What is our primary use case?
The major use case for CrowdStrike Falcon Sandbox is that we are using it with customers who need to check and validate the data the users are uploading to them, to check all the files and all the data received, to make sure that there is no suspicious data, no threat, and so on.
How has it helped my organization?
Since I'm working with CrowdStrike Falcon Sandbox, I would say that the solution enhances a company's threat intelligence, as it's a very powerful solution. Through multiple experiences, it proves it protects the customers from multiple threats, either as an internal threat or from an external threat. It's very updated and very quick to detect. The mean time to detect is really fast, so it's a powerful solution.
What is most valuable?
The multi-platform analysis in the product is very effective, as it helps to identify threats through powerful scanning and detection, and in response as well.
Comparing to other products, this product performs very well in terms of stability and detection, which is important because other products may encounter problems in operations. This product is powerful in detection, which is the most important part because any customer wants a solution that detects what's happening. This is the real strength of CrowdStrike Falcon Sandbox. It's really powerful in detection; it detects any minor change, any minor injection in the data or whatsoever. The visibility is really good. CrowdStrike Falcon Sandbox has one unified platform to manage everything, which is really nice. It has one agent and one console. One agent to install in the machine, and this one agent will give capabilities. I can have visibility into one console, and through this one console, I can do multiple things and manage multiple solutions within CrowdStrike Falcon Sandbox.
I know that the memory forensic feature in CrowdStrike Falcon Sandbox is well-regarded, as CrowdStrike Falcon Sandbox is really famous for this. It's one of the most well-known companies in forensics, and many customers are getting CrowdStrike Falcon Sandbox involved when they are in threat or when they face a threat. They do their forensics in a really good way, and they are reaching a very powerful result. I have experienced this with multiple customers who asked CrowdStrike Falcon Sandbox to interfere and do the forensics, knowing exactly what amount of harm or what amount of breach has been done into their network. CrowdStrike Falcon Sandbox can manage this and give them full visibility about what has been done, what has been remediated, and what has been lost.
The API integrations they offer are extensive and improve threat analysis and collaboration in general, as they have a wide range of integrations with multiple products and multiple vendors, multiple solutions. Throughout the one year and a half, I didn't face any scenario with integrations except for the file monitoring for the AIX. This is the only case I have faced with them, as they don't support IBM AIX file monitoring. But aside from this, their integration spectrum is really wide, really big, and strong, allowing them to integrate with multiple products.
What needs improvement?
As for room for improvement, we can mention that maybe some additional integrations will be beneficial to cover the whole use cases.
For how long have I used the solution?
I have been dealing with CrowdStrike Falcon Sandbox for a year and a half.
What do I think about the scalability of the solution?
I would rate the scalability of the solution as very scalable, as it can support medium businesses, small businesses, and large enterprise businesses as well.
How are customer service and support?
I would rate the technical support from CrowdStrike Falcon Sandbox as very good.
If I would rate support on a scale of 0 to 10, with 10 being the best, I would give them nine points.
How would you rate customer service and support?
How was the initial setup?
The product is very easy to install, as implementing CrowdStrike Falcon Sandbox is not complicated at all.
Which other solutions did I evaluate?
When comparing CrowdStrike Falcon Sandbox with other competitors like SolarWinds or Netwrix, I would definitely advise CrowdStrike Falcon Sandbox, as it is very powerful, very well-known, and very recommended for our customers. Whenever I see a use case that matches CrowdStrike Falcon Sandbox, I instantly recommend it.
What other advice do I have?
Regarding the price, if I am purchasing a single module from CrowdStrike Falcon Sandbox, maybe it's not the best option pricewise. However, if I am acquiring multiple solutions or multiple modules from CrowdStrike Falcon Sandbox, for sure CrowdStrike Falcon Sandbox will provide the best option, the best price.
My clients usually have the solution on cloud. They utilize both private and public cloud. The cloud services are natively CrowdStrike Falcon Sandbox cloud, as they use AWS. Purchasing the product from AWS Marketplace can be done. However, for CrowdStrike Falcon Sandbox specifically, I purchase this product directly from the vendor, not through AWS.
I would give this product an overall rating of 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)