CrowdStrike Falcon - An Unified Endpoint Security Solution.
Use Cases and Deployment Scope
I'm a security analyst who uses CrowdStrike Falcon for day-to-day endpoint monitoring and response. There is no such problem compared to the competitors. It does its job really well. Our scope is to monitor endpoint assets, including workstations, servers, and DCs (Windows OS, Linux OS, and macOS), for any suspicious or malicious behavior or attempts.
Pros
- Monitor Endpoint Assets for Anomalies using AI/ML.
- Manage Threat hunting using its overwatch function.
- Managing the asset inventory.
- The identity protection feature detections and stop attacks that abuse user identities.
- The Exposure Management function helps in identifying application and OS vulnerabilities before attackers exploit them.
Cons
- The new NG-SIEM has a complex console to handle, which can be more smoother.
- All the features look perfect and there is no room for improvement.
Likelihood to Recommend
Crowdstrike is a unified platform for monitoring endpoint devices, whether they're workstations, servers, cloud-native machines, or even mobile devices. It uses AI/ML to monitor anomalies and suspicious behavior, including zero-day attacks. It is suitable for large organizations but may be costlier or less appropriate for smaller organizations, those who want an on-prem EDR setup, and those who need custom scanning based on compliance requirements.
