AA

Anup A.

Network Security Engineer

Information Services

Mid-Market (51-1000 emp.)

6/12/2026

"Lightweight Deployment, Powerful Incident Response Visibility"

5/5

What do you like best about CrowdStrike Falcon Endpoint Protection Platform?

The single-agent architecture actually lives up to the marketing buzz coming from an environment that was bogged down by clunky legacy av suites rolling out the falcon sensor via SCCM was incredibly straightforward. our end-users don't even notice it running because it barely touches local system resources there are no heavy local signature updates choking up machine memory at 9 AM.

From an incident response perspective, the great graph visualization makes life significantly easier during a triage. being able to trace a malicious process execution tree from a stray script back to its origin down to the exact command-line arguments saves us a massive amount id investigation time the behavioral detection tuning handle zero-days without throwing an un Review collected by and hosted on G2.com.

What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?

The tool is incredibly capable but the platform's modular structure can be a bit overwhelming during budget planning as getting advanced capabilities like hyper-granular identity telemetry or specialized USB controls means adding specific modules that said it does allow you to build a highly customized security stack rather than paying for a bloated all-in-one suite you don't fully use.

One the administrative side the management console has a sharp learning curve for tier-1 analysts the UI is exceptionally logic it takes some dedicated hands -on-time to confidently map out policy exclusions without feeling a bit intimidated by the sheer number of prevent toggles Review collected by and hosted on G2.com.

What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?

We were struggling with massive blind spots on our remote endpoints, especially with developers spinning up unmanaged local VMs and accidentally exposing sensitive internal data falcon gave our security team immediate real-time visibility across our entire distributed workforce without requiring our users to be consistently tunneled through a corporate VPN.

By moving away from static signature defenses to falcon's behavioral indicators of attack (IOAs), we've drastically cut down mean time to detect (MTTD). It successfully caught a lateral movement attempt involving a compromised service account that traditional tools would have glossed over it effectively consolidated three different legacy security utilities down into one console, which cleared a tin of technical overhead from our day-to-day operations queue. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

See what 418 reviewers think of CrowdStrike Falcon Endpoint Protection Platform

4.6 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews)