A popular choice for Data Loss Prevention is CrowdStrike Falcon. This is the primary function our clients leverage it for, as it offers industry-leading DLP capabilities.
Head of Information Technology at SIT
Helps protect our data, is stable, and reasonably priced
Pros and Cons
- "The DLP is the most valuable feature of CrowdStrike Falcon."
- "The console is not user-friendly or visually appealing and has room for improvement."
What is our primary use case?
How has it helped my organization?
CrowdStrike Falcon has helped our customers secure their confidential data.
What is most valuable?
The DLP is the most valuable feature of CrowdStrike Falcon. Additionally, the scanning is good and the deployment is easy.
What needs improvement?
The console is not user-friendly or visually appealing and has room for improvement. I would like a single pane of glass dashboard.
Buyer's Guide
CrowdStrike Falcon
June 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
855,156 professionals have used our research since 2012.
For how long have I used the solution?
I have been an integrator of CrowdStrike Falcon for one day.
What do I think about the stability of the solution?
CrowdStrike Falcon is stable.
Which solution did I use previously and why did I switch?
I have also worked with Trend Micro and Panda.
How was the initial setup?
The initial deployment is straightforward. I would rate the ease of setup nine out of ten.
Two people are required for the deployment.
I need to upgrade the software occasionally but it doesn't require continuous maintenance.
While the specific deployment time varies depending on each client's individual environment, on average the process can be completed in a couple of days.
What was our ROI?
I only deploy the solution for clients, I don't calculate their ROI.
What's my experience with pricing, setup cost, and licensing?
CrowdStrike Falcon's pricing is reasonable. We can customize features and that affects the pricing.
We pay 40,000 dirhams per 100 users.
What other advice do I have?
I would rate CrowdStrike Falcon nine out of ten.
Our clientele ranges from small to enterprise-level businesses.
I recommend CrowdStrike Falcon as it provides all the features of an EDR.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

IT Consultant at a comms service provider with 5,001-10,000 employees
Provides real-time monitoring and response to security incidents
Pros and Cons
- "The most valuable feature of CrowdStrike Falcon for me is its unified sensor, applicable across all models."
- "There is room for improvement in managing multiple customer IDs."
What is our primary use case?
We use CrowdStrike Falcon mostly for EDR.
How has it helped my organization?
We implemented CrowdStrike Falcon to gain better control over our endpoints, servers, and work sessions. Unlike traditional antivirus programs, Falcon's sophisticated features allow us to comprehensively manage and enhance security, providing a more robust solution for our specific needs.
In the past year, Falcon has significantly improved our organization's security by consolidating endpoint management. With a single call to Falcon, we can oversee all endpoints, eliminating the need for multiple platforms and streamlining our security operations for better efficiency and awareness.
What is most valuable?
The most valuable feature of CrowdStrike Falcon for me is its unified sensor, applicable across all models. This consistency simplifies operations, and while the analytics and server capabilities are significant, having a single sensor for all models stands out as the key advantage in managing security effectively.
What needs improvement?
There is room for improvement in managing multiple customer IDs. Enhancements in the console web for better control and customization of sensor features would be valuable to ensure a smoother experience in handling various customer IDs and installations.
For how long have I used the solution?
I have been using CrowdStrike Falcon for about a year.
What do I think about the stability of the solution?
I have not had any stability issues with CrowdStrike Falcon.
What do I think about the scalability of the solution?
I would rate the scalability of CrowdStrike Falcon as a ten out of ten.
How are customer service and support?
The technical support is not very good. I would rate it as an eight out of ten. One improvement could be reducing the response time for cases, as waiting two or three days, even for less critical issues, can be a bit long. Additionally, a better feedback loop on submitted ideas would enhance the efficiency of communication with the product group, providing more clarity on whether proposed features or versions will be considered.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Falcon, we used Trellix. We switched to Falcon for enhanced security, moving beyond just antivirus protection. Falcon provides more advanced features and a comprehensive security solution.
How was the initial setup?
The deployment of Falcon was relatively easy, with no major issues except occasional misconfigurations on the filter. The process for individual work sessions is fast, taking around a few minutes, but for servers, it requires more time due to the need for antivirus removal and sensor replacement, involving server restarts. Overall, the deployment time depends on the scope, ranging from minutes for work sessions to more extended periods for servers.
What other advice do I have?
At the moment, we have around twenty thousand users in our environment. Our setup spans multiple locations, mainly in Portugal, and we operate on various operating systems, including Mac, Linux, and Windows.
Falcon, being a SaaS product, doesn't require maintenance on our end. Updates are needed for servers, but they can be easily managed through the web interface without causing any inconvenience for us.
I would recommend conducting a proof of concept with CrowdStrike Falcon before making a decision. While the product has strengths, I would advise new users to address questions and doubts directly with the product team, especially when seeking new features or improvements. Ensure there is a clear communication channel for feedback and inquiries. Overall, I would rate CrowdStrike Falcon as a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
CrowdStrike Falcon
June 2025

Learn what your peers think about CrowdStrike Falcon. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
855,156 professionals have used our research since 2012.
Security Analyst at a insurance company with 1,001-5,000 employees
Used few system resources, can easily isolate infected machines, and add modules
Pros and Cons
- "I like the feature called RTC, the remote time connector."
- "I have worked with their technical support on several problems that were never fully resolved."
What is our primary use case?
We use CrowdStrike Falcon for endpoint security and response, and Horizon to manage and protect our data.
Following a 2021 security incident, the general response team recommended implementing CrowdStrike. We adopted their suggestion and found its network threat detection and prevention capabilities invaluable.
What is most valuable?
I like the feature called RTC, the remote time connector. It allows us to connect to a computer via the command line and execute commands for various functions and investigations. This eliminates the need for any additional programs. We can launch the connection and its subcommands from a single console.
The containment feature is another valuable tool. It allows us to isolate any machine exhibiting suspicious behavior or facing a detected threat. Once activated, containment immediately severs the machine's network connection and blocks user access.
What needs improvement?
Despite implementing tuning rules specifically designed to address them, we are still encountering a significant number of false positives. This issue persists even after collaborating with their support team to find a solution.
I have worked with their technical support on several problems that were never fully resolved.
For how long have I used the solution?
I have been using CrowdStrike Falcon for three years.
What do I think about the stability of the solution?
While we encountered some bugs with on-demand scanning, the overall performance and stability of the system are positive. CrowdStrike Falcon is less resource-intensive than our old McAfee solution, which often led to performance complaints due to its high memory consumption.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable. Adding new features or licenses to CrowdStrike Falcon is seamless, with no disruption to our system's performance. Installing new modules is easy because it uses the same sensor.
How are customer service and support?
While I've found screen sharing helpful with other support teams, CrowdStrike's technical support has never proactively suggested it. Instead, they've always initiated contact by calling me back after I submitted a ticket. We recently offered to screen share, but it seems it's not their preferred method. The support is good but it is not the best I have used.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we utilized Carbon Black for our endpoint security needs. However, we transitioned to CrowdStrike for several compelling reasons. As a prominent market competitor with widespread adoption among organizations, CrowdStrike offered a robust platform capable of meeting our evolving security requirements.
The 2021 incident further underscored the importance of robust security tools. CrowdStrike's capabilities proved invaluable in navigating the aftermath and instilled confidence in its continued effectiveness for future challenges.
Beyond its proven track record, CrowdStrike seamlessly integrates with our existing security ecosystem. The platform's comprehensive feature set simplifies endpoint management from a centralized console. Additionally, its granular telemetry across various modules provides invaluable insights during incident detection, enabling us to gather holistic information from each affected machine.
Furthermore, CrowdStrike consolidates our security stack by encompassing next-generation firewalls, endpoint detection and response, and real-time endpoint scanning, eliminating the need for separate solutions like McAfee. This streamlined approach enhances operational efficiency and simplifies security management.
How was the initial setup?
The initial deployment presented some challenges due to the need to install the solution on all machines. This phase, requiring careful coordination among ten people over several weeks, involved connecting all the computers to the network. However, once this foundation was laid, the subsequent rollout proceeded smoothly.
What about the implementation team?
The implementation was completed in-house by our people.
What was our ROI?
The return on investment is evident in the enhanced security posture achieved through continuous monitoring and immediate isolation of compromised machines. This proactive approach not only mitigates risk but also provides significant peace of mind for our team, alleviating concerns and optimizing their performance.
What's my experience with pricing, setup cost, and licensing?
While CrowdStrike Falcon offers significant security benefits, its high price point might make it prohibitively expensive for many small and medium-sized businesses, including companies like ours.
What other advice do I have?
I would rate CrowdStrike Falcon a nine out of ten.
CrowdStrike Falcon is a great tool. Investing in proper training on the CrowdStrike Falcon platform is highly recommended for any organization seeking to maximize its potential and avoid navigation struggles within the console. However, it's important to note that effective utilization of Falcon without CrowdStrike's managed services necessitates the formation of a dedicated team responsible for managing the solution.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Cyber Security Manager at a healthcare company with 10,001+ employees
Provides great protection and can crosscheck environments. Helpful in investigating any alerts
Pros and Cons
- "It provides very good protection and the ability to crosscheck environments."
- "Falcon could include more integrative features."
What is our primary use case?
We use the EDR feature.
What is most valuable?
This is unlike any other EDR solution that I am familiar with. It provides very good protection and the ability to crosscheck environments. It's really helpful in investigating any alerts and is easy to use. You can use some of the Splunk language to search.
What needs improvement?
We've tried some integrations with solutions, closing off false positives and things like that. Falcon could include more features in that area. In addition, some features are modularized and we're unable to buy them as we're in the healthcare field and limited in the amount we can invest.
For how long have I used the solution?
I've been using this product for close to 18 months.
What do I think about the stability of the solution?
We haven't had any stability issues.
What do I think about the scalability of the solution?
The solution is very scalable but we had issues with some groups, that manage their own devices and wanted to have access to self-manage them. We weren't able to do that, unfortunately.
How are customer service and support?
My team has interacted with tech support and I believe the issues were resolved in a timely manner.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used other solutions such as Setinel One.
How was the initial setup?
The initial setup was very straightforward and smooth.
What's my experience with pricing, setup cost, and licensing?
Falcon is more expensive than every other solution on the market. That said, they do have a better product than anyone else.
What other advice do I have?
Some of the default settings are set to 'easy' which isn't sufficient. We had some conversations around this and the recommendation was to change some of these settings to more aggressive ones on the policy side. I know some organizations have had issues automatically updating CrowdStrike to the latest version. I recommend going through the change process but saving it at minus one for a while to avoid all the negative downtimes where you might need to roll back to the previous update.
When we switched to CrowdStrike, we didn't expect it to find anything that was already on the computer because the primary reason we swapped was because of EDR. But it did find things that were dormant as well as other things.
I rate this solution nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director Of Information Technology at TollPlus LLC.
An AI-driven solution that self-activates to find issues and provide alerts
Pros and Cons
- "The solution is silent and sits on your system as one single agent."
- "Technical support could be better than what is currently offered."
What is our primary use case?
Our company's line of business includes financial transactions with an insurance policy that requires EDR protection. Compliance is part of our policy and agreement with customers.
We currently have 1,100 users of the solution.
What is most valuable?
The solution is silent and sits on your system as one single agent.
Only one or two MB of memory are consumed which is much less than other products.
The solution is AI-driven so it self-activates to find issues and provide alerts or notifications rather than running all the time.
The portal is very user-friendly so it is not difficult to manage.
The solution doesn't require system restarts. That is one disadvantage of Symantec or Kaspersky because they require restarts when you uninstall or reinstall.
What needs improvement?
Technical support could be better than what is currently offered.
For how long have I used the solution?
I have been using the solution for three months.
What do I think about the stability of the solution?
The solution is stable with no issues.
We have only used the solution for three months so will continue to monitor stability for the next several months.
I rate stability an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. We do not yet have the requirement to take an in-depth look at scalability.
I rate scalability an eight out of ten.
How are customer service and support?
Technical support could be better because there are ownership issues.
For example, when you raise a support case there is not much communication between the account manager and support. The account manager is supposed to own the case but instead is disconnected from it.
I rate support a six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used Symantec and Kaspersky.
How was the initial setup?
The setup is pretty easy to walk through without much trouble.
I rate setup an eight out of ten.
What about the implementation team?
We utilized a third-party for implementation. They helped us with the admin console, training, and the pilot setup that we eventually took over. Our internal team included two security staff and four support staff.
We were moving from Symantec and Kaspersky. We targeted our servers first because Symantec is difficult to uninstall and there is an interim process for removal. Once completed, we installed the solution.
It took about two months to complete implementation across all systems.
What was our ROI?
We did our homework in advance for cost or other things to calculate ROI. The solution met our expectations so ROI is rated a seven out of ten.
What's my experience with pricing, setup cost, and licensing?
The pricing is competitive and includes all features and support.
I rate pricing an eight out of ten.
Which other solutions did I evaluate?
We evaluated Microsoft Defender, Sophos, Symantec, and Trend Micro before choosing CrowdStrike Falcon.
What other advice do I have?
I recommend using the solution and rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Analyst at a tech services company with 501-1,000 employees
Offers robust protection and excellent visibility in a highly scalable solution with great technical support
Pros and Cons
- "The feature I like the most is the solution's detection."
- "The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool."
What is our primary use case?
We use CrowdStrike Falcon to detect and alert us to any malware in our system. In our organization, we integrated CrowdStrike with a SIEM tool, which does the alerting. If the solution detects malware and issues an EDR alert, it notifies us and begins gathering data about the detection, including the hostname, user name, the hash value of the downloaded file, and the file's reputation. Then, we can ask the user the delete the file from the PC and drives, such as USB drives, if necessary. Following removing any malicious files, we can use CrowdStrike to run an AV scan on the affected device or devices.
How has it helped my organization?
We use the solution's Horizon module to protect multi-cloud work environments and integrate with SIEM tools. Detections in CrowdStrike trigger a response from the SIEM tool, allowing us to face threats via a coordinated approach.
Horizon simplifies security management of multi-cloud environments, and the improvement has been significant. Integration with a SIEM tool makes alerting and detection very rapid, which significantly helped.
To give an example, one of our employees mistakenly downloaded a malicious phishing video. The solution quarantined the file, protecting our organization from attack.
What is most valuable?
The feature I like the most is the solution's detection.
The fact that CrowdStrike Falcon is a cloud-native solution provides us with a lot of flexibility and always-on protection. This is very important to us because it enables automatic detection and quarantining of malicious files, and that's one of the features we like most about working with the tool.
The visibility provided by the solution in multi-cloud environments is excellent; it's one of the best features.
What needs improvement?
The malware analysis could be improved, as that's what we use the solution for the most and that change would make it a better EDR tool.
For how long have I used the solution?
I've been using the solution for about three years.
What do I think about the stability of the solution?
The product's stability is good.
What do I think about the scalability of the solution?
The scalability is excellent; top tier. There are about 15 end users in our company, and they are members of the security team. We plan to increase our usage of the solution.
How was the initial setup?
It isn't challenging to deploy the solution's sensor to endpoints, and it becomes even more straightforward with some experience and understanding of the tool.
The deployment is relatively quick, though it takes a little longer than other products.
What about the implementation team?
We implemented via an in-house team as we had a lot of experience with the solution.
What's my experience with pricing, setup cost, and licensing?
The solution isn't very costly; it's affordable.
Which other solutions did I evaluate?
We evaluated a McAfee solution, and CrowdStrike has a lot more automation.
What other advice do I have?
I rate the product nine out of ten.
CrowdStrike is excellent at preventing breaches, and our security operations are more robust as a result. The automatic quarantining of malicious downloads keeps our system safe and our information out of the hands of attackers.
The solution reduces our security risk significantly; it's an advanced tool.
We learned about the solution when some of our employees saw a promotion campaign.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Cyber Security Consultant - Defensive Security at DeltaSpike Pvt Ltd
Useful AI detection, good support, and reliable
Pros and Cons
- "The most valuable features of CrowdStrike Falcon are the AI in detecting and real-time detections."
- "CrowdStrike Falcon could improve the EDR functionality. Once the functionality of the solution improves, it will be even better in the market and able to compete with Carbon Black."
What is our primary use case?
We are using CrowdStrike Falcon for the EDR mainly.
What is most valuable?
The most valuable features of CrowdStrike Falcon are the AI in detecting and real-time detections.
What needs improvement?
CrowdStrike Falcon could improve the EDR functionality. Once the functionality of the solution improves, it will be even better in the market and able to compete with Carbon Black.
In a future release, if there were XDR features it would be beneficial.
For how long have I used the solution?
I have been using CrowdStrike Falcon for approximately two years.
What do I think about the stability of the solution?
CrowdStrike Falcon is a stable solution. However, you need to good internet connection for functionality.
What do I think about the scalability of the solution?
CrowdStrike Falcon is scalable. We have below 1,000 endpoints and it scales well.
We have approximately 700 to 800 people using the solution. Additionally, we have approximately 150 servers running with 815 clients.
How are customer service and support?
We used the support at the initial stages of deployment and the support was good. I became familiar with the tool quickly and did not need their support anymore.
How was the initial setup?
The initial setup of CrowdStrike Falcon is straightforward. Our deployment was done in a phased approach, we did it first with 200 servers, then 100 at a time after. We did not roll out the solution all at once throughout the company.
What about the implementation team?
We did the deployment of CrowdStrike Falcon in-house. The amount of people needed for the deployment and maintenance of the solution depends on the tools used. We automate the deployment process.
What was our ROI?
The return on investment for CrowdStrike Falcon is good.
What's my experience with pricing, setup cost, and licensing?
There are three to four licensing models available to choose from for CrowdStrike Falcon. The price of CrowdStrike Falcon depends on the distributor and the reseller partner. The price we received was good.
What other advice do I have?
CrowdStrike Falcon is one of the leading solutions in the market. I would recommend this solution to others.
I rate CrowdStrike Falcon an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner and customer
Security Officer
The best endpoint protection solution
Pros and Cons
- "Since we deployed CrowdStrike, the network has become much calmer, and we now understand the sources of infections, which helps us prevent them from spreading."
- "An improvement would be to extend support to legacy and unsupported servers."
What is our primary use case?
I mainly use CrowdStrike Falcon to prevent threats and detect indicators of attacks or compromises in the network.
How has it helped my organization?
In the past, we regularly got alerts about suspicious activities in the network but couldn't understand where they were coming from. Since we deployed CrowdStrike, the network has become much calmer, and we now understand the sources of infections, which helps us prevent them from spreading. We now get immediate information about infections and can react much faster.
What needs improvement?
An improvement would be to extend support to legacy and unsupported servers. In the next release, CrowdStrike should include patch and vulnerability management, which would allow us to rely on just one solution.
For how long have I used the solution?
I've been using CrowdStrike Falcon for over a year.
What do I think about the stability of the solution?
Falcon is pretty stable - we haven't seen any kinds of performance issues like lagging, which we did experience with other endpoint protection solutions.
How are customer service and support?
CrowdStrike's technical support is very fast and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, I used Microsoft Bitdefender, but CrowdStrike was faster and better protection-wise.
How was the initial setup?
The initial setup was straightforward - it was very quick (about two and a half hours) without any downtime or issues. We also extended the installation to the remote side, which took another hour. I would rate the setup process four out of five.
What about the implementation team?
We used an in-house team.
What was our ROI?
In the past, we have around four to five engineers managing our endpoint - we have now reduced this to two engineers, which has cut costs. We've also been able to cut the time needed to find the threats and their root causes from up to six hours a day to just half an hour. I would rate our ROI as five out of five.
What's my experience with pricing, setup cost, and licensing?
We pay between $30-50 per user for a yearly license, which is more expensive than SentinelOne or Bitdefender. However, CrowdStrike gives better value for money, so I would rate their pricing four out of five. If you want to add modules or features, these are an additional cost per user.
Which other solutions did I evaluate?
We evaluated SentinelOne, but it was too heavy on the machine and slowed it down. We also did a threat simulation analysis with both SentinelOne and CrowdStrike, and SentinelOne wasn't able to detect or block the threats.
What other advice do I have?
CrowdStrike Falcon is the best endpoint protection solution I've used so far. I would advise anybody thinking of implementing it to go for it, as CrowdStrike will provide more visibility, depth, and context to threats and allow you to understand what's going on. I would give Falcon a rating of ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Extended Detection and Response (XDR) Security Information and Event Management (SIEM) Endpoint Protection Platform (EPP) Threat Intelligence Platforms Endpoint Detection and Response (EDR) Attack Surface Management (ASM) Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
Microsoft Defender for Endpoint
Fortinet FortiEDR
Microsoft Sentinel
Splunk Enterprise Security
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Fortinet FortiClient
Elastic Security
HP Wolf Security
Symantec Endpoint Security
Buyer's Guide
Download our free CrowdStrike Falcon Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- What is the biggest difference between CrowdStrike and Cylance?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- Is Crowdstrike Falcon better than Trend Micro Deep Security?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- How does Crowdstrike Falcon compare with FireEye Endpoint Security?