CrowdStrike Falcon

CrowdStrike Falcon

CrowdStrike
+
+

Related Products

  • Orca Security
    606 Ratings
    Visit Website
  • ThreatLocker
    700 Ratings
    Visit Website
  • ESET PROTECT Advanced
    2,304 Ratings
    Visit Website
  • Daylight
    11 Ratings
    Visit Website
  • ManageEngine ADAudit Plus
    619 Ratings
    Visit Website
  • Safetica
    415 Ratings
    Visit Website
  • Iru
    1,385 Ratings
    Visit Website
  • ManageEngine EventLog Analyzer
    211 Ratings
    Visit Website
  • Veeam Data Platform
    1,265 Ratings
    Visit Website
  • Adaptive Security
    91 Ratings
    Visit Website

About

CrowdStrike Falcon is a cloud-native cybersecurity platform that provides advanced protection against a wide range of cyber threats, including malware, ransomware, and sophisticated attacks. It leverages artificial intelligence (AI) and machine learning to detect and respond to threats in real time, offering endpoint protection, threat intelligence, and incident response capabilities. The platform uses a lightweight agent that continuously monitors endpoints for signs of malicious activity, providing visibility and protection without significant impact on system performance. Falcon’s cloud-based architecture ensures fast updates, scalability, and rapid threat response across large, distributed environments. Its comprehensive security features help organizations prevent, detect, and mitigate potential cyber risks, making it a powerful tool for modern enterprise cybersecurity.

About

NetWitness Platform brings together evolved SIEM and threat defense solutions that deliver unsurpassed visibility, analytics and automated response capabilities. These combined capabilities help security teams work more efficiently and effectively, up-leveling their threat hunting skills and enabling them to investigate and respond to threats faster, across their organization’s entire infrastructure—whether in the cloud, on premises or virtual. Gives security teams the visibility they need to detect sophisticated threats hiding in today’s complex, hybrid IT infrastructures. Analytics, machine learning, and orchestration and automation capabilities make it easier for analysts to prioritize and investigate threats faster. Detects attacks in a fraction of the time of other platforms and connects incidents to expose the full attack scope. NetWitness Platform accelerates threat detection and response by collecting and analyzing data across more capture points.

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Large and mid-sized enterprises across diverse industries, particularly those that require advanced threat detection and response, such as finance, healthcare, manufacturing, technology, and government. It is especially suited for organizations dealing with sensitive data and facing complex cyber threats, often with a large workforce and intricate IT infrastructure

Audience

IT security teams looking for an accelerated threat detection and response from endpoint to the cloud to rapidly detect targeted attacks

Support

Phone Support Not Supported
24/7 Live Support Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version Not Supported
Free Trial Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Not Supported

Reviews/Ratings

Overall 4.6 / 5
ease 4.4 / 5
features 4.6 / 5
design 4.4 / 5
support 4.3 / 5

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Pros & Cons from Real Users

Pros

  • In CrowdStrike Falcon the best feature is, it will detect the malware in real time and it will block immediately. We can see the real time logs in the NextGen SIEM that is very useful to correlated with the incident. It will be the best solution I have never seen and it will be best in on-demand scan to prevent the data at rest. We can create the workflow for the predefined detection.
  • Falcon's cloud-native architecture allows for outstanding scalability, making it suited for companies of all sizes, from small businesses to huge corporations. It combines standard antivirus features with new detection techniques like as anomaly detection, making it more successful in preventing sophisticated attacks (fileless malware, ransomware).
  • CrowdStrike Falcon EDR offers real-time monitoring and detection of threats, enabling security teams to respond instantly to potential breaches or malicious activity. This minimizes damage and downtime during an attack. As a fully cloud-native solution, CrowdStrike requires no on-premises infrastructure, ensuring quick deployment, automatic updates, and the ability to scale according to organizational needs. The endpoint agent is lightweight and optimized to minimize system performance impact. It works silently in the background without interrupting users or consuming excessive resources CrowdStrike leverages global threat intelligence and AI-powered analytics to provide actionable insights into the nature, origin, and impact of threats. This allows organizations to take proactive measures against evolving threats. CrowdStrike integrates effortlessly with other security solutions, SIEMs, and IT management tools, ensuring a cohesive security ecosystem without compatibility issues.
  • CrowdStrike ability to identify, investigate, and mitigate threats quickly minimizes potential damage from cyber incidents. CrowdStrike Falcon agent is lightweight and efficient, consuming minimal system resources, which ensures it doesn’t hinder endpoint performance. CrowdStrike integrates with Zero Trust frameworks, enabling organizations to enforce strict access controls and prevent unauthorized access. CrowdStrike includes identity threat detection and response capabilities, protecting against credential theft, privilege escalation, and other identity-based attacks.
  • CrowdStrike is entirely cloud-based, offering seamless scalability and reducing the need for on-premise hardware.This enables faster deployment and real-time updates. CrowdStrike leverages artificial intelligence and machine learning to analyze massive amounts of data and detect threats proactively, even before they can cause harm. The Falcon platform provides comprehensive endpoint protection, combining threat detection, response, and prevention in a single, unified solution.

Cons

  • Some cases it will not contain the machines in the offline state. Troubleshooting will take some time to resolve the issue. Sometime it will take high CPU consumption.
  • Although Falcon may continue to defend endpoints offline for a period of time, it must periodically sync with the cloud for full functionality and updates, which might be a negative in some cases. OnDemand Scan feature not available for the Linux environment in Falcon
  • The pricing structure can be a challenge for small to medium-sized organizations with limited budgets. While the solution is highly effective, its premium pricing might be out of reach for some. While the agent does provide some offline protection, its full potential, such as cloud-based analytics and threat intelligence, requires active connectivity to CrowdStrike’s cloud platform.
  • Crowdstrike Falcon has more advanced features and integrations may require specialized knowledge or significant setup time, potentially complicating deployment. In environments with many endpoints, the centralized cloud-based processing might occasionally face latency issues due to high data traffic.
  • CrowdStrike solutions, while feature-rich, can be expensive, making it less accessible for small businesses or organizations with tight budgets. CrowdStrike provides some offline protections, its effectiveness is reduced without real-time cloud access for advanced threat detection and updates.

Training

Documentation Supported
Webinars Supported
Live Online Not Supported
In Person Supported

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Not Supported

Company Information

CrowdStrike
Founded: 2011
United States
www.crowdstrike.com/platform/

Company Information

NetWitness
Founded: 1997
United States
www.netwitness.com

Alternatives

Alternatives

Fidelis Elevate

Fidelis Elevate

Fidelis Security
NetworkMiner

NetworkMiner

Netresec
TrendAI Vision One

TrendAI Vision One

Trend Micro

Categories

Categories

Endpoint Detection and Response (EDR) Features

Behavioral Analytics Supported
Blacklisting/Whitelisting Not Supported
Continuous Monitoring Supported
Malware/Anomaly Detection Supported
Prioritization Not Supported
Remediation Management Supported
Root Cause Analysis Not Supported

Computer Security Features

Anti Spam Not Supported
Antivirus Supported
Audit Trail Supported
Compliance Management Not Supported
Database Security Audit Not Supported
File Access Control Supported
Financial Data Protection Not Supported
Maintenance Scheduling Not Supported
Real Time Monitoring Supported
Security Event Log Supported
Virus Definition Update Not Supported
Vulnerability Protection Supported

Endpoint Protection Features

Activity Log Supported
Antivirus Supported
Application Security Supported
Behavioral Analytics Supported
Device Management Supported
Encryption Not Supported
Signature Matching Supported
Web Threat Management Supported
Whitelisting / Blacklisting Supported

Endpoint Detection and Response (EDR) Features

Behavioral Analytics Supported
Blacklisting/Whitelisting Not Supported
Continuous Monitoring Supported
Malware/Anomaly Detection Supported
Prioritization Supported
Remediation Management Supported
Root Cause Analysis Supported

Integrations

Chronicle SOAR Supported
D3 Smart SOAR Supported
Google Digital Risk Protection Supported
SOC Prime Platform Supported
Swimlane Supported
ThreatConnect Risk Quantifier (RQ) Supported
ThreatQ Supported
Abstract Security Supported
CyberDNA Command and Control Center Supported
Falcon Data Protection Supported
Falcon Forensics Supported
Falcon Prevent Supported
Onum Supported
OpenText Managed Extended Detection and Response Supported
Reclaim Security Supported
SCADAfence Not Supported
Sendmail Supported
Sola Security Supported
TrustCloud Supported

Integrations

Chronicle SOAR Supported
D3 Smart SOAR Supported
Google Digital Risk Protection Supported
SOC Prime Platform Supported
Swimlane Supported
ThreatConnect Risk Quantifier (RQ) Supported
ThreatQ Supported
Abstract Security Not Supported
CyberDNA Command and Control Center Not Supported
Falcon Data Protection Not Supported
Falcon Forensics Not Supported
Falcon Prevent Not Supported
Onum Not Supported
OpenText Managed Extended Detection and Response Not Supported
Reclaim Security Not Supported
SCADAfence Supported
Sendmail Not Supported
Sola Security Not Supported
TrustCloud Not Supported
Claim CrowdStrike Falcon and update features and information
Claim CrowdStrike Falcon and update features and information
Claim NetWitness and update features and information
Claim NetWitness and update features and information