What is our primary use case?
The solution is moving in that direction. One of the things I appreciate about this is that it is not a closed environment. When you look at organizations like Secureworks and Rapid7, they are trying to lock things down. The versatility and agility of Falcon solution provides a better angle in terms of endpoint detection response and endpoint security.
Improving user behavior analytics is what I am focusing on. That is core. Understanding what users are doing, how they are doing it, what is anticipated, being very reactive and zeroing in on zero days, and being able to knock it down quickly is where I am looking for them to focus.
What is most valuable?
CrowdStrike, Inc. [Private Offer Only] is the core of the EDR endpoint detection response in the market right now and it still is. The combination of AI Defense moving in that direction and them incorporating artificial intelligence is significant. Overall, when I speak to customers, CrowdStrike, Inc. [Private Offer Only] is my core versus others. Although they have some issues with too much built-in functionality, they are going to have to streamline because of artificial intelligence, but I think they are going to refine that in their next deployment.
Beyond just the threat intelligence, the Falcon app was upgraded to Falcon because of the SOC in that ES solution. The biggest aspect for Falcon from an e-discovery perspective is retention issues for that in terms of investigation and bringing Falcon in for a breach. The upgrade was at the MBTA for a breach issue with Keolis, which was my last experience of using Falcon for that purpose.
What needs improvement?
They should listen more to their community. They need to do a lot more bundling of things as part of it instead of treating everything as an upgrade or an enhancement. The problem that is hurting them is that there is a cost all the time for upgrading.
They are late in the game. When you look at Exabeam, they have always been focused on behavior analytics. This new journey into that era has enhanced it because it provides detection and baselining of behavior when someone is using that endpoint. It is an added feature that has benefited the enterprise in terms of defensive depth. It is definitely a good feature.
For how long have I used the solution?
I have been using CrowdStrike, Inc. [Private Offer Only] for a long time. Before CrowdStrike, Inc. [Private Offer Only] came to market, that company was bought by BlackBerry, and I deployed that solution. This has been since approximately 2017, 18, or 19.
How are customer service and support?
I give customer service a rating of 10. I do recommend it to my clients. I have found it to be very good, though I am just concerned about price.
What other advice do I have?
I have not used every feature myself. My team has used it in part to augment other tools. There are other tools that have come out on the market that do a better job than what CrowdStrike, Inc. [Private Offer Only] can do in certain areas, but the Falcon ecosystem itself, both from a reactive and proactive perspective, has benefited the company. However, you cannot be a master of everything and a master of none, so you have to be careful. That is what I worry about them.
I am an end user and have been an end user for a long time. I have attended their conference a long time ago. Watching them, I believe that before everybody wants to get into the market with the opportunity of being better, I am looking for consistency. I tell people to look for someone who has good technical support and good response in terms of incident response when you do have an incident. That is where Falcon comes in. They have certainly served us well in the past and in a couple of incidents that I have been involved in with Falcon. I think that it is a great product as far as EDR goes, and I think it is going to many places. My overall review rating for this solution is 9.5 out of 10.