CrowdStrike Falcon Pros and Cons

CrowdStrike Falcon Pros

Security Analyst II at a healthcare company with 10,001+ employees
I like the dashboard nature of it. Everything is clickable, linkable, and information is easy to obtain and find. How it presents that information is probably the biggest win as far as the information correlation aspect. The presentation of it is very good.
View full review »
Chief Information Security Officer at a real estate/law firm with 10,001+ employees
As long as the machine is connected to the Internet, and CrowdStrike is running, then it will be on and we will have visibility; no VPNing in or making some type of network connection. CrowdStrike always there and running in the background; for us, that is big. We wanted something that could give us data as long as the machines connected to the Internet and be almost invisible to the employees.
View full review »
Information Security Analyst at a insurance company with 1,001-5,000 employees
The 10 hours a week that we are freeing up from having to manage and monitor our AV solution has really allowed us to focus on other areas of the business. This has been a huge return on investment.
View full review »
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2021.
534,226 professionals have used our research since 2012.
Enterprise Cybersecurity Architect at Swagelok Company
Probably the most valuable thing to me is the real-time response piece. The fact that I can connect to an endpoint as long as it is on the Internet, no matter where it is globally. I can remove files from the endpoint, drop files on the endpoint, stop processes, reboot it, run custom scripts, and deploy software. Pretty much no other tool can do all that.
View full review »
IT Security Analyst at U.S. Venture, Inc.
From what we have seen, it is very scalable. We have recently acquired a company where someone had a ransomware attack when we joined networks. Within the course of just a few days, we were able to easily get CrowdStrike rolled out to about 300 machines. That also included the removal of that company's legacy anti-malware tool.
View full review »
Associate Director - Infrastructure Engineering at AFT
The UI is simple and self-explanatory. Everything is easy to understand.
View full review »
AT
Chief Security Officer at a financial services firm with 201-500 employees
The OverWatch is the most valuable feature to me. It's a 24x7 monitoring service, and when they see anything suspicious in my environment, they will investigate.
View full review »
Cyber Security Engineer at a legal firm with 501-1,000 employees
It has definitely minimized resources. When everything was on-prem, there was a lot more work maintaining it. One of the big value tickets: I don't have lists of hundreds of exceptions for certain applications that I have to maintain, add, delete, and move. The very nature of the product has lessened my workload considerably.
View full review »
MK
Dy General Manager at a real estate/law firm with 501-1,000 employees
There's almost no maintenance required. It's very low if there's any at all.
View full review »
Director, IT & Systems Security at Tilson Technology Management
The Protect functionality on the laptops provides great visibility into what's occurring, and the cloud management of the platform is what we needed.
View full review »

CrowdStrike Falcon Cons

Security Analyst II at a healthcare company with 10,001+ employees
I would like them to improve the correlation of data in the search algorithms. When we run an investigation, malware, phishing, etc., I want to look at multiple endpoints at once to correlate that data to see the likenesses, e.g., how are they not alike or what systems and processes are running across those systems? I don't want to have to run the same search in their Spotlight module five, 10, 15, or 100 times to get 100 different results, copy that data out, and then correlate it on my own. In a very simple way, I want to be able to load up a comma-delimited list giving me the spotlight data on these X amount of hosts, letting me search for it quickly. We have had to go back to CrowdStrike, and say, "Our search are taking far too long for even one host." They did bump up the cores and that did improve performance, but it is still kind of slow to get that Spotlight data. That is probably our biggest pain point. I think that needs some help. I understand this kind of information access is probably not the easiest thing to do. It is probably a big ask depending on how their back-end is setup.
View full review »
Chief Information Security Officer at a real estate/law firm with 10,001+ employees
I would love to see more investment in Insight because CrowdStrike have an opportunity to potentially displace some of the vulnerability management vendors with the visibility they can see over time. I want to see them continue to evolve, e.g., what other things can they disrupt which are operational things we have to continue to do as an organization.
View full review »
Information Security Analyst at a insurance company with 1,001-5,000 employees
It would be nice if they did have some sort of Active Directory tie-in, whether that be Azure or on-prem. Sometimes, it is difficult for us to determine if we are missing any endpoints or servers in CrowdStrike. We honestly don't have a great inventory, but it would be nice if CrowdStrike had a way to say this is everything in your environment, Active Directory-wise, and this is what doesn't have sensors. They try to do that now with a function that they have built-in, but I have been unsuccessful in having it help us identify what needs a sensor. So, better visibility of what doesn't have a sensor in our environment would be helpful.
View full review »
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2021.
534,226 professionals have used our research since 2012.
Enterprise Cybersecurity Architect at Swagelok Company
A year and a half ago or more, if you put in a support request by email, then it wasn't timely addressed. It could be a day to three days before you received a response, which was a bit frustrating. There was a lot of customer feedback around this issue, which has been greatly refined.
View full review »
IT Security Analyst at U.S. Venture, Inc.
I would like to see a little bit more in the offline scanning ability. This just comes from my background in what I have done in other positions. They only scan on demand, so I always have this fear that we sometimes maybe email out a dormant virus and can be held liable for that. That is something where I would like to see a little bit more robustness to the tool.
View full review »
Associate Director - Infrastructure Engineering at AFT
Basically, they don't cover legacy OS or applications. That's the only issue we're concerned about
View full review »
AT
Chief Security Officer at a financial services firm with 201-500 employees
If we have a dashboard capability to uninstall agents, I think that would be great.
View full review »
Cyber Security Engineer at a legal firm with 501-1,000 employees
There are some aspects of the UI that could use some improvement, e.g., working in groups. I build a group, then I have to manually assign prevention policies, update policies, etc., but there is no function to copy that group. So, if I wanted to make a subgroup for troubleshooting or divide workstations into groups of laptops and desktops, then I have to manually build a brand new group. I can't just copy a build from one to another. Additionally, in order to do any work within a group, I have to first do the work on the respective prevention policy page or individual policy page, then remove the group if the group is assigned to a different prevention policy, remove the prevention policy, and then add the new one in. So, it can get a little hectic. It would be easier if I could add and remove things from the group page rather than having to go into the policy pages to do it.
View full review »
MK
Dy General Manager at a real estate/law firm with 501-1,000 employees
The solution needs to have integration with on-premises security devices and security facilities. That means all the security products, including the perimeter firewall, the DMZ.
View full review »
Director, IT & Systems Security at Tilson Technology Management
The console is a little cluttered and at times, finding what you're looking for is not intuitive.
View full review »
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: September 2021.
534,226 professionals have used our research since 2012.