Senior Sales Engineer at a tech services company with 11-50 employees
Real User
Top 10
Sep 1, 2026
My main use case for CrowdStrike Falcon Insight XDR is to investigate incidents with the process tree and use their real-time response. I always start by understanding what user is related to the incident, also the workstation or server related to the incident so I can open the host management group and understand more about that server. If we have some IOC or IOA involved, I try to place some Next-Gen SIEM workflow. As a sales engineer, I am looking to understand my customer's objectives and I really try to design the best XDR way to work, so I'm trying to put some additional retention so we can correlate more incidents and understand the attack in a holistic point of view, unifying other products the customer may have.
Senior Manager at a consultancy with 11-50 employees
Real User
Top 20
Sep 1, 2026
I tend to focus on SIEM implementations, so using CrowdStrike Falcon Insight XDR involves getting that agent out there, using it to collect telemetry, and feeding that into a SIEM.
Learn what your peers think about CrowdStrike Falcon Insight XDR. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
CrowdStrike Falcon Insight XDR provides adversary-driven detection and response across endpoints and beyond. It combines AI-powered endpoint detection and response with integrated threat intelligence and expert context to deliver high-quality, context-rich detections that help security teams identify and prioritize sophisticated threats.
Automated leads and Charlotte AI, combined with attack-path visibility, adversary context and MITRE ATT&CK mappings, help analysts investigate incidents...
I do not recommend using this review at all.
My main use case for CrowdStrike Falcon Insight XDR is to investigate incidents with the process tree and use their real-time response. I always start by understanding what user is related to the incident, also the workstation or server related to the incident so I can open the host management group and understand more about that server. If we have some IOC or IOA involved, I try to place some Next-Gen SIEM workflow. As a sales engineer, I am looking to understand my customer's objectives and I really try to design the best XDR way to work, so I'm trying to put some additional retention so we can correlate more incidents and understand the attack in a holistic point of view, unifying other products the customer may have.
I tend to focus on SIEM implementations, so using CrowdStrike Falcon Insight XDR involves getting that agent out there, using it to collect telemetry, and feeding that into a SIEM.