Security Engineer at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 2, 2026
My main use case for CrowdStrike Falcon is mostly endpoint detection, scanning the endpoints to protect our endpoints in our hospital environment against any malicious files, downloads, and executions. A specific example of how I have used CrowdStrike Falcon for endpoint detection is when it catches a suspicious PowerShell execution from a suspicious file and a suspicious exe exemption. I investigate those events accordingly. CrowdStrike usually stops that execution, but there is some possibility that it may not block those executions. I investigate those incidents using CrowdStrike along with other tools, not only CrowdStrike.
For my main use cases with CrowdStrike Falcon, we tested vulnerability assessment and we also tested threats, AI intrusion threats, and vulnerability detection.
My main use cases for CrowdStrike Falcon mostly center around their Falcon EDR offering and the suite around it, such as what used to be called Spotlight and Complete, OverWatch, and all those capabilities.
IT Support Engineer at a media company with 51-200 employees
Real User
Top 10
Sep 1, 2026
My main use case for CrowdStrike Falcon is to deploy it to our endpoints, set update policies, and sometimes use the advanced search to search up specific events. I also used it in the past to query app usage, and the sensor collects DNS request logs that I use to determine whether or not people are actively using the licenses that we give them, such as Cloud licensing, ChatGPT, Figma, and others. My usage of CrowdStrike Falcon is limited to the advanced search feature. I am not a security engineer, and I use it to help fill in the gaps for my job function. Since we don't have much of a security team, we let CrowdStrike Falcon operate independently. My use of CrowdStrike Falcon has not expanded since my initial deployment. I use my limited time to look at things when necessary, and my usage has been limited to what I have already described.
Co-Owner at a manufacturing company with 1,001-5,000 employees
Real User
Top 5
Sep 1, 2026
My main use case for CrowdStrike Falcon is endpoint protection. I use CrowdStrike Falcon for general endpoint remediation if users happen to click on malicious content.
Security Analyst at a manufacturing company with 501-1,000 employees
Real User
Top 20
Sep 1, 2026
My main use case for CrowdStrike Falcon is to remediate any time someone downloads something malicious. I tend to remediate it and check in on the users to make sure there are no false positives. If it is something malicious, then I have to triage it. A specific example of when I used CrowdStrike Falcon was when someone had downloaded something that they were not supposed to download. I looked at the hash value, saw that it was malicious, reached out to the user, warned them to exercise caution, and from there, they removed it and our IT team scanned their device.
Information Security Manager Iam at ExactCare Pharmacy
Real User
Top 10
Sep 1, 2026
Our main use cases for CrowdStrike Falcon are that we are a Falcon Complete customer and we are likely expanding in the next year. We are going to go with Next Gen SIM. I am here because I already took my class. We are going to integrate Identity, and we might be doing AIDR as well.
data and cyber security manager at a construction company with 11-50 employees
Real User
Top 20
Sep 1, 2026
CrowdStrike Falcon serves as our main endpoint protection and vulnerability management solution, particularly for scanning. We deploy it across our environment using the MDR, endpoint protection, and SIM solution. Due to our organization being very merger and acquisition heavy, one of our primary use cases is rapidly deploying CrowdStrike Falcon to all endpoints when we bring on a new organization.
Senior Secops Engineer at a program development consultancy with 1,001-5,000 employees
Real User
Top 10
Sep 1, 2026
My main use case for CrowdStrike Falcon is endpoint detection for the most part. The other part would be all the other capabilities that we use it for, such as identity, detection, policies, response, RTR, and forensics.
My main use case for CrowdStrike Falcon is endpoint detection. We look at the telemetry data from endpoint protection and determine policy violation, abnormal activities, and usage details for endpoint detection.
Our main use cases for CrowdStrike Falcon are endpoint security and USB access, with endpoint security being our primary focus. I can describe a security incident where CrowdStrike Falcon helped my team detect and stop a threat. One of our IT help desk analysts downloaded a BIOS update from Dell without realizing it contained a critical vulnerability. CrowdStrike Falcon helped us block that download and alerted us to investigate it. We were able to follow up, see what process was running, and determine that our analyst needed to double-check that we were downloading and uploading up-to-date BIOS updates. My use of CrowdStrike Falcon has expanded since my initial deployment from endpoint security to USB access. We were initially managing USB access through GPO, but we decided to transition to CrowdStrike Falcon because it provided us with greater visibility.
Director, Information Security Services at a university with 10,001+ employees
Real User
Top 10
Sep 1, 2026
My main use case for CrowdStrike Falcon is protecting high value assets and servers. For example, we typically have a lot of people doing click-through for downloads of remote management and ScreenConnect type software, so CrowdStrike Falcon is really good at identifying those user interactions, the clicks, and the hacker trying to come in and log in using that ScreenConnect software; we do see that a lot.
CISO at a financial services firm with 1,001-5,000 employees
Real User
Top 10
Sep 1, 2026
My main use case for CrowdStrike Falcon is protecting endpoints and cloud security. For endpoint or cloud security, I do a lot of threat hunting inside my environment using all the telemetry that CrowdStrike Falcon provides, and I tackle incidents by quarantining, deleting, and investigating remotely, among other actions. I have a lot of old software and operating systems, and CrowdStrike Falcon helps me protect all the boundaries of those systems.
Senior IT Engineer at a healthcare company with 201-500 employees
Real User
Top 20
Sep 1, 2026
My main use case for CrowdStrike Falcon is for endpoint detection. CrowdStrike Falcon endpoint is installed on all workstations, and I use it to detect threats and to assist with vulnerability remediation in my day-to-day work.
Lead Endpoint Security Engineer at Depository Trust & Clearing Corporation
Real User
Top 10
Sep 1, 2026
My main use cases for CrowdStrike Falcon are endpoint security, using one sensor to deploy various different types of tools. The end goal is less agent on an endpoint where I could accomplish so much with just one sensor installed, and that truly impresses me.
My main use case for CrowdStrike Falcon is protection for containers and protection for the cloud in general. I protect my entire modern AWS environment with CrowdStrike Falcon for containers, and for the cloud part, I use CrowdStrike's CSPM visibility, the CNAPP, and also the identity component. Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by changing the response time and reducing the number of employees needed for monitoring. The benefits of having multiple security capabilities integrated into a single platform include using just one agent, which makes our lives much easier, and having a single administration interface that correlates logs. I replaced traditional CSPMs with CrowdStrike Falcon, and that was the main advantage: providing real-time protection. A security incident where CrowdStrike Falcon helped my team detect or prevent a threat involved a case with a secretary where someone tried social engineering to install an Ndesk, and we saw it—OverWatch intervened.
My main use cases for CrowdStrike Falcon involve everything security. In more detail, we use Falcon Complete to ensure our users are completely covered.
We use AWS to manage CrowdStrike Falcon. CrowdStrike Falcon is a cloud-native solution, and from the user side, we do not directly manage or choose the cloud provider. CrowdStrike handles the back-end infrastructure. As per my understanding, we simply access the CrowdStrike Falcon console in our cloud and deploy the endpoint agent. So from our perspective, we use it as a cloud-based service without directly interacting with the underlying cloud provider.
CrowdStrike Falcon's main use case is endpoint security and threat detection, which are the primary purposes for which we are using it. A day-to-day example of using CrowdStrike Falcon for endpoint security detection occurs when a user downloads suspicious files. The system detects this activity and triggers an alert to the administrator. CrowdStrike Falcon detects abnormal behavior of the system, and an alert is generated in a console. When I log into the console, I can see that some users are trying to access malicious files which are harmful for the organization. The security team isolates the endpoint based on this judgment. We can investigate using process trees and logs in CrowdStrike Falcon. Additionally, USB device control helps sometimes with USB blocking and data access via external storage.
Presales Manager at a tech vendor with 5,001-10,000 employees
Reseller
Top 20
Dec 15, 2025
I deal with endpoint security, firewall, and XDR solutions. I use Sangfor and work with Trend Micro and CrowdStrike. I use CrowdStrike Falcon for enterprise companies, which is what I typically recommend.
We are using CrowdStrike Falcon because it has very low surface impact and minimal consumption of our resources, and we mainly use it for our endpoint protection. CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions. We find it very unique that CrowdStrike Falcon, which we deployed in many countries wherever our offices are, can be installed very quickly, maintained on a single console, single panel of console, and it's really easy to use and deploy. We primarily use it for endpoint protection.
I am a customer of CrowdStrike Falcon through a consultant, and our company is headquartered in India, while our consultant is a sister company also located in India. We use CrowdStrike Falcon internally in our company. I am using CrowdStrike Falcon for its purpose, which is to save the company from any attacks, viruses, or whatever threats are available.
The main use cases for CrowdStrike Falcon from my customers are the lightweight agent, which is very easy to use, and it will protect the complete environment in a single dashboard. A specific use case from my customers for CrowdStrike Falcon is that the SaaS-based single agent can protect all the platforms.
In my cybersecurity strategy, I use CrowdStrike Falcon mainly as an EDR solution for us. Currently, we are using it as an EDR. We are also in discussion along with the CrowdStrike team where we can have a managed SOC integrated. In the online industry, we are using CrowdStrike Falcon, specifically in online classified, which you could call e-commerce.
We are protecting our endpoints, workstations, servers, and cloud workloads. This includes effective use of antivirus and detection and response capabilities. I am working at Arab Open University, and we are using CrowdStrike Falcon as our security product.
For our use cases, we are using it to collect IOCs, and we also are using EDR, with injection integrated with our SIM solution to create some use cases. What I find beneficial about CrowdStrike Falcon is that it performs effectively. We are focusing only on EDR and creating use cases regarding user processes or endpoints, particularly user behavior analytics.
Security Engineer at a tech services company with 201-500 employees
Real User
Top 5
Feb 12, 2025
As a security analyst, I primarily focus on creating rules, conducting investigations, and integrating new devices with our CrowdStrike system. After these integrations, I also check the status to ensure everything is functioning properly.
Our organization still uses Infoblox, and my role is a little bit different now. I am conducting the POC of new solutions, which we have to deploy in our infrastructure. I evaluate the new products, and then if we purchase them, we deploy them.
I am currently using CrowdStrike Falcon as an EDR, which is integrated with SIEM. We also work in a real-time environment with the product. As a Falconist, I perform investigation actions on it. There are three different kinds of alerts I deal with: one based purely on IOCs, another process-oriented IOA, and those based on machine learning alerts. This is what I work on, and it is actually a good tool. It has multiple features, including real-time connection to the RTR environment, allowing direct remote host connection through CrowdStrike. I have multiple options like host search and event search, enabling me to do everything I need. It's a comprehensive package. It's a challenging tool to explore, but once accustomed to it, it is quite excellent.
Trainee Engineer at COMPASS IT Solutions & Services Pvt.Ltd.
Real User
Aug 9, 2024
It gives an overview and insights into my AD accounts. It shows if any identity, like an AD user, is compromised, has a weak password, or is logging in from an unusual system. Any anomalies.
Manager, Security Operations Centre at Phillips Consulting Limited
Real User
Jul 26, 2024
We use the solution for endpoint security. We use the tool to ensure the endpoints are protected from abnormal activities, people don't run different scripts, and people don't compromise endpoints and use them to get into the network.
It also helps you with access, like we have dark web monitoring and admin protection management. So, the use cases can vary from organization to organization, but every organization has different value in it.
The tool helps to increase security because the threats we face keep changing, so we need better protection. In the past, we've faced some attacks on our network, and while we managed to deal with them, we realized we needed even stronger protection. That's why we decided to implement CrowdStrike Identity Protection.
CrowdStrike Falcon delivers AI-powered endpoint protection, detection, and response to help organizations stop malware, ransomware, fileless attacks, and sophisticated adversaries. Built on the cloud-native Falcon platform and a single lightweight sensor, it combines prevention, EDR, threat intelligence, and automated response to protect endpoints while simplifying security operations.
What features make CrowdStrike Falcon stand out?
AI-Powered Prevention: Uses next-generation antivirus,...
My main use case for CrowdStrike Falcon is endpoint detection and response.
My main use case for CrowdStrike Falcon is mostly endpoint detection, scanning the endpoints to protect our endpoints in our hospital environment against any malicious files, downloads, and executions. A specific example of how I have used CrowdStrike Falcon for endpoint detection is when it catches a suspicious PowerShell execution from a suspicious file and a suspicious exe exemption. I investigate those events accordingly. CrowdStrike usually stops that execution, but there is some possibility that it may not block those executions. I investigate those incidents using CrowdStrike along with other tools, not only CrowdStrike.
My main use cases for CrowdStrike Falcon are incident response to attacks, alerting, and threat intelligence.
For my main use cases with CrowdStrike Falcon, we tested vulnerability assessment and we also tested threats, AI intrusion threats, and vulnerability detection.
My main use cases for CrowdStrike Falcon are endpoint security, intrusion detection and response, and a SIM tool.
My main use cases for CrowdStrike Falcon mostly center around their Falcon EDR offering and the suite around it, such as what used to be called Spotlight and Complete, OverWatch, and all those capabilities.
My main use case for CrowdStrike Falcon is to deploy it to our endpoints, set update policies, and sometimes use the advanced search to search up specific events. I also used it in the past to query app usage, and the sensor collects DNS request logs that I use to determine whether or not people are actively using the licenses that we give them, such as Cloud licensing, ChatGPT, Figma, and others. My usage of CrowdStrike Falcon is limited to the advanced search feature. I am not a security engineer, and I use it to help fill in the gaps for my job function. Since we don't have much of a security team, we let CrowdStrike Falcon operate independently. My use of CrowdStrike Falcon has not expanded since my initial deployment. I use my limited time to look at things when necessary, and my usage has been limited to what I have already described.
My main use case for CrowdStrike Falcon is endpoint protection. I use CrowdStrike Falcon for general endpoint remediation if users happen to click on malicious content.
My main use case for CrowdStrike Falcon is to remediate any time someone downloads something malicious. I tend to remediate it and check in on the users to make sure there are no false positives. If it is something malicious, then I have to triage it. A specific example of when I used CrowdStrike Falcon was when someone had downloaded something that they were not supposed to download. I looked at the hash value, saw that it was malicious, reached out to the user, warned them to exercise caution, and from there, they removed it and our IT team scanned their device.
Our main use cases for CrowdStrike Falcon are that we are a Falcon Complete customer and we are likely expanding in the next year. We are going to go with Next Gen SIM. I am here because I already took my class. We are going to integrate Identity, and we might be doing AIDR as well.
CrowdStrike Falcon serves as our main endpoint protection and vulnerability management solution, particularly for scanning. We deploy it across our environment using the MDR, endpoint protection, and SIM solution. Due to our organization being very merger and acquisition heavy, one of our primary use cases is rapidly deploying CrowdStrike Falcon to all endpoints when we bring on a new organization.
My main use case for CrowdStrike Falcon is endpoint detection for the most part. The other part would be all the other capabilities that we use it for, such as identity, detection, policies, response, RTR, and forensics.
My main use case for CrowdStrike Falcon is EDR. For EDR, I use CrowdStrike Falcon for identity, endpoint management, and device control.
My main use case for CrowdStrike Falcon is endpoint detection. We look at the telemetry data from endpoint protection and determine policy violation, abnormal activities, and usage details for endpoint detection.
Our main use cases for CrowdStrike Falcon are endpoint security and USB access, with endpoint security being our primary focus. I can describe a security incident where CrowdStrike Falcon helped my team detect and stop a threat. One of our IT help desk analysts downloaded a BIOS update from Dell without realizing it contained a critical vulnerability. CrowdStrike Falcon helped us block that download and alerted us to investigate it. We were able to follow up, see what process was running, and determine that our analyst needed to double-check that we were downloading and uploading up-to-date BIOS updates. My use of CrowdStrike Falcon has expanded since my initial deployment from endpoint security to USB access. We were initially managing USB access through GPO, but we decided to transition to CrowdStrike Falcon because it provided us with greater visibility.
My main use case for CrowdStrike Falcon is protecting high value assets and servers. For example, we typically have a lot of people doing click-through for downloads of remote management and ScreenConnect type software, so CrowdStrike Falcon is really good at identifying those user interactions, the clicks, and the hacker trying to come in and log in using that ScreenConnect software; we do see that a lot.
My main use cases for CrowdStrike Falcon include endpoint defense, investigations, and triage.
My main use case for CrowdStrike Falcon is protecting endpoints and cloud security. For endpoint or cloud security, I do a lot of threat hunting inside my environment using all the telemetry that CrowdStrike Falcon provides, and I tackle incidents by quarantining, deleting, and investigating remotely, among other actions. I have a lot of old software and operating systems, and CrowdStrike Falcon helps me protect all the boundaries of those systems.
My main use case for CrowdStrike Falcon is for endpoint detection. CrowdStrike Falcon endpoint is installed on all workstations, and I use it to detect threats and to assist with vulnerability remediation in my day-to-day work.
My main use cases for CrowdStrike Falcon are endpoint security, using one sensor to deploy various different types of tools. The end goal is less agent on an endpoint where I could accomplish so much with just one sensor installed, and that truly impresses me.
My main use case for CrowdStrike Falcon is protection for containers and protection for the cloud in general. I protect my entire modern AWS environment with CrowdStrike Falcon for containers, and for the cloud part, I use CrowdStrike's CSPM visibility, the CNAPP, and also the identity component. Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by changing the response time and reducing the number of employees needed for monitoring. The benefits of having multiple security capabilities integrated into a single platform include using just one agent, which makes our lives much easier, and having a single administration interface that correlates logs. I replaced traditional CSPMs with CrowdStrike Falcon, and that was the main advantage: providing real-time protection. A security incident where CrowdStrike Falcon helped my team detect or prevent a threat involved a case with a secretary where someone tried social engineering to install an Ndesk, and we saw it—OverWatch intervened.
My main use case for CrowdStrike Falcon is vulnerability management.
My main use cases for CrowdStrike Falcon involve everything security. In more detail, we use Falcon Complete to ensure our users are completely covered.
We use AWS to manage CrowdStrike Falcon. CrowdStrike Falcon is a cloud-native solution, and from the user side, we do not directly manage or choose the cloud provider. CrowdStrike handles the back-end infrastructure. As per my understanding, we simply access the CrowdStrike Falcon console in our cloud and deploy the endpoint agent. So from our perspective, we use it as a cloud-based service without directly interacting with the underlying cloud provider.
CrowdStrike Falcon's main use case is endpoint security and threat detection, which are the primary purposes for which we are using it. A day-to-day example of using CrowdStrike Falcon for endpoint security detection occurs when a user downloads suspicious files. The system detects this activity and triggers an alert to the administrator. CrowdStrike Falcon detects abnormal behavior of the system, and an alert is generated in a console. When I log into the console, I can see that some users are trying to access malicious files which are harmful for the organization. The security team isolates the endpoint based on this judgment. We can investigate using process trees and logs in CrowdStrike Falcon. Additionally, USB device control helps sometimes with USB blocking and data access via external storage.
I am using CrowdStrike Falcon because I want to secure my end-user devices.
I use it for cloud workload protection and threat detection in AWS environments.
I deal with endpoint security, firewall, and XDR solutions. I use Sangfor and work with Trend Micro and CrowdStrike. I use CrowdStrike Falcon for enterprise companies, which is what I typically recommend.
We are using CrowdStrike Falcon because it has very low surface impact and minimal consumption of our resources, and we mainly use it for our endpoint protection. CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions. We find it very unique that CrowdStrike Falcon, which we deployed in many countries wherever our offices are, can be installed very quickly, maintained on a single console, single panel of console, and it's really easy to use and deploy. We primarily use it for endpoint protection.
I am a customer of CrowdStrike Falcon through a consultant, and our company is headquartered in India, while our consultant is a sister company also located in India. We use CrowdStrike Falcon internally in our company. I am using CrowdStrike Falcon for its purpose, which is to save the company from any attacks, viruses, or whatever threats are available.
The main use cases for CrowdStrike Falcon from my customers are the lightweight agent, which is very easy to use, and it will protect the complete environment in a single dashboard. A specific use case from my customers for CrowdStrike Falcon is that the SaaS-based single agent can protect all the platforms.
It help us relate an attack to an user. It also checks for misconfiguration on the active directory.
In my cybersecurity strategy, I use CrowdStrike Falcon mainly as an EDR solution for us. Currently, we are using it as an EDR. We are also in discussion along with the CrowdStrike team where we can have a managed SOC integrated. In the online industry, we are using CrowdStrike Falcon, specifically in online classified, which you could call e-commerce.
We are protecting our endpoints, workstations, servers, and cloud workloads. This includes effective use of antivirus and detection and response capabilities. I am working at Arab Open University, and we are using CrowdStrike Falcon as our security product.
I am using it for endpoint protection.
For our use cases, we are using it to collect IOCs, and we also are using EDR, with injection integrated with our SIM solution to create some use cases. What I find beneficial about CrowdStrike Falcon is that it performs effectively. We are focusing only on EDR and creating use cases regarding user processes or endpoints, particularly user behavior analytics.
As a security analyst, I primarily focus on creating rules, conducting investigations, and integrating new devices with our CrowdStrike system. After these integrations, I also check the status to ensure everything is functioning properly.
Our organization still uses Infoblox, and my role is a little bit different now. I am conducting the POC of new solutions, which we have to deploy in our infrastructure. I evaluate the new products, and then if we purchase them, we deploy them.
I am currently using CrowdStrike Falcon as an EDR, which is integrated with SIEM. We also work in a real-time environment with the product. As a Falconist, I perform investigation actions on it. There are three different kinds of alerts I deal with: one based purely on IOCs, another process-oriented IOA, and those based on machine learning alerts. This is what I work on, and it is actually a good tool. It has multiple features, including real-time connection to the RTR environment, allowing direct remote host connection through CrowdStrike. I have multiple options like host search and event search, enabling me to do everything I need. It's a comprehensive package. It's a challenging tool to explore, but once accustomed to it, it is quite excellent.
CrowdStrike Falcon is used for incident response.
It gives an overview and insights into my AD accounts. It shows if any identity, like an AD user, is compromised, has a weak password, or is logging in from an unusual system. Any anomalies.
We use the solution for endpoint security. We use the tool to ensure the endpoints are protected from abnormal activities, people don't run different scripts, and people don't compromise endpoints and use them to get into the network.
It also helps you with access, like we have dark web monitoring and admin protection management. So, the use cases can vary from organization to organization, but every organization has different value in it.
We use the solution for Windows and non-Windows infrastructure. We have Falcon clients on all our machines.
The tool helps to increase security because the threats we face keep changing, so we need better protection. In the past, we've faced some attacks on our network, and while we managed to deal with them, we realized we needed even stronger protection. That's why we decided to implement CrowdStrike Identity Protection.