Falcon within three minutes. It was really fast. We were able to find what we needed, figure out it was malicious, and then we revoked the tokens within three minutes. It was really quick and probably the fastest reaction we ever had.

What is most valuable?

Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats. We are a lot faster than we were previously. The investigations are easier. I can do forensics a lot faster and easier than what our last vendor had for us, which was Arctic Wolf.

The benefits I have seen from having multiple security capabilities on a single platform include having all the data in one place, which makes it easy. It makes it a lot faster for me to find what I need and to correlate that data as well, so it helps a lot.

Having endpoint, identity, cloud, and other security telemetry in CrowdStrike Falcon benefits us because we can correlate a lot more data from different places where we could not before. We had to copy and paste session ID numbers and UUIDs from one place to the other.

What needs improvement?

I did not think much about how CrowdStrike Falcon can be improved. For additional features that should be included in the next release, I would suggest the ability to save my queries, which would make it a lot easier. The only other thing I can think of is to make the query buttons, such as the save and load query buttons, a little bit bigger and easier to access.

For how long have I used the solution?

I have been using CrowdStrike Falcon for about a year now.

What do I think about the stability of the solution?

I would assess the stability and reliability of CrowdStrike Falcon as very stable and very reliable. We have not had it give us a lot of false positives.

I have not experienced any downtime, crashes, or performance issues.

What do I think about the scalability of the solution?

CrowdStrike Falcon sensor has had an impact on endpoint performance and my ability to deploy security at scale. The sensor itself on some of the machines had a little bit of a learning curve and some growing pains when we installed it at first. We had some users complain that CrowdStrike Falcon was blocking their application, but as soon as we got the necessary exclusions in place, everything was fine. It was a little bit of a learning curve for some of our developers.

How are customer service and support?

I would evaluate customer service and technical support as great. I have only had to call customer support once and they were great.

What was great about my experience with technical support is that they were responsive and called me back.

Which solution did I use previously and why did I switch?

I replaced Arctic Wolf because Arctic Wolf did our vulnerability management and our SIEM. CrowdStrike Falcon replaced that. We were also using ESET and Bitdefender, and CrowdStrike Falcon also replaced those for our endpoint.

What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that I have used many cybersecurity tools, and CrowdStrike Falcon is on the cutting edge of cybersecurity. You have more features, your detections are better, and they are more reliable. I prefer CrowdStrike Falcon much better than all the tools I have used. I used to work for a competitor, so I worked for LogRhythm a long time ago, and LogRhythm is still stuck in the past.

How was the initial setup?

I would describe my experience with deploying CrowdStrike Falcon as really easy to deploy. We set it up in NinjaOne and pushed it out and used a GPO for the rest.

What worked well was the installation, which went really well. We did not have any major issues getting it installed. The only challenges we had were that it started blocking things right away before we could get the exclusions in place.

What about the implementation team?

My use of CrowdStrike Falcon has expanded since my initial deployment. We are still in the process of expanding to other things. We are about to start using the AIDR feature, which we were not using previously. We had not rolled out VM management until very recently. We were still using Arctic Wolf for that, and we just started using CrowdStrike Falcon for that as well. We are still expanding it and turning on features that we did not have before.

What was our ROI?

I have seen return on investment with CrowdStrike Falcon. Whatever it costs, it was worth it.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing was easy. I cannot provide data points or examples because I do not know what we paid for it.

Which other solutions did I evaluate?

CrowdStrike Falcon has allowed me to consolidate or replace other security tools.

What other advice do I have?

The advice I would give to other organizations considering CrowdStrike Falcon is to deploy it on the endpoints. However, do not install it until you are ready and have the exclusions in place. A good feature that could be added would be a monitoring mode when you first install it, so it does not start blocking things right away. I give CrowdStrike Falcon a rating of ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriate
PeerSpot user
reviewer2894940 - PeerSpot reviewer
PTPM at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 1, 2026
Endpoint telemetry has transformed how my team detects misuse and responds to data risks
Pros and Cons
  • "The advice I would give to others looking into using CrowdStrike Falcon is that they have great capabilities and good pricing options."
  • "CrowdStrike Falcon is pretty accurate and reliable, but the only part where we lack visibility is whether the endpoint has started reporting or is not reporting."

What is our primary use case?

My main use case for CrowdStrike Falcon is endpoint detection. We look at the telemetry data from endpoint protection and determine policy violation, abnormal activities, and usage details for endpoint detection.

How has it helped my organization?

CrowdStrike Falcon has improved the workload and productivity of my security team by force multiplying our existing capability. The Falcon sensor has positively impacted endpoint performance and my ability to deploy security at scale because it is a one-click solution. We can pick the policies we want to roll out based on the targeted group, and we are able to do that.

What is most valuable?

The best features CrowdStrike Falcon offers are the telemetry data at the endpoint and the ability to control sensitive actions such as screenshot, copy-paste, and printing.

The controls over sensitive actions help my team detect unjustified business use cases of taking actions. Through CrowdStrike Falcon endpoint monitoring, we are able to detect who is taking these unjustified accesses, and then we take corrective action.

CrowdStrike Falcon has positively impacted our organization by enabling us to detect unauthorized business use cases early enough. We have built our machine learning models to raise the alarm to detect data exfiltration sooner and improve the time to response.

Using the Falcon platform has changed the way our security team detects, investigates, and responds to threats by providing more insight on the data. That insight used to be reactive; now, proactively we can set the control based on this data, and based on the baseline usage, we can deploy our security controls.

The benefits I have seen from having multiple security capabilities on a single platform is that it is a one-stop shop, allowing me to have all the capabilities under one platform so I do not have to navigate between multiple tools.

What needs improvement?

CrowdStrike Falcon can be improved with more capabilities such as watermarking and preventing sensitive content from being screenshotted.

CrowdStrike Falcon is pretty accurate and reliable, but the only part where we lack visibility is whether the endpoint has started reporting or is not reporting. We do not have data on how many endpoints on a given day are reporting versus not reporting, so we would appreciate that visibility. This way, we know where the endpoint is not recording and can take corrective action to ensure we have updated endpoints.

For how long have I used the solution?

I have been using CrowdStrike Falcon for over three years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

CrowdStrike Falcon's scalability is good, as we are able to scale to half a million endpoints.

How are customer service and support?

We do not directly deal with CrowdStrike customer support, but we have a dedicated team who obtained our licensing. We work with them and provide our input to them, and they in turn work with CrowdStrike support to get things addressed.

Which solution did I use previously and why did I switch?

Before using CrowdStrike Falcon, we used Reveal and next-generation Reveal, and we are still using it. Once the parity between Reveal and CrowdStrike Falcon is there, we will deprecate Reveal and move on to Falcon.

How was the initial setup?

I purchased CrowdStrike Falcon through the AWS Marketplace.

What about the implementation team?

CrowdStrike Falcon is deployed in my organization in a private cloud.

What was our ROI?

I have seen a return on investment, and as I mentioned, our partner team handles all the licensing and cost aspects. We are the consumers of the Falcon endpoint data.

What's my experience with pricing, setup cost, and licensing?

I do not directly handle the pricing, setup cost, and licensing, as we work with a partner team who handles the licensing and cost. I do not have to worry about it.

Which other solutions did I evaluate?

Before choosing CrowdStrike Falcon, I evaluated Reveal as an option.

What other advice do I have?

The advice I would give to others looking into using CrowdStrike Falcon is that they have great capabilities and good pricing options. They offer good stability as well as large coverage, so they are truly a leader in the market. The Falcon sensor has positively impacted endpoint performance and my ability to deploy security at scale because it is a one-click solution. We can pick the policies we want to roll out based on the targeted group, and we are able to do that.

What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is its scale and ease of deployment, plus the telemetry data. However, there are some capabilities which I still need CrowdStrike Falcon to update, so that will provide an edge over the other existing tools which I am using.

Falcon has not yet allowed me to consolidate or replace other security tools, as we are still using other competitive tools, but our end goal is to have those benefits existing in CrowdStrike Falcon, so that we can deprecate other tools and use CrowdStrike Falcon exclusively.

I can describe a security incident where Falcon helped my team detect a threat by allowing us to see a user accessing unauthorized GenAI third-party applications, which is not within their business standard operating procedure. We took action and blocked those third-party websites, and that insight came from CrowdStrike Falcon endpoint data.

I would rate this product an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 1, 2026
Flag as inappropriate
PeerSpot user
reviewer2894994 - PeerSpot reviewer
IT Support Engineer at a media company with 51-200 employees
Real User
Top 20
Sep 1, 2026
Advanced endpoint insights have improved license usage tracking and strengthened security response
Pros and Cons
  • "My advice to others looking into using CrowdStrike Falcon is that it is a very powerful tool that provides a lot of insights."
  • "I have not seen a return on investment from CrowdStrike Falcon."

What is our primary use case?

My main use case for CrowdStrike Falcon is to deploy it to our endpoints, set update policies, and sometimes use the advanced search to search up specific events.

I also used it in the past to query app usage, and the sensor collects DNS request logs that I use to determine whether or not people are actively using the licenses that we give them, such as Cloud licensing, ChatGPT, Figma, and others.

My usage of CrowdStrike Falcon is limited to the advanced search feature. I am not a security engineer, and I use it to help fill in the gaps for my job function.

Since we don't have much of a security team, we let CrowdStrike Falcon operate independently. My use of CrowdStrike Falcon has not expanded since my initial deployment. I use my limited time to look at things when necessary, and my usage has been limited to what I have already described.

What is most valuable?

I believe the advanced search is one of the best features CrowdStrike Falcon offers.

What stands out to me about the advanced search in CrowdStrike Falcon is that it gives me a lot of insight into what my endpoints are doing, which is helpful as a sysadmin.

CrowdStrike Falcon has positively impacted my organization by being a lightweight sensor. In the past, we dealt with issues where users complained that our deployed endpoint detection and remediation tool was using too much bandwidth on a computer or CPU usage. However, I found no complaints with CrowdStrike Falcon, which is beneficial.

Regarding how the lightweight sensor of CrowdStrike Falcon affected my team's productivity, there are fewer complaints about slowdowns from my end users and less time spent in a console trying to figure out why slowdowns are occurring, which definitely frees up time.

What needs improvement?

CrowdStrike Falcon can be improved by adding some sort of data-at-rest insights into what is on these PCs. I know there are other tools that CrowdStrike offers that do this, but I have not had any experience with them.

For how long have I used the solution?

I have been using CrowdStrike Falcon for about three years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

CrowdStrike Falcon's scalability is good.

How are customer service and support?

I have limited contact with customer support for CrowdStrike Falcon, but the group that helped onboard us was great.

I can rate the customer support based on my limited experience. The onboarding team deserved a ten.

Which solution did I use previously and why did I switch?

I started directly with CrowdStrike Falcon and did not previously use a different solution.

I have used CrowdStrike Falcon to replace Sophos, which was the tool that users were complaining was causing slowdowns.

How was the initial setup?

The setup process is very easy.

What was our ROI?

I have not seen a return on investment from CrowdStrike Falcon. It provided me a little more insight into what is going on in my environment, but it is difficult to quantify into a dollar amount.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for CrowdStrike Falcon was that pricing was very expensive, so much so that we could not justify onboarding it at first. However, after some back and forth with CrowdStrike representatives and getting quotes from other providers, CrowdStrike was willing to work with us to adjust some items included in the subscription contract and provided us a price that we could justify to our finance team.

Which other solutions did I evaluate?

Before choosing CrowdStrike Falcon, I evaluated other options such as Sophos, Microsoft Defender, and Carbon Black.

What other advice do I have?

I have no experience with CrowdStrike Falcon's AI capabilities.

I have no experience with the accuracy and reliability of output from CrowdStrike Falcon's AI capabilities.

I cannot comment on whether CrowdStrike Falcon is deployed in my organization on public cloud, private cloud, hybrid cloud, or on-premises, as I have no experience with how it is deployed.

The benefits of having multiple security capabilities on a single platform like CrowdStrike Falcon include ease of access, as I don't need to jump between tools, and compatibility, as things just work.

I can describe a security incident where CrowdStrike Falcon helped my team detect a threat. We needed to determine whether the Axios attack was going to impact us and whether any sensitive proprietary code may have been stolen. With CrowdStrike Falcon's advanced search, I was able to determine that we were not affected and that we had nothing to worry about.

CrowdStrike Falcon has affected the workload of my IT team by making us seem more competent in the security aspect of things. I was able to quickly provide an update to my CTO on whether this was going to impact us, and that is a significant achievement for me.

My advice to others looking into using CrowdStrike Falcon is that it is a very powerful tool that provides a lot of insights. I have trusted it for three years and believe you could as well. I would rate this product a perfect ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 1, 2026
Flag as inappropriate
PeerSpot user
Security Engineer at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 2, 2026
Advanced detection has protected hospital endpoints and supports rapid investigation of threats
Pros and Cons
  • "CrowdStrike Falcon has positively impacted my organization day-to-day when it catches any suspicious activities or any malicious files in my environment."
  • "There are definitely a couple of things CrowdStrike Falcon should improve, but I don't have all of them in my mind at this moment."

What is our primary use case?

My main use case for CrowdStrike Falcon is mostly endpoint detection, scanning the endpoints to protect our endpoints in our hospital environment against any malicious files, downloads, and executions. A specific example of how I have used CrowdStrike Falcon for endpoint detection is when it catches a suspicious PowerShell execution from a suspicious file and a suspicious exe exemption. I investigate those events accordingly. CrowdStrike usually stops that execution, but there is some possibility that it may not block those executions. I investigate those incidents using CrowdStrike along with other tools, not only CrowdStrike.

What is most valuable?

In my opinion, the best features CrowdStrike Falcon offers are definitely the MDR solution, which is the best in the field. I also appreciate its next-gen SIEM solutions, and I am interested in CrowdStrike's DLP solutions as well. There is also an OverWatch MSSP feature, but I don't use it in my environment yet.

Out of those features I mentioned, I rely on the MDR solution the most day-to-day. I definitely use MDR, which is what I pay for the most. I use next-gen SIEM, but I use Splunk as a SIEM solution, so in CrowdStrike's next-gen SIEM, I use it only for the CrowdStrike events. I don't ingest data from other tools to CrowdStrike's next-gen SIEM. The EDR solution is my favorite one.

CrowdStrike Falcon has positively impacted my organization day-to-day when it catches any suspicious activities or any malicious files in my environment. That definitely impacts my organization positively.

What needs improvement?

There are definitely a couple of things CrowdStrike Falcon should improve, but I don't have all of them in my mind at this moment. I would need to check my notes to provide you with a comprehensive list.

For how long have I used the solution?

I have been working in my current field for two years.

What do I think about the stability of the solution?

CrowdStrike Falcon has no issues and is stable.

What do I think about the scalability of the solution?

CrowdStrike Falcon handles growth well, and its scalability is good.

How are customer service and support?

Customer support is great. I am happy with my representative.

Which solution did I use previously and why did I switch?

I previously used Dell EDR.

What other advice do I have?

Regarding CrowdStrike Falcon's AI capabilities, I don't work in the governance department, and my organization doesn't 100% implement the AI features in my environment. I know CrowdStrike is using AI to triage the events, so the events are 99% triaged before coming to me. I don't have a better answer for this question.

Regarding the accuracy and reliability of CrowdStrike Falcon's AI output, I am not able to answer that question as I have no information about it.

CrowdStrike Falcon has not allowed me to consolidate or replace other security tools.

Having multiple security capabilities on a single platform like CrowdStrike Falcon definitely has advantages but also disadvantages. I don't want to put all the eggs in one basket, so I appreciate CrowdStrike and use some of its capabilities, but I don't want to put all my security investments in CrowdStrike. I prefer to use other tools as well.

CrowdStrike Falcon's sensor has not had any issues on endpoint performance, and my ability to deploy security at scale has not been negatively impacted.

CrowdStrike Falcon has made things easier regarding the workload and productivity of my security team.

What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is definitely its innovation, common usage, and ease of use. I would rate my overall experience with this product a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriate
PeerSpot user
reviewer2895246 - PeerSpot reviewer
Security Engineer at a financial services firm with 10,001+ employees
Real User
Top 20
Sep 4, 2026
Centralized endpoint protection has streamlined threat response and reduced security team workload
Pros and Cons
  • "Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats much faster and more robustly."
  • "I have not used CrowdStrike Falcon support in the last couple of months, but I would say it is average."

What is our primary use case?

My primary use case for this solution is the administration of CrowdStrike Falcon. I administer CrowdStrike Falcon and ensure it remains operational. My use case for CrowdStrike Falcon itself is endpoint protection.

What is most valuable?

Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats much faster and more robustly. Investigating detections is easier to review. Alerts happen and the platform makes them pop up on the screen, which is very user-friendly.

The benefits I have seen from having multiple security capabilities on a single platform are how comprehensive its detection capabilities are with such little overhead. The platform uses low CPU and low memory but provides really quick evaluation of what is occurring. CrowdStrike Falcon has affected the workload and productivity of my security team by streamlining maintenance and ensuring it remains operational. This has given us time back to focus on non-CrowdStrike Falcon related activities. The platform is not complicated and is very streamlined to maintain.

What needs improvement?

CrowdStrike Falcon can be improved by continuing what it is doing as it remains stable. Although we have had issues where a new sensor was released with some bugs that caused us problems, that has subsided, especially since last summer. All new releases have been very stable.

For how long have I used the solution?

I have been using CrowdStrike Falcon for about four years.

How are customer service and support?

I have not used CrowdStrike Falcon support in the last couple of months, but I would say it is average. When I open a ticket, it may be ignored for the rest of the day and not addressed until the next day. While we have an account manager to leverage, their first-level support tends to ask the same questions repeatedly, which is not beneficial. I would place support at a five on a scale of one to ten.

What was our ROI?

I cannot put a number to it, but I am saving a lot more time with this platform compared to other solutions that I used in the past. I would not be able to put a number on the return on my investment in this platform as I am not involved in that aspect.

What other advice do I have?

A security incident where CrowdStrike Falcon helped my team detect and stop a threat involved an application developer who created a script that was going out of control on a server, and it would have deleted all the files from the main file system. CrowdStrike Falcon detected it and immediately stopped it, which was very helpful. This was an internal mistake and not caused by an adversary. The damages would have been a complete loss of the server and it would have had to have been rebuilt.

CrowdStrike Falcon sensor does not negatively impact endpoint performance. We just need to ensure that it is deployed properly to all endpoints, and deployment is straightforward, quick, and not very complicated.

I am not using AI within CrowdStrike Falcon at this time. It depends on what part of AI is considered. I have seen examples where the language and chatbot features are not impressive, but the other AI features are progressing really fast. At some point, we will integrate and test AI features, but not at this time.

I have not consolidated or replaced other security tools outside of what I work on. What differentiates CrowdStrike Falcon from other security platforms I have used or evaluated is its granular firewall capabilities. We are introducing CrowdStrike Falcon firewall onto Linux where we traditionally used Red Hat Linux local firewall policy. By managing through CrowdStrike Falcon, we have one central place to manage all our firewall policies, which saves a lot of time.

The use of CrowdStrike Falcon has expanded since my initial deployment by looking for opportunities to add firewall capabilities. Firewall is already operational on Windows, so Linux is a new expansion area, and beyond that, we are always updating the sensor and adding in the new prevention policies that become available.

My advice to other companies considering CrowdStrike Falcon is to start small, experiment, and keep at it by continuing to work on expanding its use. I would rate this review as an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 4, 2026
Flag as inappropriate
PeerSpot user
reviewer2894523 - PeerSpot reviewer
System Administrator at a consumer goods company with 501-1,000 employees
Real User
Top 20
Sep 2, 2026
Unified security platform has improved vulnerability visibility and strengthened remediation
Pros and Cons
  • "The benefits I have seen from having multiple security capabilities on a single platform are that you get to see things at different angles."
  • "CrowdStrike Falcon can be improved because there are a lot of duplicated endpoints and CrowdStrike does not know how to identify that smartly."

What is our primary use case?

My main use case for CrowdStrike Falcon is vulnerability management.

What is most valuable?

The benefits I have seen from having multiple security capabilities on a single platform are that you get to see things at different angles. Instead of just one perspective, you get multiple perspectives.

The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is that it is nice having everything in one place, but also we just get visibility into something that we would not have known about at all before.

CrowdStrike Falcon has allowed us to consolidate or replace other security tools because it is our only one.

What needs improvement?

CrowdStrike Falcon can be improved because there are a lot of duplicated endpoints and CrowdStrike does not know how to identify that smartly. That would be a huge improvement. Additionally, the user interface is a little bulky and could use some streamlining. It often feels hard to understand and know exactly where to click to find the information that you need. Although there are a lot of options that make CrowdStrike Falcon powerful, it also makes it very difficult to navigate to exactly what you are looking for. It almost takes an expert in the platform to be able to extract the information that you need.

For how long have I used the solution?

I have been using CrowdStrike Falcon for three years.

What do I think about the stability of the solution?

I assess the stability and reliability of CrowdStrike Falcon as good, with no complaints there.

I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.

What do I think about the scalability of the solution?

The impact of CrowdStrike Falcon sensor on endpoint performance is little to none. Deploying security at scale with CrowdStrike Falcon as our main tool for vulnerabilities and exposures means it is a big impact for our company.

The impact of using CrowdStrike Falcon is that we have visibility into our endpoint management and we can address it as things come across.

How are customer service and support?

I would evaluate customer service and technical support, but I may not be the best person to answer this question because I have never had to engage customer service or technical support.

What about the implementation team?

I would describe my experience with deploying CrowdStrike Falcon as I did not deploy it, so I do not have a strong opinion on that.

What was our ROI?

I have seen return on investment with CrowdStrike Falcon, though maybe not in a traditional sense because we have not had any serious breaches. We are pretty good at remediating the critical issues before they happen, which I think is a testament to CrowdStrike Falcon.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing is beyond my knowledge at the organization level because I did not deal with any of that as far as the pricing goes.

What other advice do I have?

CrowdStrike Falcon has definitely increased the workload of my security team. They definitely have a lot more to do because they see a lot more. The main issue is not with CrowdStrike Falcon itself but with how my team prioritizes things properly, which is a personal concern.

We had a lot of browser vulnerabilities that we recently remediated. CrowdStrike Falcon found those vulnerabilities for us and we patched them up and they are good to go now.

The advice I would give to other organizations considering CrowdStrike Falcon is that it is definitely worth using, but you should have somebody become an expert in the platform. My overall rating for CrowdStrike Falcon is 8.7 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriate
PeerSpot user
Dipak M Gohil - PeerSpot reviewer
IT Manager at Jord International Pty Ltd
Real User
Top 5
Sep 3, 2025
Efficient threat detection and seamless deployment improve overall security
Pros and Cons
  • "CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions."
  • "I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does."

What is our primary use case?

We are using CrowdStrike Falcon because it has very low surface impact and minimal consumption of our resources, and we mainly use it for our endpoint protection.

CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions.

We find it very unique that CrowdStrike Falcon, which we deployed in many countries wherever our offices are, can be installed very quickly, maintained on a single console, single panel of console, and it's really easy to use and deploy. We primarily use it for endpoint protection.

What is most valuable?

The single panel console of CrowdStrike Falcon is very user-friendly, which is what we are looking for. Having multiple administrators between various offices with this single console gives us the ability to see all offices, branch offices, and partners, making it very useful to detect machines, identify machines, and check security risks. Everything in the single console is very useful.

CrowdStrike Falcon has positively impacted our organization in terms of efficiency because it's very lightweight, easy to deploy, easy to manage, and works very efficiently. It quickly detects issues and doesn't have a signature-based system, so it works fast and takes immediate action.

What needs improvement?

I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does.

For how long have I used the solution?

We have been using CrowdStrike Falcon for the past seven years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable; I have not had any issues with reliability or downtime.

What do I think about the scalability of the solution?

For scalability, CrowdStrike Falcon deserves a perfect score of ten out of ten.

How are customer service and support?

Regarding customer support, our experience has been really positive as they are very quick to assist us.

The customer support deserves a rating of ten out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were previously using Symantec Endpoint because we were not getting proper quotations, pricing, or support, particularly in India, which is why we wanted to switch.

What was our ROI?

In terms of return on investment, we find that CrowdStrike Falcon has ROI covered because less manpower is required. It's very easy to deploy without many IT admins, saving time, and while I cannot specify the money saved, the time saved is money in terms of manpower. This makes it very useful, quick to run, quick to install, easy to manage, and easy to deploy.

What's my experience with pricing, setup cost, and licensing?

We do not find any price challenges or setup costs with CrowdStrike Falcon; everything is smooth.

Which other solutions did I evaluate?

We evaluated three products, which were Sophos, CrowdStrike Falcon, and Trend Micro, before choosing CrowdStrike Falcon.

What other advice do I have?

In some cases, we have Excel files with VBA code inside, and CrowdStrike Falcon detects that it's a bit risky for us. When people download EXE files that are threats to our organization, it detects them very quickly. It also detects threats under ZIP files and can show us the path from where it came and where it goes, allowing us to easily see where the infection is and where it has spread.

My advice for others looking into using CrowdStrike Falcon is that as an endpoint protection solution, Falcon is always reliable, and I can recommend that this is the product you can deploy and forget all the worries.

We are an end user customer of CrowdStrike Falcon; we are not a partner or reseller, and we are not receiving any gift card or incentive for this review. We are just sharing our experience as an end user and as an IT Manager.

I rate CrowdStrike Falcon 9 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.