CrowdStrike Falcon Room for Improvement

Chintan-Vyas - PeerSpot reviewer
Associate Director at KPMG

Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files.

The product could be more accurate in terms of performance.

We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.

View full review »
JS
Director of IT at a tech services company with 51-200 employees

It would be nice if the dashboard had some more information upfront, and looked a little better. Having a cooler dashboard is nice to have, although it is not as important as the functionality, which is very good.

View full review »
Syed Ubaid Ali Jafri - PeerSpot reviewer
Head of Cyber Defense & Offensive Security at Habib Bank Limited

Area of Improvement

The products still require improvement in the Apple environment (Mac). Currently, this solution (as of July 2022) is not compatible with MAC OS (X), Catalina, or Big Sur.

Similarly, the product is also not compatible with Unix-based systems including AIX, Darwin, and FreeBSD.

CS Falcon sensing capabilities for non-domain machines should be enhanced since the agent doesn't detect the neighbor's IP Address and/or any anomaly which was identified in the network for the non-domain machine.

Additional Features required in the Next release:

The product requires an add-on feature which should be a turnkey feature if it requires to be turned on to XDR no changes should be required to be made on the user end as the agent is already installed.

View full review »
Buyer's Guide
CrowdStrike Falcon
April 2024
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,667 professionals have used our research since 2012.
JA
Security Analyst II at a healthcare company with 10,001+ employees

When we first went to CrowdStrike and purchased it, a lot of my team members all had the same issue: There was too much information. Initially, when the user logged in, they were getting dumped on, like a five-gallon bucket of ice. Trying to sort through it all, you can get lost easily. Until you have really had time in the solution to really digest how to use things, it is information overload. We didn't get that from Palo Alto XDR.

I would like them to improve the correlation of data in the search algorithms. When we run an investigation, malware, phishing, etc., I want to look at multiple endpoints at once to correlate that data to see the likenesses, e.g., how are they not alike or what systems and processes are running across those systems? I don't want to have to run the same search in their Spotlight module five, 10, 15, or 100 times to get 100 different results, copy that data out, and then correlate it on my own. In a very simple way, I want to be able to load up a comma-delimited list giving me the spotlight data on these X amount of hosts, letting me search for it quickly. We have had to go back to CrowdStrike, and say, "Our search are taking far too long for even one host." They did bump up the cores and that did improve performance, but it is still kind of slow to get that Spotlight data. That is probably our biggest pain point. I think that needs some help. I understand this kind of information access is probably not the easiest thing to do. It is probably a big ask depending on how their back-end is setup. 

View full review »
AK
Senior Data Hosting and Security Special at Two aquate

We'd like to see more integration capabilities. 

We need more log storage as CrowdStrike will dump all logs to the centralized server. 

View full review »
Robert S. Balter - PeerSpot reviewer
Owner at RSBPC

The content-filtering features for children could be improved. We have young grandchildren aged 12 and 8. My daughter, their mother, wants to keep them from getting in trouble on the net. She looked at all these other solutions from Google, Microsoft, etc., and she couldn't figure out how to make any of those work. I told her that I bet CrowdStrike could handle this. Sure enough, CrowdStrike can do exactly that. It's the same solution that the Defense Department gets. It works, but it's a little complicated to implement. It could be simpler to set the policies. 

View full review »
EH
Chief Information Security Officer at a real estate/law firm with 10,001+ employees

There is so much data in their dashboarding and other stuff like, but there is also still some work to do on, "How do you boil it up to certain higher levels/executives?" There is a lot of good technical detail, but in the position that I sit in, sometimes it is a little hard when I am not in it day in, day out to come to what is the real executive level sorts of things. For example, CrowdStrike shows incidents, but what are the things that I really need to worry about as a CISO at a company? That is the one area for improvement.

Finally, they bought a company that is doing SIEM, which is interesting to me. When I first started with CrowdStrike in my previous organization, four or five years ago, I went to CrowdStrike, and said, "I don't want to have to buy or continue to support our SIEM product. I would rather use you guys. Can I pay you extra money to hold that data and do those things so we can have that functionality? Then, I can get one rid of a solution." At that time, they told me, "No, we're not a SIEM company." I did not like the answer, but I respected it. Now that they bought one, and I am like, "Wow, I guess I was just a few years too early." So, I'm glad to see those sorts of things. I am glad to see them evolving into those areas where I saw it years ago, where they are strong, and displace others.

I would love to see more investment in Insight because CrowdStrike have an opportunity to potentially displace some of the vulnerability management vendors with the visibility they can see over time. I want to see them continue to evolve, e.g., what other things can they disrupt which are operational things we have to continue to do as an organization. Then, I can have less vendors and put more effort into one solution that we really want to operationalize.

View full review »
JT
Director - IT Security Operations at a manufacturing company with 10,001+ employees

CrowdStrike Suites and the way that it bundles things can be a bit challenging. It should be easier to integrate with the other stuff that they sell or be included with what they sell. We have one piece, then they are talking about another piece on vulnerability management all of the sudden, and we don't own that piece. We can see it in the console, but nothing shows up. It simply appears within the tool as an option, but we can't use it without purchasing it.

View full review »
Niranjan N - PeerSpot reviewer
Sr Analyst at ATOS

CrowdStrike Falcon sometimes wrongly flags things as malicious. Let's say a user is active on Chrome only. Sometimes, our cross-segmenting will fetch from the backend data and show that it is malicious because of memory or CPU utilization.

View full review »
Marcelino Bocanegra - PeerSpot reviewer
Cybersecurity solution architect Individual Contributor at IQSEC SA

There are some areas where some customers would prefer a different service.

View full review »
CK
IT Network Infrastructure Manager at HENSOLDT

The portal can be clunky to navigate at times and has room for improvement.

View full review »
Jordan Swanson - PeerSpot reviewer
Information Security Assurance Engineer at School District of Lee County

The ability to receive text alerts natively in the console would be kind of cool. Some people put their email on quiet hours, so having it natively in the system would be nice.

I know that they offer an identity piece and a firewall piece and we haven't subscribed to or purchased either of those, but having some of that data in the base program would be good, and then if you want more control, you pay for it. There's times where I want to look at an internet history of a device that's remote, or I want to see logins, successful or unsuccessful. I don't want to manage identity and I don't want CrowdStrike to alert on it, but it would be nice if the ability to see the data was included with the base product. Then that could kind of get your foot in the door with having the ability to look at that information, but not being able to do anything actionable with it.

View full review »
Sandesh Dumbre - PeerSpot reviewer
Senior Information Security Engineer at a tech services company with 1,001-5,000 employees

File integrity monitoring could be improved. They need to have more clarity on the policies and how we can apply them to get the file modification details. In terms of vulnerability management, CrowdStrike doesn't have the network scanning feature, which other competitors have.

We sometimes get false positives. We have had to create some exceptions. However, we have been able to minimize the noise. 

View full review »
Ali Minissi - PeerSpot reviewer
Group IT Director - Technical Operations at a construction company with 10,001+ employees

CrowdStrike Falcon could be enhanced by extending its security capabilities to include NDR and XDR.

The pricing has room for improvement.

View full review »
AT
Chief Security Officer at a financial services firm with 201-500 employees

The deployment process is an area that needs to be improved. For some reason, CrowdStrike does not provide any help in terms of how to deploy the agent in a more efficient manner. They just don't provide the support there, which leaves their customers to figure out how to push agents out, either through GPO or through BigFix or through SCCM, and there was no support on that side. Not being able to complete the deployment in an efficient manner is one of the huge weaknesses.

It would be good if they had a feature to remove agents. We're in a transaction processing environment and if CrowdStrike is affecting a transaction processing server, we need to uninstall that agent pretty fast. Right now, the uninstall has to be done manually, which is not great. If we have a dashboard capability to uninstall agents, I think that would be great.

The dashboard seems a little bit too clunky in the sense that it's spread out in so many ways that if you don't log in on a daily basis, you're going to forget where things are. They can do a better job in organizing the dashboard.

View full review »
SH
Director, IT & Systems Security at Tilson

The console is a little cluttered and at times, finding what you're looking for is not intuitive. Once you find it, it's great, but it's not always very intuitive as to how to find exactly what you're looking for sometimes.

View full review »
JM
Information Security Analyst at a insurance company with 1,001-5,000 employees

It would be nice if they did have some sort of Active Directory tie-in, whether that be Azure or on-prem. Sometimes, it is difficult for us to determine if we are missing any endpoints or servers in CrowdStrike. We honestly don't have a great inventory, but it would be nice if CrowdStrike had a way to say this is everything in your environment, Active Directory-wise, and this is what doesn't have sensors. They try to do that now with a function that they have built-in, but I have been unsuccessful in having it help us identify what needs a sensor. So, better visibility of what doesn't have a sensor in our environment would be helpful.

View full review »
GK
Information Security, Sr. Analyst at a wholesaler/distributor with 10,001+ employees

We would like to be able to perform on-demand scanning, rather than relying on the scheduler. Right now, CrowdStrike does not have an on-demand scanner. They have the always-on, but we have found instances where artifacts are being blocked from running, but they're not being removed. With an on-demand scanner, we would have the ability to remove those artifacts from an end user's machine.

I would like to see the multi-site environment functionality added in the next release. Currently, we are working under a single-site environment, and on the roadmap, they mentioned having the ability to have a multi-site environment.

View full review »
KR
Cyber Security Manager at a university with 10,001+ employees

We've tried some integrations with solutions, closing off false positives and things like that. Falcon could include more features in that area. In addition, some features are modularized and we're unable to buy them as we're in the healthcare field and limited in the amount we can invest. 

View full review »
Sathya Paul - PeerSpot reviewer
Director Of Information Technology at TollPlus LLC.

Technical support could be better than what is currently offered. 

View full review »
ManojKumar42 - PeerSpot reviewer
Information Security Engineer at a non-tech company with 10,001+ employees

I've found that CrowdStrike's technical support could benefit from increased technical expertise. In my experience, their representatives haven't been able to resolve my issues as effectively as I would have liked.

View full review »
Khushru_Mistry - PeerSpot reviewer
CTO at GM Modular

If CrowdStrike can further expand its support for XDR compatibility, that would give it an edge over all the other competing new products.

View full review »
AS
Cyber Security Engineer at a legal firm with 501-1,000 employees

There are some aspects of the UI that could use some improvement, e.g., working in groups. I build a group, then I have to manually assign prevention policies, update policies, etc., but there is no function to copy that group. So, if I wanted to make a subgroup for troubleshooting or divide workstations into groups of laptops and desktops, then I have to manually build a brand new group. I can't just copy a build from one to another. Additionally, in order to do any work within a group, I have to first do the work on the respective prevention policy page or individual policy page, then remove the group if the group is assigned to a different prevention policy, remove the prevention policy, and then add the new one in. So, it can get a little hectic. It would be easier if I could add and remove things from the group page rather than having to go into the policy pages to do it.

View full review »
Ganesh-Jadhav - PeerSpot reviewer
Senior Cyber Security Analyst at Securonix

They are good at what they are doing, but they can add more use cases. They can improve their documentation. It is a very big aspect where they are lacking. They have documentation, but it is behind the wall of authentication. It is not available publicly.

In terms of features, I would like them to add detailed logging functionality in CrowdStrike. Currently, CrowdStrike detects the threats immediately based on the IOCs and the signature-based policies or many threat behaviors, but in terms of logging those threats, it is not very good. The information that they provide in the logs is very little. They can build more analytics into it. If they can add more information about an event, it will be beneficial for us and everyone else who is using CrowdStrike.

View full review »
DL
Head Deputy Head of IT, Information Technology's Projects & Developments Center at a energy/utilities company with 201-500 employees

While Falcon's advanced capabilities offer robust security solutions, it's worth noting that some of these features may come at a higher cost. This could potentially make it a less economical option for small to medium-sized businesses operating on tighter budgets. It's important for such companies to weigh the benefits of Falcon's comprehensive protection against their financial constraints to make an informed decision.

View full review »
HB
Security Officer

An improvement would be to extend support to legacy and unsupported servers. In the next release, CrowdStrike should include patch and vulnerability management, which would allow us to rely on just one solution.

View full review »
NC
IT Security Analyst at U.S. Venture, Inc.

I would like to see a little bit more in the offline scanning ability. This just comes from my background in what I have done in other positions. They only scan on demand, so I always have this fear that we sometimes maybe email out a dormant virus and can be held liable for that. That is something where I would like to see a little bit more robustness to the tool. 

View full review »
MK
Associate Director - Infrastructure Engineering at AFT

If an operating system is stopped by support by the original vendor like Microsoft, or maybe Apple, within a few weeks, CrowdStrike will also decide they no longer support it, and they kind of move on. I understand their model. However, if we still have the OS, it's hard to keep it protected. So, for example, if Microsoft decides to stop supporting or patching a solution, Crowdstrike too will stop supporting it and making updates. It's still a useable product, it's just not getting updates or patches and therefore may be vulnerable. 

The result is that we can't guarantee we're going to be able to protect that hardware or operating system. We either have to upgrade to a newer platform, which sometimes is not possible because you have a legacy application. Whatever that constraint is, sometimes we're not able to move things. We still have to rely on other products to support that. That's the only quandary I have with them. 

Basically, they don't cover legacy OS or applications. That's the only issue we're concerned about.

When a file is infected or it detects a ransomware file network, when it does remediate, it should self-heal as Sophos does. That's a good feature to have, but I don't know enough pros and cons about that to kind of recommend that because if it is a false positive, that may be a problem. If it detected a valid file and if for some reason it decides, "Oh, this looks like an infection," and maybe it's not actually infected, and if it goes in and remediates it by replacing it with an older file, that may be a problem. However, I don't know, because I've never used that feature or heard anybody say that's a problem.

View full review »
Dev Kudtharkar - PeerSpot reviewer
Director of Information Technology at Slice

Forensic controls have room for improvement, and CrowdStrike Falcon can add more features here.

Another improvement could be the support for this product could be cheaper.

View full review »
EW
Security Principal at Trifecta Cloud Security Solutions

CrowdStrike needs to quit making up stuff about its features and functionality to bash its competition.

I would like to see CrowdStrike become closer to an agentless solution where I wouldn't have to deploy software and maintain the version of the solution.

View full review »
JavierFernandez - PeerSpot reviewer
Head of IT at Alantra

CrowdStrike Falcon could improve the logs by making them free to the API.

View full review »
AbhishekBirkett - PeerSpot reviewer
Senior Manager - Enterprise Accounts at Hitachi Systems, Ltd.

In a future release, I would like to see more integrations for data breaches and security features.

View full review »
AK
Lead Engg. Information Assurance at ACPL Systems Pvt Ltd

CrowdStrike Falcon could improve by adding manual scanning or serverless scanning. It is not available at this time.

View full review »
MG
Enterprise Cybersecurity Architect at Swagelok Company

There is nothing existing today that I would change very much about the solution. Because of the capability of the data that they are ingesting, they have the ability to create tools leveraging that data to enhance the capability of the platform. The possibilities are endless.

View full review »
Jawaria Abbas - PeerSpot reviewer
Security Engineer at a computer software company with 201-500 employees

The dashboard area must be improved. We have integration with Splunk, and we are creating a dashboard there. Their dashboard area must be up to date. It should have more details and more options to create the reports and things like that.

I have some concerns about their support. I am not happy or satisfied with their support. Something happened, and we opened a ticket. Their support engineer just vanished, and after a month, he came back and told us that he was off work and could not pursue the ticket. He said that he now has the time, but logs are gone because there is a time limit. We were asked to repeat the test. This is very unusual for me. 

View full review »
Nakul Chopra - PeerSpot reviewer
Owner at IT Solution

We can't do scanning audits or device blocking or application control. There are traditional antivirus features missing in XDR, and that is an issue. 

View full review »
Krishna .R - PeerSpot reviewer
Cyber Security Regional Head at a computer software company with 1,001-5,000 employees

For CrowdStrike to work, all the machines need to have an internet connection. This makes it challenging to assist customers without an internet connection. We would like to have a mechanism or relay to make this possible.  

View full review »
MA
Pre-Sales Engineer at EliteVAD

The pricing is a bit too high. They need to adjust their target market.

I'd like to see a risk assessment or vulnerability management feature to show the company risk factors for the endpoints that have Crowdstrike deployed. 

I'm not sure if they offer patch management. If they don't, they really should. For larger enterprises, managing all those endpoints and trying to figure out which needs a patch can get tedious.

View full review »
RB
IT Consultant at a comms service provider with 5,001-10,000 employees

There is room for improvement in managing multiple customer IDs. Enhancements in the console web for better control and customization of sensor features would be valuable to ensure a smoother experience in handling various customer IDs and installations.

View full review »
GC
Security Analyst at a insurance company with 1,001-5,000 employees

Despite implementing tuning rules specifically designed to address them, we are still encountering a significant number of false positives. This issue persists even after collaborating with their support team to find a solution.

I have worked with their technical support on several problems that were never fully resolved.

View full review »
SW
AVP of Tech at a insurance company with 201-500 employees

I do not have any notes for improvement. It just works. 

They offered a white glove service that was extremely costly. When we got into it, we saw it was relatively easy. If I was being nitpicky, I'd say that I don't like being sold something that's unnecessary. That's the only downside I've seen to the solution. 

View full review »
RC
Security Systems Analyst at a retailer with 5,001-10,000 employees

This solution lacks basic functionality, such as being able to perform on-demand scanning. This presents a challenge when it comes to the payment card industry, PCI which has that as built-in requirements for the PCI DSS standard.

I would also like to see the endpoint firewall component produce some level of logging and feedback. 

View full review »
MW
Chief Information Security Officer at a hospitality company with 5,001-10,000 employees

They need to strengthen the forensic capabilities of this product, for e-discovery.

View full review »
JS
Director Of Information Technology at DLZ Construction Svs.

Improvement could be made in the number of false positives we get, there are more than there needs to be. Typical Windows functions sometimes get stopped by CrowdStrike. In general, I'd rather err on the side of safety but some of these are really straightforward functions that should get through.

For the future, I think they need to keep building on their extensibility, the capability to be extended, so that it's not lost and we can utilize the knowledge that we're gaining from the endpoints. 

View full review »
Neeruganti Santhosh Kumar - PeerSpot reviewer
Security Analyst at a tech services company with 501-1,000 employees

The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool. 

View full review »
RG
Cybersecurity Analyst at a computer software company with 51-200 employees

The detection time has room for improvement.

View full review »
Sandeep Sehrawat - PeerSpot reviewer
Information Technology Security Consultant at Sify Technologies

CrowdStrike should provide better visibility in its reporting. There should be more forensic details about detected threats.

View full review »
Park Armstrong - PeerSpot reviewer
Chief Technical and Solution Architect at Vertigo Inc.

The skillsets needed to run CrowdStrike Falcon are extensive if you want to get the most value out of the tool.

In a future release, the mobile space can use improvement. However, some of those constrained are by Apple and other platforms as to what they can do on the platform. Some of the limitations are industry-based.

View full review »
BH
Service at Four-U Office Inc

The solution doesn't have a whole lot of email security on offer. We did know that going into the purchase, however. We decided to get a different solution for that aspect of security.

They have a sandbox feature, but it's all they do. They have different grades. There's the Socket Pro and then there's an ADR. Then there's another one where they pretty much watch your system for you. And it's all different. It's all based on the price you want to spend. I wasn't going to drop a large amount of money.

They don't really have anything when it comes to scanning attachments. That would be something I would like.

View full review »
UG
Vice President at a financial services firm with 10,001+ employees

The current database schema presents challenges and has potential for improvement.

The technical support response time can be improved.

There are a lot of false positives reported.

View full review »
Waleed Omar - PeerSpot reviewer
Information Security Specialist at Arab Open University

There could be more flexibility in terms of policy defining and certain features, like USB controls, should come standard with the license. Many CrowdStrike Falcon competitors are cheaper and offer a slew of features in the standard license.

CrowdStrike Falcon is not so flexible. We need a specific admin control or maybe supervised controls to change or modify the settings.

View full review »
BS
Specialist, Lead Desktop Support at a energy/utilities company with 5,001-10,000 employees

The overall cost of CrowdStrike Falcon could be reduced.

View full review »
JM
President and CEO at a tech services company with 51-200 employees

The price is too high.

View full review »
Gogineni Venkatachowdary - PeerSpot reviewer
Cloud Operations Center Analyst at a pharma/biotech company with 10,001+ employees

The performance could be better. It's a bit slow. When we click to launch the dashboard, it should be more responsive.

View full review »
MJ
Server Administrator at TIR Canada

The solution keeps changing their website to the point that it's hard to navigate. Also, the technical support is kind of hit-or-miss. Sometimes they really respond quickly and sometimes I don't hear from them for a long time.

View full review »
Dan Brunnquell - PeerSpot reviewer
Director Of Information Technology at a financial services firm with 11-50 employees

CrowdStrike Falcon by itself does not supply in-depth reporting. 

Falcon Protect does what it does. It's endpoint security — nothing more, nothing less. 

What it does, It does well. However, if you need more information on what it found and how it got there (including board reporting and compliance reporting), that's not there. Some of the other solutions that are available give you that, right out of the box.

View full review »
GH
Senior Cyber Security Analyst with 1,001-5,000 employees

Any kind of integration that you want to do, such as using the API to connect to a SIEM, is complex and it will be expensive to do. It is quite a pricey product.

View full review »
DA
Sr. IT Support Executive at a hospitality company with 1,001-5,000 employees

I'm new to the solution. Currently, I'm comparing it to other EDR solutions to see if anything is missing, however, I'm still learning the ins and outs of the product.

It may be due to the fact that I am new, however, I'm having trouble understanding their licensing.

It does take more time to scan than other solutions.

The solution should continue to make the learning curve as short as possible by providing even more training and documentation.

View full review »
Madhawa Liyanage - PeerSpot reviewer
Cyber Security Consultant - Defensive Security at DeltaSpike Pvt Ltd

CrowdStrike Falcon could improve the EDR functionality. Once the functionality of the solution improves, it will be even better in the market and able to compete with Carbon Black.

In a future release, if there were XDR features it would be beneficial.

View full review »
CA
Product Manager at a comms service provider with 51-200 employees

I have experience with a product called SentinelOne, which has a feature that allows for the customization of query languages. I would like to see such a feature for CrowdStrike

I want to be able to create independent groups, each managed by its own admin, so I can isolate the group I use for demonstration purposes.

I have heard about CrowdStrike collecting personal information for marketing purposes, but that's not something I was looking for.

View full review »
MK
Dy General Manager at a real estate/law firm with 501-1,000 employees

The solution needs to have integration with on-premises security devices and security facilities. That means all the security products, including the perimeter firewall, the DMZ. 

I'd really like to have a complete solution. Right now most of the incidents happen on our endpoints. It is visible at the endpoint, the end server. If this can have a correlation tool that could actually give us a comprehensive dashboard, that would be useful. It could give us top-down visibility and could be from the firewall or any kind of security protection tool. It could be part of the DNS protection suite. However, that's why it's so important to have better integration capabilities.

If this endpoint is trying to get at this particular website and it is identified as DNS level protection, that also comes to this dashboard. Around 80% to 90% view of whatever it is happening with this endpoint, whatever action it is doing, can be inspected on the dashboard.

 If the endpoint is protected by CrowdStrike. I am only to access this application through a CrowdStrike protected device. 

View full review »
Murali Krishnan L - PeerSpot reviewer
Technical Manager (SOC Operations) at Novac Technology Solutions

Crowdstrike Falcon XDR can improve the integration. There are some locks on the cloud to on-premise integrations.

View full review »
MH
DGM IT at Union Bank of Colombo

I would like to see equal support across all versions. Aside from that, I would say most of the features are there. 

View full review »
LM
Information Security Officer at a financial services firm with 51-200 employees

In the future release of CrowdStrike Falcon, they should add a sandbox feature.

View full review »
Dan Brunnquell - PeerSpot reviewer
Director Of Information Technology at a financial services firm with 11-50 employees

I miss a feature for the USB control that they have as an add-on. I haven't gotten to the point where I want to pay for it, but the features that I miss are available.

The biggest issue with Falcon as a standalone product is it doesn't have very much reporting.
Out of the box, the only weakness is the level of reporting.

All the analytics and the telemetry are there, it's just a matter of getting to it. Other vendors offer some of that stuff right out of the box.

CrowdStrike Falcon has been very low maintenance. There are features on it that I haven't touched yet. I've got a SIEM that I haven't really had time to explore fully. I have a patch management system that does what it does. I have a firewall and IDS that do what they do, and I have an endpoint security system that does what it does.

MSPs keep asking how one person can keep up to the different solutions and alerting, if you don't have any problems, then it's pretty easy to keep up. Everything does what it does.  I don't experience any of the issues that apparently a lot of people have on their network. How can I tell you what to improve if it's doing what it's supposed to do? 

View full review »
DC
Director of Cloud Architecture at a energy/utilities company with 10,001+ employees

We have had to open a case with the technical support to get some issues and bugs resolved, but they were resolved relatively quickly.

View full review »
SN
Chief Technology Officer at a manufacturing company with 1,001-5,000 employees

The pricing structure should allow for some flexibility.

View full review »
GM
SOC Analyst at a financial services firm with 1,001-5,000 employees

I believe that most of the features are perfect for my needs, anything else is only icing on the cake.

It can be expensive depending on the features you select.

The technical support could be improved.

View full review »
MK
Junior Security Engineer at Altron

Falcon could be improved with more function on the mobile end of things and better optimization with mobile devices. In the next release, CrowdStrike should include the ability to send logs to SIM tools.

View full review »
TZ
Chief Information Security Officer at a manufacturing company with 10,001+ employees

The management reporting functionality needs to be improved.

We would like to see more features for vulnerability management included.

View full review »
SE
Senior System Engineer at a computer software company with 1,001-5,000 employees

The solution overall is a good product, and we don't see too much room for improvement.

Support, particularly related to after-sales and after deployment, could be improved a bit. If you need to connect to support, it takes at least a day to reach the support team and get a proper reply.

The solution could use better device control.

View full review »
AJITHH G - PeerSpot reviewer
Solution Engineer at AppSmart

I would like to see a more accurate integration and an option to check the local machine.

View full review »
AE
Infrastructure Manager at Quaracrm

They should provide us with good visibility for everything.

View full review »
JP
Senior Engineer at Neosecure

CrowdStrike Falcon could improve by having an easier way to search and use the interface for extracting queries from the data. The interface could improve.

View full review »
PG
IT Manager at a consultancy with 5,001-10,000 employees

Unfortunately, native applications are not supported.

View full review »
CA
Product Manager at a comms service provider with 51-200 employees

CrowdStrike Falcon needs to improve their host management system.

View full review »
MH
Cloud Solution architect at VaporVM

Dashboard creation is one of the areas for improvement in CrowdStrike Falcon. Sometimes, management asks for a custom dashboard, so my team has to collect data from CrowdStrike Falcon, integrate that in Splunk, then create the dashboard in Splunk. The Splunk dashboard is more elaborate, so the CrowdStrike Falcon dashboard needs improvement.

Another area for improvement in the tool is the malware detection report, as it needs to be more detailed and include some graphics so that if you want to present that data in a nutshell, it's easier to do. For example, the report should consist of some graphical representation that shows a month's worth of data.

In terms of an additional feature I'd like CrowdStrike Falcon to have, it's the device posture assessment feature that detects the device posture within the network. Whichever device connects to the corporate network, my company should be able to analyze the device posture. Then there should be communication with the network, which means that as soon as a device connects, CrowdStrike Falcon can assess the device posture, detect its corporate asset, and decide whether it should be allowed on the network.

View full review »
Akash Jogbond - PeerSpot reviewer
Team Lead at Foresight Software Solutions

This solution could be improved with greater scope for admins to make changes to the solution. Human input and intelligence has little value as the solution is built on artificial intelligence. 

View full review »
NiteshSharma - PeerSpot reviewer
Pre-Sales Architect at Network Techlab (I) Pvt. Ltd

Sometimes CrowdStrike changes the GUI, and they need to be better at informing us and providing guidance concerning that.

I would like to see a web filtering feature, and better application features. This would make the product easier to sell to smaller businesses, and would make it so that devices follow the applied policies anywhere; even when users are at home or travelling in another country, for example.

View full review »
RV
Business Development Manager - Security at a computer software company with 201-500 employees

Setting up and installing CrowdStrike Falcon is not easy, so an area for improvement is for that process to be simplified.

View full review »
TS
Executive Technology Advisor at Vitso

I think there's an opportunity to enhance the AI or at least the traps to say, if something changes from this baseline, let us know and flag it. It's got a pretty good engine to do that on its own but it's one of the things that are important to us, so I'm just trying to increase the time-to-issue identification.

By comparison to buying into the Microsoft suite, it was definitely less costly. CrowdStrike can be costly.

View full review »
ES
Director of Security at a insurance company with 51-200 employees

It probably needs more integration with firewall vendors. 

It needs integration with other technologies. It doesn't play well with anything else. It is more of a standalone solution. Therefore, integration with other technologies would be great.

View full review »
AV
IT Workplace Coordinator at a consumer goods company with 1-10 employees

The support for different OS versions needs improvement because sometimes due to business conditions, updating our OS is impossible. For example, I have a production environment connected to the PNC that runs Windows XP on computers that CrowdStrike Falcon does not support.

View full review »
OA
Especialista em Segurança da Informação - DFIR at a financial services firm with 501-1,000 employees

CrowdStrike Falcon could improve if it became an XDR. When we look only to an end-point, we lost the context of the environment. I know it's another line of design of the product. However, if CrowdStrike becomes an XDR, it could be very good.

View full review »
HA
Senior Associate - IT at a financial services firm with 51-200 employees

I would like to see the machine learning feature enhanced.

View full review »
HF
Consultant at a computer software company with 51-200 employees

On the firewall management side, there should be more granularity. There should also be more granularity for device control. Everything else is brilliant.

View full review »
DN
Security Analyst at a computer software company with 10,001+ employees

The management of the solution could improve.

View full review »
SS
Security Engineer at a tech services company with 11-50 employees

The GUI can use improvement, it's cloud-based so sometimes the interface can be a bit slow. The interface could use a little bit more speed. 

When I change the policies for some users, I would like to have an option to apply that policy immediately. Right now, I have to wait for the users to connect to the cloud to take the new policy. I would like for them to develop the ability to have an option to apply the post the policy immediately.

View full review »
FI
Solution Architect at a comms service provider with 1,001-5,000 employees

I would like CrowdStrike to provide some correlation in the threat analysis, so we can visualize things better.

View full review »
it_user871761 - PeerSpot reviewer
Senior Financial Analyst - Data Analytics at a energy/utilities company with 1,001-5,000 employees

It would be nice if we could extrapolate indicators of compromise and write them within sandboxes.

View full review »
SI
Engineering manager at a consultancy with 1,001-5,000 employees

CrowdStrike should add support for ransomware protection.

Additional antivirus functionality should be included. However, this is not a big problem.

View full review »
LM
Head Of Infrastructure at a insurance company with 201-500 employees

The reporting part is basic. It's not that intuitive and you cannot go further backward in terms of historical information.

The Integration with tools, SOC tools, could be better. 

View full review »
NS
Information Security Consultant at a tech vendor with 501-1,000 employees

There are a couple of issues with the compatibility to some of the operating systems. But, I see that there are a lot of things in the pipeline. They have a roadmap, and continuously are improving. Within the last three months I have seen lot of new features in the overall CrowdStrike suite.

A couple of things were on the cosmetic part. CrowdStrike needed some improvements on the report functionalities, specifically the dashboard functionalities. Technically there a lot of things also coming from a visual perspective. There are a couple of things they still need to work out like the dashboards. The dashboard does not have the facility to export the reports in a PDF format, which I can quickly share with internal stakeholders. These are minor things, but they are in the pipeline.

View full review »
AM
Analista de segurança de TI at a tech services company with 1-10 employees

The solution could improve by providing more types of reports because it's in the detection span you cannot re-export anything. If it could be exported to a CSV file directly there it would help a lot. I currently need to do this by API to get what I need.

In the next release, it would be beneficial to have a DLP or CASB solution.

View full review »
FB
Director & CEO at a tech services company with 1-10 employees

The solution is very good but tighter integration around XDR could be included. There are a lot of open integrations, but they are external factors that cause dependencies on the integrator, not really on CrowdStrike, so it's a bit of a challenge as there is no comprehensive solution. Additionally, the solution is dependent on Windows technical support.

View full review »
KG
Security Engineer at a tech services company with 10,001+ employees

The current version of Falcon does not support DLP which is a may be a good to have in a EDR Solution. It must be included in the future version if possible. There must be a on-premise versions. MDM is also coming soon must also have ability to be controled from same dashboard.

View full review »
NS
Technical Architect at a consultancy with 10,001+ employees

In the six months that I have been using CrowdStrike, it has not been able to detect anything. We have been using Trend Micro and it has detected some malicious activities.

We have CrowdStrike conduct some inner forensic investigations in hopes that it will be more advanced and detect things that may have been missed by Trend Micro.

It would be helpful to have some prebuilt search queries based on the top ten queries in the industry for detection.

View full review »
AM
Works

The management  and log aggregation need some improvement. We have had some issues with the logs. 

View full review »
Buyer's Guide
CrowdStrike Falcon
April 2024
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,667 professionals have used our research since 2012.