Senior DevSecOps Engineer at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Sep 2, 2026
Training is the biggest thing that could be improved; there is not a lot of training, and it is not that accessible. The ability to implement profile groups requires SCIM to be configured. SCIM is not in the documentation. SCIM is required if you want to do just-in-time access provisioning for profile groups for new users, and that is not in the documentation. It took a lot of communication with support to figure that out. The AI detections on anything about a severity five or lower could be improved; many of those are more on the informational side. There have not been too many with a severity of five or lower, detection-wise, that have actually been useful as an analyst.
Security Engineer at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 2, 2026
There are definitely a couple of things CrowdStrike Falcon should improve, but I don't have all of them in my mind at this moment. I would need to check my notes to provide you with a comprehensive list.
Senior Vice President, Director of Information Security at a financial services firm with 201-500 employees
Real User
Top 10
Sep 1, 2026
I believe CrowdStrike Falcon can be improved by continuing to keep up the good work, staying informed about global developments, and keeping us updated. I would like to see additional features in the next release, such as SafeMind and further advancements in how AI is used to attack, react, and build defenses, which I think is terrific.
Vice President, Information & Security at a tech vendor with 201-500 employees
Real User
Top 10
Sep 1, 2026
CrowdStrike Falcon can be improved in that the UI takes a little bit to understand where to go and how to get there. With every new release, I see a change in the user interface that makes it much easier to follow. An additional feature that should be included in the next release is free AI.
IT Support Engineer at a media company with 51-200 employees
Real User
Top 10
Sep 1, 2026
CrowdStrike Falcon can be improved by adding some sort of data-at-rest insights into what is on these PCs. I know there are other tools that CrowdStrike offers that do this, but I have not had any experience with them.
Co-Owner at a manufacturing company with 1,001-5,000 employees
Real User
Top 5
Sep 1, 2026
We heard that the newest features coming soon are a major improvement that we would definitely be interested in. We have seen the announcement for the Red Team, Blue Team features, and they sound excellent. We are planning to use AI within CrowdStrike Falcon in the future.
Security Analyst at a manufacturing company with 501-1,000 employees
Real User
Top 20
Sep 1, 2026
To improve CrowdStrike Falcon, I suggest continuing what you are doing, continuing with customer support and checking quarterly schedules, and everything will be good.
Information Security Manager Iam at ExactCare Pharmacy
Real User
Top 10
Sep 1, 2026
CrowdStrike Falcon can be improved by continuing to keep everything on the cutting edge. The product works and is stable, as long as we do not have a rehash of what happened in the summer of 2024 because I dealt with that frontline. The product works well, is not a resource hog, and is the best in the class. Just keep progressing and adding new features as the IT field changes for the next ten to twenty years. From my perspective on identity access management, there are additional features I would like to see included in the next release of CrowdStrike Falcon. I am just getting started with the Identity portion of CrowdStrike Falcon, so if you ask me this next year, I would probably give you a great answer, but right now I cannot.
data and cyber security manager at a construction company with 11-50 employees
Real User
Top 20
Sep 1, 2026
The main complaint that myself and leadership have about CrowdStrike Falcon is that the cost has become expensive compared to competitors. Cost is really the only significant area needing improvement for CrowdStrike Falcon. More direct connectors on the SIM side could be beneficial, but I am already quite satisfied with the current offerings, and I understand that some limitations depend on vendors rather than CrowdStrike, such as Fortinet. I have not used many of the AI capabilities of CrowdStrike Falcon yet, though I have experimented with Charlotte to a limited extent. From what I have seen of CrowdStrike Falcon, the AI capabilities seem to work fairly well in terms of accuracy and reliability of output. The only factor preventing a perfect rating is the actual cost of the product, as it is expensive. It is best in market, but it is somewhat pricey compared to achieving a full ten.
Senior Secops Engineer at a program development consultancy with 1,001-5,000 employees
Real User
Top 10
Sep 1, 2026
The only downside is trying to figure out all the agents or all of the machines that do not have CrowdStrike Falcon on them, unlike SentinelOne which has a feature for that, along with a feature where you can roll back to detect ransomware if you ever get ransomware. CrowdStrike Falcon can be improved by having the ability to scan the network to determine what machines do not have CrowdStrike Falcon on, which is a big one, and having the ability to roll back from the volume image if you get encrypted. Other than that, it is pretty solid; you have a monopoly on the field as of now.
Security Analyst at a manufacturing company with 201-500 employees
Real User
Top 10
Sep 1, 2026
One specific example of how CrowdStrike Falcon can be improved would be the ability to export the device control exceptions for auditability purposes, and perhaps a cleaner UI.
CrowdStrike Falcon can be improved with more capabilities such as watermarking and preventing sensitive content from being screenshotted. CrowdStrike Falcon is pretty accurate and reliable, but the only part where we lack visibility is whether the endpoint has started reporting or is not reporting. We do not have data on how many endpoints on a given day are reporting versus not reporting, so we would appreciate that visibility. This way, we know where the endpoint is not recording and can take corrective action to ensure we have updated endpoints.
We are not currently using AI within CrowdStrike Falcon, but that is definitely something that we want to explore further because we know that CrowdStrike values the discovery of AI and ensuring you have full coverage. CrowdStrike Falcon can be improved by strengthening the focus on AI and keeping up with responding to AI as it constantly evolves. It would be beneficial to have more information on that.
Director, Information Security Services at a university with 10,001+ employees
Real User
Top 10
Sep 1, 2026
I am pretty happy with CrowdStrike Falcon where it is. I do like some of the new features being added to it with some of the AI pieces and the SIM, and we have not really broached those pieces yet, but I think we are really interested in at some point expanding our portfolio. Regarding CrowdStrike Falcon's AI capabilities, I think it still needs a little bit of time to learn and improve itself in the environment, but overall it has been pretty accurate.
Cyber Security Analyst II at a retailer with 10,001+ employees
Real User
Top 10
Sep 1, 2026
CrowdStrike Falcon can be improved by addressing the side tabs and menu options, which represent the biggest area for enhancement. I cannot identify any additional features that should be included in the next release unless they address that menu structure.
CISO at a financial services firm with 1,001-5,000 employees
Real User
Top 10
Sep 1, 2026
I think that bringing more AI and insights into anomalies could be helpful for CrowdStrike Falcon. I would also appreciate having CrowdStrike Falcon on legacy systems such as IBM AIX. Currently, I am not using AI within CrowdStrike Falcon, but I plan to do so.
Lead Endpoint Security Engineer at Depository Trust & Clearing Corporation
Real User
Top 10
Sep 1, 2026
CrowdStrike Falcon could be improved in several areas. For the next release, I have seen exposure management and some new modules coming up. If I had to compare with other products, it's not there yet. I was wondering if modules could be enhanced, especially on SSPM and exposure management.
System Administrator at a consumer goods company with 501-1,000 employees
Real User
Top 10
Sep 1, 2026
CrowdStrike Falcon can be improved because there are a lot of duplicated endpoints and CrowdStrike does not know how to identify that smartly. That would be a huge improvement. Additionally, the user interface is a little bulky and could use some streamlining. It often feels hard to understand and know exactly where to click to find the information that you need. Although there are a lot of options that make CrowdStrike Falcon powerful, it also makes it very difficult to navigate to exactly what you are looking for. It almost takes an expert in the platform to be able to extract the information that you need.
CrowdStrike Falcon can be improved by continuing to adapt to everything that is going on with AI and other developments in the world. The one improvement I would suggest for the future is to make the console side of CrowdStrike Falcon more user-friendly, but as explained, most of those details are not things we need to worry about because those are things that Falcon Complete takes care of; overall, it is all good.
Network Security Engineer at a retailer with 11-50 employees
Real User
Top 5
Jun 4, 2026
CrowdStrike Identity Protection is generally strong for detecting identity-based attacks and tying identity signals into endpoint and cloud telemetry, but like most enterprise IAM/ITDR tools, there are a few areas where users commonly see room for improvement:
One frequent point is complexity in initial setup and tuning. Organizations often find that integrating identity data sources (like Active Directory, Entra ID, and cloud apps) and calibrating detection policies takes time and skilled engineering effort. Out-of-the-box value is good, but maximizing accuracy usually requires careful tuning to reduce noise.
Another area is alert fatigue and prioritization. While the platform is powerful at detecting suspicious identity behavior, some teams report that early deployments generate a high volume of alerts that need refinement. Better built-in prioritization or more adaptive baselining could improve day-to-day usability.
Visibility depth across hybrid identity environments can also be a limitation in some cases. In complex setups with multiple identity providers, legacy AD, and SaaS apps, correlation is strong but not always perfectly unified, so analysts may still need to pivot between consoles or data views.
There is also feedback around reporting and compliance customization. Security teams sometimes want more flexible, audit-ready reporting templates without having to export data into external SIEM tools.
Finally, cost and licensing transparency can be a concern for some organizations, especially when expanding across endpoints, identity, and cloud modules. Pricing can become complex as scope increases.
While CrowdStrike Falcon is strong overall, there are a few areas where it could be improved. First, the user interface can be a bit complex for new users. Sometimes, navigating through different sections and understanding detailed alerts takes time, especially for teams without deep security expertise. The cost is also something to consider, as the features and additional modules can increase pricing, which may be a challenge for smaller teams. Additionally, some integrations with simpler reporting would be helpful. The onboarding process for new users is a bit challenging for beginners to understand all features and workflows in the product. More simplified documentation, step-by-step guides, and real-world examples could help new users get comfortable faster. A structured onboarding or basic training module would be very useful for teams who are new to endpoint security tools. In addition, having more in-product guidance and tooltips within the dashboard could make navigation easier and reduce the learning curve. Overall, improving training resources and onboarding support would make the platform more user-friendly, especially for new users.
Regarding improvements in reports, when I try to pull a custom report, there are some mismatches, or it does not look professional. I hope CrowdStrike will improve their custom report or inbuilt report to look professional rather than appearing like just adding numbers. Based on the requirement, they should improve their custom reports.
As of now, CrowdStrike Falcon does not have application control and web control. If CrowdStrike Falcon applies those types of features, it will be more reliable and stronger than any other antivirus or next-gen antivirus in the world or in the industries.
I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does.
One area for improvement in CrowdStrike Falcon could be the user interface and reports; it requires some improvements to be easily handled. For the reporting in CrowdStrike Falcon, I need specific data because in most reports, some of the data is not with that importance for the collector, so the reports need to be more specific for each purpose.
I recommend that some deep-dive trainings are required for the NG SIEM, specifically for their next-generation SIEM module, as they need some basic trainings for that. To clarify, deep-dive trainings are required specifically for the NG SIEM or next-gen SIEM.
To make CrowdStrike Falcon better for the next release, I recommend that they should have a model where it works as agentless. In terms of everything which the agent pushes to the server or to the single console, having a feature where you can have another port, which is SNMP or your network devices or OT devices, which you can specifically monitor, would be great.
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
If tomorrow is the next release of the product, new features would be helpful, but at the moment, the product is very good. Nothing specific comes to mind about what new features they can add. For further improvements, I can only think of one example because this is very important for us; they could reduce the price. Then it would deserve a rating of seven.
We do not leverage AI within the CrowdStrike Falcon, as we are using different products LLM, and I am unsure if CrowdStrike has the capability to integrate it with local LLM or if I need to use commercial LLM such as OpenAI. I am currently investigating SOAR in CrowdStrike because I have seen some articles about it, but I am uncertain if it is operational now or still in development. I do not have any specific features I would want to see included in CrowdStrike.
Security Engineer at a tech services company with 201-500 employees
Real User
Top 5
Feb 12, 2025
Currently, users manually input IOCs, and it would be beneficial if IOCs released by major companies were automatically integrated into CrowdStrike. We retrieve files from vendors, which incurs costs. Automating this process could be cost-effective and time-saving.
The KDR solution is immature. They do not have much preemption in ITDR. Threat prevention should be their first priority, and false positive reductions are needed. They should improve their support as well. Response resolution time is too high.
In CrowdStrike, with the variety of security tools available, learning the different query languages can be challenging. I use KQL queries with Sentinel and AQL with QRadar, and CrowdStrike's query language is different as well. This requires constant learning for security analysts. Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial. The event search tab in CrowdStrike is complex, though the host search is more straightforward and gets details from the past week. The querying system, similar to Splunk, could be made more user-friendly.
IT Specialist at a consultancy with 1-10 employees
Real User
Top 10
Oct 8, 2024
The new interface, the UI, seems a bit messy. The previous one was quite clear. It might be because of my adaptation to it. That's what I see as needing improvement.
Trainee Engineer at COMPASS IT Solutions & Services Pvt.Ltd.
Real User
Aug 9, 2024
I'm concerned about the recent issue in July 2024. It involved a faulty content configuration update. What if another update causes the same problem again?
One thing that is not yet available is attack simulation. For example, if someone tries to attack your Active Directory on inactive accounts, a cyber attacker could hack those accounts and try to get into your company. This could be a feature to add. It would give a fake reply each time someone tries to hack it. Multiple companies that I know of would like that.
As customers, we always update our systems whenever a new release is available, with clients connecting directly to the Internet for these updates. We have an agent who manages these updates on the clients, but as an organization, we don’t have control over them. CrowdStrike should assess the impact on endpoints before releasing such updates. Our organization now seeks AI-based stock monitoring to prioritize thousands of alerts generated across various platforms. The AI integration is still in its early stages, so we would like to see Falcon develop tools that can integrate with multiple platforms and help identify the highest-priority alerts.
Improvement is always possible. It's challenging to gauge how much future mitigation is provided, especially since we've only been using the product for about one and a half years. Every product faces this challenge because nothing is ever completely foolproof. So, besides relying on technology, we also focus on increasing our staff's awareness of security issues. Feedback from my colleagues suggests that the reporting and dashboarding of incidents could be improved.
CrowdStrike Falcon delivers AI-powered endpoint protection, detection, and response to help organizations stop malware, ransomware, fileless attacks, and sophisticated adversaries. Built on the cloud-native Falcon platform and a single lightweight sensor, it combines prevention, EDR, threat intelligence, and automated response to protect endpoints while simplifying security operations.
What features make CrowdStrike Falcon stand out?
AI-Powered Prevention: Uses next-generation antivirus,...
Training is the biggest thing that could be improved; there is not a lot of training, and it is not that accessible. The ability to implement profile groups requires SCIM to be configured. SCIM is not in the documentation. SCIM is required if you want to do just-in-time access provisioning for profile groups for new users, and that is not in the documentation. It took a lot of communication with support to figure that out. The AI detections on anything about a severity five or lower could be improved; many of those are more on the informational side. There have not been too many with a severity of five or lower, detection-wise, that have actually been useful as an analyst.
There are definitely a couple of things CrowdStrike Falcon should improve, but I don't have all of them in my mind at this moment. I would need to check my notes to provide you with a comprehensive list.
I believe CrowdStrike Falcon can be improved by continuing to keep up the good work, staying informed about global developments, and keeping us updated. I would like to see additional features in the next release, such as SafeMind and further advancements in how AI is used to attack, react, and build defenses, which I think is terrific.
CrowdStrike Falcon platform is too new to suggest ways it could be better or additional features that should be included in the next release.
CrowdStrike Falcon can be improved in that the UI takes a little bit to understand where to go and how to get there. With every new release, I see a change in the user interface that makes it much easier to follow. An additional feature that should be included in the next release is free AI.
I do not have much to offer regarding how CrowdStrike Falcon can be improved.
CrowdStrike Falcon can be improved by adding some sort of data-at-rest insights into what is on these PCs. I know there are other tools that CrowdStrike offers that do this, but I have not had any experience with them.
We heard that the newest features coming soon are a major improvement that we would definitely be interested in. We have seen the announcement for the Red Team, Blue Team features, and they sound excellent. We are planning to use AI within CrowdStrike Falcon in the future.
To improve CrowdStrike Falcon, I suggest continuing what you are doing, continuing with customer support and checking quarterly schedules, and everything will be good.
CrowdStrike Falcon can be improved by continuing to keep everything on the cutting edge. The product works and is stable, as long as we do not have a rehash of what happened in the summer of 2024 because I dealt with that frontline. The product works well, is not a resource hog, and is the best in the class. Just keep progressing and adding new features as the IT field changes for the next ten to twenty years. From my perspective on identity access management, there are additional features I would like to see included in the next release of CrowdStrike Falcon. I am just getting started with the Identity portion of CrowdStrike Falcon, so if you ask me this next year, I would probably give you a great answer, but right now I cannot.
The main complaint that myself and leadership have about CrowdStrike Falcon is that the cost has become expensive compared to competitors. Cost is really the only significant area needing improvement for CrowdStrike Falcon. More direct connectors on the SIM side could be beneficial, but I am already quite satisfied with the current offerings, and I understand that some limitations depend on vendors rather than CrowdStrike, such as Fortinet. I have not used many of the AI capabilities of CrowdStrike Falcon yet, though I have experimented with Charlotte to a limited extent. From what I have seen of CrowdStrike Falcon, the AI capabilities seem to work fairly well in terms of accuracy and reliability of output. The only factor preventing a perfect rating is the actual cost of the product, as it is expensive. It is best in market, but it is somewhat pricey compared to achieving a full ten.
The only downside is trying to figure out all the agents or all of the machines that do not have CrowdStrike Falcon on them, unlike SentinelOne which has a feature for that, along with a feature where you can roll back to detect ransomware if you ever get ransomware. CrowdStrike Falcon can be improved by having the ability to scan the network to determine what machines do not have CrowdStrike Falcon on, which is a big one, and having the ability to roll back from the volume image if you get encrypted. Other than that, it is pretty solid; you have a monopoly on the field as of now.
One specific example of how CrowdStrike Falcon can be improved would be the ability to export the device control exceptions for auditability purposes, and perhaps a cleaner UI.
CrowdStrike Falcon can be improved with more capabilities such as watermarking and preventing sensitive content from being screenshotted. CrowdStrike Falcon is pretty accurate and reliable, but the only part where we lack visibility is whether the endpoint has started reporting or is not reporting. We do not have data on how many endpoints on a given day are reporting versus not reporting, so we would appreciate that visibility. This way, we know where the endpoint is not recording and can take corrective action to ensure we have updated endpoints.
We are not currently using AI within CrowdStrike Falcon, but that is definitely something that we want to explore further because we know that CrowdStrike values the discovery of AI and ensuring you have full coverage. CrowdStrike Falcon can be improved by strengthening the focus on AI and keeping up with responding to AI as it constantly evolves. It would be beneficial to have more information on that.
I am pretty happy with CrowdStrike Falcon where it is. I do like some of the new features being added to it with some of the AI pieces and the SIM, and we have not really broached those pieces yet, but I think we are really interested in at some point expanding our portfolio. Regarding CrowdStrike Falcon's AI capabilities, I think it still needs a little bit of time to learn and improve itself in the environment, but overall it has been pretty accurate.
CrowdStrike Falcon can be improved by addressing the side tabs and menu options, which represent the biggest area for enhancement. I cannot identify any additional features that should be included in the next release unless they address that menu structure.
I think that bringing more AI and insights into anomalies could be helpful for CrowdStrike Falcon. I would also appreciate having CrowdStrike Falcon on legacy systems such as IBM AIX. Currently, I am not using AI within CrowdStrike Falcon, but I plan to do so.
CrowdStrike Falcon can be improved by integrating with other platforms I utilize like InTune, ScreenConnect, and TeamViewer.
CrowdStrike Falcon could be improved in several areas. For the next release, I have seen exposure management and some new modules coming up. If I had to compare with other products, it's not there yet. I was wondering if modules could be enhanced, especially on SSPM and exposure management.
I think CrowdStrike Falcon could be improved by making the interface more modern and simpler.
CrowdStrike Falcon can be improved because there are a lot of duplicated endpoints and CrowdStrike does not know how to identify that smartly. That would be a huge improvement. Additionally, the user interface is a little bulky and could use some streamlining. It often feels hard to understand and know exactly where to click to find the information that you need. Although there are a lot of options that make CrowdStrike Falcon powerful, it also makes it very difficult to navigate to exactly what you are looking for. It almost takes an expert in the platform to be able to extract the information that you need.
CrowdStrike Falcon can be improved by continuing to adapt to everything that is going on with AI and other developments in the world. The one improvement I would suggest for the future is to make the console side of CrowdStrike Falcon more user-friendly, but as explained, most of those details are not things we need to worry about because those are things that Falcon Complete takes care of; overall, it is all good.
CrowdStrike Identity Protection is generally strong for detecting identity-based attacks and tying identity signals into endpoint and cloud telemetry, but like most enterprise IAM/ITDR tools, there are a few areas where users commonly see room for improvement:
One frequent point is complexity in initial setup and tuning. Organizations often find that integrating identity data sources (like Active Directory, Entra ID, and cloud apps) and calibrating detection policies takes time and skilled engineering effort. Out-of-the-box value is good, but maximizing accuracy usually requires careful tuning to reduce noise.
Another area is alert fatigue and prioritization. While the platform is powerful at detecting suspicious identity behavior, some teams report that early deployments generate a high volume of alerts that need refinement. Better built-in prioritization or more adaptive baselining could improve day-to-day usability.
Visibility depth across hybrid identity environments can also be a limitation in some cases. In complex setups with multiple identity providers, legacy AD, and SaaS apps, correlation is strong but not always perfectly unified, so analysts may still need to pivot between consoles or data views.
There is also feedback around reporting and compliance customization. Security teams sometimes want more flexible, audit-ready reporting templates without having to export data into external SIEM tools.
Finally, cost and licensing transparency can be a concern for some organizations, especially when expanding across endpoints, identity, and cloud modules. Pricing can become complex as scope increases.
While CrowdStrike Falcon is strong overall, there are a few areas where it could be improved. First, the user interface can be a bit complex for new users. Sometimes, navigating through different sections and understanding detailed alerts takes time, especially for teams without deep security expertise. The cost is also something to consider, as the features and additional modules can increase pricing, which may be a challenge for smaller teams. Additionally, some integrations with simpler reporting would be helpful. The onboarding process for new users is a bit challenging for beginners to understand all features and workflows in the product. More simplified documentation, step-by-step guides, and real-world examples could help new users get comfortable faster. A structured onboarding or basic training module would be very useful for teams who are new to endpoint security tools. In addition, having more in-product guidance and tooltips within the dashboard could make navigation easier and reduce the learning curve. Overall, improving training resources and onboarding support would make the platform more user-friendly, especially for new users.
Regarding improvements in reports, when I try to pull a custom report, there are some mismatches, or it does not look professional. I hope CrowdStrike will improve their custom report or inbuilt report to look professional rather than appearing like just adding numbers. Based on the requirement, they should improve their custom reports.
As of now, CrowdStrike Falcon does not have application control and web control. If CrowdStrike Falcon applies those types of features, it will be more reliable and stronger than any other antivirus or next-gen antivirus in the world or in the industries.
I believe that AI-powered SOAR workflow suggestions could streamline incident response.
To improve my recommendation to a perfect score, I would focus on better selling skills and improved integration with different vendors.
I don't think anything is missing in CrowdStrike Falcon, but if they can manage their SOC solution instead of users or the end users or customers doing that, it will be very useful, just as Sophos does.
One area for improvement in CrowdStrike Falcon could be the user interface and reports; it requires some improvements to be easily handled. For the reporting in CrowdStrike Falcon, I need specific data because in most reports, some of the data is not with that importance for the collector, so the reports need to be more specific for each purpose.
I recommend that some deep-dive trainings are required for the NG SIEM, specifically for their next-generation SIEM module, as they need some basic trainings for that. To clarify, deep-dive trainings are required specifically for the NG SIEM or next-gen SIEM.
To make CrowdStrike Falcon better for the next release, I recommend that they should have a model where it works as agentless. In terms of everything which the agent pushes to the server or to the single console, having a feature where you can have another port, which is SNMP or your network devices or OT devices, which you can specifically monitor, would be great.
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.
If tomorrow is the next release of the product, new features would be helpful, but at the moment, the product is very good. Nothing specific comes to mind about what new features they can add. For further improvements, I can only think of one example because this is very important for us; they could reduce the price. Then it would deserve a rating of seven.
We do not leverage AI within the CrowdStrike Falcon, as we are using different products LLM, and I am unsure if CrowdStrike has the capability to integrate it with local LLM or if I need to use commercial LLM such as OpenAI. I am currently investigating SOAR in CrowdStrike because I have seen some articles about it, but I am uncertain if it is operational now or still in development. I do not have any specific features I would want to see included in CrowdStrike.
Currently, users manually input IOCs, and it would be beneficial if IOCs released by major companies were automatically integrated into CrowdStrike. We retrieve files from vendors, which incurs costs. Automating this process could be cost-effective and time-saving.
The KDR solution is immature. They do not have much preemption in ITDR. Threat prevention should be their first priority, and false positive reductions are needed. They should improve their support as well. Response resolution time is too high.
In CrowdStrike, with the variety of security tools available, learning the different query languages can be challenging. I use KQL queries with Sentinel and AQL with QRadar, and CrowdStrike's query language is different as well. This requires constant learning for security analysts. Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial. The event search tab in CrowdStrike is complex, though the host search is more straightforward and gets details from the past week. The querying system, similar to Splunk, could be made more user-friendly.
The new interface, the UI, seems a bit messy. The previous one was quite clear. It might be because of my adaptation to it. That's what I see as needing improvement.
I'm concerned about the recent issue in July 2024. It involved a faulty content configuration update. What if another update causes the same problem again?
I would like a centralized deployment where I could roll out or push it to all endpoints.
One thing that is not yet available is attack simulation. For example, if someone tries to attack your Active Directory on inactive accounts, a cyber attacker could hack those accounts and try to get into your company. This could be a feature to add. It would give a fake reply each time someone tries to hack it. Multiple companies that I know of would like that.
As customers, we always update our systems whenever a new release is available, with clients connecting directly to the Internet for these updates. We have an agent who manages these updates on the clients, but as an organization, we don’t have control over them. CrowdStrike should assess the impact on endpoints before releasing such updates. Our organization now seeks AI-based stock monitoring to prioritize thousands of alerts generated across various platforms. The AI integration is still in its early stages, so we would like to see Falcon develop tools that can integrate with multiple platforms and help identify the highest-priority alerts.
Improvement is always possible. It's challenging to gauge how much future mitigation is provided, especially since we've only been using the product for about one and a half years. Every product faces this challenge because nothing is ever completely foolproof. So, besides relying on technology, we also focus on increasing our staff's awareness of security issues. Feedback from my colleagues suggests that the reporting and dashboarding of incidents could be improved.