Try our new research platform with insights from 80,000+ expert users
Murali Krishnan L - PeerSpot reviewer
Technical Manager (SOC Operations) at a tech services company with 1,001-5,000 employees
Real User
Top 20Leaderboard
Sep 1, 2022
User-friendly, simple setup, and good user interface
Pros and Cons
  • "The most valuable features of Crowdstrike Falcon XDR are Spotlight and Discovery, they are helpful. Additionally, the console is user-friendly, with fewer false positives than other solutions."
  • "Crowdstrike Falcon XDR can improve the integration. There are some locks on the cloud to on-premise integrations."

What is our primary use case?

We are using Crowdstrike Falcon XDR for security.

What is most valuable?

The most valuable features of Crowdstrike Falcon XDR are Spotlight and Discovery, they are helpful. Additionally, the console is user-friendly, with fewer false positives than other solutions.

What needs improvement?

Crowdstrike Falcon XDR can improve the integration. There are some locks on the cloud to on-premise integrations.

For how long have I used the solution?

I have been using Crowdstrike Falcon XDR for approximately one year.

Buyer's Guide
CrowdStrike Falcon
February 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,733 professionals have used our research since 2012.

What do I think about the stability of the solution?

Crowdstrike Falcon XDR is a highly stable solution.

What do I think about the scalability of the solution?

Crowdstrike Falcon XDR is scalable for what we use it for. We are using the maximum number of endpoints, which is 1,000.

How are customer service and support?

The support from Crowdstrike Falcon XDR is of a middle level. It is not good and it is not bad.

I rate the support from Crowdstrike Falcon XDR a six out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We were previously using FireEye EDR. We switched to Crowdstrike Falcon XDR because we were facing a lot of issues, such as false positives.

How was the initial setup?

The initial setup of Crowdstrike Falcon XDR is easy. We installed it manually, and it took us approximately one month to complete the implementation of the solution.

I rate the setup of Crowdstrike Falcon XDR an eight out of ten.

What about the implementation team?

We did the implementation of Crowdstrike Falcon XDR in-house. We use two engineers for the maintenance and it is simple. 

Which other solutions did I evaluate?

We evaluated SentinelOne before choosing Crowdstrike Falcon XDR.

What other advice do I have?

My advice to others is this solution is easy to deploy, and there is no planning required.

I rate Crowdstrike Falcon XDR a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Madhawa Liyanage - PeerSpot reviewer
Cyber Security Consultant - Defensive Security at a security firm with 11-50 employees
Consultant
Aug 31, 2022
Useful AI detection, good support, and reliable
Pros and Cons
  • "The most valuable features of CrowdStrike Falcon are the AI in detecting and real-time detections."
  • "CrowdStrike Falcon could improve the EDR functionality. Once the functionality of the solution improves, it will be even better in the market and able to compete with Carbon Black."

What is our primary use case?

We are using CrowdStrike Falcon for the EDR mainly.

What is most valuable?

The most valuable features of CrowdStrike Falcon are the AI in detecting and real-time detections.

What needs improvement?

CrowdStrike Falcon could improve the EDR functionality. Once the functionality of the solution improves, it will be even better in the market and able to compete with Carbon Black.

In a future release, if there were XDR features it would be beneficial.

For how long have I used the solution?

I have been using CrowdStrike Falcon for approximately two years.

What do I think about the stability of the solution?

CrowdStrike Falcon is a stable solution. However, you need to good internet connection for functionality.

What do I think about the scalability of the solution?

CrowdStrike Falcon is scalable. We have below 1,000 endpoints and it scales well.

We have approximately 700 to 800 people using the solution. Additionally, we have approximately 150 servers running with 815 clients.

How are customer service and support?

We used the support at the initial stages of deployment and the support was good. I became familiar with the tool quickly and did not need their support anymore.

How was the initial setup?

The initial setup of CrowdStrike Falcon is straightforward. Our deployment was done in a phased approach, we did it first with 200 servers, then 100 at a time after. We did not roll out the solution all at once throughout the company.

What about the implementation team?

We did the deployment of CrowdStrike Falcon in-house. The amount of people needed for the deployment and maintenance of the solution depends on the tools used. We automate the deployment process.

What was our ROI?

The return on investment for CrowdStrike Falcon is good.

What's my experience with pricing, setup cost, and licensing?

There are three to four licensing models available to choose from for CrowdStrike Falcon. The price of CrowdStrike Falcon depends on the distributor and the reseller partner. The price we received was good.

What other advice do I have?

CrowdStrike Falcon is one of the leading solutions in the market. I would recommend this solution to others.

I rate CrowdStrike Falcon an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner and customer
PeerSpot user
Buyer's Guide
CrowdStrike Falcon
February 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,733 professionals have used our research since 2012.
reviewer1869621 - PeerSpot reviewer
Security Officer
Real User
Jun 8, 2022
The best endpoint protection solution
Pros and Cons
  • "Since we deployed CrowdStrike, the network has become much calmer, and we now understand the sources of infections, which helps us prevent them from spreading."
  • "An improvement would be to extend support to legacy and unsupported servers."

What is our primary use case?

I mainly use CrowdStrike Falcon to prevent threats and detect indicators of attacks or compromises in the network.

How has it helped my organization?

In the past, we regularly got alerts about suspicious activities in the network but couldn't understand where they were coming from. Since we deployed CrowdStrike, the network has become much calmer, and we now understand the sources of infections, which helps us prevent them from spreading. We now get immediate information about infections and can react much faster.

What needs improvement?

An improvement would be to extend support to legacy and unsupported servers. In the next release, CrowdStrike should include patch and vulnerability management, which would allow us to rely on just one solution.

For how long have I used the solution?

I've been using CrowdStrike Falcon for over a year.

What do I think about the stability of the solution?

Falcon is pretty stable - we haven't seen any kinds of performance issues like lagging, which we did experience with other endpoint protection solutions.

How are customer service and support?

CrowdStrike's technical support is very fast and responsive.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, I used Microsoft Bitdefender, but CrowdStrike was faster and better protection-wise.

How was the initial setup?

The initial setup was straightforward - it was very quick (about two and a half hours) without any downtime or issues. We also extended the installation to the remote side, which took another hour. I would rate the setup process four out of five.

What about the implementation team?

We used an in-house team.

What was our ROI?

In the past, we have around four to five engineers managing our endpoint - we have now reduced this to two engineers, which has cut costs. We've also been able to cut the time needed to find the threats and their root causes from up to six hours a day to just half an hour. I would rate our ROI as five out of five.

What's my experience with pricing, setup cost, and licensing?

We pay between $30-50 per user for a yearly license, which is more expensive than SentinelOne or Bitdefender. However, CrowdStrike gives better value for money, so I would rate their pricing four out of five. If you want to add modules or features, these are an additional cost per user.

Which other solutions did I evaluate?

We evaluated SentinelOne, but it was too heavy on the machine and slowed it down. We also did a threat simulation analysis with both SentinelOne and CrowdStrike, and SentinelOne wasn't able to detect or block the threats.

What other advice do I have?

CrowdStrike Falcon is the best endpoint protection solution I've used so far. I would advise anybody thinking of implementing it to go for it, as CrowdStrike will provide more visibility, depth, and context to threats and allow you to understand what's going on. I would give Falcon a rating of ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Younghoon-Youn - PeerSpot reviewer
Director of Security Solution Business at a wholesaler/distributor with 1-10 employees
Real User
May 28, 2022
SaaS security solution that is efficient in running antivirus processes using little storage
Pros and Cons
  • "The most useful feature is that we do not need to install or keep signature files. Regular scanning that consumes a lot of computer resources is not needed."
  • "This solution is relatively expensive."

What is our primary use case?

We use this solution for next generation antivirus and EDR.

How has it helped my organization?

Developers previously complained their resources required regular scanning on their system. This made their system and response time slow. This has since been improved using this solution. 

What is most valuable?

The most useful feature is that we do not need to install or keep signature files. Regular scanning that consumes a lot of computer resources is not needed.

Based on the documentation CrowdStrike provide, the solution provides a number one detection ratio which we like. 

For how long have I used the solution?

We have used this solution for one year. 

What do I think about the stability of the solution?

This is a stable solution as it is cloud based. We have 3000 users making use of it. 

How are customer service and support?

The support team responses are often a little bit slow. I would rate them a three out of five. 

Which solution did I use previously and why did I switch?

We previously used Cisco AMP.

How was the initial setup?

The initial setup is straightforward. I would rate it a five out of five. The deployment was a replacement project and it took three months.

What about the implementation team?

We used a third party for installation. 

What was our ROI?

We don't need to maintain onsite servers and deep end user updates with the new vulnerabilities. Considering the required server hardware and maintenance workload, the ROI will be achieved in a year or one and a half years.

What's my experience with pricing, setup cost, and licensing?

This solution is relatively expensive. 

What other advice do I have?

I would advise others to first evaluate AV or EDR and then investigate the current endpoint protection solution that are already using in their organization. They should then check what kind of tools can be placed with CrowdStrike. 

I would rate this solution a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Customer but recently joined partnership programme
PeerSpot user
Park Armstrong - PeerSpot reviewer
Chief Technical and Solution Architect at a tech vendor with 51-200 employees
Real User
May 21, 2022
Beneficial crowdsourcing intelligence, robust, and useful multi-tenant architecture
Pros and Cons
  • "The most valuable feature of CrowdStrike Falcon is crowdsourcing intelligence."
  • "The skillsets needed to run CrowdStrike Falcon are extensive if you want to get the most value out of the tool."

What is our primary use case?

I use CrowdStrike Falcon for endpoint security and compliance auditing.

How has it helped my organization?

We use CrowdStrike Falcon for discovery when anything goes wrong because it gives us a full history of what's happening. It acts as a preventative model for inappropriate activity. Additionally, we use it for compliance reasons.

What is most valuable?

The most valuable feature of CrowdStrike Falcon is crowdsourcing intelligence.

What needs improvement?

The skillsets needed to run CrowdStrike Falcon are extensive if you want to get the most value out of the tool.

In a future release, the mobile space can use improvement. However, some of those constrained are by Apple and other platforms as to what they can do on the platform. Some of the limitations are industry-based.

For how long have I used the solution?

I have been using CrowdStrike Falcon for approximately one year.

What do I think about the stability of the solution?

The stability of CrowdStrike Falcon is great, I have never had the slightest problems.

What do I think about the scalability of the solution?

CrowdStrike Falcon is highly scalable.

CrowdStrike Falcon is implemented company-wide on every device.

I have approximately one hundred protected endpoints, but the number of users that log on to the tools is approximately four.

How are customer service and support?

CrowdStrike Falcon needs to better its SE sales engineer team. The people didn't fully understand all the different parts of their solution. It's the endpoint protection and it is the essence of what we're trying to receive, they should know their solution very well.

I rate the support from CrowdStrike Falcon a three out of five.

Which solution did I use previously and why did I switch?

I previously used an anti-virus solution, but it didn't do all the things I needed regarding endpoint protection. That's why I added the CrowdStrike Falcon piece to the puzzle. I still have the anti-virus running. I don't need it technically, but I still have it running.

How was the initial setup?

The initial setup of CrowdStrike Falcon is in the medium range of difficulty. You will need a coach and be guided through it.

The time it took to do the full implementation from the beginning to end, from when the contract was turned on, and by the time I turned it on and had everything up was fairly fast because we piloted CrowdStrike Falcon at first. When I bought the solution, it was almost fully implemented. The full process took approximately two months.

I rate the ease of deployment for CrowdStrike Falcon a two out of five.

What about the implementation team?

We had some coaching help from the vendor to do the implementation of the solution. We have three people that can manage this solution.

What was our ROI?

This is not a tool you buy because it gives a return on investment. It's a tool you buy because the cost of not having it is far greater than the cost of having it if you have a problem.

What's my experience with pricing, setup cost, and licensing?

There are approximately a hundred different modules you have to purchase, depending on what you want to do. I have most of the modules. How it works is you buy the portfolio, you have to decide all the components you want in it, and then they price out a bundle for you. I have almost all of the package features in my bundle. You only need to pay for the modules you want.

The cost of CrowdStrike Falcon annually is approximately $10,000.

I rate the price of CrowdStrike Falcon a three out of five.

Which other solutions did I evaluate?

I studied the entire industry before choosing CrowdStrike Falcon. I evaluated many other solutions, such as Manage Engine, Malwarebytes, Checkpoint, McAfee, and Microsoft.

We choose CrowdStrike Falcon because it was fit for the purpose of our business. I needed a cloud solution and I needed it to be a SAS offering that was easy to use. It boiled down to features and fit for purpose, not features and functionality.

CrowdStrike Falcon platform was more robust. It was a true multi-tenant architecture, not a hosted instance. The crowdsourcing nature of CrowdStrike Falcon is a large benefit, all of the threat data is real-time and applied to you real-time from all around the world.

What other advice do I have?

My advice to others is to take a serious look at CrowdStrike Falcon. It's a good solution.

I rate CrowdStrike Falcon an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Business Development Manager - Security at a computer software company with 201-500 employees
Real User
Feb 7, 2022
Intelligent and easy to use endpoint protection and threat identification solution
Pros and Cons
  • "Easy to use, intelligent, and stable threat detection software."
  • "The installation process for this software needs to be simplified."

What is our primary use case?

CrowdStrike Falcon is used for endpoint protection for businesses. It's used for identifying threats.

What is most valuable?

Most of the entry-level security provisions are based on identification, but CrowdStrike Falcon is a market changer because it does not need any kind of signature to identify or update threats.

All organizations face the big challenge of maintaining and updating their security processes. They need to do the update, but then it doesn't go beyond 90%, so CrowdStrike Falcon moved away from the update requirement, so there won't be a need to upgrade for certain types of technology, or for new technology. Not needing to update means the job of maintaining the updates will be taken off the plate of the IT department, which could mean big relief for the customers.

CrowdStrike Falcon is able to identify threats based on processes, rather than looking at signatures and this is what I like about this solution.

I like that it's easy to use, as expected from any cloud solution. CrowdStrike Falcon is an intelligent solution. It's as good as the top solution in the market.

We haven't seen anybody complaining about CrowdStrike Falcon, and we haven't had any customer using this solution who had been attacked by ransomware, so this is proof of how good this solution is.

What needs improvement?

Setting up and installing CrowdStrike Falcon is not easy, so an area for improvement is for that process to be simplified.

For how long have I used the solution?

We've been using CrowdStrike Falcon for two years.

What do I think about the stability of the solution?

I find CrowdStrike Falcon a stable solution.

How was the initial setup?

Installing this solution was not easy. One challenge from the installation is that you always have to replace something, e.g. your Crowdstrike password, macros, etc., before you're able to complete the setup.

What other advice do I have?

We are not carrying CrowdStrike Falcon Complete because it's a managed service, so customers have not really gotten to that level. What we're working with is CrowdStrike Falcon.

Deployment of this solution took us three to five days. We have 2,000 users of CrowdStrike Falcon, and we have 110 different locations across India and some other parts of the world. We have people who manage this solution, but it doesn't require much managing, because the only challenge is removing the old solution, then replacing it with the new one.

I'm recommending CrowdStrike Falcon to other people who are looking into using it, because it's a good solution.

I'm rating CrowdStrike Falcon an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
it_user1424862 - PeerSpot reviewer
Cyber Security Engineer at a legal firm with 501-1,000 employees
Real User
Apr 7, 2021
The cloud-based management console is easy to maintain and takes a load off our hands
Pros and Cons
  • "It has definitely minimized resources. When everything was on-prem, there was a lot more work maintaining it. One of the big value tickets: I don't have lists of hundreds of exceptions for certain applications that I have to maintain, add, delete, and move. The very nature of the product has lessened my workload considerably."
  • "There are some aspects of the UI that could use some improvement, e.g., working in groups. I build a group, then I have to manually assign prevention policies, update policies, etc., but there is no function to copy that group. So, if I wanted to make a subgroup for troubleshooting or divide workstations into groups of laptops and desktops, then I have to manually build a brand new group. I can't just copy a build from one to another. Additionally, in order to do any work within a group, I have to first do the work on the respective prevention policy page or individual policy page, then remove the group if the group is assigned to a different prevention policy, remove the prevention policy, and then add the new one in. So, it can get a little hectic. It would be easier if I could add and remove things from the group page rather than having to go into the policy pages to do it."

What is our primary use case?

We are using it primarily for NGAV, but we also use their EDR product and Falcon OverWatch.

Most of our internal stuff is still on-prem. We do use SaaS for vendor products, but our internal environment is still mostly on-prem.

How has it helped my organization?

I think everyone is trying to move away from on-prem solutions. Having the cloud-based management console makes it a lot easier to maintain. It takes a load off our hands as engineers and analysts. It helps with upgrades and patching, I don't have to worry about on-prem servers for maintenance, but also as another thing to defend against, so getting rid of that is definitely beneficial.

As a cloud-native solution, it provides us with flexibility and always-on protection. I don't have to worry about data center failures on my end. I don't have to worry about any issues in our server rooms affecting the protection of the environment as a whole. Having CrowdStrike take that responsibility is a load off our backs.

Falcon has been very successful in preventing breaches. In the beginning, there were a lot of false positives as Falcon learned our environment, but I would definitely give it a positive rating overall for protecting our environment.

What is most valuable?

The NGAV portion is the most valuable feature. The primary reason that we went with the product was their reputation. In practice, it has been a definite step up from where we were previously.

We are using Falcon Investigate, which is their EDR tool. The EDR has made it infinitely easier to investigate into more detail on end user workstations and servers. Any sort of detection where I can go back into the EDR tool and dig down deeper into the endpoint is great. This was a function that we did not have previously.

What needs improvement?

There are some aspects of the UI that could use some improvement, e.g., working in groups. I build a group, then I have to manually assign prevention policies, update policies, etc., but there is no function to copy that group. So, if I wanted to make a subgroup for troubleshooting or divide workstations into groups of laptops and desktops, then I have to manually build a brand new group. I can't just copy a build from one to another. Additionally, in order to do any work within a group, I have to first do the work on the respective prevention policy page or individual policy page, then remove the group if the group is assigned to a different prevention policy, remove the prevention policy, and then add the new one in. So, it can get a little hectic. It would be easier if I could add and remove things from the group page rather than having to go into the policy pages to do it.

For how long have I used the solution?

I have been using it less than a year. We are relatively new customers.

What do I think about the stability of the solution?

My impressions of the stability are positive. I haven't had any problems since implementation with stability or availability.

Minimal maintenance is required on our side post-deployment, but it still does require maintenance. If I have to build out new groups or a troubleshooting group, e.g., tweaking policies if machines change subnets, then there is still maintenance required.

All post-implementation maintenance and administration is handled by a single security engineer.

What do I think about the scalability of the solution?

We are a relatively small firm, but I have had no problems in my deployment plans. I could easily see this scaling upwards.

In total, we are protecting roughly 1500 endpoints.

How are customer service and technical support?

They have been very on point and helpful. I have never had to ask them where they are. They are always following up with me trying to keep the tickets live, so that is great. I have been very impressed.

Which solution did I use previously and why did I switch?

We replaced Symantec Endpoint Protection. On the one hand, we wanted a fully NGAV. Symantec was still using a hybrid model, a mix of signature-based and behavioral-based detections, so moving over into a full NGAV product was important to us. We wanted to stay up to date on the ever changing nature of malware, especially since we have been seeing more malware nowadays that can evade strictly detection-based systems. Also, Symantec support was very hard to track down or talk to. All in all, CrowdStrike has been more responsive to any questions or concerns, which is big when you are dealing with vendor solutions.

Fortunately, we have not experienced any major detections. However, testing-wise, CrowdStrike has been more effective overall.

How was the initial setup?

Deployment was pretty easy. We scripted out a process in GPO, then we were able to deploy it fairly seamlessly.

We managed to deploy it to all our servers within a week or two. That was mostly due to getting clearance from server owners, not due to the CrowdStrike installation. Then, for the workstations, it was a bit longer just because of office locations and when people had their computers on. The CrowdStrike process was very smooth. It was really just the bureaucracy part that took a while.

We had to change management protocols. We put it out to dev servers and workstations in detect-only mode as we deployed CrowdStrike to endpoints that had a preexisting AV system still on them, in order to avoid any time where a system would not be protected by an antivirus system. So, we deployed CrowdStrike, then disabled the previous antivirus system and activated CrowdStrike's prevention policies, then uninstalled the previous antivirus system.

What about the implementation team?

Four or five people were involved in the deployment: a security engineer, two workstation engineers, and various server owners.

What was our ROI?

It is protecting our environment, so it is worth the cost.

It has definitely minimized resources. When everything was on-prem, there was a lot more work maintaining it. One of the big value tickets: I don't have lists of hundreds of exceptions for certain applications that I have to maintain, add, delete, and move. The very nature of the product has lessened my workload considerably.

What's my experience with pricing, setup cost, and licensing?

The pricing was very fair for what we got.

Different components are additional price points. We got the components that were right for us, but other organizations may require more (or less) components to suit their needs.

Which other solutions did I evaluate?

CrowdStrike is an industry leader. When we were looking for a replacement technology for NGAV, their name was on the top of a Google search.

We did a PoC with CrowdStrike. We deployed the PoC only to a select group of test machines, so we were able to deploy rather quickly. The PoC helped immensely in the decision-making process.

We did evaluate Cylance and Carbon Black. All the products that we investigated looked good. In the end, we went with CrowdStrike because of: 

  1. The reputation of the organization in the AV community.
  2. Its out-of-the-box readiness. 
  3. Ease of maintenance and administration.

What other advice do I have?

Take the time you need in the beginning to fully build out all the groups and prevention policies that you will need. It may take a bit longer during the initial setup, but it is worth it in the long run because it makes maintenance down the line much easier than having to build new groups or prevention policies as they come up. Definitely take the time needed in the beginning. Then, later down the road all you have to do is check some boxes, as opposed to building out brand new groups and prevention policies, which can take awhile.

In the beginning, there will be a bunch of false positives as it learns your environment. However, those are very easily handled within the UI, creating IOA or machine learning exceptions. With our previous solution, we had a couple hundred exceptions, and with CrowdStrike, we have six or so.

CrowdStrike has fulfilled its function very well. We got it specifically to serve the purpose that it is serving.

It is a solid nine out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user1539093 - PeerSpot reviewer
Information Security, Sr. Analyst at a wholesaler/distributor with 10,001+ employees
Real User
Mar 31, 2021
Good support, activity dashboard provides a holistic view from a security standpoint
Pros and Cons
  • "The most valuable feature is the activity dashboard because it gives you a holistic view of your environment from a security standpoint."
  • "We would like to be able to perform on-demand scanning, rather than relying on the scheduler."

What is our primary use case?

We use CrowdStrike Falcon as our EDR solution, including antivirus.

How has it helped my organization?

As Symantec ended its endpoint protection, we were able to roll out CrowdStrike.

It is important to us that CrowdStrike is cloud-based because the way I understand it, that's their main engine for their next-gen EDR solution. The fact that it's cloud-native, flexible, and offers always-on protection is important because we want to have 24-hour monitoring of our environment. It is important to us that we don't have to worry about upgrades.

This product has worked flawlessly to prevent breaches, and then it has allowed us to prevent any downtime.

It has minimized our footprint because having the ability to implement the prevention policies has allowed us to focus on other projects. The prevention policies are working for us.

What is most valuable?

The most valuable feature is the activity dashboard because it gives you a holistic view of your environment from a security standpoint.

What needs improvement?

We would like to be able to perform on-demand scanning, rather than relying on the scheduler. Right now, CrowdStrike does not have an on-demand scanner. They have the always-on, but we have found instances where artifacts are being blocked from running, but they're not being removed. With an on-demand scanner, we would have the ability to remove those artifacts from an end user's machine.

I would like to see the multi-site environment functionality added in the next release. Currently, we are working under a single-site environment, and on the roadmap, they mentioned having the ability to have a multi-site environment.

For how long have I used the solution?

We have been using CrowdStrike Falcon for approximately eight months.

What do I think about the stability of the solution?

Stability-wise, they are very advanced in the next-gen antivirus game. CrowdStrike Falcon is always available.

What do I think about the scalability of the solution?

We have approximately 5,000 machines that are being managed. As time moves on, this number will grow, but we don't expect it to get larger in the near future.

How are customer service and technical support?

I would rate the technical support that we received during the deployment, as well as post-deployment, very well. They were very knowledgeable and gave us all of the tools we needed to have a successful deployment.

Which solution did I use previously and why did I switch?

Prior to Falcon, we were using Symantec antivirus. It was out of date, which is why we replaced it.

How was the initial setup?

It is very easy to deploy the solution's sensor to our endpoints. We use an automated process. 

Our deployment took between two and three months, with paperwork, communication, and roll-out timeframes. Our implementation strategy included using IBM's BigFix application to push to Windows machines, and then we used a solution for the Mac to push it out remotely as well.

What about the implementation team?

Our IT Services team deployed this solution, and they leveraged consultants from CrowdStirke to get the proper packages for the process.

I'm sure that there is administration and upgrades to do, as sensors need to be updated or policies need to be adjusted. We have a group of approximately five people who are security engineers, IT Services, and directors who use it.

What's my experience with pricing, setup cost, and licensing?

With respect to pricing, my suggestion to others is to evaluate the environment and purchase what you need.

Which other solutions did I evaluate?

We looked at different options, such as Carbon Black, as we were replacing Symantec as our EDR solution, and CrowdStrike was the top winner. CrowdStrike is always on, 24 hours. Analysis, with the prevention and the detection policies, as well as the USB policies, are all very beneficial. The one thing that CrowdStrike did not have is the on-demand scanner.

What other advice do I have?

My advice for anybody who is interested in implementing CrowdStrike Falcon is to review and evaluate your environment and compare their EDR solutions.

I would rate this solution a ten out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer:
PeerSpot user
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2026
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros sharing their opinions.