IT Director at a construction company with 201-500 employees
Real User
Top 5
Sep 2, 2026
I think it is a great product and if you have an environment, it is probably worth adding to it. Regarding CrowdStrike Falcon Insight XDR's AI capabilities, I think it is a very good start and I believe they will continue to improve it. I observe improvements in our processes for detecting and investigating because we use Falcon Complete, so I do not have to investigate. My advice for others looking into using CrowdStrike Falcon Insight XDR is to invest in professional services, as having people guide you through setups is well worth it. I rate CrowdStrike Falcon Insight XDR a 10 because I trust and love it.
Senior Sales Engineer at a tech services company with 11-50 employees
Real User
Top 10
Sep 1, 2026
The capabilities that most differentiate CrowdStrike Falcon Insight XDR from other endpoint or XDR solutions are related to the anatomy of the attack, which I believe CrowdStrike Falcon Insight XDR accomplishes with perfection. Since adopting CrowdStrike Falcon Insight XDR, I always try to position the adversary over what we have for our endpoint, which really helps us as threat hunters to understand the attack faster, including whether it is a nation-state attack or a script kiddie. The value I get from correlating activity across endpoints and other security domains with CrowdStrike Falcon Insight XDR is substantial. The Next-Gen Identity Security integration is quite excellent and allows us to understand the attack context because we are unifying the endpoint plus the identity. I believe the detection capabilities of CrowdStrike Falcon Insight XDR are the best I have tried since we understand the full context of the attack rather than just relying on an IOC or a hash. CrowdStrike Falcon Insight XDR reduces alert volume and analyst investigation time significantly. At Defense, we are one step ahead, working with Foundry and putting intelligence inside the Falcon Fusion workflow to improve processes, and CrowdStrike Falcon Insight XDR was just the beginning. I use the MITRE ATT&CK framework, always trying to understand the attack point of view. Understanding initial access, persistence, and credential attacks with respect to this framework helps us to understand the attack faster and apply the necessary protections. The impact of the Falcon sensor on endpoint performance compared to solutions I previously used is negligible. I have never received complaints or concerns about the sensor from my customers, as it is really lightweight. CrowdStrike Falcon Insight XDR has affected the productivity and effectiveness of my SOC since we are applying AI-driven intelligence relying on traffic models, which allows us to work with other solutions. For example, customers at Google wanting to move to CrowdStrike benefit from the intelligence enhancements we have implemented after winning Mandiant. To others looking into using CrowdStrike Falcon Insight XDR, I advise understanding the architecture and the FPP platform first, learning about the tools, the prevent feature such as NGAV, firewall management, device control, IOCs, IOAs, beacons, and so forth. After grasping this, it is crucial to understand how an attack works and how CrowdStrike analyzes behavior, as this will help illustrate the product's quality. I give this product a rating of ten out of ten.
Senior Manager at a consultancy with 11-50 employees
Real User
Top 20
Sep 1, 2026
CrowdStrike Falcon Insight XDR has positively affected the productivity and effectiveness of my SOC. Without a doubt, it is making their lives easier. Some of my clients do not necessarily run a full SOC per se, but it is part of the individual's day job and it just makes it a bit easier for them so they can get on and do other things. The impact that the Falcon sensor has on endpoint performance compared with solutions I previously used has been fine from a performance perspective. I think its ability to self-update is probably one of the best things about it compared to some other products where there is a lot of manual effort involved in updating. I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon Insight XDR. The advice I would give to other organizations considering CrowdStrike Falcon Insight XDR is to just try it out. It is easy enough to put in there and try, and you do not have to throw away your existing toolset. I give this product a review rating of 9.
Learn what your peers think about CrowdStrike Falcon Insight XDR. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
CrowdStrike Falcon Insight XDR provides adversary-driven detection and response across endpoints and beyond. It combines AI-powered endpoint detection and response with integrated threat intelligence and expert context to deliver high-quality, context-rich detections that help security teams identify and prioritize sophisticated threats.
Automated leads and Charlotte AI, combined with attack-path visibility, adversary context and MITRE ATT&CK mappings, help analysts investigate incidents...
I think it is a great product and if you have an environment, it is probably worth adding to it. Regarding CrowdStrike Falcon Insight XDR's AI capabilities, I think it is a very good start and I believe they will continue to improve it. I observe improvements in our processes for detecting and investigating because we use Falcon Complete, so I do not have to investigate. My advice for others looking into using CrowdStrike Falcon Insight XDR is to invest in professional services, as having people guide you through setups is well worth it. I rate CrowdStrike Falcon Insight XDR a 10 because I trust and love it.
The capabilities that most differentiate CrowdStrike Falcon Insight XDR from other endpoint or XDR solutions are related to the anatomy of the attack, which I believe CrowdStrike Falcon Insight XDR accomplishes with perfection. Since adopting CrowdStrike Falcon Insight XDR, I always try to position the adversary over what we have for our endpoint, which really helps us as threat hunters to understand the attack faster, including whether it is a nation-state attack or a script kiddie. The value I get from correlating activity across endpoints and other security domains with CrowdStrike Falcon Insight XDR is substantial. The Next-Gen Identity Security integration is quite excellent and allows us to understand the attack context because we are unifying the endpoint plus the identity. I believe the detection capabilities of CrowdStrike Falcon Insight XDR are the best I have tried since we understand the full context of the attack rather than just relying on an IOC or a hash. CrowdStrike Falcon Insight XDR reduces alert volume and analyst investigation time significantly. At Defense, we are one step ahead, working with Foundry and putting intelligence inside the Falcon Fusion workflow to improve processes, and CrowdStrike Falcon Insight XDR was just the beginning. I use the MITRE ATT&CK framework, always trying to understand the attack point of view. Understanding initial access, persistence, and credential attacks with respect to this framework helps us to understand the attack faster and apply the necessary protections. The impact of the Falcon sensor on endpoint performance compared to solutions I previously used is negligible. I have never received complaints or concerns about the sensor from my customers, as it is really lightweight. CrowdStrike Falcon Insight XDR has affected the productivity and effectiveness of my SOC since we are applying AI-driven intelligence relying on traffic models, which allows us to work with other solutions. For example, customers at Google wanting to move to CrowdStrike benefit from the intelligence enhancements we have implemented after winning Mandiant. To others looking into using CrowdStrike Falcon Insight XDR, I advise understanding the architecture and the FPP platform first, learning about the tools, the prevent feature such as NGAV, firewall management, device control, IOCs, IOAs, beacons, and so forth. After grasping this, it is crucial to understand how an attack works and how CrowdStrike analyzes behavior, as this will help illustrate the product's quality. I give this product a rating of ten out of ten.
CrowdStrike Falcon Insight XDR has positively affected the productivity and effectiveness of my SOC. Without a doubt, it is making their lives easier. Some of my clients do not necessarily run a full SOC per se, but it is part of the individual's day job and it just makes it a bit easier for them so they can get on and do other things. The impact that the Falcon sensor has on endpoint performance compared with solutions I previously used has been fine from a performance perspective. I think its ability to self-update is probably one of the best things about it compared to some other products where there is a lot of manual effort involved in updating. I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon Insight XDR. The advice I would give to other organizations considering CrowdStrike Falcon Insight XDR is to just try it out. It is easy enough to put in there and try, and you do not have to throw away your existing toolset. I give this product a review rating of 9.