CrowdStrike Falcon Endpoint Protection Platform Reviews (438)

View 3 Video Reviews
Reviews

CrowdStrike Falcon Endpoint Protection Platform Reviews (438)

View 3 Video Reviews
4.6
438 reviews

What do users say?

Generated using AI from real user reviews
Users most consistently praise the lightweight agent that runs quietly without slowing down systems, paired with strong real-time threat detection that catches behavioral and zero-day attacks traditional tools miss. The cloud-based console makes deployment and visibility straightforward across endpoints. The most common drawbacks are higher pricing with paid add-on modules and a learning curve that requires tuning to reduce alert noise.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
AB
Ansh B.
Associate Security Engineer
Capital Markets
Mid-Market (51-1000 emp.)
"Crowdstrike Falcon: Proactive Security, Steep Learning Curve"
5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

What I like best about Crowdstrike Falcon is how Lightweight it feels compared to traditional antivirus solutions. A lot of endpoint protection tools tend to bog down your system with constant scans and updates, but Falcon runs quietly in the background without really affecting performance which honestly surprised me given how much it's doing under the hood.

The cloud-native architecture is another big plus, Since everything is managed through the cloud, there's no need to deal with on-prem servers or constant manual updates. New threat intellgence and detection capabilities just get pushed out automatically, so you're always working with the latest protections without lifting a finger.

I also really appreciate the visibility and detail it gives you when something does get flagged. Instead of just saying "this file is bad," It shows you the full attack chain what triggered it, what process did what, and how it all connects. That kind of context makes it so much easier to actually understand what happened and respond properly, instead of just reacting blindly.

And honestly, the speed of detection stands out too. Threats get flagged almost instantly, which gives a lot of peace of mind when you're responsilble for keeping syetem secure. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

One thing that bugs me a bit about Falcon is the pricing. It's definately on the higher end compared to some other endpoint protection tools, and smaller teams or businesses, that cost can add up fast especially once you start adding on extra modules for things like identity protection or threat intelligence. It almost feels like the "full experience" is locked behind multiple add-ons rather than one straightforward package.

The console UI can also feel a bit overwhelming at first. There's just so much data, so many tabs, and so may ways to drill into things that it takes a while to actually get comfortable navigating it. For someone new to the platform, it's not the most intuitive experience right out of the gate.

Another thing alert fatigue is real. Beacuse it's so thorough, you sometimes get a lot of detections or alerts, and not all of them turn out to be critical. It takes some tuning and experience to fatigue out what actually needs immediate attention verus what's just noise. Without proper triage, it can feel like a lot ot keep up with.

Lastly, support response times can vary. Sometimes you get quick, helpful responses, but other times especially for more complex issues it can take longer than you'd expect, which is frustrating when you're dealing with a potential secuirty incident. Review collected by and hosted on G2.com.

AA
Anup A.
Network Security Engineer
Information Services
Mid-Market (51-1000 emp.)
"Lightweight Deployment, Powerful Incident Response Visibility"
5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

The single-agent architecture actually lives up to the marketing buzz coming from an environment that was bogged down by clunky legacy av suites rolling out the falcon sensor via SCCM was incredibly straightforward. our end-users don't even notice it running because it barely touches local system resources there are no heavy local signature updates choking up machine memory at 9 AM.

From an incident response perspective, the great graph visualization makes life significantly easier during a triage. being able to trace a malicious process execution tree from a stray script back to its origin down to the exact command-line arguments saves us a massive amount id investigation time the behavioral detection tuning handle zero-days without throwing an un Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

The tool is incredibly capable but the platform's modular structure can be a bit overwhelming during budget planning as getting advanced capabilities like hyper-granular identity telemetry or specialized USB controls means adding specific modules that said it does allow you to build a highly customized security stack rather than paying for a bloated all-in-one suite you don't fully use.

One the administrative side the management console has a sharp learning curve for tier-1 analysts the UI is exceptionally logic it takes some dedicated hands -on-time to confidently map out policy exclusions without feeling a bit intimidated by the sheer number of prevent toggles Review collected by and hosted on G2.com.

AD
Aman D.
Artificial Intelligence Engineer
Mid-Market (51-1000 emp.)
"Strong Endpoint Protection, But Takes Time to Master"
4.5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

The behavioral detection is what really won me over — it caught a suspicious lateral movement attempt that signature-based tools would've easily missed. The Threat Graph makes visualizing attack chains simple, which saves a lot of investigation time. Agent is super lightweight, no performance complaints from end users whatsoever. SIEM integration was painless and alerts are actually actionable, not just noise. Overall, it's shifted our team from constantly reacting to actually staying ahead, which makes a huge difference day to day. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

The learning curve is real — when we first onboarded, junior team members struggled to make sense of the alert volume and what actually needed immediate attention. Policy tuning also took longer than expected to get right, lots of trial and error in the beginning. And if you want to dig deep into investigations, you really need someone with solid security experience on the team otherwise you're just scratching the surface of what the platform can do. Review collected by and hosted on G2.com.

SP
Suraj P.
Technical Specialists
Enterprise (> 1000 emp.)
"XDR detection"
5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

I like how easy it is to deploy CrowdStrike Falcon Endpoint Protection Platform. Because it’s entirely cloud-based, it’s straightforward to roll out at scale across endpoints and servers. Resource utilization is minimal, so end users aren’t bottlenecked during day-to-day work. The detection rate is top-notch and, in my experience, among the best in the industry, which helps give us an edge over attackers.

I also value the different modules it can integrate with, since it works seamlessly with other Falcon modules as well as third-party vendors. The initial setup was simple, and the documentation was robust and genuinely helpful. CrowdStrike Charlotte AI has also been very useful for investigations and log correlation. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

The pricing for SMBs can be improved. The UI/UX can also be improved as it's outdated and it needs to be more intuitive. Also, if the other Falcon modules were included with endpoint protection in the base package, it would be a great advantage. The current UI/UX of CrowdStrike seems outdated and it's not easy to navigate and not easy on the eyes. Review collected by and hosted on G2.com.

Nihal J.
NJ
Nihal J.
Cyber Security Engineer
Mid-Market (51-1000 emp.)
"Top-Notch Security with Easy Deployment"
5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

I like how easy it is to deploy CrowdStrike Falcon Endpoint Protection Platform. Because it’s entirely cloud-based, it’s straightforward to roll out at scale across endpoints and servers. Resource utilization is minimal, so end users aren’t bottlenecked during day-to-day work. The detection rate is top-notch and, in my experience, among the best in the industry, which helps give us an edge over attackers.

I also value the different modules it can integrate with, since it works seamlessly with other Falcon modules as well as third-party vendors. The initial setup was simple, and the documentation was robust and genuinely helpful. CrowdStrike Charlotte AI has also been very useful for investigations and log correlation. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

The pricing for SMBs can be improved. The UI/UX can also be improved as it's outdated and it needs to be more intuitive. Also, if the other Falcon modules were included with endpoint protection in the base package, it would be a great advantage. The current UI/UX of CrowdStrike seems outdated and it's not easy to navigate and not easy on the eyes. Review collected by and hosted on G2.com.

DP
Deep P.
SIEM Engineer
Small-Business (50 or fewer emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Reliable Endpoint Security That Actually Makes Investigations Easier"
4.5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

What i like most about crowdstrike falcon is how lightweight yet powerful it is..It has minimal impact on endpoints while still providing strong behavioural detection and real-time visibility. The centralized console makes it easy to investigate and respond to threats quickly without juggling multiple tools also main advantage of crowdstrike endpoint protection platform is that it fetches data only one time then the data is shared between all the platforms like cloud security and next-gen siem Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

One downside of CrowdStrike Falcon is that its pricing can be on the higher side, especially once you start adding multiple modules. The UI also feels a bit complex at first, particularly for new users, and some advanced features require a learning curve to fully utilize. You also need to learn their CQL language to query data from multiple sources. Additionally, sometimes policies take a long time to get applied to endpoints. Overall, it’s a powerful platform, but there are a few areas where it still needs improvement. Review collected by and hosted on G2.com.

Rajat M.
RM
Rajat M.
IT Support Specialist
Information Technology and Services
Enterprise (> 1000 emp.)
"Lightweight and Effectively Transparent Endpoint Security"
4/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

I appreciate that CrowdStrike Falcon Endpoint Protection Platform is lightweight, unlike legacy antivirus software that heavily taxed our systems. The lightweight design doesn't lock up our machines, as it runs quietly in the background. I also value the automatic blocking feature, which keeps my mind at ease, knowing it handles threats without intervention. I find the ability to isolate a computer from the network a handy feature for isolating issues quickly. One of the standout features is the extensive visual process tree, which streamlines alerts by showing a clear attack chain. It has changed how I handle investigations by providing precise sequences of events, like spotting if a user opened a phishing link that triggered a hidden script. This feature is a lifesaver for my team, making our daily tasks less cumbersome by eliminating guesswork and providing fast answers to executive queries. Also, it gives us a complete history of events in less than two minutes, letting us address concerns promptly and find the root cause of issues efficiently. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

I find the interface fields scattered. Over the years, as new modules have been added, it feels like they made it scattered. I think they need a simple mode toggle or workspace customization for general IT administrators who don't need to see all the dense, advanced features. Another issue is with update trust. Ever since a massive, global update glitch, managing and tracking which endpoints missed an update can be clunky. They should offer more granular control over updates and clearer alerts when a sensor update fails to apply. Also, they should consider lowering the cost. Finally, I think adding a junior analytics alert feature could help, so that lower-level team members can access what they need. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
GI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"Flawless Cloud Management, Zero Performance Impact"
5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

I use CrowdStrike Falcon Endpoint Protection Platform as our primary enterprise endpoint security solution and I really appreciate its incredibly lightweight agent. It provides top-tier, real-time security and behavioral threat detection without hogging system resources or slowing down user machines. I really enjoy the network isolation feature as it works flawlessly, allowing me to instantly disconnect a compromised device from the network with one click while still maintaining my remote connection to fix it. I also found the initial setup to be incredibly easy since it is 100% cloud-native, requiring minimal effort and allowing me to deploy the lightweight agent across all company devices without needing a single reboot. The platform integrates seamlessly with our Microsoft Azure infrastructure and our centralized SIEM system, which aids in consolidated security logging and rapid incident response. I would rate it a solid 10 out of 10 for its flawless cloud management and zero impact on PC performance, making it the ultimate endpoint protection for any enterprise. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

The centralized cloud dashboard can feel overwhelming because the user interface has a steep learning curve with too many sub menus. Also, the advanced threat hunting queries (Falcon Insight) require deep specialized knowledge, so making the query syntax more intuitive would be a great improvement for daily operations. Review collected by and hosted on G2.com.

Prem K.
PK
Prem K.
Siem Engineer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Strong Endpoint Protection with Excellent Threat Detection"
4.5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

I like CrowdStrike Falcon Endpoint Protection Platform for its strong threat detection and lightweight agent. The cloud-based management console is easy to use and the platform provides excellent visibility into endpoint activity. It allows our team to respond to security incidents quickly and efficiently. The initial setup was easy and efficient, with the lightweight agent deploying quickly and minimal effort required for configuration. I would highly recommend it due to its ease of management, cloud-native architecture, and its ability to help organizations respond to threats quickly. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

CrowdStrike Falcon works very well overall, there are few areas that could be improved. The pricing can be relatively high for smaller organizations, especially when additional modules are required. Some advanced features require time to learn and alert tuning is sometimes needed to reduce noise. More flexible reporting and dashboard customization would also be welcome improvements Review collected by and hosted on G2.com.

MT
Manisha T.
Assistant Manager
Small-Business (50 or fewer emp.)
"Reliable and Powerful Endpoint Protection Platform"
2.5/5
What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

Cloud-native architecture

Falcon runs from the cloud, so there’s no heavy on-premise infrastructure to maintain. Deployment and updates are usually faster and simpler.

Lightweight agent

Compared to many traditional antivirus tools, the Falcon sensor uses relatively low system resources, which users often appreciate on employee laptops and servers. Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

High cost

Many organizations feel the licensing and add-on modules can become expensive, especially for smaller companies or growing environments.

Complexity for new users

While powerful, the platform can have a learning curve for administrators who are new to EDR/XDR tools or advanced threat hunting.

Alert volume / tuning required Review collected by and hosted on G2.com.