What is our primary use case?
Falcon serves as our primary solution for endpoint and cloud security. We use it to continuously monitor endpoints, detect suspicious or malicious activity, and investigate potential threats. When an endpoint displays unusual behavior or a suspicious process starts running, Falcon helps identify the activity, generate an alert, and provides the security team with the visibility needed to investigate and respond quickly.
Falcon functions as our endpoint protection, threat detection, and incident investigation platform. We use it to continuously monitor endpoints, identify suspicious processes or unusual behavior, and investigate security alerts. Threat hunting represents another important use case, where we search for indicators of compromise and potential threats across the environment. Once a threat is confirmed, we can isolate the affected endpoint and take remediation action quickly.
Falcon is integrated into our existing security workflow mainly through our SIEM and security monitoring tools. Falcon generates endpoint alerts and telemetry which are forwarded to the central monitoring system for correlation with other security events. From there, the security team investigates the alert, validates the threat, and uses Falcon's response capabilities such as endpoint isolation or remediation. This integration gives us a more centralized workflow from detection through investigation and response.
How has it helped my organization?
Falcon has had a positive impact on the organization mainly by improving our overall security posture. It helps us detect threats earlier, investigate incidents faster, and respond quickly when an endpoint is compromised. The automated detection and response capabilities also reduce manual efforts for the security team. Overall, it provides us better visibility across endpoints, reduces security risks, and helps the team respond to incidents more effectively.
The specific outcomes we have seen since using Falcon include faster threat detection and quicker incident response. Falcon has helped us identify suspicious endpoint activity earlier, contain affected devices through isolation, and reduce the amount of manual investigation required. It has also improved our visibility across endpoints, which makes it easier to investigate incidents and reduces the risk of threats spreading through the environment.
What is most valuable?
Falcon's best feature is its real-time threat detection and endpoint visibility. It provides us detailed information about processes, users, network activity, and suspicious behavior, which makes investigations much faster. I find the automated response and endpoint isolation very useful because we can quickly contain a compromised device before the threat spreads.
Another particularly valuable feature is the automated response capability. When Falcon detects suspicious or malicious activity, it can automatically take predefined actions such as blocking the threat or isolating the affected endpoints from the network. This is especially useful during an active incident because it reduces the time between detection and containment. It also helps the security team avoid handling every alert manually and allows us to focus more on investigation and remediation.
Threat hunting represents another strong feature of Falcon. It provides us detailed endpoint telemetry so we can proactively search for suspicious processes, unusual network activities, or indicators of compromise, even before alerts are generated. This capability is useful for finding hidden threats and investigating security incidents more deeply.
What needs improvement?
One area where Falcon could be improved is by making the platform easier to use for new users. Some of the advanced investigations and threat hunting features can take time to learn. I would also prefer to see more intuitive dashboards and simpler policy configurations, along with clearer cost visibility and more straightforward reporting. These changes would make it easier for teams to get value from Falcon without needing as much specialized expertise.
Better alert prioritization and noise reduction would be a valuable improvement so the team can focus on the most critical threats without dealing with too many low-value alerts. Falcon could also make advanced threat hunting queries and investigation workflows more intuitive for less experienced users. Better reporting, more customizable dashboards, and simpler integrations with third-party security tools would also strengthen the overall experience.
For how long have I used the solution?
I have been using Falcon for around a year. I primarily use it for endpoint security, threat detection, monitoring, suspicious activity identification, and incident investigation support.
What do I think about the stability of the solution?
Falcon is quite stable in our system. We generally do not see significant performance or reliability issues from Falcon sensors running in the background. It provides continuous protection without noticeably affecting normal endpoint performance, which is important for our day-to-day operations.
What do I think about the scalability of the solution?
Falcon is highly scalable. It can protect a small number of endpoints as well as large enterprise environments with thousands of devices because the management platform is cloud-based. Scaling mainly involves deploying Falcon sensor to additional endpoints rather than managing additional security infrastructure. It can also handle growing telemetry and security events without requiring a major change to the deployment model.
How are customer service and support?
Customer support has been good overall. The support team is responsive when we have technical issues. They typically provide useful guidance for troubleshooting and configuration. For more complex security cases, escalation can sometimes take longer, but overall, I consider Falcon support reliable and useful.
Which solution did I use previously and why did I switch?
Before Falcon, we used a more traditional endpoint security solution, but it required more manual investigation and had less visibility into endpoint activity. We switched to Falcon mainly because of its strong real-time detection, better endpoint telemetry, threat hunting capabilities, and faster automated response. It provides the security team better visibility and helps us respond to threats more efficiently.
How was the initial setup?
Falcon is deployed in our organization on endpoints and servers using Falcon sensors. We started with a controlled rollout to a smaller group of systems, configured the prevention and detection policy, and then expanded it across the environment. We also integrated Falcon with our existing security monitoring tools so the security team can generally review alerts, investigate threats, and respond to incidents.
Falcon is primarily deployed on a cloud-based SaaS security platform. The Falcon management console is hosted in CrowdStrike's cloud, with the Falcon sensor installed on the organization's endpoints.
What was our ROI?
Falcon has saved us a meaningful amount of time mainly by reducing manual investigations and speeding up incident responses. Instead of manually checking individual endpoints, we can quickly review endpoint telemetry, identify suspicious activity, and take response actions from the platform. I estimate it saves several hours per security incident depending on the complexity of the investigation.
What's my experience with pricing, setup cost, and licensing?
We purchased Falcon directly through CrowdStrike's sales team, working with their authorized sales or account representative. The purchase and licensing were handled as an enterprise subscription based on our endpoint and security requirements.
Falcon is licensed mainly on a subscription basis with pricing depending on the specific Falcon modules. The pricing and overall setup were very straightforward for us. The main setup is done by our technical team, but our management team verifies the pricing and all details, so we do not involve ourselves in the pricing aspects.
Which other solutions did I evaluate?
Before choosing Falcon, we evaluated Microsoft Defender for Endpoint. It provided solid basic endpoint protection, but we found Falcon to be stronger for advanced threat detection, detailed endpoint visibility, threat hunting, and faster incident response. That was the main reason we moved to Falcon.
What other advice do I have?
I rate Falcon nine out of ten overall. It has strong threat detection, endpoint visibility, automated response, and threat hunting capabilities. I hold back one point mainly because some advanced features have a learning curve and could be more intuitive.
I give Falcon nine out of ten because it performs very well in the areas that matter most to us: real-time threat detection, endpoint visibility, threat hunting, and automated response. It helps us detect and contain threats quickly and reduces manual security work. I am not giving it ten because some advanced features have a learning curve and the alert management, dashboard, and investigation workflows could be more intuitive.
Falcon's AI capabilities can be very useful for improving threat detection, investigation, and responses, but governance and security are extremely important. The AI should operate with clear access control and policies, proper protection of sensitive data, and auditability of AI-driven actions. I also want transparency regarding how AI recommendations are generated and human oversight for high-impact response actions. Overall, AI should improve the security team's efficiency without introducing additional privacy or security risks.
Falcon's AI capabilities are useful and reasonably trustworthy, especially for detecting suspicious behavior and helping with investigations, but I would not rely on AI alone for critical security decisions. I still want human review, a clear audit trail, and strong control over sensitive data and automated actions.
CrowdStrike's Falcon platform serves as the cloud provider for Falcon's deployment.
I would advise organizations to first determine their security requirements and endpoint coverage, then evaluate which Falcon modules they actually need. It is also worth doing a pilot before a full rollout and making sure the security team is comfortable with the investigation and threat hunting features. Overall, if strong endpoint visibility, threat detection, and automated response are prioritized, I would definitely recommend considering Falcon.