Sign in Agent Mode
Categories
Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

9 AWS reviews

External reviews

46 reviews
from

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    Dotan Sadka

Centralized threat visibility has improved detection speed and strengthened endpoint protection

  • April 26, 2026
  • Review from a verified AWS customer

What is our primary use case?

Our company has been using CrowdStrike Falcon for about 2 years. During that time, it has been a great help in detecting and responding to various security threats. We mainly use it for endpoint security management.

CrowdStrike Falcon is used in various ways in our company. It has been especially effective in detecting and blocking unknown malware or ransomware attacks in real time. For example, recently CrowdStrike Falcon immediately detected a phishing link that came in via an employee's email and prevented it from spreading across the entire network. It also plays a big role in monitoring the security status of remote workers' devices and consistently applying security policies.

We have had real experiences with threat detection. At one point, CrowdStrike Falcon's behavioral analysis detected activity in our system that was different from normal patterns and flagged it as suspicious. Investigation revealed that it was part of a new type of APT attack, and fortunately, we were able to block it in the early stage. In that process, I felt that CrowdStrike Falcon's behavior-based detection technology played the biggest role. It would have been difficult to detect using traditional signature-based methods.

What is most valuable?

After that incident, we strengthened our internal response process for phishing attacks. We started to immediately analyze threat information detected by CrowdStrike Falcon and set up additional automated rules to proactively block similar types of attacks. Compared to before we adopted CrowdStrike Falcon, the biggest improvement has been in visibility into security threats and response speed. In the past, we had to manually analyze logs from multiple security solutions, but now we can see all threat information at a glance and respond quickly from a single CrowdStrike Falcon console.

Thanks to CrowdStrike Falcon's cloud-based architecture, deployment and management were very lightweight. With our previous solutions, the agents were heavy and sometimes affected system performance. But we had no such issues with CrowdStrike Falcon. In terms of cost, although there was some initial investment, by consolidating multiple security tools into one and increasing operational efficiency, I feel it is definitely worth the investment in the long term.

CrowdStrike Falcon's greatest strength is its real-time threat detection and response capabilities. In particular, its detection method based on indicators of attack is very effective at blocking even unknown threats. Another big advantage is that because it uses a lightweight agent and a cloud-native approach, it provides strong security without performance degradation.

The integrated threat intelligence feature in CrowdStrike Falcon provides detailed background information on detected threats, the attacker's tactics, and correlations with other attacks, which greatly helps our analysis team quickly understand the severity of threats and respond appropriately. The user interface is intuitive, so new team members took very little time to adapt to CrowdStrike Falcon.

What needs improvement?

CrowdStrike Falcon is a very powerful tool, but at times the high initial adoption cost can be burdensome. To get the maximum benefit, as in our case where we integrate it with other security systems, a certain level of expertise is required, which is somewhat disappointing. Sometimes updates can cause unexpected issues in the system, so rigorous pre-testing is essential, and that is another point of concern.

In the future, I would like to see even smoother integration with other security tools. If more flexible pricing models or SMB-focused packages were introduced so that small and medium-sized businesses can adopt it without too much burden, I think many more organizations could benefit.

For how long have I used the solution?

I have been working in this field for about 5 years. I started as a security engineer and now I mainly handle analysis work.

What do I think about the stability of the solution?

CrowdStrike Falcon's stability is rated very highly. During the period we have used it at our company, we have not experienced any system downtime or unexpected errors caused by security-related stability issues. However, as I mentioned earlier regarding updates, we are always mindful that content configuration updates can potentially cause problems. I believe thorough pre-testing and phased rollout are essential.

What do I think about the scalability of the solution?

We also have experience with scalability. As our company grew and the number of endpoints increased, CrowdStrike Falcon scaled without any issues. Because it is cloud-based, we were able to integrate many devices in real time without installing additional hardware, and we did not notice any performance degradation. We gained confidence that we could maintain stable security even as the organization grew.

How are customer service and support?

I have experience with CrowdStrike's customer support. When we introduced CrowdStrike Falcon, we needed technical support due to integration issues with our existing systems, and the support team responded very quickly and professionally. They understood our special network configuration and provided tailored solutions, which allowed us to resolve the issue quickly. Overall, satisfaction with customer support is quite high.

I would give the customer support service an 8. The professional help was very useful, but occasionally the wait time was longer than expected.

Which solution did I use previously and why did I switch?

We used a few other solutions before adopting CrowdStrike Falcon. We evaluated traditional antivirus programs and other EDR products. The decisive reason we switched to CrowdStrike Falcon was the real-time threat detection capability and overwhelming analysis speed. In particular, CrowdStrike Falcon's behavior-based detection technology was far superior to other products, and the lightweight agent allowed us to strengthen security without worrying about system performance degradation, which was important.

How was the initial setup?

I would like to mention CrowdStrike Falcon's API extensibility. We have integrated CrowdStrike Falcon with our existing Security Information and Event Management system, that is, SIEM, so we can centrally manage and analyze security alerts. This has greatly improved the efficiency of our security operations.

The automation feature that helped the most when integrating with SIEM was the process where a critical alert in CrowdStrike Falcon automatically creates a ticket in the SIEM and sends a notification to the person in charge. This greatly reduced response delays. The difficult part of the integration process was aligning the log formats of the different systems, but thanks to the documentation and support provided by CrowdStrike, we were able to resolve it relatively smoothly.

What was our ROI?

CrowdStrike Falcon has had several positive impacts on our company. First of all, it has greatly reduced the time required to analyze and respond to security threats, allowing team members to focus on more important and strategic security tasks. By preventing actual security breaches, we were able to avoid potential business losses and raise our security level to a higher tier.

Based on our internal analysis, our average threat response time has been reduced by about 30 percent compared to before. The false positive rate, that is, the number of false alarms, has dropped significantly, while the number of valid alerts that the security team actually has to handle has decreased by more than 50 percent. This prevented unnecessary resource waste and allowed us to respond more efficiently to security threats.

We also saw effects in workforce optimization. As the false positive rate decreased and analysis efficiency increased, the security team was able to safely manage more endpoints than before with fewer people. Thanks to that, we could reassign the freed-up staff to other important tasks such as threat hunting and strengthening security policies.

What's my experience with pricing, setup cost, and licensing?

As I mentioned earlier, the initial adoption cost is somewhat high, and there is a certain level of difficulty involved in integrating it with other security systems, which is a drawback. Sometimes unexpected issues can occur after updates, so rigorous pre-testing is essential—this is another aspect I would like to see improved.

In terms of pricing, we use the enterprise bundle, and while the initial cost was somewhat high, considering the wide range of features and the security benefits, we determined that the investment was worthwhile. We contracted licenses based on the number of users, and it was nice that they could be flexibly adjusted to fit our company's size.

Which other solutions did I evaluate?

There were solutions we compared. For example, Microsoft Defender for Endpoint had the advantage of good integration with existing Microsoft environments and was cost-effective. SentinelOne, on the other hand, had excellent AI-based automation, but we felt it consumed a lot of system resources. CrowdStrike Falcon struck the best balance between performance and efficiency, and we gave it the highest score especially in its ability to detect unknown threats.

What other advice do I have?

If I were to advise other companies considering adopting CrowdStrike Falcon, I would say they should not only look at its powerful security features but also thoroughly evaluate whether it fits their current environment and threat profile. In particular, it is essential to develop a thorough integration plan with existing systems and to establish an update management process to ensure stable operations. I would also recommend actively leveraging customer support if needed. My overall review rating for CrowdStrike Falcon is 9.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Dhiren Jethwa

Endpoint security has improved and real-time detection and response reduce false positives

  • April 17, 2026
  • Review from a verified AWS customer

What is our primary use case?

CrowdStrike Falcon's main use case is endpoint security and threat detection, which are the primary purposes for which we are using it.

A day-to-day example of using CrowdStrike Falcon for endpoint security detection occurs when a user downloads suspicious files. The system detects this activity and triggers an alert to the administrator. CrowdStrike Falcon detects abnormal behavior of the system, and an alert is generated in a console. When I log into the console, I can see that some users are trying to access malicious files which are harmful for the organization. The security team isolates the endpoint based on this judgment. We can investigate using process trees and logs in CrowdStrike Falcon. Additionally, USB device control helps sometimes with USB blocking and data access via external storage.

What is most valuable?

The best features CrowdStrike Falcon offers are endpoint detection and response, cloud-native lightweight agent, AI-powered threat detection, threat hunting, and Falcon Overwatch.

The feature I use the most is endpoint detection and response, which you can call EDR. EDR makes the difference in this case because it provides real-time alerts for suspicious activity and full process tree visibility showing what ran, what spawned, and what is happening inside the LAN on the endpoint. It allows for quick investigation of endpoint logins and quick host isolation to stop the spread.

Using CrowdStrike Falcon typically leads to faster threat detection, quicker response, and better visibility across the endpoints. This means I can understand, or an administrator can understand the logs and situation, what is happening with the endpoint, and what suspicious behaviors are occurring inside the endpoints. It has reduced false positives and has a lightweight performance impact, resulting in no heavy use or heavy scans of the agent. User productivity is also increased on the endpoint side.

What needs improvement?

Regarding improvements in reports, when I try to pull a custom report, there are some mismatches, or it does not look professional. I hope CrowdStrike will improve their custom report or inbuilt report to look professional rather than appearing like just adding numbers. Based on the requirement, they should improve their custom reports.

For how long have I used the solution?

I have been using CrowdStrike Falcon for around one year.

What do I think about the stability of the solution?

CrowdStrike Falcon is very stable.

What do I think about the scalability of the solution?

The scalability of CrowdStrike Falcon is very good and very positive.

How are customer service and support?

Customer support is also appreciated as it is very good. I have raised multiple tickets with technical support, and every time I have received a good response from customer support.

Which solution did I use previously and why did I switch?

We did not use any kind of solution previously.

What was our ROI?

Before CrowdStrike Falcon, there were 40 to 50 alerts per day with many antivirus detections and time wasted validating non-issues. When we installed the CrowdStrike Falcon agent on the endpoint, there are now 10 to 15 meaningful alerts that we can work on and isolate the system. There is a 60 to 70 percent reduction in false positives, allowing us to disregard those. Additionally, higher quality behavioral detection based on pattern analysis is justified. The investigation time has been reduced from three to four hours to one to two hours, and per user, we used to take around 10 to 15 minutes, but now with the reduced false positives, we can troubleshoot or inspect users within five minutes.

What's my experience with pricing, setup cost, and licensing?

The pricing is very straightforward and negotiable. The license is thoughtful and very fruitful. The licensing is pretty simple, so it has a very good impact with the licensing, setup cost, and pricing with respect to CrowdStrike Falcon.

Money is saved because if a user is receiving spam alerts or spam emails which are damaging the organization's privacy, the number of alerts, data threatening, DLP, data extraction, and everything has been reduced. There is a big impact on the organization's security posture as well as time saved while doing troubleshooting, allowing us to monitor that alert via one single console. The positive impact is significant, and the money saved is a very good effect for the organization.

Which other solutions did I evaluate?

We have not evaluated another option before choosing CrowdStrike Falcon.


    Pavan Ingaleshwar

Improved endpoint visibility has reduced incident response time and strengthens threat investigations

  • April 14, 2026
  • Review provided by PeerSpot

What is our primary use case?

I have been using CrowdStrike Falcon for the past two years. My main use case for CrowdStrike Falcon is endpoint protection, threat protection, and investigating suspicious activities on endpoints in my day-to-day work.

In one case, we received an alert about suspicious PowerShell activities detected on one of the endpoints, and CrowdStrike Falcon detected the issue and generated an alert on our SIM solution as well. We started investigating that endpoint using CrowdStrike Falcon, confirming through the process tree that there was suspicious execution, and we began isolating the endpoint device to prevent further impact. That is how we used CrowdStrike Falcon for monitoring and investigating endpoint devices.

We also use CrowdStrike Falcon for endpoint activities and for responding to malware alerts, which is a significant part of our process.

What is most valuable?

CrowdStrike Falcon offers several features that stand out to me, including a feature called Process Tree visibility, where we can see the entire attack history including how it started, how it initiated the connection, how it ended, and the intentions behind that particular incident. Additionally, it has great threat intelligence data, isolation automation, detailed process visibility, a real-time threat blocking system, and behavioral threat detection that helps in responding to incidents on endpoints. These are the best features I have ever used.

I wish more people knew about the Process Tree visibility feature because it helps to understand the full attack chain quickly, making it a very impactful feature I have ever used.

CrowdStrike Falcon has positively impacted my organization by improving endpoint security. Even if end users are doing something on their endpoints without their knowledge, such as receiving documents from vendors, the endpoints will scan attachments before delivery, and if they are malicious, it will detect them and provide notifications and alerts. It has positively impacted endpoint security and reduced the response time for incidents and alerts.

In my experience, I noticed that the Mean Time To Respond (MTTR) has reduced by around 30 to 40 percent due to faster detection and response achieved by the Falcon agents.

What needs improvement?

CrowdStrike Falcon requires experience and knowledge about tuning, as proper tuning is required. Improvement could focus on this aspect, as well as simplifying the user interface for new users and different department employees, since it sometimes generates a lot of false positives. They should concentrate on this as well.

They can work on better reporting and simplifying the interface to enhance the overall user experience.

CrowdStrike Falcon provides very good visibility into endpoint activity, including process execution and behavior. It is not only useful for the security department; it is beneficial for other departments as well. If something happens, even developers can log into CrowdStrike Falcon to check what is happening with their endpoints. Every tool should be built with this capability in mind, including CrowdStrike Falcon, which could also work on improving user interface design.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable, with no major issues I have faced.

What do I think about the scalability of the solution?

CrowdStrike Falcon is highly scalable.

How are customer service and support?

The customer support is good, and I have reached out to them.

Which solution did I use previously and why did I switch?

We were previously using SentinelOne and Microsoft Defender but switched to CrowdStrike Falcon for better detection capabilities, especially for a client handling numerous attachments and endpoint activities.

What was our ROI?

I have seen a return on investment due to strong detection and faster response capabilities of CrowdStrike Falcon.

What's my experience with pricing, setup cost, and licensing?

The pricing, according to my knowledge, is subscription-based, depending on how many endpoints and modules the organization needs to use.

Which other solutions did I evaluate?

Before choosing CrowdStrike Falcon, we evaluated SentinelOne and Microsoft Defender because we needed better detection and visibility.

What other advice do I have?

My advice for others looking into using CrowdStrike Falcon is to have a clear understanding of how to properly fine-tune and monitor the system to get the full benefits. If they are good at these aspects, they can confidently purchase it and start working towards endpoint protection.

CrowdStrike Falcon is a strong solution with faster responses to endpoint-related incidents and alerts. Overall, it is a very robust solution for organizations dealing with endpoint security, and they can confidently choose CrowdStrike Falcon and make it work effectively. I would rate this product a 9 out of 10.


    reviewer2788083

Proactive threat hunting has improved breach prevention and now provides deeper endpoint visibility

  • December 15, 2025
  • Review provided by PeerSpot

What is our primary use case?

I deal with endpoint security, firewall, and XDR solutions. I use Sangfor and work with Trend Micro and CrowdStrike. I use CrowdStrike Falcon for enterprise companies, which is what I typically recommend.

How has it helped my organization?

CrowdStrike Falcon has helped my customers predict and prevent potential breaches because of its proactive approach.

What is most valuable?

The most valuable features in CrowdStrike Falcon are its AI capabilities. The lightweight agent has a positive impact on system performance and visibility through ease of use. I utilize its Threat Graph for threat hunting.

What needs improvement?

To improve my recommendation to a perfect score, I would focus on better selling skills and improved integration with different vendors.

For how long have I used the solution?

I have been working with CrowdStrike Falcon for approximately five years.

Which solution did I use previously and why did I switch?

I have previously worked with a Total Information Management Corporation solution.

Which other solutions did I evaluate?

I work with competitors as well, and there is good competition to Sangfor at the moment.

What other advice do I have?

I have experience with these products from prior use. I work with security vendors and some of my customers use Trend Micro and CrowdStrike as well. My experience has been positive and I have been satisfied. The pricing might be a little expensive, but I find it cost-effective. I do not find CrowdStrike Falcon to be the most expensive when comparing pricing with competitors. I would rate this solution an 8 out of 10.


    Dipak M Gohil

Efficient threat detection and seamless deployment improve overall security

  • September 03, 2025
  • Review provided by PeerSpot

What is our primary use case?

We are using CrowdStrike Falcon because it has very low surface impact and minimal consumption of our resources, and we mainly use it for our endpoint protection.

CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions.

We find it very unique that CrowdStrike Falcon, which we deployed in many countries wherever our offices are, can be installed very quickly, maintained on a single console, single panel of console, and it's really easy to use and deploy. We primarily use it for endpoint protection.

What is most valuable?

The single panel console of CrowdStrike Falcon is very user-friendly, which is what we are looking for. Having multiple administrators between various offices with this single console gives us the ability to see all offices, branch offices, and partners, making it very useful to detect machines, identify machines, and check security risks. Everything in the single console is very useful.

CrowdStrike Falcon has positively impacted our organization in terms of efficiency because it's very lightweight, easy to deploy, easy to manage, and works very efficiently. It quickly detects issues and doesn't have a signature-based system, so it works fast and takes immediate action.

What needs improvement?

I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does.

For how long have I used the solution?

We have been using CrowdStrike Falcon for the past seven years.

What do I think about the stability of the solution?

CrowdStrike Falcon is stable; I have not had any issues with reliability or downtime.

What do I think about the scalability of the solution?

For scalability, CrowdStrike Falcon deserves a perfect score of ten out of ten.

How are customer service and support?

Regarding customer support, our experience has been really positive as they are very quick to assist us.

The customer support deserves a rating of ten out of ten.

Which solution did I use previously and why did I switch?

We were previously using Symantec Endpoint because we were not getting proper quotations, pricing, or support, particularly in India, which is why we wanted to switch.

What was our ROI?

In terms of return on investment, we find that CrowdStrike Falcon has ROI covered because less manpower is required. It's very easy to deploy without many IT admins, saving time, and while I cannot specify the money saved, the time saved is money in terms of manpower. This makes it very useful, quick to run, quick to install, easy to manage, and easy to deploy.

What's my experience with pricing, setup cost, and licensing?

We do not find any price challenges or setup costs with CrowdStrike Falcon; everything is smooth.

Which other solutions did I evaluate?

We evaluated three products, which were Sophos, CrowdStrike Falcon, and Trend Micro, before choosing CrowdStrike Falcon.

What other advice do I have?

In some cases, we have Excel files with VBA code inside, and CrowdStrike Falcon detects that it's a bit risky for us. When people download EXE files that are threats to our organization, it detects them very quickly. It also detects threats under ZIP files and can show us the path from where it came and where it goes, allowing us to easily see where the infection is and where it has spread.

My advice for others looking into using CrowdStrike Falcon is that as an endpoint protection solution, Falcon is always reliable, and I can recommend that this is the product you can deploy and forget all the worries.

We are an end user customer of CrowdStrike Falcon; we are not a partner or reseller, and we are not receiving any gift card or incentive for this review. We are just sharing our experience as an end user and as an IT Manager.

I rate CrowdStrike Falcon 9 out of 10.


    Mohamed-Atta

Provides comprehensive threat protection and seamless integration with third-party tools

  • September 02, 2025
  • Review provided by PeerSpot

What is our primary use case?

I am a customer of CrowdStrike Falcon through a consultant, and our company is headquartered in India, while our consultant is a sister company also located in India.

We use CrowdStrike Falcon internally in our company.

I am using CrowdStrike Falcon for its purpose, which is to save the company from any attacks, viruses, or whatever threats are available.

What is most valuable?

The most useful feature of CrowdStrike Falcon is protection, though it cannot be described in one word.

Protection is the main purpose of CrowdStrike Falcon.

CrowdStrike Falcon has positively impacted my organization by providing good protection, logs, and reports, which I find very good.

What needs improvement?

One area for improvement in CrowdStrike Falcon could be the user interface and reports; it requires some improvements to be easily handled.

For the reporting in CrowdStrike Falcon, I need specific data because in most reports, some of the data is not with that importance for the collector, so the reports need to be more specific for each purpose.

For how long have I used the solution?

I have been working with CrowdStrike Falcon for around three years.

What do I think about the stability of the solution?

Regarding stability and reliability, I find CrowdStrike Falcon to be stable; nothing has happened since we installed it, and there are no bugs or issues from the software.

What do I think about the scalability of the solution?

I can say that CrowdStrike Falcon is sufficient in terms of scalability from my point of view; it is capable of working with our current infrastructure or setup, and I believe it's sufficient.

How are customer service and support?

My interaction with technical support for CrowdStrike Falcon was fine; they supported me and provided a solution for my issue.

Based on my experience, I would rate the technical support for CrowdStrike Falcon an eight.

Which solution did I use previously and why did I switch?

Before CrowdStrike Falcon, I used an application called Kaspersky, but not for the same purposes.

Which other solutions did I evaluate?

I did not evaluate other options before choosing CrowdStrike Falcon because it was a forced decision from our headquarters, from the mother company.

What other advice do I have?

Currently, I do not remember exactly what version of CrowdStrike Falcon we are using because I'm managing the team, but I can check the right version later.

We are using the latest version of CrowdStrike Falcon.

CrowdStrike Falcon has not helped me predict and prevent potential breaches by itself, but with support from other applications such as Splunk and Windows Defender, it has contributed.

I integrate CrowdStrike Falcon with third-party tools.

I have to integrate CrowdStrike Falcon with other applications to get the most protection, and the integration is smooth and everything works well.

I am using the lightweight agent.

For the system performance, the lightweight agent is fine; it has not affected performance too much, and generally it's acceptable.

I rate CrowdStrike Falcon eight out of ten.


    BambangTrisilo

Seamless management and installation elevate cybersecurity architecture

  • May 28, 2025
  • Review from a verified AWS customer

What is our primary use case?

I am using CrowdStrike Falcon for laptop, desktop, our server, and VM, including Linux, Windows server, and Linux server.

What is most valuable?

The most beneficial features of CrowdStrike Falcon are that it is easy to install, easy to manage, lightweight, and it can stop breaches.

The impact of CrowdStrike Falcon lightweight agents on system performance and visibility is good, with only one agent required.

Speaking about the utilization of Falcon threat graph for threat hunting, it helps my security team to predict and prevent potential breaches.

Considering that CrowdStrike Falcon is a cloud-native architecture, the elimination of on-premises infrastructure makes cybersecurity maintenance cost and complexity minimal, because we only need to install it and then monitor from the dashboard.

What needs improvement?

In Indonesia for SMB companies, the price is higher than other solutions.

For SMB organizations, the price may be higher than others, which means they have to think twice about it, but for enterprise companies, the cost is not a concern.

I have been using it for about six years and do not have any problems. The pricing is the only issue.

For how long have I used the solution?

I have been using CrowdStrike Falcon since 2019, before the pandemic.

What was my experience with deployment of the solution?

In terms of deployment of CrowdStrike Falcon, it is quite easy and there are no challenges with deployment.

What do I think about the stability of the solution?

As for stability, I would rate it around eight because last year they faced some downtime with around eight thousand computers, but it will improve.

What do I think about the scalability of the solution?

For scalability, I would rate it a nine because they can scale efficiently with many users.

How are customer service and support?

Technical support from CrowdStrike Falcon is good because usually in Indonesia we have a partner, and if the partner cannot address the issue, we discuss with CrowdStrike directly.

I would rate technical support a nine out of ten.

Which solution did I use previously and why did I switch?

I used McAfee before CrowdStrike Falcon for the same use case. I switched to CrowdStrike Falcon because McAfee did not have machine learning or AI capabilities at that time.

What was our ROI?

CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.

I am not sure about the exact percentage of money it saves, as I have to calculate the risks, but we are satisfied because CrowdStrike Falcon has stopped breaches and prevented hackers.

Which other solutions did I evaluate?

I used McAfee before CrowdStrike Falcon for the same use case. I switched to CrowdStrike Falcon because McAfee did not have machine learning or AI capabilities at that time.

What other advice do I have?

My rating for CrowdStrike Falcon would be eight points because there are many antivirus competitors. For those who want to use CrowdStrike Falcon, they should be mindful of the higher price compared to others.


    Bhupesh-Sharma

Long-term experience has led to streamlined deployments and flexible solutions

  • May 21, 2025
  • Review provided by PeerSpot

What is our primary use case?

The typical use case for CrowdStrike Falcon depends on what kind of service the customer is looking for. Most customers look for antivirus, endpoint detection and response, or possibly managed detection and response, which leads them to reach out to us.

When we speak to the customer, they usually tell us that they're looking for antivirus or endpoint detection and response, and we then introduce CrowdStrike Falcon.

What is most valuable?

CrowdStrike Falcon has many valuable features. The solution is used for multiple functions, including MDR, XDR, and CNA solution. It depends on which category you're looking for, and you have to customize the customer's equation accordingly.

CrowdStrike Falcon can be deployed both on-premise and in the cloud, and it's an on-call solution that can be deployed anywhere by simply deploying the agent on the end devices.

What needs improvement?

Certain areas of CrowdStrike Falcon have room for improvement, but it depends on the specific services being discussed. CrowdStrike offers multiple services, and most of the product comes in the Falcon service, so it's important to be specific regarding whether the discussion is about ADR, antivirus, XDR, or MDR, as it's one of the best solutions in the market.

I believe nothing can be done to make CrowdStrike Falcon a ten out of ten, as I think it's one of the best solutions in the market. However, rating it a ten overall would imply there's no scope for improvement, but to survive in the market, changes must be made every day. Every customer and solution has tendencies for improvement, which is why I'm not giving a perfect score.

For how long have I used the solution?

I have more than two years of experience working with CrowdStrike Falcon.

What do I think about the stability of the solution?

I find nothing to miss in terms of stability; there are no glitches, and the solution is stable.

What do I think about the scalability of the solution?

I would rate the scalability of CrowdStrike Falcon highly because it only depends on the customer's infrastructure and what kind of scalable environment they have. There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.

How are customer service and support?

I would rate the technical support from CrowdStrike as good, actually more than good.

How was the initial setup?

CrowdStrike Falcon can be deployed both on-premise and in the cloud, and it's an on-call solution that can be deployed anywhere by simply deploying the agent on the end devices.

What was our ROI?

The return on investment from CrowdStrike EDR depends on each company's circumstances and how they are utilizing the solution.

What's my experience with pricing, setup cost, and licensing?

The price of CrowdStrike Falcon depends on which product we are discussing, as pricing can vary significantly based on the customer's profile and budget.

What other advice do I have?

We are part two of CrowdStrike. The time it takes to deploy CrowdStrike Falcon depends on the customer setup.

My clients vary in size, as we can reach all types of businesses, whether small, medium, or enterprise.

Based on my experience, I would recommend CrowdStrike Falcon solutions to other people. I rate the solution an eight out of ten.


    Jai Prakash Sharma

Continuous monitoring strengthens security despite past challenges

  • May 21, 2025
  • Review provided by PeerSpot

What is our primary use case?

In my cybersecurity strategy, I use CrowdStrike Falcon mainly as an EDR solution for us. Currently, we are using it as an EDR. We are also in discussion along with the CrowdStrike team where we can have a managed SOC integrated.

In the online industry, we are using CrowdStrike Falcon, specifically in online classified, which you could call e-commerce.

What is most valuable?

For threat detection, the most effective feature I find in CrowdStrike Falcon is 24/7 managed monitoring, which is basically a next-gen antivirus and next-gen endpoint detection and response. In endpoint detection and response, the best part is 24/7 365 continuous monitoring to the endpoint for identifying any suspicious activity.

CrowdStrike Falcon serves as a next-gen AV, which basically does AI-based behavioral analysis to detect and act on malware or ransomware.

The automated response capabilities in CrowdStrike Falcon handle incidents based on the behavior of the activity, performing analysis in case it finds more objectionable content. If there is blocking or breaking any of your site map or something of that sort, it is an untraditional way. If the traffic behaves suspiciously, it triggers an automated response to block it. Additionally, if it detects a file which might have an extension of MIME type of maybe a document whereas it is self-replicating, that sends a suspicious activity alert. In such cases, the detection happens automatically. Because in case it's a zero-day, many times such files automatically get put in a sandbox to extract it and see why it is identified as malware. It offers automated threat detection as well, not only automated response.

Falcon's integration capabilities with other tools enhance my security posture because it has a very lightweight agent, and having a unified console gives us complete visibility, including endpoints, servers, containers, cloud workloads, everything.

What needs improvement?

To make CrowdStrike Falcon better for the next release, I recommend that they should have a model where it works as agentless. In terms of everything which the agent pushes to the server or to the single console, having a feature where you can have another port, which is SNMP or your network devices or OT devices, which you can specifically monitor, would be great.

For how long have I used the solution?

I have been using CrowdStrike Falcon for more than two years now.

What was my experience with deployment of the solution?

CrowdStrike Falcon is fairly easy to set up, according to my experience and our team's experience. Since we have a heterogeneous environment, for Windows it is very straightforward and easy, but for Linux it is a bit complex since you need to automate it. If you have a bulk force, then you have to use some CMF or something similar. Overall, it is still fairly easy.

For deployment, it takes approximately a couple of minutes.

What do I think about the stability of the solution?

During these two years with CrowdStrike Falcon, I certainly faced some problems, including the known CrowdStrike outage, which was quite pinching and brought many of the Windows-related services to a halt just because of one bad configuration push from CrowdStrike tracks.

Except for the incident mentioned above, I have not seen any recent issues with stability.

What do I think about the scalability of the solution?

CrowdStrike Falcon is easy to scale for my company's needs.

How are customer service and support?

I have contacted CrowdStrike for issues, and the response was poor. That particular experience was pretty bad, with people not knowing what was happening, how to mitigate, or what to do. We were in a bad situation, but after a couple of hours, their communication started flowing fine, and things gradually started improving. For that particular instance, I would rate it less than four.

Which solution did I use previously and why did I switch?

Before working with CrowdStrike Falcon, I evaluated options such as Carbon Black and SentinelOne.

How was the initial setup?

CrowdStrike Falcon is fairly easy to set up, according to my experience and our team's experience. Since we have a heterogeneous environment, for Windows it is very straightforward and easy, but for Linux it is a bit complex since you need to automate it. If you have a bulk force, then you have to use some CMF or something similar. Overall, it is still fairly easy.

For deployment, it takes approximately a couple of minutes.

What was our ROI?

As for return on investment after implementing CrowdStrike Falcon, I would say if it is protecting my environment, that itself meets my expectations so far.

What's my experience with pricing, setup cost, and licensing?

CrowdStrike Falcon is pretty expensive.

Which other solutions did I evaluate?

I do not see a lot of advantages in CrowdStrike Falcon; however, because of one particular problem, we had to give away SentinelOne. Otherwise, all three products are quite comparable.

What other advice do I have?

For those who would like to use CrowdStrike Falcon, I recommend negotiating hard on commercial terms because it is not an easy or affordable solution. From a commercial standpoint, you should negotiate hard, but technically, it is not very difficult.

CrowdStrike Falcon is a user-friendly tool.

On a scale of one to ten, I rate CrowdStrike Falcon an eight.


    Rojal Barreto

Advanced AI integration boosts security effectiveness

  • May 20, 2025
  • Review provided by PeerSpot

What is our primary use case?

I am using it for endpoint protection.

What is most valuable?

The features I appreciate the most are numerous; the overall product is very good, actually.

This is an advanced tool in terms of AI which is implemented and integrated. CrowdStrike Falcon has a ransom detection time of less than 50 seconds. Detection and taking down violations and breaches takes a minimum time of 59 seconds. Intelligence is very good, as AI is integrated with this solution. The integration capabilities in CrowdStrike Falcon are very good.

What needs improvement?

If tomorrow is the next release of the product, new features would be helpful, but at the moment, the product is very good. Nothing specific comes to mind about what new features they can add.

For further improvements, I can only think of one example because this is very important for us; they could reduce the price. Then it would deserve a rating of seven.

For how long have I used the solution?

We have been using it for three to four years and have not encountered any issues.

What was my experience with deployment of the solution?

Regarding challenges or problems with the product, I haven't noticed any current drawbacks. The challenge occurred last year in July when there was some patch update failure, which caused many issues. However, we have overcome that situation.

What do I think about the stability of the solution?

The stability is good.

What do I think about the scalability of the solution?

We have been using it for three to four years and have not encountered any issues. More experience with this product might come with increased usage.

How are customer service and support?

The technical support from CrowdStrike Falcon is good.

I would rate the support an eight.

How was the initial setup?

The installation and deployment are straightforward. It is very good and can be integrated with the management engine.

What was our ROI?

The Return On Investment saves around 30%.

What's my experience with pricing, setup cost, and licensing?

The licensing cost and setup costs are affordable.

What other advice do I have?

I am a computer engineer by profession.

The maintenance is automatic.

I would rate CrowdStrike Falcon as nine overall.