No more typing reviews! Try our Samantha, our new voice AI agent.
Sathya Paul - PeerSpot reviewer
Director Of Information Technology at TollPlus LLC.
Real User
Dec 10, 2022
An AI-driven solution that self-activates to find issues and provide alerts
Pros and Cons
  • "The solution is silent and sits on your system as one single agent."
  • "Technical support could be better than what is currently offered."

What is our primary use case?

Our company's line of business includes financial transactions with an insurance policy that requires EDR protection. Compliance is part of our policy and agreement with customers. 

We currently have 1,100 users of the solution. 

What is most valuable?

The solution is silent and sits on your system as one single agent.

Only one or two MB of memory are consumed which is much less than other products. 

The solution is AI-driven so it self-activates to find issues and provide alerts or notifications rather than running all the time.

The portal is very user-friendly so it is not difficult to manage. 

The solution doesn't require system restarts. That is one disadvantage of Symantec or Kaspersky because they require restarts when you uninstall or reinstall. 

What needs improvement?

Technical support could be better than what is currently offered. 

For how long have I used the solution?

I have been using the solution for three months. 

Buyer's Guide
CrowdStrike Falcon
September 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,517 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable with no issues. 

We have only used the solution for three months so will continue to monitor stability for the next several months. 

I rate stability an eight out of ten. 

What do I think about the scalability of the solution?

The solution is scalable. We do not yet have the requirement to take an in-depth look at scalability. 

I rate scalability an eight out of ten. 

How are customer service and support?

Technical support could be better because there are ownership issues. 

For example, when you raise a support case there is not much communication between the account manager and support. The account manager is supposed to own the case but instead is disconnected from it. 

I rate support a six out of ten. 

Which solution did I use previously and why did I switch?

We previously used Symantec and Kaspersky. 

How was the initial setup?

The setup is pretty easy to walk through without much trouble. 

I rate setup an eight out of ten. 

What about the implementation team?

We utilized a third-party for implementation. They helped us with the admin console, training, and the pilot setup that we eventually took over. Our internal team included two security staff and four support staff.

We were moving from Symantec and Kaspersky. We targeted our servers first because Symantec is difficult to uninstall and there is an interim process for removal. Once completed, we installed the solution. 

It took about two months to complete implementation across all systems. 

What was our ROI?

We did our homework in advance for cost or other things to calculate ROI. The solution met our expectations so ROI is rated a seven out of ten. 

What's my experience with pricing, setup cost, and licensing?

The pricing is competitive and includes all features and support.

I rate pricing an eight out of ten. 

Which other solutions did I evaluate?

We evaluated Microsoft Defender, Sophos, Symantec, and Trend Micro before choosing CrowdStrike Falcon. 

What other advice do I have?

I recommend using the solution and rate it an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Neeruganti Santhosh Kumar - PeerSpot reviewer
Security Analyst at a tech services company with 501-1,000 employees
Reseller
Nov 22, 2022
Offers robust protection and excellent visibility in a highly scalable solution with great technical support
Pros and Cons
  • "The feature I like the most is the solution's detection."
  • "CrowdStrike is excellent at preventing breaches, and our security operations are more robust as a result."
  • "The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool."

What is our primary use case?

We use CrowdStrike Falcon to detect and alert us to any malware in our system. In our organization, we integrated CrowdStrike with a SIEM tool, which does the alerting. If the solution detects malware and issues an EDR alert, it notifies us and begins gathering data about the detection, including the hostname, user name, the hash value of the downloaded file, and the file's reputation. Then, we can ask the user the delete the file from the PC and drives, such as USB drives, if necessary. Following removing any malicious files, we can use CrowdStrike to run an AV scan on the affected device or devices.

How has it helped my organization?

We use the solution's Horizon module to protect multi-cloud work environments and integrate with SIEM tools. Detections in CrowdStrike trigger a response from the SIEM tool, allowing us to face threats via a coordinated approach.

Horizon simplifies security management of multi-cloud environments, and the improvement has been significant. Integration with a SIEM tool makes alerting and detection very rapid, which significantly helped.

To give an example, one of our employees mistakenly downloaded a malicious phishing video. The solution quarantined the file, protecting our organization from attack.

What is most valuable?

The feature I like the most is the solution's detection.

The fact that CrowdStrike Falcon is a cloud-native solution provides us with a lot of flexibility and always-on protection. This is very important to us because it enables automatic detection and quarantining of malicious files, and that's one of the features we like most about working with the tool. 

The visibility provided by the solution in multi-cloud environments is excellent; it's one of the best features. 

What needs improvement?

The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool. 

For how long have I used the solution?

I've been using the solution for about three years. 

What do I think about the stability of the solution?

The product's stability is good. 

What do I think about the scalability of the solution?

The scalability is excellent; top tier. There are about 15 end users in our company, and they are members of the security team. We plan to increase our usage of the solution. 

How was the initial setup?

It isn't challenging to deploy the solution's sensor to endpoints, and it becomes even more straightforward with some experience and understanding of the tool. 

The deployment is relatively quick, though it takes a little longer than other products.

What about the implementation team?

We implemented via an in-house team as we had a lot of experience with the solution. 

What's my experience with pricing, setup cost, and licensing?

The solution isn't very costly; it's affordable.

Which other solutions did I evaluate?

We evaluated a McAfee solution, and CrowdStrike has a lot more automation. 

What other advice do I have?

I rate the product nine out of ten. 

CrowdStrike is excellent at preventing breaches, and our security operations are more robust as a result. The automatic quarantining of malicious downloads keeps our system safe and our information out of the hands of attackers.  

The solution reduces our security risk significantly; it's an advanced tool.  

We learned about the solution when some of our employees saw a promotion campaign. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
CrowdStrike Falcon
September 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,517 professionals have used our research since 2012.
Jordan Swanson - PeerSpot reviewer
Information Security Assurance Engineer at School District of Lee County
Real User
Sep 15, 2022
Robust threat hunting and great ability to do on-keyboard remote response and quarantining of devices
Pros and Cons
  • "It's ability to do threat hunting is really great, quite robust, and even allows you to do hygiene stuff."
  • "The solution is very scalable; our proof of concept was a few devices and now at full scale we have 50,000 devices, and because it's a cloud console, if you do the implementation right and the sensor is put on in an automated process, it doesn't matter how many computers you have, it just runs."
  • "The ability to receive text alerts natively in the console would be kind of cool."

What is our primary use case?

We integrate the data from this solution with ExtraHop, which is an NDR. Being able to move between both platforms and have network-level data and transactions over the network feed into XDR CrowdStrike is really powerful. It helps us make better decisions, it makes better decisions without human intervention, and it hones the analytics a little bit. The EDR aspect of it works almost exactly the same as the regular Falcon product. I will say that it's probably a lot better at scale than what we're using it for. I work at a school district, so for the individual schools, it's nice to see and isolate issues and have reports built by individual school locations rather than just everything looking like a whole hodgepodge of computers.

What is most valuable?

It's ability to do threat hunting is really great, quite robust, and even allows you to do hygiene stuff, like look for old versions of applications that maybe you forgot about or find stuff that people are running that maybe you don't want on your network, and it lets you get rid of those. Also, its ability to do on-keyboard remote response and run PowerShell script through the sensor is pretty sick. It's ability to quarantine devices is also pretty great.

What needs improvement?

The ability to receive text alerts natively in the console would be kind of cool. Some people put their email on quiet hours, so having it natively in the system would be nice.

I know that they offer an identity piece and a firewall piece and we haven't subscribed to or purchased either of those, but having some of that data in the base program would be good, and then if you want more control, you pay for it. There's times where I want to look at an internet history of a device that's remote, or I want to see logins, successful or unsuccessful. I don't want to manage identity and I don't want CrowdStrike to alert on it, but it would be nice if the ability to see the data was included with the base product. Then that could kind of get your foot in the door with having the ability to look at that information, but not being able to do anything actionable with it.

For how long have I used the solution?

I have been using this solution for two years. 

What do I think about the stability of the solution?

The solution has never failed. The only false positives that we get are ones that we test with. I do true and false positive testing every month to make sure stuff is working correctly and the solution picks up on it. 

What do I think about the scalability of the solution?

The solution is very scalable. Our proof of concept was a few devices and now at full scale we have 50,000 devices. It's a cloud console, so if you do the implementation right and the sensor is put on in an automated process, it doesn't matter how many computers you have. It just runs. They have sensors for every kind of device: Macs, Windows, Linux, and I think even Android.

How are customer service and support?

The support is great. They're quick to respond and you see the same names pretty consistently. They probably do it by region or account or something like that, so it's not just a random person every time.

How was the initial setup?

The setup is as complex as you want to make it. They have engineers that help you. We did a proof of concept first and that was pretty seamless. If you want to build out a bunch of dynamic groups and have different policies affect the different groups separately, you can. If you want to purchase a bunch of licenses for integration with different products, they partner with a bunch of different security vendors and you can make it as complex or simple as you want. If you just want NextGen AV, you can just have NextGen AV and it's super simple and the sensor just sits on a computer, but if you have a bunch of data and want it to be really complicated and want to be able to do whatever you want, you can do that too. It's pretty flexible, in that sense.

What about the implementation team?

Getting it off the ground took myself, one CrowdStrike engineer, and we could have done it with one systems engineer, but we had two because one was on the client side for the Windows hosts and one was for enterprise for the data center and servers. We did it with four people, and me and one other guy manage it ourselves.

What other advice do I have?

We pay for Overwatch, which is kind of like a sock where someone that works for CrowdStrike monitors certain aspects of your network, and then they can make notes and quarantine devices for you, and they'll alert you at 2:00 in the morning. It's really great, but it takes two people to manage the alerts after a bit of tuning to make sure that the stuff that is on your network that you want to be there, that's getting picked up by CrowdStrike, is excluded. I get maybe ten alerts a day, but that comes from having good hygiene in other areas. If you're not preventing those alerts or fixing the problems that CrowdStrike is picking up, you're going to have a lot of work to do, but if you use CrowdStrike as a hygiene tool, it's a lot easier to manage.

My advice would be to automate as much of the management as you can. Sensor deployment can be really annoying, but if you figure out how to automate it in your environment, that will make it way easier. That way, as the devices are provisioned, they have the sensor on them and they just pop up into your console. I know some people do it by hand and that's a nightmare.

I would rate this solution as a nine out of ten. It's really good. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chintan-Vyas - PeerSpot reviewer
Associate Director at a financial services firm with 10,001+ employees
Real User
Top 10
Jun 12, 2022
Easy to set up with good behavior-based analysis but needs a single-click recovery option
Pros and Cons
  • "The scalability is good."
  • "The Insight feature is one we found the most useful."
  • "The product could be more accurate in terms of performance."
  • "With CrowdStrike, we have found that there are a few missed detections. We would not say it is completely reliable or 100% reliable, however, the ratio of missed detection is more in CrowdStrike."

What is most valuable?

The Insight feature is one we found the most useful. It does behavior-based analysis and gives us the most appropriate information.

The initial setup was easy.

It's pretty stable.

The scalability is good.

What needs improvement?

Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files.

The product could be more accurate in terms of performance.

We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.

For how long have I used the solution?

I've been working with the solution for three years. 

What do I think about the stability of the solution?

With CrowdStrike, we have found that there are a few missed detections. We would not say it is completely reliable or 100% reliable, however, the ratio of missed detection is more in CrowdStrike. In SentinelOne, we found that it was more accurate. We are seeing it act more efficiently.

What do I think about the scalability of the solution?

We haven't had any issues with scalability. Being a cloud solution, it can scale well. 

How are customer service and support?

Technical support is average. We are not seeing any extraordinary service and not many issues also. It's average, it is as expected.

Which solution did I use previously and why did I switch?

I'm also familiar with Symantec, Trend Micro, SentinelOne, and FireEye.

How was the initial setup?

The initial setup was pretty straightforward. It's not overly complex. You still need expertise, however, it's pretty reasonable. 

What about the implementation team?

We did not need any outside assistance. 

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution is average. 

What other advice do I have?

We are a managed security service provider.

We are using a SaaS offering and therefore, in terms of the version, we are not bothering so much on worrying which we are on. It is automatically getting updated. We are running on the latest version at all times.

While I would recommend the solution, CrowdStrike, when it first came into the market, it was sort of a single choice for many customers. Now, we can see there are many other competitors also. Those are providing pretty good functionalities in a more efficient way. We could see that other solutions are better than CrowdStrike.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2385126 - PeerSpot reviewer
Head Cyberdefense at a tech vendor with 5,001-10,000 employees
MSP
Top 20
Jun 2, 2024
Proactively blocks threats, provides insights, and integrates seamlessly
Pros and Cons
  • "The endpoint and server management are the most valuable features of CrowdStrike Falcon."
  • "CrowdStrike Falcon's GUI requires improvement for user-friendliness."

What is our primary use case?

We use CrowdStrike Falcon for intrusion prevention management.

How has it helped my organization?

CrowdStrike Falcon proactively blocks threats and provides us with insights.

CrowdStrike Falcon integration is seamless.

What is most valuable?

The endpoint and server management are the most valuable features of CrowdStrike Falcon.

What needs improvement?

CrowdStrike Falcon's GUI requires improvement for user-friendliness. The console's available options are unclear, making it difficult to understand and extract details. Additionally, correlating information within the console and reports proves challenging.

For how long have I used the solution?

I have been using CrowdStrike Falcon for two years.

What do I think about the stability of the solution?

CrowdStrike Falcon had some initial stability issues in our environment, likely due to its new integration. However, it appears to have matured and is now functioning reliably.

What do I think about the scalability of the solution?

Being cloud-based, CrowdStrike Falcon offers easy scalability. Adding licenses through procurement increases resources without the need for additional hardware, making scaling straightforward.

How are customer service and support?

While the technical support meets all response time commitments outlined in our Service Level Agreement, some users believe they should strive for a higher standard – a Security Level Target. This means responding to security incidents immediately, not just within SLA windows. Security tools are crucial for our environment's protection, and their use shouldn't be limited by SLA constraints.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

After using Symantec, Trend Micro, McAfee, and VMware Carbon Black, we migrated to CrowdStrike Falcon due to a lack of support from the previous vendors and their shortcomings in comprehensive threat detection.

What other advice do I have?

I would rate CrowdStrike Falcon eight out of ten.

The maintenance required is reasonable.

We have 6,000 endpoints in our environment.

CrowdStrike Falcon shines with its user-friendliness, providing clear insights into the endpoint environment. Proactive features are a major plus, offering actionable items and valuable attack path simulations that empower better decision-making.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Roberto Massa - PeerSpot reviewer
Managing Director at a tech services company with 11-50 employees
Reseller
May 12, 2024
Is user-friendly, maintenance-free, and stable
Pros and Cons
  • "I like the vulnerability assessment and proactive hunting features of CrowdStrike Falcon."
  • "To simplify the budgeting process for our clients, CrowdStrike should consider offering bundled packages that include essential features."

What is our primary use case?

We are a CrowdStrike Falcon distributor that helps clients monitor their environments for malicious activity coming from the internet.

How has it helped my organization?

Both users and administrators find CrowdStrike Falcon easy to use.

What is most valuable?

I like the vulnerability assessment and proactive hunting features of CrowdStrike Falcon.

What needs improvement?

To simplify the budgeting process for our clients, CrowdStrike should consider offering bundled packages that include essential features. The separate model pricing structure can make it challenging for clients to gain approval for their security needs.

CrowdStrike could consider regional pricing models to better reflect the economic realities of different markets.

For how long have I used the solution?

I have been using CrowdStrike Falcon for 2 years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable.

What do I think about the scalability of the solution?

CrowdStrike Falcon is scalable.

Which solution did I use previously and why did I switch?

We have also used Sophos. CrowdStrike Falcon is a better solution but Sophos is more affordable.

How was the initial setup?

The deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

The cost of CrowdStrike Falcon in Latin America seems high relative to the economic conditions in the region.

What other advice do I have?

I would rate CrowdStrike Falcon 9 out of 10.

To realize the benefits of CrowdStrike Falcon, it's recommended to conduct a proof of concept first. You should then start to see the advantages within a few months.

No maintenance is required from our end.

To ensure the successful implementation of CrowdStrike Falcon, it's essential to have a complete network map and inventory of all resources and devices.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Ganesh-Jadhav - PeerSpot reviewer
Senior Cyber Security Analyst at Securonix
Real User
Mar 12, 2024
Fast, easy to use, and integrates easily with any OS
Pros and Cons
  • "Its integration capability is valuable. It integrates easily with any OS."
  • "In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it."

What is our primary use case?

We use it for threat detection and threat hunting.

How has it helped my organization?

We are an MSP. We have deployed this in our customer environment, and we use it to detect threats in their environment. It is beneficial for customers to find cybersecurity-related threats on the endpoints.

The out-of-the-box configurations and threat intelligence provided by CrowdStrike are better than other vendors and competitors in this field. It improves our security strategy because we are building threat intelligence on top of CrowdStrike-provided detection.

We are building SIEM use cases on top of the data provided by CrowdStrike. There is reliability, and the response that we get from it is very fast. If any incident happens on the endpoint, it immediately detects that and sends that to our SIEM.

Endpoint security is a very crucial aspect of cybersecurity. Integrating CrowdStrike helps a lot to identify and dig deeper into the threats.

What is most valuable?

Its integration capability is valuable. It integrates easily with any OS. 

What needs improvement?

They are good at what they are doing, but they can add more use cases. They can improve their documentation. It is a very big aspect where they are lacking. They have documentation, but it is behind the wall of authentication. It is not available publicly.

In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it. If they can add more information about an event, it will be beneficial for us and everyone else who is using CrowdStrike.

For how long have I used the solution?

I have been using this solution for four years. I have had hands-on experience with it for about two to three years.

What do I think about the stability of the solution?

It is a stable product.

How are customer service and support?

I have not interacted with their support team. It is not a part of my job.

Which solution did I use previously and why did I switch?

I work with multiple vendors, not only CrowdStrike, in the endpoint space, and the CrowdStrike UI is better than others. The response of CrowdStrike is better than other vendors.

How was the initial setup?

It is deployed on the cloud. Its deployment is of moderate complexity. It is not easy, and it is also not difficult. Overall, it is easy to deploy and manage CrowdStrike Falcon across the organization.

What other advice do I have?

I would definitely recommend CrowdStrike Falcon. It is better than other solutions, such as VMware Carbon Black. CrowdStrike is doing better in this space. 

If you are using CrowdStrike Falcon for the first time, it will be easy for you. You can definitely use it.

Overall, I would rate CrowdStrike Falcon an eight out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2279184 - PeerSpot reviewer
Vice President at a financial services firm with 10,001+ employees
Real User
Feb 5, 2024
Helps protect against malware and the maintenance is straightforward, but there are a lot of false positives
Pros and Cons
  • "The malware protection is the most valuable feature of CrowdStrike Falcon."
  • "The current database schema presents challenges and has potential for improvement."

What is our primary use case?

Our organization relies on CrowdStrike, a standalone endpoint security solution, to safeguard our bare-metal machines. CrowdStrike continuously monitors for threats on all endpoints. If it detects any suspicious activity, such as malware or malicious processes, it immediately alerts us for investigation. 

What is most valuable?

The malware protection is the most valuable feature of CrowdStrike Falcon.

What needs improvement?

The current database schema presents challenges and has potential for improvement.

The technical support response time can be improved.

There are a lot of false positives reported.

For how long have I used the solution?

I have been using CrowdStrike Falcon for almost four years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable. 

What do I think about the scalability of the solution?

CrowdStrike Falcon is scalable.

How are customer service and support?

The technical support is good but the response time can be improved.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used VMware Carbon Black Endpoint. CrowdStrike Falcon is more of an EDR solution.

What other advice do I have?

I would rate CrowdStrike Falcon a seven out of ten.

The maintenance is straightforward.

CrowdStrike Falcon is deployed independently in our environment and we have 30 users.

While CrowdStrike Falcon offers valuable security tools for larger organizations with extensive infrastructure, its complexity might not be ideal for smaller businesses with limited IT resources.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Dev Kudtharkar - PeerSpot reviewer
Director of Information Technology at Slice
Real User
Apr 11, 2023
Effective for threat detection and remediation
Pros and Cons
  • "The most valuable features are the complete IPS and IDS."
  • "Forensic controls have room for improvement."

What is our primary use case?

Our primary use case is IPS and IDS.

How has it helped my organization?

CrowdStrike Falcon is extensively used by all 2,000 employees.

What is most valuable?

The most valuable features are the complete IPS and IDS. Both the feature provide good measures for threat detection and prevent network intrusions. 

What needs improvement?

Forensic controls have room for improvement, and CrowdStrike Falcon can add more features here.

Another improvement could be the support for this product could be cheaper.

For how long have I used the solution?

I have been using CrowdStrike Falcon for two years. We are using version 6.5.1.

What do I think about the stability of the solution?

It is a stable solution. I would rate it a nine out of ten.

What do I think about the scalability of the solution?

The scalability of CrowdStrike Falcon is quite good. There are around 2,000 users in our organization. I would rate it an eight out of ten. There are a few things, such as the forensic part and the investigation, that can be improved.

Which solution did I use previously and why did I switch?

I have worked on many other IDS solutions, but I found CrowdStrike Falcon to be the best.

How was the initial setup?

The setup is pretty straightforward. The deployment took some time because we didn't have an NBM solution. We installed it two years ago. But now it's clear, and we don't need much time to deploy it.

What about the implementation team?

The tech support is good but can be expensive when it goes out of the subscription.

What was our ROI?

I have seen a good return on investment.

What's my experience with pricing, setup cost, and licensing?

There is a license-based model. We use the yearly license. I would rate pricing a seven out of ten, where one is cheap, and ten is very expensive.

What other advice do I have?

I highly recommend people use CrowdStrike Falcon. Overall, I rate it a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cyber Security Manager at a healthcare company with 10,001+ employees
Real User
Apr 11, 2023
Provides great protection and can crosscheck environments. Helpful in investigating any alerts
Pros and Cons
  • "It provides very good protection and the ability to crosscheck environments."
  • "Falcon could include more integrative features."

What is our primary use case?

We use the EDR feature.

What is most valuable?

This is unlike any other EDR solution that I am familiar with. It provides very good protection and the ability to crosscheck environments. It's really helpful in investigating any alerts and is easy to use. You can use some of the Splunk language to search. 

What needs improvement?

We've tried some integrations with solutions, closing off false positives and things like that. Falcon could include more features in that area. In addition, some features are modularized and we're unable to buy them as we're in the healthcare field and limited in the amount we can invest. 

For how long have I used the solution?

I've been using this product for close to 18 months. 

What do I think about the stability of the solution?

We haven't had any stability issues. 

What do I think about the scalability of the solution?

The solution is very scalable but we had issues with some groups, that manage their own devices and wanted to have access to self-manage them. We weren't able to do that, unfortunately.

How are customer service and support?

My team has interacted with tech support and I believe the issues were resolved in a timely manner.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used other solutions such as Setinel One.

How was the initial setup?

The initial setup was very straightforward and smooth.

What's my experience with pricing, setup cost, and licensing?

Falcon is more expensive than every other solution on the market. That said, they do have a better product than anyone else.

What other advice do I have?

Some of the default settings are set to 'easy' which isn't sufficient. We had some conversations around this and the recommendation was to change some of these settings to more aggressive ones on the policy side. I know some organizations have had issues automatically updating CrowdStrike to the latest version. I recommend going through the change process but saving it at minus one for a while to avoid all the negative downtimes where you might need to roll back to the previous update.

When we switched to CrowdStrike, we didn't expect it to find anything that was already on the computer because the primary reason we swapped was because of EDR. But it did find things that were dormant as well as other things.

I rate this solution nine out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.