---
title: CrowdStrike Falcon Endpoint Protection Platform Reviews
meta_title: 'CrowdStrike Falcon Endpoint Protection Platform Reviews 2026: Details,
  Pricing, & Features | G2'
meta_description: Filter 439 reviews by the users' company size, role or industry
  to find out how CrowdStrike Falcon Endpoint Protection Platform works for a business
  like yours.
aggregate_rating:
  rating_value: 4.6
  review_count: 439
  scale: '5'
date_modified: '2026-07-21'
parent_category:
  name: Endpoint Protection
  url: https://www.g2.com/categories/endpoint-protection
---

# CrowdStrike Falcon Endpoint Protection Platform Reviews
**Vendor:** CrowdStrike  
**Category:** [Endpoint Protection Platforms](https://www.g2.com/categories/endpoint-protection-platforms)  
**Average Rating:** 4.6/5.0  
**Total Reviews:** 439
## About CrowdStrike Falcon Endpoint Protection Platform
Organizations today face a serious challenge: managing numerous security vendors and tools while confronting an ever-evolving threat landscape. Sophisticated adversaries are becoming smarter, faster, and more evasive, launching complex attacks that can strike in minutes or even seconds. Traditional security approaches struggle to keep pace, leaving businesses vulnerable. The CrowdStrike Falcon Platform addresses this by offering a unified, cloud-native solution. It consolidates previously siloed security solutions and incorporates third-party data into a single platform with one efficient and resource-conscious agent, leveraging advanced AI and real-time threat intelligence. This approach simplifies security operations, speeds analyst decision making, and enhances protection to stop the breach, allowing organizations to reduce risk with less complexity and lower costs. CrowdStrike&#39;s Falcon Platform includes: - Endpoint Security: Secure the endpoint, stop the breach - Identify Protection: Identity is the front line, defend it - Next-Gen SIEM: The future of SIEM, today - Data Protection: Real-time data protection from endpoint to cloud - Exposure Management: Understand risk to stop breaches - Charlotte AI: Powering the next evolution of the SOC



## CrowdStrike Falcon Endpoint Protection Platform Pros & Cons
**What users like:**

- Users appreciate the **lightweight performance and powerful threat detection** of CrowdStrike Falcon, enhancing operational efficiency and security. (113 reviews)
- Users value the **effective threat detection** of CrowdStrike Falcon, ensuring robust security without compromising system performance. (103 reviews)
- Users appreciate the **ease of use** of CrowdStrike Falcon, benefiting from a lightweight and efficient security solution. (98 reviews)
- Users appreciate the **advanced real-time threat protection** of CrowdStrike Falcon, enhancing security with minimal system impact. (97 reviews)
- Users appreciate the **strong threat detection** of CrowdStrike Falcon, effectively catching both known and unknown threats seamlessly. (90 reviews)
- Users appreciate the **lightweight nature** of CrowdStrike Falcon, which secures devices without impacting performance. (80 reviews)
- Detection Efficiency (76 reviews)
- Reliability (76 reviews)
- Efficiency (67 reviews)
- Cybersecurity (65 reviews)

**What users dislike:**

- Users find the **cost of CrowdStrike Falcon** to be high, especially for smaller teams needing advanced features. (54 reviews)
- Users face **initial complexity and a steep learning curve** with CrowdStrike Falcon, making it challenging for non-technical personnel. (39 reviews)
- Users find the **initial learning curve** of CrowdStrike challenging, especially transitioning from other systems like Splunk. (35 reviews)
- Users find the **high cost and limited features** frustrating, particularly for smaller teams needing advanced capabilities. (31 reviews)
- Users express concern over **pricing issues** , especially for smaller organizations needing advanced features with additional licensing costs. (29 reviews)
- Learning Difficulty (27 reviews)
- Users are frustrated by the **lack of essential features** , such as remediation options and limited detection on MAC endpoints. (24 reviews)
- Not User-Friendly (21 reviews)
- Improvements Needed (20 reviews)
- Users find the **complex interface** confusing, limiting effective use and making navigation unnecessarily difficult. (19 reviews)

## CrowdStrike Falcon Endpoint Protection Platform Reviews
  ### 1. Advanced Threat Detection with Ease of Use

**Rating:** 4.5/5.0 stars

**Reviewed by:** Akhilesh  T. | IT Specialist, Mid-Market (51-1000 emp.)

**Reviewed Date:** March 25, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I use CrowdStrike Falcon Endpoint Protection Platform as a next-gen endpoint security to protect our organization against advanced cyber threats. I appreciate the endpoint security that goes beyond traditional antivirus, offering features like machine learning at the initial stage after installation, behavior-based threat detection, and a lightweight agent. The detailed process tree for any detection provides accurate investigation reports and makes it easy to understand the root cause. I also like its ability to detect zero-day attacks and unknown malware. The initial setup was easy and straightforward with support from the CrowdStrike team.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I have some concerns about pricing and cost transparency with CrowdStrike Falcon Endpoint Protection Platform. Also, learning to use the advanced features isn't very easy.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It protects our endpoints from modern cyber threats, providing more visibility and device control.

  ### 2. Excellent Network Containment, RTR, and Endpoint & Identity Protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Subhajji S. | SOC Admin, Enterprise (> 1000 emp.)

**Reviewed Date:** April 21, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Network containment, RTR, and managing endpoints and workflows, identity protection everything is so good

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Endpoint on-demand scan: if I initiate a scan on an offline host, it won’t run when the host comes back online, and the scan just fails. It would be really helpful to have a feature where an on-demand scan can be queued and then automatically start once the endpoint is online again.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It helps with data breaches and with protecting the organisation from malware, and similar threats.

  ### 3. CrowdStrike Falcon Endpoint Protection : Security and Features ( EDR)

**Rating:** 5.0/5.0 stars

**Reviewed by:** anshu Y. | Network Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 02, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

We have been using Crowstrike's Falcon Platform for over 5 years now. It is great at what is does and while the Falcon Platform itself can be pricey (though about on par for the competition), additional tools are included or very affordable (SIEM/Log Collector or CSPM for example). It's very easy to deploy, especially in a modern setting. The functionality within the tool is exactly what our team is looking for - EDR, isolation, remote response, and more. Charlotte AI helps detection and response with autonomous reasoning and action.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Good Product for security point of view but  TAC support can be much better. 
Also, Cost is very High. But all over product is good.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Real-Time Detection - Uses advanced behavioral analytics to identify and stop attacks quickly. Lightweight Cloud-Native Agent - Minimal impact on endpoint performance with easy deployment and updates. Intuitive User Interface - Clean, user-friendly dashboard that simplifies monitoring and incident response.

  ### 4. Excellent Endpoint Visibility and Vulnerability Detection

**Rating:** 4.5/5.0 stars

**Reviewed by:** Akanksha . | Security Executive, Enterprise (> 1000 emp.)

**Reviewed Date:** May 08, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

It gives over all view of all the endpoints in the environment, giving visibility of the vulnerabilities, tracking all the sign-in logs, detecting any anomalous behavior and have many features like containment, exposure visibility

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Overall the platform is great but it can improve the structure of the reports

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Giving visibility of all the asset in one single platform, we can track the status, user activity, any suspicious logins, vulnerabilty

  ### 5. Fit for purpose

**Rating:** 4.0/5.0 stars

**Reviewed by:** Stewart C. | Security Operations Specialist

**Reviewed Date:** June 17, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon stands out for its cloud-native design, strong behavioral threat detection, and lightweight agent. It provides real-time visibility and response across endpoints, with deep telemetry for investigation. Its integrated threat intelligence and scalable platform make it effective for detecting advanced attacks while being easy to deploy and manage.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon
Can be expensive 

Learning curve for query/search features 

Alert noise without tuning 

Cloud-dependent for full functionality

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Problems solved: Detects advanced threats, improves visibility, speeds response, reduces tool sprawl.
Benefits: Faster response, lower breach risk, easier investigations, simpler management.

  ### 6. Lightweight, Accurate, But Challenging Query Language

**Rating:** 4.5/5.0 stars

**Reviewed by:** Tarun G. | Staff Eningeer II, Consulting, Enterprise (> 1000 emp.)

**Reviewed Date:** November 28, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon has been one of the most dependable EDR platforms I’ve used. The agent is extremely lightweight, which makes a big difference in keeping system performance smooth. Its detection accuracy is consistently strong and really helps us stay ahead of threats.  The asset discovery feature is one of my favorites—it gives us clear visibility into what’s actually running in our environment and makes managing assets much easier. The built-in vulnerability assessment is also very reliable and helps us quickly identify and prioritize issues. Overall, the platform’s defensive capabilities and real-time protection give us a strong sense of confidence in our media security.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The biggest challenge for me has been CrowdStrike’s query language. Coming from Splunk, which is more intuitive and easier to work with, the transition feels unnecessarily difficult. Having to juggle different syntaxes—CrowdStrike, Splunk, SIEM tools, Defender—slows things down and interrupts the workflow when I’m trying to run quick searches or investigations. Better documentation or easier mapping to familiar query formats would help a lot.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike gives us a strong, lightweight, and effective layer of endpoint protection. It improves our visibility, strengthens our defenses, and helps us detect and respond to threats much faster. It also makes vulnerability management more efficient, which is a big plus for maintaining a secure media environment.

**Official Response from Emily Crouch:**

> Thank you for sharing your positive experience with CrowdStrike Falcon Endpoint Protection Platform! We're thrilled to hear that you find the platform dependable, lightweight, and accurate in threat detection. We appreciate your feedback regarding the query language challenge. We understand the importance of a user-friendly interface and will certainly take your suggestions into consideration for future improvements. If you need any assistance or further clarification on the query language or any other aspect of the platform, please don't hesitate to reach out to our support team. We're here to help ensure you have a seamless experience with CrowdStrike Falcon. 

Thank you for choosing us to enhance your endpoint protection and vulnerability management!

  ### 7. Effortless Deployment and Powerful AI-Driven Protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Manoj J. | Customer Support Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 26, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

It has Easy deployment and management. Single Lightweight agent. As it has AI/ML powered for real-time scanning it stops modern attacks, suspicious behavior, providing highly accurate detection with a low rate of false positives. It has lot of integration option with third-party tools.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

- It is not weakness but Console can be very hard to understand in the beginning but its very user friendly.
- Due to its continuous monitoring platform can generate lot of high volume alerts. But later on we can fine tune policy to whitelist false positives so its not an issue.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

- CrowdStrike stops modern fileless attacks, exploits, and behavioral tactics with help of its NGAV powered by AI/ML as it focuses on behavior of a process rather than just file hash.
- CrowdStrike solves the problem of Lack of visibility with its detailed endpoint activity along with process tree. This gives analysts instant, deep visibility and ability to search all endpoint for related activity.
- CrowdStrike solves the problem of CPU utilization issue as its lightweight agent is connected to CrowdStrike cloud. This eliminates the need of heavy on-premise infrastructure. It ensures minimal performance impact on end-user.
- Benefits from above points: Superior breach prevention, Faster incident response, Lower operation cost and complexity, Improved user productivity.

  ### 8. Cloud-Native Security That Delivers Fast, Powerful Protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Anup P. | Customer Support Engineer, Security and Investigations, Small-Business (50 or fewer emp.)

**Reviewed Date:** November 26, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Its cloud-native architecture enables fast deployment and low system overhead.
Real-time protection works effectively without relying on heavy local agents.
Behavior-based Detection helps identify both known and unknown threats.
Integrated threat intelligence strengthens overall security effectiveness.
Continuous  monitoring supports quick investigation and response.
The centralized console is user-friendly and simplifies endpoint management.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The platform can be expensive for an small organisation,since the program is solution as premium solution,
Alert volume can be high until the system is turned properly,which can initially create more noise for security team.
Some integrations and advanced features require additional setup or expertise.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon Endpoint Protection Platform tackles the challenge of advanced cyber threats such as malware, ransomware, and fileless attacks by offering real-time detection and prevention. Its behavior-based monitoring, combined with integrated threat intelligence, allows for the rapid identification of both known and unknown threats. For me, this means my endpoints stay secure, the risk of breaches is minimized, incident investigations are more straightforward, and I can respond to potential threats more quickly and effectively.

**Official Response from Emily Crouch:**

> Thank you for sharing your detailed feedback on CrowdStrike Falcon Endpoint Protection Platform. We're thrilled to hear that you appreciate the platform's cloud-native architecture, real-time protection, behavior-based detection, and user-friendly console.

We understand your concerns about the cost for small organizations, alert volume, and the need for additional setup for integrations and advanced features. We continuously strive to improve our offerings and provide value to all our customers.

  ### 9. Real-Time Threat Detection Without Slowing Down Systems

**Rating:** 5.0/5.0 stars

**Reviewed by:** Vishal D. | Sales Manager, Small-Business (50 or fewer emp.)

**Reviewed Date:** November 19, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

1. The platform picks up a suspicious behavior in real time without slowing down systems.
2. It doesn't come up with very bulky signatures or heavy updates.
3. Their intel consistently helps identify advanced attack early, especially fileless or behavioral - based threats.
4. Everything runs from the cloud, so endpoints stay fast and protected.
5. Deployment is surprisingly very easy, because the lightweight agent installs quickly.
6. Falcon integrates well with SIEM, SOAR tools, and other security platforms.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

1. The solution is powerful but can feel expensive for smaller teams and organizations with tight budgets.
2. Advanced features like threat hunting require some experience to fully leverage.
3. The interface is packed with features, which takes time for new users to get used to it.
4. Customer support responses during busy periods, can take longer than expected.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

1. CrowdStrike Falcon blocks ransomware, malware and fileless attacks at the behavioral level, which keeps my endpoints safe even when threats try to bypass traditional antivirus.

2. Because it's cloud-native, it protects devices without heavy scans or signatures, keeping user machines fast and productive.

3. The platform correlates alerts automatically, helping me understand the root cause quickly instead of manual digging through logs.

  ### 10. Continues to be leader in security

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brian M. | Assistant Project Manager, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2023

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

We switched to crowdstrike complete and now our security is completely taken care of. Throughout the last year we have seen the security system work as expected when faced with threats. I am confident in our protections.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

My only complaint for crowdstrike would be to connect the support page with the general login. Having two separate logins is cumbersome.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

We manage many users over an array of different devices. Crowd strike provides us with a universal antivirus platform that keeps everything safe. This has made the IT department more productive as they can now focus there energy on other things.

  ### 11. Excellence in Workflow Automation and Asset Management

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Retail | Enterprise (> 1000 emp.)

**Reviewed Date:** October 22, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The most useful features of CrowdStrike are its workflow automation, host containment, and asset management capabilities. CrowdStrike’s most valuable features include workflow management, host containment, and asset management.workflow automation, host containment, and asset management

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

We are using the most user-friendly option, and I don't think anyone would dislike it.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

We are working on security features focused on host blocking, threat monitoring, IOA analysis, workflow integration, and automated script execution. Our work focuses on enhancing security through host blocking, threat monitoring, IOA detection, workflow integration, and script automation. We are developing advanced security features, including host containment, real-time threat monitoring, IOA-based detection, workflow automation, and script execution capabilities.

  ### 12. Crowdstrike Helps Your Technical Health, and Mental Health

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Consumer Goods | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 09, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The fact that the platform is so insanely robust and granular is an absolute lifesaver. I can make my rules ridiculously complicated if I want to, or I can set up more of a “set and forget” approach that I don’t have to think about again until something actually triggers. The detection rating feels unmatched—the platform gathers more threat intelligence than almost anyone else in the world—and that has been a complete game changer for us. No more spending all day hunting through false positives, and no more overly complex reports that don’t make sense and are frustrating to explain to management. Everything is there, it’s ready, and it’s exportable. You can do just about anything with Crowdstrike, and when I say that, I quite literally mean it.

If you want to sleep at night knowing your organization is protected with what I consider the best protection available on the market, I’d strongly suggest going with Crowdstrike. I’m personally sleeping better at night, and members of my team are far less stressed on weekends—we’re no longer dreading a call that our infrastructure has been compromised.

We use this as our main source of protection across our entire enterprise.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

It's a complex beast to master - it takes time. That's not even really a dislike, it's more of a fact. If you want to be able to fully understand the product, and use all of the features to their fullest, you need to sit down, and do some training and education. Anything worth using though, takes time to master.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

The ever present issue of a breach - if we are breached, we know that response and remediation will take place in minutes, not hours or days. You can do everything right, but the end user is always going to be your weakest link, and the juciest target. However, while users maybe juicy targets, Crowdstrikes Spotlight Vulnerability Mangement platform gives me the ability to patch Windows on the fly, and show me what other third programs need to be patched as well. Not only that, but the remediation time frame window reports, and the general reporting ability of Spotlight is amazing. The reports are straightforward and easy to read for non-technical members of management. They aren't focused on flashy statistics - they're focused on giving you a no frills picture of what's going on in your environment.

  ### 13. Accurate Threat Detection with Centralized Endpoint Visibility

**Rating:** 5.0/5.0 stars

**Reviewed by:** Varma B. | Assistant IT Managr, Enterprise (> 1000 emp.)

**Reviewed Date:** January 16, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon endpoint protection platform provides accurate detection and timely warnings of threats. It also offers centralized management and clear visibility across hosts, making it easier to monitor and manage endpoints from one place.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Setting up the API connectors for Log Management in the Next-Gen SIEM is a bit complicated but support is always there to help with that

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Legacy antivirus tools often can’t reliably detect or stop modern threats such as ransomware, fileless malware, zero-day attacks, credential theft, and lateral movement, largely because they tend to depend on signature-based detection and periodic scans.

Falcon Solution: It uses AI-powered detection, behavioral analytics, and next-gen antivirus capabilities to identify and block threats in real time

  ### 14. Real-Time AI Threat Detection with Strong Endpoint Visibility

**Rating:** 5.0/5.0 stars

**Reviewed by:** Akash Y. | Cyber Security Engineer, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 28, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

It is real time threat detection using AI and machine learning. It provides strong visibility across all endpoints, works without showing down systems, and helps detects & respond to threat quickly from a single cloud based console.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

It can be difficult to use for new users because of its complex interface. Some features require advanced knowledge to configure properly, and alert tuning can be taking time.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike falcon solves the problem of detecting and stoppings cyber threats quickly and accurately. It uses cloud-based analytics and AI to monitor and protect our devices from malware, ransomware and other attacks. It continuously monitors endpoint activity and detects suspicious behavior in real time.

  ### 15. Feature-Rich EDR

**Rating:** 5.0/5.0 stars

**Reviewed by:** Daniel S. | Security Engineer Jr, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 07, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

It has features you don't see in other technologies; it's a fantastic EDR and offers plenty of options for configuration and customization—something that's difficult to find in other technologies.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The learning curve is steep, and there are many modules that change frequently

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Implementing better security policies to strengthen teams against potential breaches, using RTR connections to deploy scripts, and the new approach CrowdStrike is taking with SIEM help provide greater visibility into events as they occur.

  ### 16. Cloud-Native, Intuitive Dashboards and Lightweight Agents—A Solid Endpoint Security Tool

**Rating:** 3.5/5.0 stars

**Reviewed by:** Dhruv V. | DevOps Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** May 05, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I think its cloud native architecture and intuitive dashboards are very helpful to manage endpoint security and also their agents are also lightweight so no need of performance drop on endpoints

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I have seen other products also so i think their pricing are bit higher than competitors so smaller teams with limited budgets not able to use this and also initial setup is also bit complex for new users

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It solves our bigger problem of our cloud security posture we have improved a lot with this platform and also it helps us to quickly solve the incidents happen on endpoints

  ### 17. Excellent Visibility and Investigation Tools

**Rating:** 5.0/5.0 stars

**Reviewed by:** Liliana K. | Cybersecurity Threat Management Specialist, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 12, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The Kestrel Lead Generator has got to be the best development CrowdStrike has put out so far. This feature has saved me so much time in detection investigations!

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The fact that their query language is only slightly different than SQL. If you know SQL and jump into this platform, CQL is similar enough but different enough to slightly annoy you.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Visibility and quick detection/incident resolution within each endpoint. It's always beneficial when mean time to resolution is reduced and CrowdStrike has helped us get our time down and feel better about the security of our environment.

  ### 18. Best EDR Tool in the industry

**Rating:** 5.0/5.0 stars

**Reviewed by:** Paul J.

**Reviewed Date:** June 17, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike is the best EDR I’ve used. It provides incredible insight into our large number of endpoints on a granular level including Processes, Command Line Arugments, Network traffic, etc.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The Forensics Module is brilliant for rapid triage across our environment but I don’t like playing middle man in AES. I’d rather have access to the actual artifacts.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

we have a large number of endpoints in the environment and CS provides a single pane of glass across the board.

  ### 19. Exceptional Prevention and Seamless Integration

**Rating:** 4.5/5.0 stars

**Reviewed by:** Kartik C. | Assistant Consultant, Information Technology and Services, Enterprise (> 1000 emp.)

**Reviewed Date:** January 21, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I find the standout feature of CrowdStrike Falcon Endpoint Protection Platform to be its blazing-fast threat detection powered by cloud AI, which consistently outperformed our old tools. Beyond the cloud AI, I also appreciate Falcon's managed threat hunting and seamless integrations. The 24/7 expert threat detection is excellent at uncovering stealthy threats that our team might miss. Additionally, its lightweight agent and AI prevention have fixed our performance issues from old antivirus software. The initial setup was straightforward, even with our large scale, taking about 2-3 weeks for over 10,000 endpoints. Overall, I rate Falcon a solid 9 out of 10 because of its exceptional prevention, scalability, and unmatched value.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

While Falcon excels overall in my firm, some tweaks can make it better like alert tuning challenges when there is a flood of alerts. If there is a custom rule to configure those, that would be great. Some OOTB policies for software dev workflows would be a cherry on top. Role-based dashboard customization which powers different dashboards for devs and full forensics for hunters.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon tackles endpoint security headaches from ransomware threats to compliance demands, offering fast threat detection with cloud AI, 24/7 expert threat hunting, and seamless integration.

  ### 20. Robust Security with Excellent Visibility

**Rating:** 4.5/5.0 stars

**Reviewed by:** Lata A.

**Reviewed Date:** January 21, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I like CrowdStrike Falcon's lightweight, cloud-native design and strong threat detection. It runs quietly in the background without slowing down systems but is extremely effective at catching known and unknown threats, including fileless attacks. The real-time visibility and detailed threat intelligence make investigations easier, and the console is intuitive once you get used to it. It provides a high level of confidence in endpoint protection without adding operational complexity. The initial setup was easy, requiring only the installation of a lightweight agent, and endpoints were protected almost immediately. The cloud-based console meant there was no on-prem infrastructure to manage, and most default policies worked well out of the box, allowing the team to get up and running quickly. I also appreciate its excellent integration with SIEM tools, identity platforms, and ticketing systems to streamline monitoring, investigations, and incident response workflows. Switching from a traditional antivirus solution to CrowdStrike Falcon gave us better visibility, faster detection, and stronger protection against modern threats.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Reporting and alert tuning can feel complex for new users, and advanced features are costly. Offline protection and granular policy customization could be improved. Reporting and alert tuning have a steep learning curve and need better templates. Advanced features are expensive and would benefit from more flexible pricing.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

I use CrowdStrike Falcon for real-time threat detection, prevention, and response. It solves the challenge of detecting advanced threats and gives clear endpoint visibility. It reduces response time, eliminates on-prem infrastructure, and simplifies threat investigation with centralized insights.

  ### 21. Lightweight, Invisible Agent with Powerful One-Click Network Containment

**Rating:** 4.0/5.0 stars

**Reviewed by:** Bibek M. | IT Admin, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 19, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The best part is definitely the single, lightweight agent. Unlike our old antivirus, which used to slow down laptops and require constant reboots for updates, Falcon is almost invisible to end users. I also really love the 'Network Containment' feature being able to isolate an infected machine from the network with one click (while still keeping the connection to the console) is a huge stress reliever for our team.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

It’s a 'premium' product with a premium price tag. If you’re a smaller shop, it’s hard to justify the cost compared to something like SentinelOne or even Defender for Business. Also, the learning curve is pretty steep. The query language (FQL) is powerful but it isn't exactly intuitive—you really have to spend time in the documentation to do anything beyond basic alert checking. I also wish the reporting templates were a bit more flexible without having to export data elsewhere.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

The biggest problem Falcon solved for us was 'alert fatigue.' Before switching, we were drowning in notifications from our legacy AV that mostly turned out to be false positives. Falcon’s behavioral AI is much more accurate—it filters out the noise so when my team gets an alert, they actually take it seriously. It’s also saved us a ton of time on deployment. We can push the agent to hundreds of remote machines without a reboot, which means no more scheduling late-night maintenance windows just to update our security.

  ### 22. Superior Endpoint Protection with Intuitive Interface and Rapid Threat Detection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Christopher S. | IT Manager, Enterprise (> 1000 emp.)

**Reviewed Date:** December 03, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon delivers superior endpoint protection through a combination of lightweight agents, rapid cloud-based detection, and highly accurate behavioral analytics.  The platform excels at identifying threats early, preventing execution, and providing deep visibility into what occurred on the endpoint.  The interface is intuitive, making it easy to investigate alerts, understand the root cause, and take action quickly.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

There isn’t much to dislike.  Pricing can occasionally be a barrier for smaller organizations, and some advanced features (Falcon Insight, identity protection, etc) require additional licensing to unlock their full potential.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon provides robust, always-on endpoint protection that significantly reduces the risk of malware, ransomware, and credential-based attacks.  Because the platform reliably detects and prevents threats before they escalate, it allows our team to shift focus from reactive security work to key projects and strategic deliverables.

**Official Response from Emily Crouch:**

> We're glad to hear that CrowdStrike Falcon's endpoint protection platform has been beneficial for your organization by reducing the risk of malware and ransomware attacks. We understand the importance of balancing security needs with budget considerations, and we're continuously working to provide options that meet the needs of organizations of all sizes.

  ### 23. Lightweight, Cloud-Native Endpoint Security with Powerful AI Threat Detection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** January 15, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Its lightweight, cloud-native design that delivers strong security without slowing down systems. It provides real-time, AI-driven threat detection that effectively stops advanced attacks, while the centralized dashboard gives clear visibility across all endpoints and makes investigation and response easier. Deployment and management are straightforward, and the platform scales well, making it reliable and efficient for enterprise environments. Good support

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

What I dislike about CrowdStrike Falcon Endpoint Protection Platform is that it can be expensive, especially for small or budget-conscious organizations.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon Endpoint Protection Platform solves the problem of detecting and stopping modern cyber threats that traditional antivirus tools often miss, such as ransomware, fileless attacks, and zero-day malware. It does this by using cloud-native architecture and AI-driven threat detection, giving real-time visibility across all endpoints and enabling faster investigation and response. This benefits me by strengthening overall security, reducing the risk of breaches, and making it easier to manage and respond to incidents across the organization without heavy infrastructure or performance impact on devices.

  ### 24. Hunting using Falcon CrowdStrike

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Telecommunications | Enterprise (> 1000 emp.)

**Reviewed Date:** July 26, 2022

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The telemetry can be leveraged for Threat Hunts. If logs are available in backwaters, it is easy to identify the root cause by correlating the process id.  The installed Applications module acts as an organisation's inventory to identify and eliminate malicious/unwanted apps if needed

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

It would be great if the Advanced search results could differentiate between servers and workstations

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Blocks Malicious/suspicious processes based on Signature/Machine Learning
New executables without any signatures/Inbuilt exe's are blocked if spawning unnecessary process based on Machine Learning
The RTR feature helps an Analyst grab the files required for Analysis and isolate device if Host is compromised

  ### 25. Cloud-Native Security Solution

**Rating:** 4.5/5.0 stars

**Reviewed by:** Pankaj K. | Manager Cyber Security, Security and Investigations, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 16, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I like the cloud-native architecture of CrowdStrike Falcon Endpoint Protection Platform, as it eliminates the need for on-premise management with hardware. The lightweight agent and the fact that a single agent manages both EPP and XDR is a big plus for me. It's always up-to-date, which is great. Fast incident investigation is another feature that I find beneficial. I also appreciate the provision with the tenant provided by CrowdStrike, mass deployment with MDM solutions, and policy creation according to best practices.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The solution is very good, but there are support challenges I'm facing. When I raise a ticket in the support portal with a priority 1 issue, there's a response delay and I often have to provide multiple logs.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

I use CrowdStrike Falcon Endpoint Protection Platform for agent connectivity and analyzing threats. I like its cloud-native architecture, lightweight agents, and fast incident investigation.

  ### 26. Powerful Cloud-Native EDR with Seamless Performance

**Rating:** 4.0/5.0 stars

**Reviewed by:** BENOIT C. | IT MANAGER, Enterprise (> 1000 emp.)

**Reviewed Date:** January 13, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I appreciate its cloud-native architecture and the single lightweight agent that provides powerful EDR capabilities without impacting system performance.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

What I dislike is the high licensing cost and the steep learning curve required to master its complex management console.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It eliminates security silos and stops breaches using AI-driven detection while maintaining peak system performance.

**Official Response from Emily Crouch:**

> Thank you for sharing your feedback on CrowdStrike Falcon Endpoint Protection Platform. We're thrilled to hear that you appreciate its cloud-native architecture and powerful EDR capabilities. We understand your concerns about the licensing cost and the learning curve for the management console. We continuously strive to provide value for our customers and offer support to help navigate any challenges you may encounter. If you need assistance with the management console or have any questions about licensing, please feel free to reach out to our support team. We're here to help ensure you get the most out of our platform. 

  ### 27. Strong Real-Time Protection That’s Easy to Manage

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sachin D. | technical support engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** February 10, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon provides strong, real-time protection against modern cyber threats while being easy to manage. It uses cloud based intelligent to detect and stop malware, ransomware, and advanced attack without slowing down systems.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon is that it can be expensive especially for smaller team and organizations. Some advanced features require additional modules, which increases overall cost.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It solves the problem of advanced and fast-moving cyber threats that traditional Antivirus tools often fail to detect. It helps protects system from malware, ransomware, and suspicious behaviour continually monitoring endpoints and stopping threats in real-time.

  ### 28. CrowdStrike Falcon: Protecting Endpoints with Intelligence

**Rating:** 5.0/5.0 stars

**Reviewed by:** Aishwarya  R. | Senior Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 14, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

1. Cloud-Native Architecture
2. AI-Driven Threat Detection
3. Centralized Visibility and Response
4. Rapid Incident Response
5. Scalable for Any Environment
6. Continuous Threat Intelligence
CrowdStrike Falcon is its powerful, proactive threat detection and response, delivered through a lightweight, scalable, cloud-native platform that gives security teams deep visibility and control.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Cost, Learning Curve, Alert Volume, Custom Integrations

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

1. Advanced Threat Protection
2. Real-Time Endpoint Visibility
3. Rapid Incident Response
4. Proactive Threat Hunting
5. Simplified Management at Scale
CrowdStrike Falcon solves challenges around malware, ransomware, visibility, incident response, and threat hunting, benefiting us by enhancing security, reducing risks, and improving operational efficiency across all endpoints.

**Official Response from Emily Crouch:**

> We're glad to hear that you appreciate the cloud-native architecture, AI-driven threat detection, and centralized visibility and response features of CrowdStrike Falcon. These are key components of our platform that help provide powerful, proactive threat detection and response.

  ### 29. Strong and Reliable Endpoint Protection.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Harsh K. | Technical Consultant, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The improved AI-driven threat correlation and automated response workflows make it faster to detect and contain sophisticated attacks with less manual effort.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Alert noise and interface complexity could still be reduced to help teams prioritize incidents more efficiently.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It addresses key challenges such as detecting advanced cyberattacks (e.g., ransomware and malware) in real time, while also reducing our reliance on multiple, complex security tools by offering a unified, cloud-based platform. This helps us improve threat visibility, respond to incidents faster, and boost overall security efficiency, all while keeping system performance lightweight.

  ### 30. Easy Setup and Smooth Performance, but Room for Improvement

**Rating:** 3.0/5.0 stars

**Reviewed by:** Shamir A. | IT generalist, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 30, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Setting up the product is very easy and straightforward. It begins working almost immediately and generally has little impact on system performance. The cloud console is also user-friendly and, in my experience, more pleasant to use than those offered by some competitors.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Being fully cloud-based has its advantages and drawbacks. The main downside is the limited functionality available when offline, which leaves endpoint agents with few options in situations like remote work locations or while traveling on airplanes. Additionally, the device control features are not as robust as I expected, especially considering the price, which is disappointing.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

This product offers consistent endpoint protection along with certain features for managing device fleets.

**Official Response from Emily Crouch:**

> We're pleased to hear that you found the setup process easy and that the product has had a minimal impact on system performance. We understand your concerns about the limitations of the cloud-based functionality and the device control features. Your feedback is valuable to us as we continue to improve our product. Thank you for taking the time to share your experience.

  ### 31. Always surprised by the capabilities

**Rating:** 5.0/5.0 stars

**Reviewed by:** Phil H. | Owner

**Reviewed Date:** June 17, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The CrowdStrike falcon platform, above protecting the endpoint, is quickly becoming our source of truth about all things endpoint related. From patch compliance to remediation.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Some of the menus are feeling dated and clunky, with no possibility of meaningful customisation.  We’re ready for a kestrel experience

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

This is currently aiding us resolve Unpatched Windows hosts, with a view to moving this into other OS types

  ### 32. Robust Security with AI Precision

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** November 26, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I like that the AI/ML detection provides more granular level information and results in fewer false positive alerts. I also appreciate how it provides end-to-end flow information for each alert, making it easier to navigate and identify which events need attention. The rapid deployment capability is impressive too, as rapid deployment was possible for us.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I find adding hash values (IOC) and IOA to have limited functions. Specifically, we cannot add more than 200,000 IOC, and we can only monitor them for a lesser period.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

I use CrowdStrike Falcon Endpoint Protection Platform to protect against zero-day attacks and provide antimalware protection. Its AI/ML detection gives detailed information and reduces false positives, offering end-to-end flow info to navigate critical alerts.

  ### 33. Excellent Real-Time Threat Detection with a User-Friendly Dashboard

**Rating:** 4.5/5.0 stars

**Reviewed by:** chetan  s. | Search Engine Optimization Executive, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 05, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Its lightweight agent, real-time threat detection, and cloud-native architecture provide excellent visibility into endpoints. It helps identify and stop advanced threats quickly, and it’s also easy to deploy and manage.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Some advanced features take time to learn for new users, especially for smaller IT teams that don’t have dedicated security expertise.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It helps us solve challenges related to endpoint security, threat detection, and incident response across our organization.

  ### 34. Lightweight, Fast EDR with Real-Time Cloud Threat Intelligence

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Education Management | Small-Business (50 or fewer emp.)

**Reviewed Date:** May 19, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon stands out for its lightweight, single-agent architecture, real-time cloud-based threat intelligence, and fast EDR capabilities, all with almost no performance impact.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The licensing cost is high, and the noisy detections create alert fatigue. Offline protection also feels limited when endpoints lose cloud connectivity.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It helps stop breaches by bringing AV, EDR, and threat hunting together in a single cloud-native agent. This cuts detection time from days to minutes and reduces the overall incident-response workload.

  ### 35. Strong Detection and AI-Driven Threat Protection, Though There’s Room to Improve

**Rating:** 3.5/5.0 stars

**Reviewed by:** Het T. | Employer, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 07, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I like the best feature about falcon is their strong detection capabilities and ai driven threat detection system its too good features

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I think tuning for removing noice is hard and it takes too much effort and also their advance feature required more modules so its complex and also cost is high for that

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It solves our endpoint security on remote machines very well which traditional anti virus software may miss and also management of remote machines are very efficient

  ### 36. A must to have EDR solution in the Infrastructure

**Rating:** 4.0/5.0 stars

**Reviewed by:** Vijay T. | Infrastructure Engineering Advisor, Enterprise (> 1000 emp.)

**Reviewed Date:** January 06, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon have user friendly dashboard, have a stable agent, gives less false positives, provides detailed analysis of the incident and it is very feasible to integrate with other tools.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I don't see something to dislike other than the bizarre incident that happened last year. Other than that cost is a factor to dislike, but it is worth the money I would say.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

With the traditional antivirus going obsolete, EDR solution is what is replacing those and with CrowdStrike threat analysis feature, it is giving very much detailed analysis for any threats, proactive alerts and ultimately creating a safe and secure infrastructure.

  ### 37. Peace of Mind with 24/7 Threat Detection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brian H. | Vice President, Information Technology &amp; Security

**Reviewed Date:** March 25, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I love that with CrowdStrike Falcon Endpoint Protection Platform, I don't have to worry about my endpoints. If there's a problem, they take care of it and notify me, which allows me to sleep much better at night knowing that CrowdStrike Falcon has our back. The platform is worth every penny. It's very easy to set up, and we were able to automate the deployment of the agent, making it very helpful for our team.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Absolutely nothing!

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

I use CrowdStrike Falcon Endpoint Protection Platform for threat detection, 24/7 endpoint monitoring, and remediation, allowing us to avoid hiring a round-the-clock internal staff.

  ### 38. Powerful and Reliable Endpoint Protection for Modern SOC Operations

**Rating:** 4.5/5.0 stars

**Reviewed by:** Deepanshu P. | SOC Analyst, Security and Investigations, Small-Business (50 or fewer emp.)

**Reviewed Date:** September 17, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

What I like best about CrowdStrike Falcon is how fast and reliable it is when detecting threats. Just recently, it flagged a suspicious PowerShell script running on one of our endpoints. Within minutes, we had a full timeline of the activity, including the parent process and command line details. That helped us respond quickly and avoid any impact.

As a SOC analyst , I also appreciate how easy it is to navigate. The interface is clean, and the alerts are well-organized, which makes it easier to learn and understand real-world attack patterns. It doesn’t just throw alerts—it gives context, which is super helpful when you're still building your skills.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

While CrowdStrike Falcon is a powerful and reliable platform, some features can be a bit overwhelming for new users. It takes time to get used to the interface and understand how to use all the modules effectively. Also, the filtering options in the investigation tab could be improved—sometimes it's hard to narrow down alerts quickly when you're dealing with a large volume.

A helpful improvement would be to make the search and filtering more flexible and user-friendly, especially in the event timeline and process tree views. That would make investigations faster and smoother, especially for SOC teams handling multiple incidents.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon helps us solve one of the biggest challenges in cybersecurity: detecting and responding to threats in real time across multiple endpoints. Before using Falcon, it was hard to get visibility into what was happening on devices, especially during suspicious activity. Now, we can track everything—from process execution to network connections—with detailed timelines and context.

As a SOC analyst trainee, this has been a huge benefit. It allows me to learn from real incidents while contributing to investigations. The platform also helps reduce false positives, so we can focus on actual threats instead of wasting time chasing noise. Overall, it’s made our team faster, more efficient, and more confident in our response.

  ### 39. Crowdstike Falcon EDR: A SOC Analyst 's Hands-On review

**Rating:** 5.0/5.0 stars

**Reviewed by:** Uday  P. | SOC Analyst, Security and Investigations, Mid-Market (51-1000 emp.)

**Reviewed Date:** September 26, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

As a SOC Analyst, I really value CrowdStrike Falcon’s real-time threat detection and visibility. The threat graph and behavioral analytics make it easier to investigate incidents and correlate activities quickly. I also like how lightweight the agent is—it doesn’t slow down endpoints, and updates are seamless. The dashboard is intuitive, and the detailed telemetry gives deep insights for hunting and responding to threats.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The main drawback is the steep learning curve for new analysts, especially when diving into advanced hunting queries. Some of the alerts can be very noisy, requiring fine-tuning to avoid false positives. The pricing is also on the higher side compared to other EDR solutions, which might be challenging for smaller organizations.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon helps us detect and respond to endpoint threats in real-time. It provides detailed telemetry and behavioral analytics that improve our investigation speed and reduce dwell time. The cloud-based architecture ensures scalability and seamless updates. Overall, it has strengthened our SOC capabilities by giving us better visibility, faster containment, and reduced risk of data breaches.

  ### 40. CS deployment is very straight forward, they are not only an endpoint but also a top security firm

**Rating:** 5.0/5.0 stars

**Reviewed by:** Raffy B. | Senior IT Team leader for System and Network / SECOP, Mid-Market (51-1000 emp.)

**Reviewed Date:** September 25, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The ease of implementation stood out. Deployment was fast with minimal disruption. The interface is intuitive, and the lightweight agent doesn’t impact system performance. Its broad feature set (threat detection, EDR, vulnerability management) is robust, and the frequency of use is daily since it runs seamlessly in the background. Customer support has been responsive and knowledgeable, and integration with other security tools has been straightforward.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The cost can be somewhat concerning, particularly when considering the price of additional modules such as IAM and SOAR. I hope they will consider offering free access for at least 50 to 100 devices to allow users to test their features, as this could encourage customers like me to take their product more seriously. Overall, I like their product and believe it is worth the investment.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon addresses the challenge of advanced endpoint protection by detecting and stopping threats that traditional antivirus solutions often overlook. It gives us real-time visibility into attacks, suspicious activities, and vulnerabilities across all our endpoints, whether on-premises or remote.
This has led to a noticeable reduction in security incidents, less downtime, and better compliance with internal and regulatory security standards. Since it is cloud-native, we avoid the need to maintain heavy infrastructure, and updates are applied seamlessly. As a result, our IT and security teams now spend less time responding to incidents and can focus more on proactive defense.

  ### 41. All-in-One protection with easy handling

**Rating:** 4.5/5.0 stars

**Reviewed by:** Marcel M.

**Reviewed Date:** January 16, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I appreciate that all CrowdStrike modules are unified in one platform. I particularly like the auto-update function of the endpoint sensor and the ease of operation and administration. The platform requires little CPU and RAM, which is very helpful. I also find it good that the analyst has many options to respond to attacks and receives numerous log files. The initial setup was very easy because the platform is intuitive and there are many guides available.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The UI is partially overloaded and not modern enough, sometimes the UI reaches its limits.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

I use CrowdStrike Falcon Endpoint Protection Platform for the detection of next-generation attacks with integrated threat response. All CrowdStrike modules are unified in one platform. The auto-update function, easy operation and administration, and low CPU and RAM usage are useful.

  ### 42. User-Friendly with Comprehensive Detection Insights

**Rating:** 5.0/5.0 stars

**Reviewed by:** sudha y. | customer support engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** November 26, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

The software is user-friendly and provides comprehensive information regarding detections and incidents. Implementation is straightforward, and the customer support team is responsive and helpful.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The ON-DEMAND SCAN feature can be somewhat troublesome to use on the platform. It scans only PE files.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Traditional antivirus (AV) solutions, which typically rely on signature-based detection, often have difficulty keeping up with advanced threats such as zero-day exploits, fileless malware, ransomware, and other sophisticated attack methods. Falcon’s next-generation antivirus (NGAV) engine uses machine learning (ML) and behavioral analysis to identify and stop even threats that have not been seen before. This approach results in stronger protection with fewer vulnerabilities. Faster detection and containment also help minimize potential damage and reduce downtime.

**Official Response from Emily Crouch:**

> We're pleased to hear that CrowdStrike Falcon's next-generation antivirus engine is effectively addressing the challenges of traditional AV solutions and providing stronger protection with faster detection and containment. We're dedicated to continuously enhancing our platform to meet the evolving threat landscape.

  ### 43. Robust IT Security Solution with Comprehensive Protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Amjith N. | Manager IT, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 25, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

This is a very good solution that provides nearly all the necessary security measures for IT systems, effectively protecting them from unauthorized access. The solution is robust and stands out as a dominant force in IT security protection.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I wouldn't say I dislike it, but I do have some suggestions for improvement, particularly regarding the user interface of the dashboards and the technical language used throughout. It would be helpful if simpler technical terms were used, making it easier for non-technical people to understand.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It has resolved most of my IT security concerns through features like EDR, XDR, identity protection, VA, and many others. We have confidence in CrowdStrike's capabilities and the range of features it offers.

  ### 44. Probably the most effective and real time Endpoint Protection Platform with pro detection capabilities

**Rating:** 4.5/5.0 stars

**Reviewed by:** Atanu M. | Security Consultant, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 06, 2024

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Falcon's detection and protection capabilities have improved more than before. All this with very minimal CPU demands.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

Pricing point could be improved. Also it does not really allow much options in terms of on prem data requirements since it is mostly a cloud heavy platform. Most tools have robust on-prem support as well.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

Any suspicious activities or process is detected immediately and terminated. For example, i tried to download an installation file of an application . Crowdstrike immediately alerted about it and even closed the browser session to ensure the activity is not proceeded.

  ### 45. Exception in malicious behaviour patterns

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software

**Reviewed Date:** June 22, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

It can catch great 0 day vulnerability based on behavioural patterns. No performance impact on the device.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I don’t like reporting. Its a bit clunky and not very flexible.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It helped to block few worms across engineering team where ppl are using open source tools and dint check the versions.

  ### 46. Lightweight Single-Agent Solution with Rapid Threat Hunting

**Rating:** 4.0/5.0 stars

**Reviewed by:** Ayush Kumar R. | Project management, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 18, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

It's lightweight, single agent architecture and rapid threat hunting capabilities

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The cost is high and it is also quite complex and difficult mainly for newer teams and it sometimes generate false positives

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

It helps solve problems related to advanced cyberattacks and also provides minor security alerts, such as system slowdowns and operational silos. Falcon unifies various tools, offers faster remedies, and is user-friendly, with better overall visibility.

  ### 47. Comprehensive Endpoint Protection with Real-Time, AI-Powered Threat Detection

**Rating:** 4.0/5.0 stars

**Reviewed by:** Oren A. | Infrastructure Security Manager, Mid-Market (51-1000 emp.)

**Reviewed Date:** February 06, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

CrowdStrike Falcon provides comprehensive endpoint protection with advanced threat detection capabilities. The real-time monitoring and AI-powered analysis help identify and respond to threats quickly. The cloud-native architecture makes deployment and management straightforward across our organization.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The pricing can be on the higher side for smaller organizations. Some advanced features require additional training to fully utilize. Occasionally, false positives can create extra work for the security team to investigate.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

CrowdStrike Falcon is solving our endpoint security challenges by providing real-time threat detection and response capabilities. It helps prevent ransomware attacks and other malware from compromising our systems. The platform benefits us by reducing the time to detect and respond to security incidents, minimizing potential damage and downtime.

  ### 48. Lightweight Agent with Powerful Threat Detection and Easy Deployment

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sandeep R. | Linux Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 26, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

yes, it's a very useful and very lightweight agent with CPU/RAM usage. A single agent handles  many functions. The threat detection is excellent it can detect file-less attacks, ransomware,zaro-day exploits, and behavior-based threats.

Itprovides strong visibility by showing every process, command, network activity, and the full attack timeline. The makes incident response and root-casue analysis much easier. Most importantly, it is very easy to deploy.

The customer supoort is supper friendly.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

The cost is relatively high, especially for small businesses, as licensing and premium modules can be expensive. Since it is cloud native, it relies heavily on cloud  connectivity. If network connectivity is poor or interrupted, some protection feature and visibility may be degrade.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

The crowdStrike falcon solve the problem of advanced cyber-attackes that traditionally antivirus tools cannot detect, It protect endpoints form malware, ransomware, file-less attacks.

This is beneficial becasue it reduces breach risj, store attacks early and improves incident reponse time.

**Official Response from Emily Crouch:**

> We're thrilled to hear that you find our Falcon Endpoint Protection Platform to be useful and effective in threat detection. We understand your concerns about cost and reliance on cloud connectivity, and we are committed to finding solutions to make our platform more accessible and resilient. Thank you for your feedback and for choosing CrowdStrike.

  ### 49. Satisfaction in using Crowdstrike products

**Rating:** 5.0/5.0 stars

**Reviewed by:** André B. | Especialista Cybersegurança Blue Team Sênior

**Reviewed Date:** May 18, 2026

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

Falcon Endpoint Security offers a range of sophisticated products that cover the full attack ecosystem on a host, and it includes a sensor that runs almost imperceptibly on the workstation.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I don’t have any complaints about this module. It feels very complete and well put together.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

As explained, it covers the entire protection ecosystem with just a single sensor, bringing a high number of benefits.

  ### 50. Lightweight Agent, Robust Security Insight

**Rating:** 4.5/5.0 stars

**Reviewed by:** Venkateshan G. | Senior Manager IT

**Reviewed Date:** November 25, 2025

**What do you like best about CrowdStrike Falcon Endpoint Protection Platform?**

I really appreciate how lightweight the agent of CrowdStrike Falcon Endpoint Protection Platform is; it's so unobtrusive that I barely notice it's running on my machines. Over the past three years, I haven't experienced any cybersecurity issues, which speaks volumes about the platform's effectiveness. Additionally, I find the platform’s use of sensor-based technology with Charlotte AI particularly impressive, as it aligns well with our strategic vision and roadmap. We are even considering adding more modules, like Identity and Access Management (IDAM), during upcoming renewals due to our positive experience so far.

**What do you dislike about CrowdStrike Falcon Endpoint Protection Platform?**

I find the real-time monitoring through the command-line interface to be a bit challenging and not as user-friendly as expected. The firewall functionality within CrowdStrike Falcon sometimes does not work as expected, which can be frustrating. I am also disappointed with the delayed response from customer support when I raise tickets. The initial setup and deployment were quite tough, especially managing the deployment manually on 3000 assets without an Active Directory push. This manual process, including setting group tags and tagging against each location, was very time-consuming.

**What problems is CrowdStrike Falcon Endpoint Protection Platform solving and how is that benefiting you?**

I find the product protects our assets from malicious attacks and provides machine insights while being lightweight and efficient with no cybersecurity issues encountered in three years.


## CrowdStrike Falcon Endpoint Protection Platform Discussions
  - [How do people see Firewall logs in  Crowdstrike . Is it Possible to view Firewall logs or requires a separated application to pull those into CS console.](https://www.g2.com/discussions/41319-how-do-people-see-firewall-logs-in-crowdstrike-is-it-possible-to-view-firewall-logs-or-requires-a-separated-application-to-pull-those-into-cs-console) - 1 comment, 1 upvote
  - [How to uninstall the CS sensor remotely from any host?](https://www.g2.com/discussions/34508-how-to-uninstall-the-cs-sensor-remotely-from-any-host) - 2 comments, 1 upvote
  - [Crowd strike have UBA??](https://www.g2.com/discussions/34282-crowd-strike-have-uba) - 1 comment, 1 upvote
  - [How does Falcon prevent work?](https://www.g2.com/discussions/how-does-falcon-prevent-work) - 1 comment
  - [Does CrowdStrike offer MFA?](https://www.g2.com/discussions/does-crowdstrike-offer-mfa) - 1 comment

- [View CrowdStrike Falcon Endpoint Protection Platform pricing details and edition comparison](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-07-21+17%3A28%3A33+-0500&secure%5Bsession_id%5D=d47b1548-8b22-40b8-9e49-7d4c8ae389f8&secure%5Btoken%5D=e4b5ac54c4d4483612eac505cf03120a7dac8af56e2cad61b8e9f5b27690a81f&format=llm_user)
## CrowdStrike Falcon Endpoint Protection Platform Integrations
  - [Abnormal Security](https://www.g2.com/products/abnormal-security-abnormal-security/reviews)
  - [Azure Active Directory Domain Services](https://www.g2.com/products/azure-active-directory-domain-services/reviews)
  - [CheckPoint](https://www.g2.com/products/checkpoint/reviews)
  - [Cymulate](https://www.g2.com/products/cymulate/reviews)
  - [Darktrace / NETWORK](https://www.g2.com/products/darktrace-network/reviews)
  - [Expel](https://www.g2.com/products/expel/reviews)
  - [FortiGate Cloud-Native Firewall (CNF)](https://www.g2.com/products/fortigate-cloud-native-firewall-cnf/reviews)
  - [FortiSIEM](https://www.g2.com/products/fortisiem/reviews)
  - [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)
  - [IBM Security QRadar NDR](https://www.g2.com/products/ibm-security-qradar-ndr/reviews)
  - [JumpCloud](https://www.g2.com/products/jumpcloud/reviews)
  - [Microsoft Azure Services](https://www.g2.com/products/microsoft-azure-services/reviews)
  - [Microsoft Entra ID](https://www.g2.com/products/microsoft-entra-id/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [Netskope One Platform](https://www.g2.com/products/netskope-one-platform/reviews)
  - [Okta](https://www.g2.com/products/okta/reviews)
  - [OneLogin](https://www.g2.com/products/onelogin/reviews)
  - [Palo Alto Cortex XSIAM](https://www.g2.com/products/palo-alto-cortex-xsiam/reviews)
  - [Palo Alto Networks Cloud NGFW](https://www.g2.com/products/palo-alto-networks-cloud-ngfw/reviews)
  - [Proofpoint Threat Response](https://www.g2.com/products/proofpoint-threat-response/reviews)
  - [Rapid7 Next-Gen SIEM](https://www.g2.com/products/rapid7-next-gen-siem/reviews)
  - [Seceon Open Threat Management Platform](https://www.g2.com/products/seceon-open-threat-management-platform/reviews)
  - [SecurityScorecard](https://www.g2.com/products/securityscorecard/reviews)
  - [ServiceNow IT Service Management](https://www.g2.com/products/servicenow-it-service-management/reviews)
  - [SISA ProACT](https://www.g2.com/products/sisa-proact/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)
  - [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews)
  - [Zscaler Internet Access](https://www.g2.com/products/zscaler-internet-access/reviews)

## CrowdStrike Falcon Endpoint Protection Platform Features
**Administration**
- Compliance
- Web Control
- Application Control
- Asset Management
- Device Control

**ServiceNow Apps**
- ServiceNow Integration
- Value

**Detection & Response**
- Response Automation
- Threat Hunting
- Rule-Based Detection
- Real-Time Detection

**Monitoring**
- Investigate
- Monitoring
- Misconfigurations
- Integrate
- Visability

**Platform Features**
- 24/7 support
- Proactive report alerts
- Application  control
- Proactive threat hunting
- Rapid response time
- Customizeable reports
- Managed Services

**Generative AI**
- AI Text Generation
- AI Text Summarization

**Generative AI**
- AI Text Summarization

**Agentic AI - User and Entity Behavior Analytics (UEBA)**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Agentic AI - AWS Marketplace**
- Autonomous Task Execution
- Multi-step Planning
- Cross-system Integration

**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Orchestration**
- Asset Management
- Security Workflow Automation
- Deployment
- Sandboxing

**Response**
- Resolution Automation
- Resolution Guidance
- System Isolation
- Threat Intelligence
- Incident Investigation

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**Network Management**
- Activity Monitoring
- Asset Management
- Log Management

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Functionality**
- System Isolation
- Firewall
- Endpoint Intelligence
- Malware Detection

**Analysis**
- Continuous Analysis
- Behavioral Analysis
- Data Context
- Activity Logging

**Management**
- Extensibility
- Workflow Automation
- Unified Visibility

**Remediation**
- Remediation
- Audit

**Automation Capabilities**
- Automated remediation
- Automated investigation
- AI Agents

**Agentic AI - ServiceNow Store Apps**
- Autonomous Task Execution
- Multi-step Planning
- Cross-system Integration
- Proactive Assistance

**Information**
- Proactive Alerts
- Malware Detection
- Intelligence Reports

**Records**
- Incident Logs
- Incident Reports

**Security**
- Data Security
- Data loss Prevention
- Security Auditing

**Incident Management**
- Event Management
- Automated Response
- Incident Reporting

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Analysis**
- Automated Remediation
- Incident Reports
- Behavioral Analysis

**Detection**
- Anomaly Detection
- Incident Alerts
- Activity Monitoring

**Analytics**
- Threat Intelligence
- Artificial Intelligence & Machine Learning
- Data Collection

**Personalization**
- Endpoint Intelligence
- Security Validation
- Dynamic/Code Analysis

**Management**
- Incident Alerts
- Incident Case Management
- Workflow Management

**Identity**
- SSO
- Governance
- User Analytics

**Security Intelligence**
- Threat Intelligence
- Vulnerability Assessment
- Advanced Analytics
- Data Examination

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Agentic AI - Security Information and Event Management (SIEM)**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Agentic AI - Extended Detection and Response (XDR) Platforms**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Generative AI**
- AI Text Summarization
- Generate Attack Scenarios
- Generate Threat Detection Rules
- Generate Threat Summaries

**Generative AI**
- AI Text Generation
- AI Text Summarization

**Services - Extended Detection and Response (XDR)**
- Managed Services

**Agentic AI - Threat Intelligence**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

## Top CrowdStrike Falcon Endpoint Protection Platform Alternatives
  - [Cynet](https://www.g2.com/products/cynet/reviews) - 4.7/5.0 (216 reviews)
  - [SentinelOne Singularity Endpoint](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews) - 4.7/5.0 (195 reviews)
  - [ThreatDown](https://www.g2.com/products/threatdown/reviews) - 4.6/5.0 (1,045 reviews)

