We're installing the solution on some of our external servers. It has a cloud portal, and we can control everything through the cloud. It's good for remote sites.
Senior Data Hosting and Security Special at Two aquate
Offers good centralization and access to remote sites with an easy setup
Pros and Cons
- "The initial setup is a very fast process."
- "We'd like to see more integration capabilities."
What is our primary use case?
What is most valuable?
I like that it has a centralized cloud, and all the agents provide visibility on our remote sites. It offers good central management. It can be accessed through external networks.
The management is taken care of. It's a complete solution that's taken care of by CrowdStrike. We don't have to do anything.
What needs improvement?
We'd like to see more integration capabilities.
We need more log storage as CrowdStrike will dump all logs to the centralized server.
For how long have I used the solution?
I've been using the solution for five years.
Buyer's Guide
CrowdStrike Falcon
June 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable enough. We have not had any downtime. The only issue is if we have issues with the internet connectivity.
How are customer service and support?
We get support from their local vendors. We have a lot of local support. If they cannot handle the case, they directly forward the issue to CrowdStrike. The downside is that support asks for too many logs. We, of course, have to investigate first and try to solve the problem ourselves.
Which solution did I use previously and why did I switch?
I've worked with Kaspersky. They are a similar solution. I've also used Microsoft Defender, which is also very similar. We do use a lot of Microsoft products, and Defender is readily available everywhere. They are the market leaders right now. Their software has very good integration across the whole Microsoft product offering. CrowdStrike, however, we have high trust with, as they are focused specifically on security, unlike Microsoft. CrowdStrike offers updates quicker than Microsoft or other services.
How was the initial setup?
The initial setup is a very fast process. Cloud solutions are fast to set up. They just give you access to their cloud and they have an API integration. It will be up and running within a few minutes.
What's my experience with pricing, setup cost, and licensing?
The tool is very expensive. It's similar to Microsoft Defender. That said, it's not overpriced. It's worth it for the level of security. We need it for our company.
What other advice do I have?
I'd rate the solution nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Cyber Defense & Offensive Security at Habib Bank Limited
Good lateral movement and overwatch detections but requires improvements in the Mac environment
Pros and Cons
- "The CS falcon agent is a lightweight agent compared with other agents of EDR products."
- "The solution fits well in the organization and took out valuable output as expected from Endpoint Detection and Response solution."
- "CS Falcon sensing capabilities for non-domain machines should be enhanced since the agent doesn't detect the neighbor's IP Address and/or any anomaly which was identified in the network for the non-domain machine."
- "Although all the preventive controls were enabled in the CS falcon dashboard, CS falcon had raised a red flag regarding fileless execution, however, the moment it let us know our system got encrypted."
What is our primary use case?
The following is a list of use cases that were tested and evaluated against Crowd Strike along with different competitors.
1 - Execution of Fileless Ransomware - The test was conducted using PowerShell script execution, the script was executed using privileges rights and it was successful. Although all the preventive controls were enabled in the CS falcon dashboard, CS falcon had raised a red flag regarding fileless execution, however, the moment it let us know our system got encrypted.
2 - Uploading large volume of Data over the cloud - Using customized script in the USB, a test was conducted to copy (.docx, .xlsx, .pptx, .png, .jpg, .pdf, .txt, .rtf) files from the system. It performs a copy operation from the whole disk and creates a password-protected .zip file in APPDATA of the complete files, once the protected file is created it then checks the internet connectivity. As soon as the script finds connectivity with 8.8.8.8, 8.8.4.4. it starts sending the protected .ZIP file over its CnC cloud.
3 - Disabling of CS Falcon Agent - I have conducted a test to disable the Falcon agent from the Windows-based OS. The agent was successfully disabled by booting up another OS and renaming of agent files from the system.
4 - Perform Privilege Task in Crowd strike - CS roles have some additional privileges. While performing host containment, it has the ability to perform the following operations without informing the user:
* Host Containment
* Isolating the host from the network;
* Copying data from the host machine into the CS cloud;
Considering the above situation it may cause a breach of user privacy due to which user can file a complaint against InfoSec team.
How has it helped my organization?
The solution fits well in the organization and took out valuable output as expected from Endpoint Detection and Response solution.
This solution supersedes the requirement of an Endpoint Protection solution. The cost of EPP can be saved while using EDR.
One good thing is the active association of the Crowd Strike team in terms of support and coordination.
Features that require further evaluation include:
Let's take an example of ten machines that require CS falcon agent installation. Apart from agent compatibility and ease of installation, one of the most important areas is the network bandwidth which would require whenever an agent updates the server through the cloud.
An estimated network bandwidth utilization takes 0.4 MB/hour for a single machine to update its probes over the cloud. If we estimate the total working hours in our case it is eight hours, the formula would be 0.4 X 8 = 3.2 MB per host per day is the data uploading requirement on the cloud. It is highly recommended to assess a number of agents and the network bandwidth requirements.
What is most valuable?
The CS falcon agent is a lightweight agent compared with other agents of EDR products. Moreover, the following is the list of valuable features which I found very useful:
1 - Lateral Movement
2 - Overwatch detections
3 - Custom IOC blocking
4 - Suspicious Process and Registry operations
5 - Azure/AWS agent installation and easy integration with SIEM
6 - Triage of the complete incident is well created in the CS dashboard. It helps to show complete details about the incident.
7 - It is an agent-based license not machine-based, so once the machine gets outdated/old, installation of the same agent license in another machine is possible.
What needs improvement?
Area of Improvement
The products still require improvement in the Apple environment (Mac). Currently, this solution (as of July 2022) is not compatible with MAC OS (X), Catalina, or Big Sur.
Similarly, the product is also not compatible with Unix-based systems including AIX, Darwin, and FreeBSD.
CS Falcon sensing capabilities for non-domain machines should be enhanced since the agent doesn't detect the neighbor's IP Address and/or any anomaly which was identified in the network for the non-domain machine.
Additional Features required in the Next release:
The product requires an add-on feature which should be a turnkey feature if it requires to be turned on to XDR no changes should be required to be made on the user end as the agent is already installed.
For how long have I used the solution?
The solution has been used for around two years, including the demo version with full features and final version with specific features.
This solution has been used without any compatibility issue and/or technical failure due to anti-virus installation.
When we procured Crowd Strike as an EDR it was on the Gartner top ranking as well.
The agent was being utilized in Windows Servers (2016, 2019), Linux Servers (Fedora, Red hat, Cent OS), Windows Endpoints (10, 11), and Mac.
What do I think about the stability of the solution?
The solution is stable and we have used it for more than 2500+ hosts.
What do I think about the scalability of the solution?
It is a cloud-based solution - so scalability is not an issue.
How are customer service and support?
When it comes to customer service and support is that the principal engages whenever required.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
This was the first product that we evaluated out of 6 (six) products.
How was the initial setup?
The setup was straightforward and it's easy to use.
What about the implementation team?
A vendor team was engaged in the installation of the complete solution.
What's my experience with pricing, setup cost, and licensing?
Licensing is relatively low than other EDR solutions.
Which other solutions did I evaluate?
We evaluated Carbon Black and FireEye.
What other advice do I have?
Crowd Strike is a good solution. However, it requires you to build more features in protecting Endpoint agents for example:
DOM Improvement
DLL's Injections
Detection of CNC in Network Neighbors
Detection of similar attack surfaces in the network.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
CrowdStrike Falcon
June 2026
Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
IT Security Operations Security Specialist at a insurance company with 1,001-5,000 employees
Good reporting capabilities and helps track machines much better
Pros and Cons
- "The solution's reporting console is phenomenal, and I can get a lot of data out of it."
- "The solution should have included remote wipe capability out of the box."
What is our primary use case?
We use the solution for end-user devices.
What is most valuable?
The reporting console is phenomenal, and I can get a lot of data out of it. The reporting capabilities are much better than anything I've used before. With CrowdStrike Falcon, we can track machines much better.
What needs improvement?
One of the things that we built and used quite regularly is a remote wipe capability within CrowdStrike Falcon. The solution should have included remote wipe capability out of the box.
If we have a compromised or stolen machine, we can quarantine it within the CrowdStrike console. However, it doesn't include a feature that enables you to remotely wipe that machine via the console. We had to build that in separately.
For how long have I used the solution?
I have been using CrowdStrike Falcon for two years.
What do I think about the stability of the solution?
We haven’t faced any issues with the solution’s stability.
What do I think about the scalability of the solution?
The solution's scalability has been amazing. We started by deploying it to 30 users, and over three months, we expanded to 5,000 users with no issues.
How are customer service and support?
For technical support, I open a ticket with the MSP, and they deal with it. Our MSP is excellent at resolving support tickets.
Which solution did I use previously and why did I switch?
We previously used Symantec Endpoint Protection. We switched to CrowdStrike Falcon because it was a new vendor with new technology.
How was the initial setup?
The solution's initial setup was very easy because we did an SCCM push for deployment.
What about the implementation team?
Our MSP did a lot of the deployment work for us. The solution was deployed by a small team in three months. It took four of us to deploy the tool to 5,000 users.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is great for us.
What other advice do I have?
It took us about three months to adjust to the new client and switch from a file-level scanner to an AI-based CrowdStrike scanner to see where we felt the differences. CrowdStrike Falcon is deployed on the cloud in our organization. From an end-user perspective, the solution does not require any maintenance after deployment.
New users should be prepared for unexpected alerts. CrowdStrike Falcon views things very differently than many conventional antivirus tools.
Overall, I rate the solution a nine out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Large account Manager at Softcell Technologies Limited
Prevent unauthorized access or identity theft from external sites
Pros and Cons
- "It helps to prevent unauthorized access or identity theft from external sites. If your identity is stolen, you can ban it."
- "One thing that is not yet available is attack simulation."
What is our primary use case?
It also helps you with access, like we have dark web monitoring and admin protection management. So, the use cases can vary from organization to organization, but every organization has different value in it.
What is most valuable?
It helps to prevent unauthorized access or identity theft from external sites. If your identity is stolen, you can ban it.
Real-time monitoring is important because it runs multiple things on a single platform, like IDA, EDR, XDR, and SIM solutions. It captures all technology with one agent, which makes it easier for us to fix customer issues.
Having a single console is helpful, especially when customers have multiple vendors for their products. It's easier to manage one partner. In this case, CrowdStrike Falcon helps.
What needs improvement?
One thing that is not yet available is attack simulation. For example, if someone tries to attack your Active Directory on inactive accounts, a cyber attacker could hack those accounts and try to get into your company. This could be a feature to add. It would give a fake reply each time someone tries to hack it. Multiple companies that I know of would like that.
For how long have I used the solution?
I have been using it for two years.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. It's a scalable solution that is very easy to deploy.
It is suitable for every kind of business, including small, medium, or enterprise businesses.
How are customer service and support?
Technical support depends on a system integrator.
CrowdStrike technical support regarding Identity Protection has a team, but if there's no issue with the agent, you can work it out yourself.
The support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy. We only have one option available right now: on the cloud. It gets applied to endpoints, but it's cloud-based.
It is very easy to integrate this product into our existing environment.
What's my experience with pricing, setup cost, and licensing?
It's a premium product.
What other advice do I have?
From my end, it works. But it can be recommended or viewed by a personal customer. We are not the sole user of CrowdStrike Falcon. It's the end user.
I would recommend using it. For me, it is the best product ever. Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Manager, Information Technology Security at Nesma
Integrates well and identifies and responds to threats much faster
Pros and Cons
- "The key aspect of CrowdStrike Falcon is its behavioral detection approach."
- "The UI is not efficient."
What is our primary use case?
Due to compliance requirements, our organization utilizes CrowdStrike Falcon as our Endpoint Detection and Response solution. This decision was particularly driven by the need to address a surge of ransomware attacks within our environment, experiencing between ten and 15 incidents at the time. The implementation of an EDR solution became crucial for effectively responding to these threats.
Our existing system lacked real-time monitoring and visibility, causing detection delays of even several minutes. CrowdStrike addressed this by offering near-instantaneous detection across the entire system. Furthermore, it allows for manual or automated response actions, significantly improving our overall incident response speed.
How has it helped my organization?
Integrating CrowdStrike Falcon with other solutions such as our SIEM was easy.
What is most valuable?
The key aspect of CrowdStrike Falcon is its behavioral detection approach. Unlike traditional signature-based platforms that rely on pre-defined patterns, Falcon analyzes an application's behavior to identify and respond to threats much faster. This makes it lightweight and minimizes impact on system performance. The sandbox feature is also valuable, while it incurs an additional cost, it can be valuable for deeper investigation.
What needs improvement?
The UI is not efficient. We are required to dig down to get more information, jumping from screen to screen.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three and a half years.
What do I think about the stability of the solution?
CrowdStrike Falcon generally ran smoothly with minimal lag.
What do I think about the scalability of the solution?
CrowdStrike Falcon meets our scaling needs. To increase usage we simply add more agents.
How are customer service and support?
Frustrated by CrowdStrike's slow and inconsistent technical support, we ended up having more success researching and resolving the issue ourselves.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
It is the 1st EDR we selected, after testing different solutions.
How was the initial setup?
Leveraging the cloud platform, the initial deployment was straightforward. We simply needed to activate and deploy the agents. While configuration for a seasoned professional only took one to two hours, the entire deployment process typically takes a couple of days.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon can be more expensive than some competitors, and its base price doesn't cover every feature. For instance, adding sandboxing for advanced malware analysis incurs an extra cost.
Which other solutions did I evaluate?
We evaluated CrowdStrike and SentinelOne. However, since we bought the CrowdStrike, we did not move forward with SentinelOne.
CrowdStrike stands out for its superior threat detection speed, lightweight agents that don't impact system performance, and its helpful recommendations for responding to threats. This combination allows us to swiftly stop even unknown threats in their tracks.
What other advice do I have?
I would rate CrowdStrike Falcon eight out of ten.
Two engineers max are required for maintenance.
We have 5,000 CrowdStrike Falcon users within our organization.
CrowdStrike Falcon utilizes a behavioral approach to security, proactively identifying threats based on their actions rather than relying on pre-defined signatures. This allows for faster response times compared to traditional signature-based systems.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Nov 3, 2025
Flag as inappropriateHead Deputy Head of IT, Information Technology's Projects & Developments Center at a energy/utilities company with 201-500 employees
The overall experience with Crowdstrike Falcon is highly positive, with seamless scalability, easy deployment, and exceptional stability once properly configured.
Pros and Cons
- "We like Falcon's network visibility. We can see how threats are evolving on PCS or in the company network. The solution's real-time incident response is very fast."
- "Some of Falcon's features are a bit pricey."
What is our primary use case?
We rely on CrowdStrike Falcon for comprehensive threat detection, prevention, and valuable insights. This robust solution also offers identity protection features. Our dedicated team of six professionals effectively manages the platform, ensuring its effectiveness across multiple locations, including our data centers and core facility.
How has it helped my organization?
CrowdStrike's advanced detection and prevention capabilities offer a superior level of protection against potential threats. Its unique feature of automated rules is designed to effectively confine threats at the device level. This automatic confinement of high alerts ensures that the device is secured immediately, buying crucial time for the dedicated response team to identify and neutralize the threat. This proactive strategy not only minimizes the potential impact of threats but also guarantees a rapid and efficient response to any security incidents, thereby enhancing the overall security posture.
What is most valuable?
We appreciate Falcon's network visibility feature as it allows us to monitor the evolution of threats on PCs and within the company network. The solution's real-time incident response is notably swift. Initially, we encountered numerous false positives during the project initiation phase. However, we managed to resolve most of them independently or with assistance from CrowdStrike support. Consequently, our security levels were significantly improved, and we elevated all parameters to their maximum. Currently, we seldom encounter false positives. Most of these were low-level alerts, while the high-level alerts were automatically quarantined.
What needs improvement?
While Falcon's advanced capabilities offer robust security solutions, it's worth noting that some of these features may come at a higher cost. This could potentially make it a less economical option for small to medium-sized businesses operating on tighter budgets. It's important for such companies to weigh the benefits of Falcon's comprehensive protection against their financial constraints to make an informed decision.
For how long have I used the solution?
We have been using CrowdStrike Falcon for nearly five years already.
What do I think about the stability of the solution?
Crowdstrike Falcon demonstrates exceptional stability once it has been properly configured with the appropriate settings. While there may be a period of adaptation and configuration required to ensure optimal performance, once the solution is in place, it operates with remarkable stability. Users can rely on Crowdstrike Falcon to consistently deliver reliable and secure protection without significant disruptions or instability.
What do I think about the scalability of the solution?
I would rate Crowdstrike Falcon a nine out of 10 for scalability. It offers seamless scalability, allowing easy expansion of the sensor deployment to accommodate growing needs. However, it's worth noting that the primary limitation one may encounter is the cost associated with deploying additional sensors.
How are customer service and support?
I rate CrowdStrike support nine out of 10. It's fantastic.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We made the switch from Symantec to Falcon because we required a solution that offered greater speed, reliability, and the ability to effectively handle the wide range of advanced threats present in the wild.
How was the initial setup?
The initial setup of Crowdstrike Falcon was straightforward and efficient. The cloud-based deployment process was seamless for most components, with the exception of the sensors. Deploying the sensors to PCs was automated and hassle-free, requiring just a few minutes per device. However, to ensure the highest level of protection and customization, we opted to manually install the sensors on our servers. This hands-on approach allowed us to have greater control and assurance over the server deployment, ensuring the best possible protection for our critical infrastructure.
What was our ROI?
We've seen an ROI in terms of time saved. It's probably around 5 percent.
What's my experience with pricing, setup cost, and licensing?
While Falcon's advanced capabilities offer robust security solutions, it's worth noting that some of these features may come at a higher cost. This could potentially make it a less economical option for small to medium-sized businesses operating on tighter budgets. It's important for such companies to weigh the benefits of Falcon's comprehensive protection against their financial constraints to make an informed decision.
Which other solutions did I evaluate?
Of course but I can't disclose this information.
What other advice do I have?
I rate Crowdstrike Falcon nine out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Cybersecurity solution architect Individual Contributor at IQSEC SA
The agent is light, so it doesn't require many resources on the machines
Pros and Cons
- "CrowdStrike enables the infrastructure managers to visualize all the events and get information about the network."
- "CrowdStrike's advantage is that the agent is light, so it doesn't require many resources on the machines, it's easy to install, and the results are useful to the organization."
- "There are some areas where some customers would prefer a different service."
What is our primary use case?
Falcon helps my client improve productivity. About 5,000 users at the client company are using the product.
How has it helped my organization?
CrowdStrike enables the infrastructure managers to visualize all the events and get information about the network.
What is most valuable?
It's important for the customer to have surety that all the workstations are protected.
What needs improvement?
There are some areas where some customers would prefer a different service.
For how long have I used the solution?
About four months ago, I and my other partners started preparing a presentation to propose CrowdStrike to a client.
What do I think about the stability of the solution?
Falcon is a highly stable product.
How are customer service and support?
I rate CrowdStrike's support 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We worked with other solutions, like Trend Micro. CrowdStrike's advantage is that the agent is light, so it doesn't require many resources on the machines. It's easy to install, and the results are useful to the organization.
How was the initial setup?
I'm not directly involved with the setup. I prepare a proposal, and another department deploys the solution. Falcon doesn't require maintenance because the product runs in a cloud environment.
What about the implementation team?
We use a reseller and an integrator.
What was our ROI?
I rate CrowdStrike Falcon 10 out of 10 for ROI.
What's my experience with pricing, setup cost, and licensing?
My customers pay for yearly licenses. I rate CrowdStrike Falcon 10 out of 10 for affordability.
What other advice do I have?
I rate CrowdStrike Falcon 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Analyst at a tech vendor with 10,001+ employees
Excels at identifying suspicious activity, helps mitigate potential security breaches, and is easy to use
Pros and Cons
- "The detection and response console is the most valuable feature."
- "We encounter occasional issues, such as when disabling network access for a host that uses CrowdStrike."
What is our primary use case?
We use CrowdStrike Falcon to investigate security detections for malicious activities in our environment.
CrowdStrike utilizes machine learning algorithms and detection rules to generate alerts for suspicious activity within our environment. We then investigate these detections individually, analyzing the details of each event.
In addition to automated detection, CrowdStrike allows for custom queries. For instance, if we need to investigate a specific host, we can leverage a cloud security language to examine its activity. Similarly, we can use CrowdStrike to search for activity related to particular users or hosts.
How has it helped my organization?
CrowdStrike Falcon provides significant additional value. It excels at identifying suspicious activity the moment an application appears in the environment, immediately bringing these incidents to the attention of our response team. Upon receiving an alert, our team can investigate and take appropriate action if anything malicious is found. In essence, CrowdStrike Falcon acts as a strong barrier against attackers.
In the past 3 years, we have encountered many scenarios where CrowdStrike Falcon has helped mitigate potential security breaches.
What is most valuable?
The detection and response console is the most valuable feature.
What needs improvement?
We encounter occasional issues, such as when disabling network access for a host that uses CrowdStrike. In these cases, the access disable process can be quite slow.
I'm using CrowdStrike Query Language, and I've noticed an issue with event backups. Searches exceeding a certain event threshold aren't capturing all results. For instance, if I run a search that returns 10,000 events in a single day, only 2,000 events are backed up. This limitation with CrowdStrike Query Language needs to be investigated.
For how long have I used the solution?
I have been using CrowdStrike Falcon for over 3 years.
What do I think about the stability of the solution?
CrowdStrike Falcon is generally stable, although event searches may occasionally experience slow performance.
What do I think about the scalability of the solution?
CrowdStrike Falcon's scalability is dependent on the license acquired.
How are customer service and support?
The technical support live chat can experience long wait times. Submitting a ticket may result in a quicker response.
Which solution did I use previously and why did I switch?
The company was using Carbon Black before I joined. When I came on board, they decided to switch to CrowdStrike.
What other advice do I have?
I would rate CrowdStrike Falcon 9 out of 10.
CrowdStrike Falcon is deployed across multiple end-user systems and locations.
I recommend CrowdStrike Falcon. It's a wonderful security platform that's easy to use and requires minimal effort to maintain.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sales Director at CLOUD MIND
Blocks suspicious activities and protects endpoints and servers from attacks
Pros and Cons
- "The product provides good monitoring features."
- "The tool is more expensive than other products in the market."
What is our primary use case?
A lot of customers face ransomware and malware attacks. The solution helps protect endpoints and servers from ransomware and malware attacks.
How has it helped my organization?
The solution has multiple layers of security, including web security. We can monitor endpoints, conduct root cause analysis, and find geolocations. If the tool finds any suspicious activity, it blocks and remediates it.
What is most valuable?
The solution makes our security operations easier. After an incident, we get complete reports and insights. The product provides good monitoring features. The product also has teams that help customers find suspicious activities. The team calls and asks us to check the updates and remediate issues. If the system can remediate it, the team does it through the system. The detection and response are in real-time. There are no security breaches. Resolving issues doesn’t take much time.
What needs improvement?
The tool is more expensive than other products in the market.
For how long have I used the solution?
I have been using the solution for more than 3 years.
What do I think about the stability of the solution?
I did not have any stability issues.
What do I think about the scalability of the solution?
It is easy to scale up. We just need to add the licenses. The product is suitable for small, medium, and large businesses. We must buy a minimum of 50 licenses.
How are customer service and support?
The support is excellent. We rarely need support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is pretty simple and clear. The time taken for deployment depends on the endpoints. It's a cloud solution. We can use Active Directory or the group policies to deploy it.
What was our ROI?
The product has a lot of use cases. There are companies that need to run their operations 24/7. It will be a big challenge if their server or infrastructure goes down. They cannot afford downtime. They need to choose the right solution for their needs.
What's my experience with pricing, setup cost, and licensing?
The price depends on the kind of service we need. If we need excellent service, we must pay a reasonable price. We can choose any pricing model if we do not want excellent service. The product is excellent. We need to pay a premium price for the tool.
Which other solutions did I evaluate?
Microsoft Defender Threat Intelligence, IBM, and Cisco are some competitors. CrowdStrike entered the market with a USP to protect endpoint servers. It has a different approach. Malwarebytes has a similar setup. I prefer CrowdStrike, though.
What other advice do I have?
I will recommend the tool to others depending on their budget. If customers have a good budget and need a premium product, they can choose CrowdStrike. No product is perfect. Overall, I rate the tool an 8 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Security Engineer at a computer software company with 201-500 employees
Makes investigation easy and has a lightweight agent
Pros and Cons
- "The CrowdStrike Falcon agent is very lightweight. Users never complain about their PCs getting stuck and things like that."
- "The dashboard area must be improved. We have integration with Splunk, and we are creating a dashboard there. Their dashboard area must be up to date. It should have more details and more options to create the reports and things like that."
What is our primary use case?
We are using it as an EDR solution for endpoint protection.
How has it helped my organization?
Everything is changing rapidly nowadays, and new threats can come into the organization from any source. I have found this product to be very useful.
If I want to drill down into an unusual activity or something else, I can do that. I can go deep into what processes were involved, what network operations were involved, and what unauthorized users wanted to do. I can see how CrowdStrike processed and blocked the operation. The investigation is very easy for me. I can go to the tree level and see what is going on. It is very useful.
What is most valuable?
The CrowdStrike Falcon agent is very lightweight. Users never complain about their PCs getting stuck and things like that. In my previous experience, when anything was getting scanned, our PCs would become slow. Users would complain about PCs getting slow. This is a positive point of CrowdStrike Falcon.
What needs improvement?
The dashboard area must be improved. We have integration with Splunk, and we are creating a dashboard there. Their dashboard area must be up to date. It should have more details and more options to create the reports and things like that.
I have some concerns about their support. I am not happy or satisfied with their support. Something happened, and we opened a ticket. Their support engineer just vanished, and after a month, he came back and told us that he was off work and could not pursue the ticket. He said that he now has the time, but logs are gone because there is a time limit. We were asked to repeat the test. This is very unusual for me.
For how long have I used the solution?
In my organization, we have been using it for the last one and a half years. I have been using it for the last two to three months because I recently joined the organization.
What do I think about the stability of the solution?
From my understanding and observation, it is a stable product, but I have been using this product only for the last two to three months. I am just in the learning phase.
What do I think about the scalability of the solution?
We have almost 3,000 users using this solution.
How are customer service and support?
I would rate CrowdStrike's support team a three out of ten. Their support is unacceptable for us. We are doing some testing ourselves. When we found an issue where CrowdStrike should have blocked something but did not, we opened a ticket with CrowdStrike. They tried to communicate with us and looked at the files that we shared. We had updated signatures, and we shared with them the SHA values, but after that, they suddenly vanished. Just two days ago, I got an email from them that the engineer was on leave and he is back now. They asked us to perform the activity again, which is unacceptable.
When any issue happened with Symantec, we opened a ticket, and they would accept their mistake if something was not caught by Symantec. They would then update the definitions and send us the latest updates. This is the way to work on the latest technology trends.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have experience with Symantec endpoint protection. As compared to Symantec, CrowdStrike is a very good product. I have also worked with Microsoft Defender.
What other advice do I have?
Every product has some advantages and disadvantages. I have worked with Microsoft Defender and Symantec, and now, I am working with CrowdStrike. Every organization's needs are very different. It depends on what the organization wants. For example, the security requirements of the banking sector are very high. The banking sector has different requirements, the retail sector has different requirements, and a software development organization has different requirements. An organization should weigh the pros and cons and decide based on the requirements.
Overall, I would rate CrowdStrike Falcon an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Extended Detection and Response (XDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Threat Intelligence Platforms (TIP) Endpoint Detection and Response (EDR) Attack Surface Management (ASM) Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
Splunk Enterprise Security
SentinelOne Singularity Endpoint
Darktrace
IBM Security QRadar
Microsoft Sentinel
Varonis Platform
Elastic Security
Huntress Managed EDR
HP Wolf Security
Trellix Endpoint Security Platform
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?




















