My main use cases for CrowdStrike Falcon include endpoint defense, investigations, and triage.
CrowdStrike Falcon delivers AI-powered endpoint protection, detection, and response to help organizations stop malware, ransomware, fileless attacks, and sophisticated adversaries. Built on the cloud-native Falcon platform and a single lightweight sensor, it combines prevention, EDR, threat intelligence, and automated response to protect endpoints while simplifying security operations.

| Product | Mindshare (%) |
|---|---|
| CrowdStrike Falcon | 5.7% |
| Microsoft Defender for Endpoint | 6.5% |
| SentinelOne Singularity Endpoint | 4.5% |
| Other | 83.3% |
| Company Size | Count |
|---|---|
| Small Business | 47 |
| Midsize Enterprise | 36 |
| Large Enterprise | 65 |
| Company Size | Count |
|---|---|
| Small Business | 2461 |
| Midsize Enterprise | 1141 |
| Large Enterprise | 3170 |
What features make CrowdStrike Falcon stand out?
What benefits can users expect?
Across industries, CrowdStrike Falcon helps organizations modernize endpoint security, improve security team efficiency, and stop sophisticated threats with AI-powered protection and adversary intelligence.
CrowdStrike Falcon was previously known as CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform.
| Author info | Rating | Review Summary |
|---|---|---|
| Cyber Security Analyst II at a retailer with 10,001+ employees | 4.5 | I value CrowdStrike Falcon for its granular threat detection, consolidation of security tools, and reduced alert fatigue. Setup was streamlined. While I noted minor hosting issues, its comprehensive capabilities and AI integration make it highly recommended. |
| Lead Endpoint Security Engineer at Depository Trust & Clearing Corporation | 4.5 | I've used CrowdStrike Falcon for five years, finding it an excellent, stable, and high-performing solution for consolidating security tools. Despite being expensive, it significantly improved our operations, and I highly recommend it. |
| Information Security Manager Iam at ExactCare Pharmacy | 4.5 | CrowdStrike Falcon transformed my security operations, offering excellent threat detection, automation, and low false positives. I find it stable, scalable, and easy to deploy, with great support and clear ROI. I plan further integration and highly recommend it. |
| Director, Information Security Services at a university with 10,001+ employees | 5.0 | CrowdStrike Falcon effectively protects high-value assets, quickly isolating threats and freeing my security team. Its stability, scalability, and lightweight client are excellent, delivering significant ROI by replacing less effective solutions and consolidating security. |
| IT Security Analysts at Royal Business Bank | 4.0 | I find CrowdStrike Falcon highly reliable for endpoint and USB security, offering excellent visibility and simplifying our workload. Its consolidated platform, easy deployment, and great support deliver significant ROI, though I'd like more AI focus. |
| Senior Secops Engineer at a program development consultancy with 1,001-5,000 employees | 4.5 | I find CrowdStrike Falcon excellent for endpoint security, consolidating tools, and boosting productivity. Its stable, scalable platform is highly valuable, though it could improve network agent discovery and ransomware rollback features. |
| Director Of IT at Sb Software Inc. | 4.5 | I highly recommend CrowdStrike Falcon for its superior visibility, lighter footprint, and easy deployment, significantly streamlining security operations. The integrated platform simplifies monitoring, correlates events across endpoint, identity, and cloud, delivering strong ROI and increased confidence. |
| Manager at Azuria Water Solutions | 5.0 | I consider CrowdStrike Falcon, with Falcon Complete, a top-notch, all-in-one security solution. It consolidates tools, drastically reduces my team's workload, and reliably stops threats with easy deployment and no performance impact. |
| Co-Owner at a manufacturing company with 1,001-5,000 employees | 5.0 | I use CrowdStrike Falcon for excellent endpoint protection, loving its automated threat remediation that significantly saves my team time. It's stable, scalable, offers great support, and I highly recommend it, rating it 10/10. |
| CISO at a financial services firm with 1,001-5,000 employees | 5.0 | CrowdStrike Falcon significantly improved my endpoint and cloud security. Its features like Threat Graph and telemetry provide great visibility, leading to faster incident response and automated threat mitigation. It saved my team time and money, proving superior to previous solutions. |

Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by making it much more granular. It allows us to dive deep into the details of an investigation and gain a deep understanding of what is occurring.
I have seen benefits from having multiple security capabilities on a single platform. It makes the unity of all the detections and information being in one place far more beneficial than having to navigate between devices, assets, or tools. This significantly reduces dwell time.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is the same; having it all in one location truly benefits the time to remediation.
CrowdStrike Falcon has affected the workload and productivity of my security team by reducing it. We utilize CrowdStrike Falcon Complete as well, and having them serve as the front line for everything eliminates many false positives. When we receive an escalation from them, it is a clear directive stating 'Here is a problem you need to fix,' rather than uncertainty about whether something might be an issue.
CrowdStrike Falcon can be improved by addressing the side tabs and menu options, which represent the biggest area for enhancement.
I cannot identify any additional features that should be included in the next release unless they address that menu structure.
I have been using CrowdStrike Falcon for three months.
I would assess the stability and reliability of CrowdStrike Falcon as good. There appear to be occasional issues with their hosting infrastructure; US2 might experience downtime occasionally. Having greater focus on that from their side would be beneficial.
I have experienced the portal being unavailable to log into only occasionally, but beyond that, there has been no significant downtime, crashes, or performance issues.
We have not noticed any hardware issues or strain from the CrowdStrike Falcon sensor on endpoint performance and our ability to deploy security at scale. It provides the fine details necessary for thorough investigations.
I would evaluate customer service and technical support as good. Since we are still in rollout and working with CrowdStrike Falcon Launch, we have not yet needed to use the actual on-demand support, but it appears to be solid.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools.
As we are still in the rollout phase, it will replace Palo XDR, to some degree Splunk, and Palo XSOAR. Having everything on one platform with a single login and single pane of glass would be truly beneficial. Those three have been the primary tools being replaced.
I would describe my experience with deploying CrowdStrike Falcon as relatively streamlined. I believe we make it difficult ourselves, but for the most part, it has been quite seamless.
Getting an endpoint removed and a new endpoint installed with a single reboot has presented some challenges.
I have seen a return on investment with CrowdStrike Falcon. The amount of alert fatigue that we would have experienced with other tools has decreased significantly.
With Palo XDR, we would constantly receive alerts, granted they were alerts we set up. However, because it lacked the granularity to specify certain conditions while excluding others, we received far more alerts. Now, escalations are very limited, which is beneficial.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that the crowd aspect of CrowdStrike is valuable because we gain insight from attack vectors and methods we do not experience ourselves, allowing us to build alerts or develop awareness for them.
My use of CrowdStrike Falcon has expanded since my initial deployment. The initial deployment focused strictly on endpoint defense. We now have endpoint, SOAR, SIEM, and even some asset inventory capabilities, which is beneficial.
Currently, we are using AI within CrowdStrike Falcon to build many of the SOAR playbooks within their SOAR solution.
The impact AI has had on my security operations allows us to investigate matters more deeply and build very specific exclusions or alerting rules, which is beneficial.
The advice I would give to other organizations considering CrowdStrike Falcon is that while there is much to tackle and accomplish, it is well worth the effort. I would rate this product 9 out of 10.
My main use cases for CrowdStrike Falcon are endpoint security, using one sensor to deploy various different types of tools. The end goal is less agent on an endpoint where I could accomplish so much with just one sensor installed, and that truly impresses me.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats. Our response ratio, which was our end goal, has decreased significantly from what it used to be.
In security incidents where multiple malware activities have occurred, CrowdStrike Falcon has prevented them, which could have resulted in much greater costs.
The benefits I have seen from having multiple security capabilities on a single platform are that it made my team's life easier by deploying one less agent on an end host, where we have seen significant performance improvement.
The value I have seen from having endpoint, identity, cloud, and other security telemetry in CrowdStrike Falcon is that a single pane of glass has really helped us. The analysts are not fatigued by moving between different platforms. It's a single pane of glass that has helped us focus on our goal.
CrowdStrike Falcon could be improved in several areas. For the next release, I have seen exposure management and some new modules coming up. If I had to compare with other products, it's not there yet. I was wondering if modules could be enhanced, especially on SSPM and exposure management.
I have been using CrowdStrike Falcon for five years.
I assess the stability and reliability of CrowdStrike Falcon as approximately 99% uptime, so it's very good.
I have experienced only the July 19th incident as downtime, crashes, or performance issues.
The impact that CrowdStrike Falcon sensor has had on endpoint performance and my ability to deploy security at scale is significant. The performance improvements have been substantial. Deploying one less agent has been easier to maintain.
I evaluate customer service and technical support as excellent. I have seen better improvement than other vendors I have worked with.
CrowdStrike Falcon has allowed me to consolidate and replace other security tools.
We decommissioned Trellix by replacing it with EDR. We also replaced Qualys by implementing exposure management.
I would describe my experience with deploying CrowdStrike Falcon as very easy and straightforward. I had a very good experience compared to other EDRs I have worked with.
What worked well is that it was easier to reach our metrics. The challenges I faced were keeping up with the sensors and sensor version updates. The deployment pace was very fast, making it difficult to keep up with.
I have seen return on investment with CrowdStrike Falcon. Addressing downtimes based on malware activities, I think we have seen great improvement.
My experience with pricing, setup cost, and licensing is that the license is expensive since it is based on per host. It is more expensive than other solutions I have dealt with.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is mainly the performance, where we have seen a vast improvement.
The impact it has had on my security operations is that it has made it easier for me to accomplish a lot of our use cases and finish all those tasks.
My use of CrowdStrike Falcon has expanded since my initial deployment as we have purchased many additional modules. We started with EDR and expanded with different modules like CrowdStrike Falcon for IT and exposure management.
I am currently using AI within CrowdStrike Falcon to write queries.
The advice I would give to other organizations considering CrowdStrike Falcon is to move forward with it. I provide this review with an overall rating of 9 out of 10.
Our main use cases for CrowdStrike Falcon are that we are a Falcon Complete customer and we are likely expanding in the next year. We are going to go with Next Gen SIM. I am here because I already took my class. We are going to integrate Identity, and we might be doing AIDR as well.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats. I think this has a lot to do with some of the automation and the ability to see things before they happen, and it results in very few false positives. Normally, if we get alerted, there is something we need to address or look into immediately.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools. We are in the process of that right now by proof of concepting out Next Gen SIM, Identity, and AIDR. We are going to be probably discontinuing our current SIM to go to Next Gen and some of our identity monitoring tools will likely be sunsetted when we get Identity spun up.
The value I have seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform is fantastic. You are seeing potential attack points from many different angles while monitoring user activities and behaviors. It is absolutely a great product and a great platform.
CrowdStrike Falcon can be improved by continuing to keep everything on the cutting edge. The product works and is stable, as long as we do not have a rehash of what happened in the summer of 2024 because I dealt with that frontline. The product works well, is not a resource hog, and is the best in the class. Just keep progressing and adding new features as the IT field changes for the next ten to twenty years.
From my perspective on identity access management, there are additional features I would like to see included in the next release of CrowdStrike Falcon. I am just getting started with the Identity portion of CrowdStrike Falcon, so if you ask me this next year, I would probably give you a great answer, but right now I cannot.
I have been using CrowdStrike Falcon for a good five years, which is when we first started.
I assess the stability and reliability of CrowdStrike Falcon as high. There was only one issue, and we all know when that was, and we hope it does not happen again.
I have not experienced any downtime crashes or performance issues with CrowdStrike Falcon. The only downtime we have ever experienced was in June of 2024.
The impact of CrowdStrike Falcon sensor on endpoint performance and my ability to deploy security at scale is minimal. Loading the sensor is really a piece of cake. We have it scripted into new machine builds and it is very easy to manage and easy to get pushed out to the base.
I would evaluate customer service and technical support for CrowdStrike Falcon as very good. Our product teams, sales engineers, and support are always good. Support is very good across the board. Everybody is friendly, knowledgeable, and wants to help, and you can feel that they want to keep your business. Many companies in this era seem like they do not care. CrowdStrike does care.
My experience with deploying CrowdStrike Falcon is positive. Getting the agent out on the workstations and servers is easy. Once you get your tenant set up and you have your CIDs and everything, building it out becomes straightforward. We have now built out three or four different tenants and it gets easier every time.
What works well with CrowdStrike Falcon deployment is that we really did not face major challenges. The biggest challenge is always finding all of the machines in your environment because asset inventories are often not accurate, new machines are coming in, and old machines are going out. So that is really the biggest challenge and that really is not a CrowdStrike Falcon issue; that is just a corporate IT issue.
I have seen return on investment with CrowdStrike Falcon. I am sure this is the case because we are in the medical industry and keeping PHI and everything safe. We have to have cyber liability insurance, and knowing that we have CrowdStrike Falcon definitely helps when it comes to the bottom line and helping our insurance rates stay at a fair level.
My experience with pricing, setup costs, and licensing for CrowdStrike Falcon is that it is pretty fair. We are always able to get to a good price and the proper amount of licensing. It is very fair.
My advice to other organizations considering CrowdStrike Falcon is to definitely work with one of the good reselling partners. We use GuidePoint, and they are fantastic. I can also say that you should really get to know your CrowdStrike Falcon team once they are assigned to your company because they are definitely assets to leverage. I would rate this product as a nine overall.
My main use case for CrowdStrike Falcon is protecting high value assets and servers. For example, we typically have a lot of people doing click-through for downloads of remote management and ScreenConnect type software, so CrowdStrike Falcon is really good at identifying those user interactions, the clicks, and the hacker trying to come in and log in using that ScreenConnect software; we do see that a lot.
The best features CrowdStrike Falcon offers include the time to discovery, the cost and effectiveness of the software, and the ability to isolate machines and allow for remediation.
The ability to isolate machines has positively impacted my operations because it can take the threats offline quickly and allow us the time that we need to be able to interact with them and get them back online properly.
CrowdStrike Falcon has positively impacted my organization by allowing our admins and our Security Operations Center folks to be able to focus on other things, giving them enough time to not just be dealing with these incidents on a regular basis, but allowing us to free that time and use it in other places more effectively.
I am pretty happy with CrowdStrike Falcon where it is. I do like some of the new features being added to it with some of the AI pieces and the SIM, and we have not really broached those pieces yet, but I think we are really interested in at some point expanding our portfolio.
Regarding CrowdStrike Falcon's AI capabilities, I think it still needs a little bit of time to learn and improve itself in the environment, but overall it has been pretty accurate.
I have been using CrowdStrike Falcon for approximately four years.
CrowdStrike Falcon is very stable.
CrowdStrike Falcon's scalability has been good because we have not had any issues. We are using automated deployment methods such as Jamf for Macs and adding AD groups, so members just get joined to an AD group, and the agent is deploying effectively, allowing us to do dozens of machines at a time without any issue.
Customer support has been good. We do have a third-party MSP that is assisting us with some of those issues, so between that and the MSP, we are actually doing pretty good.
We were primarily using Microsoft Defender before choosing CrowdStrike Falcon. It just was not very effective, especially on things like Linux and Mac.
My experience with pricing, setup cost, and licensing has been pretty seamless. We are purchasing from multiple sources for various reasons, but working with CrowdStrike Falcon directly through a third-party VAR has actually been working out really well without any issues or hiccups.
CrowdStrike Falcon has allowed us to consolidate or replace other security tools, and we have actually replaced traditional antivirus in most of our deployment cases, not requiring to have paid extra money for the high-level Defender or a third-party software for our Macs. We are able to almost ubiquitously deploy CrowdStrike Falcon to all of our Linux, Macs, and Windows boxes easily.
I think we have seen a return on investment from CrowdStrike Falcon, as generally the amount of time saved not having to threat hunt and look for these issues as they pop up saves us if we can catch it early enough from having to disable multiple users, which may be part of a later phishing event or disruption event in our environment.
Before choosing CrowdStrike Falcon, we really did not look around a lot, as we actually got such a good deal, and based on the reputation and other folks purchasing it in higher ed, we just really went back through it. We did not do a bake-off or anything.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by allowing us to focus on other things and not really worry about this. We only need to concentrate on these threats and indicators once they happen.
Having multiple security capabilities on a single platform has allowed us to work more effectively because I think the more things that you can consolidate into a single pane of glass allows the users to work more effectively without having to keep switching back and forth.
A security incident where CrowdStrike Falcon helped my team detect or stop a threat involved users getting phishing links that told them to download software, which actually downloads ScreenConnect remote access software to their workstations. CrowdStrike Falcon has been detecting these indicators, and we have been able to tell it that since it is not an authorized application within our university, we can have it stop, block, and isolate those instances and notify the SOC, which works pretty well because we are able to then isolate the user, educate the user through the help desk, and have the box re-imaged to make sure it is clean.
CrowdStrike Falcon has affected the workload or productivity of my security team by allowing us to concentrate on other things because this is very self-driven and keeps things moving.
The CrowdStrike Falcon sensor has had a positive impact on endpoint performance and my ability to deploy security at scale because we actually have not had any negative impacts at all. It has all been positive, with the exception of some maybe glitches on the Linux boxes, but there really have not been any performance or issues otherwise.
We are honestly probably not using AI within CrowdStrike Falcon as effectively as we could, but we do use it to help search for related incidents and similarities within the console to see what is there.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is the ease of use and the lightweight client, which seem to be the biggest advantages.
The best advice I could give to others looking into using CrowdStrike Falcon is to listen, understand what your options are, make sure you have a good idea of what your deployment is going to look like and plan for that, and then everything should flow freely. Do not buy it haphazardly. I would rate this review a 10 out of 10.
Our main use cases for CrowdStrike Falcon are endpoint security and USB access, with endpoint security being our primary focus.
I can describe a security incident where CrowdStrike Falcon helped my team detect and stop a threat. One of our IT help desk analysts downloaded a BIOS update from Dell without realizing it contained a critical vulnerability. CrowdStrike Falcon helped us block that download and alerted us to investigate it. We were able to follow up, see what process was running, and determine that our analyst needed to double-check that we were downloading and uploading up-to-date BIOS updates.
My use of CrowdStrike Falcon has expanded since my initial deployment from endpoint security to USB access. We were initially managing USB access through GPO, but we decided to transition to CrowdStrike Falcon because it provided us with greater visibility.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because it gives us a lot of granularity on what goes on, what processes are being run, and what is actually being executed if anyone is trying to get onto our endpoints.
The benefits I have seen from having multiple security capabilities on a single platform is that it gives us more tools to investigate and specifically tells us what happened. Having all those tools at our disposal gives us the benefit of knowing exactly what happened, what time it happened, and what process or executable was being run.
The value I have seen from having endpoint identity, cloud, and other security telemetry in CrowdStrike Falcon is that it is good to have it all consolidated in one platform so we do not have to deal with logging in and going to multiple different sources. It is all consolidated, so it is good to have one platform that we can go to.
CrowdStrike Falcon has affected the workload or productivity of my security team by simplifying it significantly. It also gives us the flexibility to simplify our processes, but if we want to get granular, we can go in deeper, investigate, and get down to the details.
We are not currently using AI within CrowdStrike Falcon, but that is definitely something that we want to explore further because we know that CrowdStrike values the discovery of AI and ensuring you have full coverage.
CrowdStrike Falcon can be improved by strengthening the focus on AI and keeping up with responding to AI as it constantly evolves. It would be beneficial to have more information on that.
I have been using CrowdStrike Falcon for about eight months, ever since I started at Royal Business Bank back in January, and it has been really good to us so far.
I would assess the stability and reliability of CrowdStrike Falcon as very reliable. A lot of the information they provide us is accurate and delivered in real-time.
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.
CrowdStrike Falcon has had a positive impact on endpoint performance and my ability to deploy security at scale. Everything has been smooth and happens autonomously. We do not have to be closely monitoring the sensor updates that get deployed. The simplicity of the process is a major advantage.
I would evaluate customer service and technical support as really good. They are very fast and usually respond within a few hours, providing us with all the information we need, including documentation, notes, and action items we need to take.
CrowdStrike Falcon has allowed us to consolidate or replace other security tools. We have had a few security tools that were redundant, and it helped us with the cost benefit of cutting those off and consolidating everything into one security tool.
We decided to cut Darktrace and stick with CrowdStrike Falcon because we realized we do not really need two platforms for the same process. Darktrace is more of a network security platform, and CrowdStrike Falcon does a little bit of both.
I would describe my experience with deploying CrowdStrike Falcon as good and simple. It has been really easy to deploy out, and if I ever need anything, the support is always really good.
What worked well during deployment was that CrowdStrike Falcon was really responsive when we faced some challenges with a recent Dell BIOS update that they were flagging. It created a lot of noise for us, but CrowdStrike Falcon had documentation on that specific type of update and let us know the response action that we needed to take.
I have seen a return on investment with CrowdStrike Falcon. The business has definitely seen a significant investment in it, particularly with the amount of visibility and the ability to triage and manage alerts that we now have.
My experience with pricing, setup cost, and licensing has been good with no complaints. It has been really simple, and they have been very honest and willing to work with us.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is the comparison with Arctic Wolf, which is a managed detection and response platform. The main difference was the granularity and the ability to give us more data to read and analyze.
I would rate CrowdStrike Falcon overall as a nine out of ten because it is a really good tool, and obviously nothing is perfect, but it is definitely a big player in the security industry. I would advise other organizations considering CrowdStrike Falcon that if you want to get more visibility and more data, then CrowdStrike Falcon is definitely something you should consider. I think their customer support is really good and their agents are very professional and smooth. If you are ever looking for more granular insights, CrowdStrike Falcon is the way to go.
My main use case for CrowdStrike Falcon is endpoint detection for the most part.
The other part would be all the other capabilities that we use it for, such as identity, detection, policies, response, RTR, and forensics.
The benefits I've seen from having multiple security capabilities on a single platform include a single pane of glass, the ability to contain, and eradicate threats easier.
The value I've seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform makes it easy to use one path to focus on specific threats and be able to correlate them together, especially with advanced search and using the graph.
CrowdStrike Falcon has definitely decreased the workload and increased the productivity of my security team compared to if we were to use something else.
The Falcon sensor's impact on endpoint performance is that it does not necessarily affect it in a negative way; the agent does not. From a security perspective, it has a very high impact with ensuring things are secure.
The only downside is trying to figure out all the agents or all of the machines that do not have CrowdStrike Falcon on them, unlike SentinelOne which has a feature for that, along with a feature where you can roll back to detect ransomware if you ever get ransomware.
CrowdStrike Falcon can be improved by having the ability to scan the network to determine what machines do not have CrowdStrike Falcon on, which is a big one, and having the ability to roll back from the volume image if you get encrypted. Other than that, it is pretty solid; you have a monopoly on the field as of now.
I have been using CrowdStrike Falcon for seven or eight years.
I would assess the stability and reliability of CrowdStrike Falcon as a 10 out of 10.
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.
My use of CrowdStrike Falcon platform has expanded significantly since my initial deployment; I started with Falcon when I worked for the government and then moved to the private sector. As an incident responder, the majority of clients did not have Falcon, and that is when I got compromised. After we installed Falcon, it made life much easier for them. As times changed, Falcon has come a long way from where it first started; I believe you switched your query language to make it faster, as one of the complaints back then was that it was too slow. Now it is much faster and scales at a large scale, so there are definitely many improvements since the first time I ever used it.
I would evaluate customer service and technical support as generally good, but we must mention 2024 because that was the issue with the blue screens; other than that, there were no other issues.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools; we replaced a couple when we added specific features.
One of the tools I replaced was Wiz; some of the Wiz sensors we replaced with CrowdStrike cloud Falcon sensor because it was cheaper, and then another one with Falcon Forensics would have been Axiom or FTK. However, we have a retainer, so we do not really dive into Falcon Forensics extensively. The identity one, I had a POC but did not prefer it for whatever reason, so I did not replace anything there that I can think of now.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that, from an EDR perspective, it has a tight grip on everything; in some aspects, such as Falcon Forensics, I have used Axiom in the past, and Axiom is probably better. For identity, there are better identity solutions out there, and for host management, Spotlight is one that we replaced Tenable with; it is pretty solid for vulnerability management, especially because it does automatic scanning. One challenge is trying to convince auditors that this is the solution now because they cannot keep up with the times. Overall, CrowdStrike Falcon is pretty amazing.
I would describe my experience with deploying CrowdStrike Falcon as pretty easy to deploy; I have not deployed it in a minute, but when I did, I just hooked it up in whatever automation platform the company at the time used and went from there.
In terms of deployment challenges, figuring out which machines do not have it is an issue I faced, while what worked well was being able to install it and having installers available for different operating systems, although legacy operating systems are difficult to get an installer for, such as 2008 and 2003.
I have seen return on investment with CrowdStrike Falcon.
Return on investment would be most likely just being able to consolidate tools; Spotlight was a big one, and asset discovery is a big one.
I do not deal with pricing, setup costs, and licensing, but I know that it is approximately 60 dollars per endpoint at MSRP, and they make deals based on that. Our sales reps are pretty good, so we just let the sales rep talk to us, and they sold us on it right there.
I would recommend CrowdStrike Falcon over Carbon Black, SentinelOne, Huntress, and any other main EDR solutions to another organization considering it.
The impact of Charlotte AI on my security operations is high from the perspective of being able to find things quicker, but if you ask it to do complex tasks, it is not necessarily the best. I would rate this review an 8 out of 10 overall.

My main use cases for CrowdStrike Falcon mostly center around their Falcon EDR offering and the suite around it, such as what used to be called Spotlight and Complete, OverWatch, and all those capabilities.
Using CrowdStrike Falcon has provided significantly more visibility than previous tools I used, as well as a more streamlined management of exceptions. There are fewer exceptions that are required for the sensor to run. It also runs significantly lighter than the previous providers that I have used in this space.
The benefits I have seen from having multiple security capabilities on a single platform are that it makes monitoring everything significantly easier. It significantly reduces the amount of time needed to do it. When I can see vulnerabilities as well as detections and identity risks all in one spot, it makes it significantly easier to manage and correlate events.
I have seen value from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform. While we have not implemented cloud yet, having identity in the same platform has definitely helped me correlate events with potentially risky identities as well as see a path from potentially compromised devices to a higher privileged identity through having that link together.
I do not have much to offer regarding how CrowdStrike Falcon can be improved.
I have been using CrowdStrike Falcon for about three or four years.
I would assess the stability and reliability of CrowdStrike Falcon as very smooth. Outside of the one blackout we experienced, everything has been working well.
I have not experienced any downtime, crashes, or performance issues outside of that event.
The impact of the CrowdStrike Falcon sensor on endpoint performance and my ability to deploy security at scale has been positive. Considering that we transitioned from a previous provider and not from a blank slate that did not have an EDR on it, we saw performance improvements when implementing CrowdStrike Falcon on systems. It was also a very easy deployment, both through N-central and Amybot for at-scale deployments. It has been very efficient at doing so.
My evaluation of customer service and technical support has overall been fairly good. We were able to resolve a couple of tickets, both at the previous employer and at this one, very smoothly and fairly quickly.
I had previously been using SentinelOne EDR alongside another EDR for its network security aspect and compliance profiles. We have essentially been able to replace SentinelOne with CrowdStrike Falcon and still get all the same visibility that I needed.
My experience with deploying CrowdStrike Falcon was very simple and straightforward. The silent install worked well. I do not think it has failed, or if it has, it was in an extremely minimal amount of cases, especially relative to other deployments that needed significantly more handholding. The one sensor that gets installed across all systems, whether Windows end-user or server device, has made deployment very simple. Deployments on Mac and Linux have also been very problem-free.
I have seen return on investment with CrowdStrike Falcon. We have saved a lot of time and significantly reduced the resources we are using, both on servers and end-user devices, which certainly has increased productivity for everyone.
Regarding my experience with pricing, setup cost, and licensing, I can speak from different perspectives. At my previous employer, we were closer to a medium-sized business, and I could easily see the value of adding CrowdStrike Falcon. I can also discuss the perspective of smaller customers who find it challenging to motivate the acquisition of CrowdStrike Falcon due to higher pricing compared to other players in the field. However, we have been fairly successful so far. On bigger enterprises, there is a very easy way to show ROI and value in implementing CrowdStrike Falcon over a competitor.
I still need a separate vendor for next-gen firewalls, for example, which CrowdStrike Falcon does not provide. However, it has allowed me to definitely consolidate on the endpoint stack between compliance, vulnerability, and actual endpoint protection.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools significantly.
My advice to other organizations considering CrowdStrike Falcon is that if the organization has the size to seriously evaluate the Complete offer, the pricing difference is usually more than justified in acquiring it.
The impact on my security operations has been that it has made us more confident in the delivery of security, both within client environments and within our own.
Reducing the workload around it enables us to do more valuable work in that space and provide security that we feel is more adequate and that we are more confident in.
I can describe a security incident where CrowdStrike Falcon helped my team detect a threat. We had an issue with a stealer log that somehow ended up on a server machine, which we were able to trace back to the administrator who accidentally uploaded it through a Samba share.
I have given this review a rating of ten out of ten.
My main use cases for CrowdStrike Falcon involve everything security. In more detail, we use Falcon Complete to ensure our users are completely covered.
The benefits I have seen from having multiple security capabilities on a single platform are significant because we do not have to go to different types of portals to get any kind of access; it is all in one. CrowdStrike is actually taking care of everything on the back end, so we do not have to worry about trying to go from one thing to another to figure out what is going on within our environment.
The value I have seen from having endpoint identity, cloud, and other security telemetry in the same Falcon platform is significant because it is a one-stop shop that eliminates the need to go from one to another; it is all in one console.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats because we use Falcon Complete, which means the majority of it is that we do not have to constantly monitor everything that is going on. Falcon Complete actually monitors that for us, and when things do pop up, we are literally just reaching out to our users and following up after the fact of everything that Falcon Complete has done to remediate the issues.
CrowdStrike Falcon has drastically reduced the workload and increased the productivity of my security team.
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is zero; it is very easy with no impact whatsoever since it is very lightweight.
CrowdStrike Falcon can be improved by continuing to adapt to everything that is going on with AI and other developments in the world.
The one improvement I would suggest for the future is to make the console side of CrowdStrike Falcon more user-friendly, but as explained, most of those details are not things we need to worry about because those are things that Falcon Complete takes care of; overall, it is all good.
I have been using CrowdStrike Falcon for four years.
Outside of the blue screen week, I have experienced really no downtime, crashes, or performance issues; the security factor of it all is top-notch.
I would assess the stability and reliability of CrowdStrike Falcon as really, really top-notch.
The impact of the Falcon sensor on endpoint performance and my ability to deploy security at scale is zero; it is very easy with no impact whatsoever since it is very lightweight.
I would evaluate customer service and technical support as still top-notch.
The tools I used previously included Trend Micro, and we were also using Proofpoint for a lot of things; much of that has been able to be consolidated into CrowdStrike Falcon, allowing us not to use those products anymore, making it feel like one console to do two things.
What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that we used Trend Micro before, and their team was nowhere near as experienced or available to us, nor were they collaborative to ensure that anything that happened was at zero trust. We were able to get most attacks handled within the first few minutes before anything abruptly took place.
I would describe my experience with deploying CrowdStrike Falcon as easy, super easy.
What worked during deployment was literally zero challenges; the biggest thing was when we went from Trend to CrowdStrike Falcon, where CrowdStrike Falcon did not care if Trend was installed, and they just took over management of everything. After that, it was just up to us to get rid of Trend Micro from all the machines that had it installed.
I have seen return on investment with CrowdStrike Falcon absolutely.
The data points or examples I can share are the many times we have almost had ransom attacks on our systems, and all of them have been stopped.
My experience with pricing, setup costs, and licensing has been very good and very easy.
CrowdStrike Falcon has allowed me to consolidate or replace other security tools, and that is all we have been using.
The advice I would give to other organizations considering CrowdStrike Falcon is that if you are really worried about the cost of it, it is worth it.
I am using AI within CrowdStrike Falcon for deep security issues, but to be honest, we do not use it completely; we really depend on Falcon Complete to do most of the work.
I really cannot think of how my use of CrowdStrike Falcon has expanded since my initial deployment.
My review rating for CrowdStrike Falcon is a 10.

My main use case for CrowdStrike Falcon is endpoint protection. I use CrowdStrike Falcon for general endpoint remediation if users happen to click on malicious content.
The automated task set is excellent. The best features CrowdStrike Falcon offers include automated tasks that remove the need for me to go in and manually remediate threats.
CrowdStrike Falcon has positively impacted my organization by removing task work that the tech would normally have to complete by using the automation processes. It has definitely saved time for my team's workload.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats as it usually detects threats and remediates them before we even have to take any action, definitely saving us a lot of time.
The benefits from having multiple security capabilities on a single platform include that it is easier to manage from a single pane of glass. CrowdStrike Falcon has allowed us to look into consolidating or replacing other security tools, and we are actually looking into that currently.
In a recent security incident, we noticed a few times where CrowdStrike Falcon stopped potential malware from running and removed it before it could establish a foothold. CrowdStrike Falcon sensor has positively impacted endpoint performance by keeping the systems clean and running optimal, aiding our ability to deploy security at scale.
We heard that the newest features coming soon are a major improvement that we would definitely be interested in. We have seen the announcement for the Red Team, Blue Team features, and they sound excellent. We are planning to use AI within CrowdStrike Falcon in the future.
I have been using CrowdStrike Falcon for about six years.
CrowdStrike Falcon is stable.
So far, there have been no issues with CrowdStrike Falcon's scalability.
The customer support for CrowdStrike Falcon has been excellent. I would rate the customer support a 10 on a scale of 1 to 10.
We did not previously use a different solution.
My experience with pricing, setup cost, and licensing has been that so far, it is very easy to work with licensing and setup.
Before choosing CrowdStrike Falcon, we evaluated other options and currently overlap with Darktrace, but Darktrace's cost is making us look elsewhere.
CrowdStrike Falcon is deployed in my organization using a hybrid cloud setup. What differentiates CrowdStrike Falcon from other cybersecurity platforms I have used or evaluated is that so far, it is a well-recognized name with good performance and a good overall reputation. I love it. My advice to others looking into using CrowdStrike Falcon is to not look at anything else and to use it instead. It works and it works great. I would rate this product a 10 out of 10.
My main use case for CrowdStrike Falcon is protecting endpoints and cloud security. For endpoint or cloud security, I do a lot of threat hunting inside my environment using all the telemetry that CrowdStrike Falcon provides, and I tackle incidents by quarantining, deleting, and investigating remotely, among other actions. I have a lot of old software and operating systems, and CrowdStrike Falcon helps me protect all the boundaries of those systems.
In my opinion, the best features CrowdStrike Falcon offers are the Threat Graph, the investigation page, and the telemetry. The Threat Graph and the telemetry help my team day-to-day by providing insights during my threat hunting process on what's running, what's happening, what rules I can build, and what TTPs may be under the radar, with the Threat Graph being useful for new joiners and day-to-day incident response actions.
CrowdStrike Falcon positively impacts my organization by helping to protect us, providing us with a lot of visibility, and helping to show my board how my protection status is currently. Since using CrowdStrike Falcon, I have seen a lot faster incident response actions, containment, and it helps me mitigate many threats automatically that I previously handled manually.
Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by bringing a lot faster incident response times, including the MTTR and MTDR key indicators. Having multiple security capabilities on a single platform like CrowdStrike Falcon is helpful because my team does not need to change a lot of interfaces or consoles, and working within just one console is more helpful, which I believe brings more value to my team's time spent on the platform.
CrowdStrike Falcon lowers the workload and augments the productivity of my security team.
I think that bringing more AI and insights into anomalies could be helpful for CrowdStrike Falcon. I would also appreciate having CrowdStrike Falcon on legacy systems such as IBM AIX. Currently, I am not using AI within CrowdStrike Falcon, but I plan to do so.
I have been working in my current field for at least fifteen years.
CrowdStrike Falcon is stable.
I just plug in more licenses and agents for scalability, and there is no complexity involved.
The customer support is excellent, as I receive a lot of help from customer support and also from my technical and sales partner.
I replaced Trend Micro with CrowdStrike Falcon, which brings more value with more precise detection and more automated responses. I previously used Trend Micro Vision One, and I switched because it was impacting me with many false positives and causing production disruptions.
CrowdStrike Falcon was not purchased through the AWS Marketplace; it was purchased with a sales partner.
I have seen money saved and time saved, as I have augmented the capacity of my current team without needing to hire more people.
My experience with pricing, setup cost, and licensing was good, as I received a lot of help from CrowdStrike Falcon itself and my sales partner Stelltech, making it a great experience.
I have evaluated other options, such as Microsoft, before choosing CrowdStrike Falcon.
CrowdStrike Falcon differentiates itself from other cybersecurity platforms I have used or evaluated by having a lower learning curve compared to its competitors, as well as better accuracy and widely recognized superior telemetry. My advice to others looking into using CrowdStrike Falcon is to conduct a POC, as I believe the product proves itself during the POC.
CrowdStrike Falcon is unique in its ability to deploy security at scale quickly, as I do not see other vendors providing such options. I do not see any impact on endpoint performance, and CrowdStrike Falcon is unique in its ability to deploy security at scale quickly, as I do not see other vendors providing such options.
The alerts and capabilities of CrowdStrike Falcon are very precise, and with the AI built in, it brings more value and is becoming more powerful in recent months. I rate this review ten out of ten.