My main use case for CrowdStrike Falcon is EDR. For EDR, I use CrowdStrike Falcon for identity, endpoint management, and device control.
The best features CrowdStrike Falcon offers are endpoint and device control, identity threat protection, and AI-generic responses. What I appreciate about the endpoint and device control in CrowdStrike Falcon is that it allows me to lock down USBs for all hosts on the policies applied company-wide.
CrowdStrike Falcon has positively impacted my organization by providing better visibility, host management, compliance, and real-time responses. A specific example that demonstrates how CrowdStrike Falcon has improved visibility or compliance is response times and compliance with NIST 800-171 for CMMC, with an example of locking down mass storage and access controls.
One specific example of how CrowdStrike Falcon can be improved would be the ability to export the device control exceptions for auditability purposes, and perhaps a cleaner UI.
I have been using CrowdStrike Falcon for one year.
CrowdStrike Falcon is stable.
CrowdStrike Falcon's scalability is great, as long as I have the licenses for more sensors.
The customer support for CrowdStrike Falcon on the commercial side is great, but the government side is not as strong.
Since my initial deployment, my use of CrowdStrike Falcon has expanded, and I definitely feel better as a security analyst, more knowledgeable, and have better investigation processes.
My experience with pricing, setup cost, and licensing is that I was able to lower the price a bit by going from a one-year to a three-year contract, but it was still very expensive for the three-year commitment.
Before choosing CrowdStrike Falcon, I did not evaluate other options, as I was not part of that decision.
I would rate CrowdStrike Falcon a nine on a scale of one to ten because I never give anything a perfect score, and it is almost a ten.
Regarding CrowdStrike Falcon's AI capabilities, I think its governance and security are great. Its accuracy and reliability of output seem reliable, but I have not used it enough, as I rely mostly on the Falcon Complete team and my own individual investigations.
CrowdStrike Falcon is now deployed in my organization on GovCloud due to the recent migration.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools, as I actually got rid of some such as Exonius.
The benefits I have seen from having multiple security capabilities on a single platform are faster response time, quicker identification for investigations, and better overall security posture.
I can describe a security incident where CrowdStrike Falcon helped my team detect or stop a threat involving individuals getting fooled by malicious emails and links, and CrowdStrike Falcon stopping it and allowing me to use the sandbox to see what would have occurred and how it was stopped.
CrowdStrike Falcon has affected the workload or productivity of my security team by making response times faster and visibility quicker and more seamless.
The CrowdStrike Falcon sensor has had a lightweight effect on endpoint performance, is easy to roll out, and there is really no difference at all when it comes to response or processes, other than being faster than it was prior to having CrowdStrike Falcon sensors on my hosts.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that so far it is the best, but it is definitely the most expensive.
My advice for others looking into using CrowdStrike Falcon is to invest in it, as it is a good solution. I would rate CrowdStrike Falcon a nine out of ten overall.