What is our primary use case?
We are currently using this solution as an ERD tool to control and remediate threat from the endpoint remotely, it serves as a next-gen antivirus solution. It can also be used in a forensic investigation, threat hunting, trend analysis, malware analysis, etc.
How has it helped my organization?
- CrowdStrike is a SaaS-based solution which means it can be operated from anywhere, which gives the admins access to control the endpoints from multiple endpoints.
- It has a very low footprint, using 1-2 % CPU and around 40 Mb of RAM, and the agent size is small and easy to deploy as well.
- It has segregation of roles at various levels for the analysts, admins, SMEs, etc.
What is most valuable?
- It can connect to host and isolate it from the network if needed; this feature helps us to investigate the endpoint without visiting the endpoint and then testing.
- It saves time and helps to contain the threat in less time.
- complete visibility into the endpoint
What needs improvement?
The current version of Falcon does not support DLP which is a may be a good to have in a EDR Solution. It must be included in the future version if possible. There must be a on-premise versions. MDM is also coming soon must also have ability to be controled from same dashboard.
For how long have I used the solution?
What do I think about the stability of the solution?
The solution is pretty stable, and it does pretty accurate work. I have never encountered any issue in this dept.
What do I think about the scalability of the solution?
The solution is scalable to multiple thousands of systems at once. There is no restriction for that.
How are customer service and technical support?
The support portal of CrowdStrike is active and helpful if needed.
Which solution did I use previously and why did I switch?
We compared multiple solutions in EDR and out of them, CrowdStrike gave the most features and value for money.
How was the initial setup?
It is pretty straightforward and without any complex mechanism.
What about the implementation team?
We as a team implemented the solution on our own, with the help of the manual and help desk.
What was our ROI?
It helps to manage a lot of threats with pretty less manpower and in a graceful way.
What's my experience with pricing, setup cost, and licensing?
The setup of CrowdStrike is very simple. It supports all three platforms (Windows, MacOS, Linux), and it has support for the specific version of the above OS. Which means sometimes, a particular OS won't be compatible with the CrowdStrike version.
Which other solutions did I evaluate?
Before choosing the solution, we evaluated various products from the Gartner magic quadrant for endpoint protection platforms (EDR and MDR).
What other advice do I have?
It comes with various modules, so you can choose the module that you need on the basis of the costing it comes with. This is definitely not cheap; it comes with a cost which may depend on the organization if they need it.