• Categories

    • Loading categories...

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. CrowdStrike Falcon
Logo of CrowdStrike Falcon

CrowdStrike Falcon

byCrowdStrike
in
4.7
2025
Market Presence: Endpoint Protection Platforms, Extended Detection and Response

Overview

Product Information on CrowdStrike Falcon

Updated 19th December 2024

What is CrowdStrike Falcon?

The CrowdStrike Falcon platform’s single lightweight endpoint agent and agent-less cloud architecture leverages artificial intelligence (AI) and offers real-time protection and visibility across the enterprise, preventing attacks on endpoints and workloads both on and off the network. Backed by adversary-driven threat intelligence and AI, the CrowdStrike Falcon platform correlates trillions of events per week in real time from across the globe, fueling an advanced data platform for security in one unified command console.

CrowdStrike Falcon Pricing

CrowdStrike Falcon Product Images

CrowdStrike Falcon Dashboard
CrowdStrike Falcon Dashboard
CrowdStrike Falcon Prevention
CrowdStrike Falcon Prevention

Overall experience with CrowdStrike Falcon

Adjunct Professor
10B - 30B USD, IT Services
FAVORABLE

“Seamless Deployment and Strong Detection Capabilities Highlight Crowdstrike Experience”

5.0
Jul 24, 2025
My overall experience has been excellent. As a previous customer for several years, I have brought Crowdstrike into several organizations. The main need has been to detect novel malicious and anomalous endpoint behavior. After evaluating several vendors, Crowdstrike was the clear winner. Key factors included the administrator interface, which is clean and intuitive for investigating alerts. This made it easy to track event sequences and determine responses to anomalies. While price was important, we also considered market share, innovation, and integrations with tools like our ticketing system, SIEM, and SOC, maximizing our investment. Measuring ROI is difficult, but the product has delivered value. It effectively handles events, quarantines malicious files, and prevents incidents, thus avoiding significant costs from investigations and threat spread. As a CISO, I have peace of mind knowing I can verify its monitoring and blocking. For example, I tested detection by downloading Mimikatz on a test machine, confirming the agent’s effectiveness. Deployment and onboarding were seamless thanks to mobile device management, enabling zero-touch installation of Crowdstrike agents and removal of our previous solution, migrating all devices in two weeks. The agent worked well with our unattended installation method and caused no compatibility issues with legacy systems; only offline devices (due to user leave) were missed—a common issue for any software. Crowdstrike Falcon scales well; it can support thousands of endpoints, and at around 500 now, I foresee no scaling issues as we grow. Its ability to detect advanced threats and suspicious behavior is very high. I’ve used Red Team tools like Stratus Red Team to simulate complex attacks (e.g., creating backdoor users, deploying scenarios across servers, laptops, and cloud). These tests validate its detection and provide a full assessment of our monitoring, SIEM, SOC, log analysis, and escalation processes.
LEAD DEVOP MANAGER
50M - 250M USD, Banking
CRITICAL

“Cloud-Based Threat Detection Offers Analytics But Causes Issues On Older Machines”

3.0
Dec 3, 2025
Work okay for endpoint protection and threat detection. Some we do see some false positives and some performace impact on older machine.

Badges

Gartner Peer Insights recognizes vendors who meet or exceed both the market average Overall Experience and the market average User Interest and Adoption score through a Customers’ Choice distinction.
2025
For Market:
Endpoint Protection Platforms

About Company

Company Description

Updated 25th July 2024

CrowdStrike is a recognized entity in the cybersecurity space, specializing in enterprise risk management through the innovative application of technology. The company focuses primarily on protecting essential business risk areas such as endpoints, cloud workloads, identity, and data. Employing the state-of-the-art CrowdStrike Security Cloud and advanced AI technology, the firm provides effective solutions. Its CrowdStrike Falcon platform uses real-time indications of attack, threat intelligence, telemetry enhanced from diverse enterprise sources, and evolving adversary knowhow for high-grade detection, automated protection and healing, advanced threat tracking, and efficient vulnerability visibility. The Falcon platform, designed in the cloud with a singular lightweight-agent architecture, offers swift deployment, unique protection and performance, and reduced complexity. Therefore, CrowdStrike delivers a significant value proposition right from the beginning.

Company Details

Updated 26th February 2025
Company type
Public
Year Founded
2011
Head office location
Remote, United States
Number of employees
5001 - 10000
Website
http://www.crowdstrike.com

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About CrowdStrike Falcon
Reviewer Insights for: CrowdStrike Falcon
Deciding Factors: CrowdStrike Falcon Vs. Market Average
Performance of CrowdStrike Falcon Across Market Features

CrowdStrike Falcon Likes & Dislikes

Like

The ability to detect novel malicious and anomalous behavior on endpoints was a critical factor in our selection. Crowdstrikes cloud-based telemetry analysis enables rapid innovationnew tactics and techniques discovered in the wild are quickly addressed, often within hours. This is a major advantage over legacy signature-based protection, which may only update daily. Response, innovation, and monitoring improvements must be measured in hours, not days. Falcon has proven highly effective at detecting advanced threats and suspicious activity. Ive used Red Team tools, especially Stratus Red Team (by Datadog), to verify detection of complex attack simulations, like creating a backdoor user. These tests offer a strong end-to-end assessment of our SOC processes, from alerting through log analysis and escalation. The administrator experience for investigating alerts is excellent; the interface is clean and intuitive, making it easy to trace events leading to an alert and determine the right response. While price is important, so are market share and innovation. Integrations are vital for maximizing value, and Crowdstrike connects seamlessly with our ticketing system, SIEM, SOC, and other endpoint health sources. Crowdstrike has addressed feedback such as enabling searches by device namea previous gap, since alerts often reference device names rather than unique IDs. The ability to create department-focused protection profiles is extremely useful, letting us apply stricter monitoring or more aggressive protection for sensitive departments like finance, while roles with less sensitive data, like marketing interns, receive baseline protection. This allows for tailored rules based on departmental risk and data classification. I havent observed Crowdstrike agents negatively impacting endpoint performance, and in terms of capabilities, I dont know of any tool doing a better job right now.

Read Full Review
Like

The platform provides immediate alerts and rapid identification of threats, helping our team response quickly. Cloud base management allows us easy access from anywhere this will reduces the need for us to be on-premis. And least detailed security analytics give deep insights into threats patterns.

Read Full Review
Like

What I like most about CrowdStrike Falcon is its proactive detection and rapid response to threats. The combination of real-time analysis, process behavior and cloud-based protection allows you to identify even unknown or fileless attacks that other traditional solutions could miss. For example, Falcon once detected suspicious activity on an endpoint that was running a legitimate script modified by an attacker. The platform automatically blocked the malicious execution and generated a detailed report with recommendations on how to enforce application policy, allowing the security team to remediate the situation without impacting operations. Additionally, the centralized interface and clear alerts make managing and monitoring all endpoints much simpler and more efficient. This gives me confidence that our devices are constantly protected without the need for constant manual intervention.

Read Full Review
Dislike

My primary concern with the product relates to the shoot themselves in the foot incident, an outage that caused significant disruption. This incident led to questions from senior leadership regarding whether we should consider switching away from Crowdstrike, given its very large impact, even affecting global air travel for a few hours. It is important to note that this was a Windows Crowdstrike outage, not a Linux Crowdstrike outage. This distinction is significant because it highlights the inherent fragility of the Windows operating system, where a single file change can lead to a blue screen of death loop, often requiring manual intervention to restore functionality. In my view, Microsoft bears a share of the blame for this outage due to the design of their operating system. Crowdstrike, to their credit, acknowledged this as a root cause analysis and published commitments to prevent similar occurrences in the future. Their stated actions include more regression testing, automated testing, and Quality Assurance (QA) of changes. While the incident was disruptive, the company's response and commitment to preventing recurrence were positive

Read Full Review
Dislike

We notice first that sometimes legitimate files or process are flagged as threats, which can disrupt workflows and required manual review to whitelist safe items. We where hopping this would solve it for use so we spend less time. Secondly, the agent can consume significant CPU and memory on older machine leading to slower performance and impacting user productivity. The incident that happed few months ago world wide that create a blue screen, cost. Should not be happed that's why they need to check careful planning they update beter.

Read Full Review
Dislike

What I like least about CrowdStrike Falcon Endpoint Protection is that, although the platform is very powerful, some reports and alerts can be too technical for non-specialized personnel. For example, when an alert is generated about advanced suspicious behavior, the report includes many details of processes and scripts that require in-depth knowledge to interpret correctly. This can slow down decision making if the team receiving the alert is not fully familiar with the terminology. Another minor point is that, at first, configuring certain advanced policies can be a bit complex, especially for organizations that do not have a dedicated security team or experience in PPE. However, these are minor aspects compared to the overall value and effectiveness of the platform.

Read Full Review

Top CrowdStrike Falcon Alternatives

Logo of SentinelOne Singularity Endpoint
1. SentinelOne Singularity Endpoint
4.7
(3070 Ratings)
Logo of Sophos Endpoint
2. Sophos Endpoint
4.8
(2395 Ratings)
Logo of Microsoft Defender for Endpoint
3. Microsoft Defender for Endpoint
4.4
(1941 Ratings)
View All Alternatives

Peer Discussions

What Your Peers Are Saying About CrowdStrike Falcon

CISO
We are already using multiple modules of Crowdstrike Falcon. Have you used CS Falcon for IT in production and, if yes, what are your experiences?
Associate Director, Information Security Management
Yes, we are and have been for some time. On servers it’s a lightweight deployment: Fast and easy In almost all cases, no reboot required Low resource consumption on the local OS Low Network usage We also find it’s quite effective at the behavioural side of blocking attackers when they get hands-on-keyboards (vs. scripted/automated) attacks. It’s an effective heterogeneous solution applying and performing quite well across Linux, Windows and macOS. Not all EDR/XDR tools are effective heterogeneous solutions.
See Full Discussion
15 May 2024307 Views2 Comments
Director of IT
We are at the edge of closing a contract with Crowdstrike Falcon Complete, a MDR-solution including managed service for monitoring the security of our infrastructure 24/7. The functionality looked promising during a short pilot we organized. We are now in the contracting phase and discovered that we need to pay upfront for a three years contract. For a managed service I find this rather strange, while I am used to pay on a monthly, quarterly or sometimes yearly basis. Does someone in the peer group has the same experience with Crowdstrike?
Director of Enablement
I was always under the perception that Crowdstrike operated on a net-60 opex model. Are they asking for the TCV in a lump sum?
See Full Discussion
25 Oct 20231.5k Views1 Comment

CrowdStrike Falcon Reviews and Ratings

4.7

(3190 Ratings)

Rating Distribution

5 Star
77%
4 Star
21%
3 Star
2%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.6

Planning & Transition

4.7

Delivery & Execution

4.7

Integration & Deployment

4.7

Service & Support

4.7

Product Capabilities

4.8

Last 12 Months
Filter Reviews
Sort By:
Most helpful
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Adjunct Professor
    10B+ USD
    IT Services
    Review Source

    Seamless Deployment and Strong Detection Capabilities Highlight Crowdstrike Experience

    5.0
    Jul 24, 2025
    My overall experience has been excellent. As a previous customer for several years, I have brought Crowdstrike into several organizations. The main need has been to detect novel malicious and anomalous endpoint behavior. After evaluating several vendors, Crowdstrike was the clear winner. Key factors included the administrator interface, which is clean and intuitive for investigating alerts. This made it easy to track event sequences and determine responses to anomalies. While price was important, we also considered market share, innovation, and integrations with tools like our ticketing system, SIEM, and SOC, maximizing our investment. Measuring ROI is difficult, but the product has delivered value. It effectively handles events, quarantines malicious files, and prevents incidents, thus avoiding significant costs from investigations and threat spread. As a CISO, I have peace of mind knowing I can verify its monitoring and blocking. For example, I tested detection by downloading Mimikatz on a test machine, confirming the agent’s effectiveness. Deployment and onboarding were seamless thanks to mobile device management, enabling zero-touch installation of Crowdstrike agents and removal of our previous solution, migrating all devices in two weeks. The agent worked well with our unattended installation method and caused no compatibility issues with legacy systems; only offline devices (due to user leave) were missed—a common issue for any software. Crowdstrike Falcon scales well; it can support thousands of endpoints, and at around 500 now, I foresee no scaling issues as we grow. Its ability to detect advanced threats and suspicious behavior is very high. I’ve used Red Team tools like Stratus Red Team to simulate complex attacks (e.g., creating backdoor users, deploying scenarios across servers, laptops, and cloud). These tests validate its detection and provide a full assessment of our monitoring, SIEM, SOC, log analysis, and escalation processes.
  • IT ASSOCIATE
    <50M USD
    Services (non-Government)
    Review Source

    Powerful, Lightweight with Proactive Threat Detection and Clear Endpount Visibiliy

    5.0
    Nov 18, 2025
    My overall experience with CrowdStrike Falcon Endpoint Protection has been very positive. The platform is light on endpoints and does not affect device performance, which has facilitated its mass deployment without end users noticing interruptions. A concrete example: during a deployment to remote employee laptops, Falcon detected a script-based malware attempt that had not been identified by our previous solution. The alert quickly reached the central dashboard, and the security team was able to isolate the affected computer, analyze the behavior, and eliminate the threat in less than an hour. On a day-to-day basis, the Falcon console provides complete endpoint visibility and facilitates incident investigation, which has significantly reduced response time and manual workload for our security team. Overall, it has been a reliable and efficient tool to protect our endpoints and minimize
  • NETWORK AND SECURITY ENGINEER
    50M-1B USD
    IT Services
    Review Source

    CrowdStrike Falcon Mobile Threat Defense delivers robust, real-time protection for enterprise mobile devices with seamless integration and simple management-with room for growth in reporting flexibility.

    4.0
    Oct 24, 2025
    CrowdStrike Falcon Mobile Threat Defense has been a solid addition to our overall endpoint security, offering strong mobile coverage without adding complexity. The deployment process was fast and agent performance onIos and Andriod devices was lightweight, with excellent battery optimization and minimal user disruption. What worked particularly wwell is its real-time mobile threat detection-identifying malicious apps, phishing links, and network-level attacks almost instantly. Integration with Microsoft Intune makes device policy enforcement seamless, improving mobile compliance posture across the organization. The Falcon console offers unified visibility across mobile and traditional endpoints, which simplifies security management and incident triage. However, areas for improvement include report customization, alert tuning for less severe risks, and occasional delays in synchronization with third-party MDMs. Overall, it's effective for managing mobile threats in enterprise-scale deployments, balancing usability with advanced AI-driven protection.
  • SENIOR CYBERSECURITY ENGINEER
    1B-10B USD
    Transportation
    Review Source

    High Cost and Setup Effort Offset By Strong Security Performance In Falcon XDR

    5.0
    Sep 12, 2025
    Our overall experience with CrowdStrike Falcon XDR has been exceptional, fundamentally elevating our security posture from reactive to proactive. We have it in a small branch and except for the day of "fire" everything went perfect and smooth. The platform provides unparalleled visibility across our entire environment, from endpoints to cloud workloads. The ability to correlate threat data from multiple sources into a single, coherent incident view has drastically reduced our investigation times and improved the accuracy of our response. While the platform carries a premium price tag (a really premium one) and required a dedicated effort to tune it for our environment, the security outcomes and operational efficiencies we've gained have justified the investment.
  • IT MANAGER
    <50M USD
    Energy and Utilities
    Review Source

    Artificial Intelligence Enhances Threat Detection Yet Cost May Challenge Smaller Firms

    4.0
    Nov 25, 2025
    Crowdstrike Falcon is a robust piece of software that is used in my organization as our primary means of defending against malware and ransomware. It has been quite adept at detecting and blocking malicious files and programs from running on endpoint PCs and traveling across the corporate network. The onboarding team was great in the initial setup and roll-out of the application. They took the time to answer all of our questions and walk us through the entire process. The support after the initial roll out has been great as well.
...
Showing Result 1-5 of 3465

Recommended Gartner Research

  • Critical Capabilities for Endpoint Protection Platforms
  • Magic Quadrant for Endpoint Protection Platforms

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.