CrowdStrike Falcon Platform logo

    CrowdStrike Falcon Platform

    The AI-native CrowdStrike Falcon Platform provides comprehensive protection across all areas of enterprise risk - devices, identities, data, endpoints and cloud. Powered by a single agent, crowdsourced data, expert threat intelligence, and advanced AI, the Falcon Platform simplifies security operations and stops breaches.

    Ratings and reviews

    4.7
    658 ratings
    83%
    15%
    1%
    1%
    0%
    15 AWS reviews
    |
    643 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (658)
    Hospital & Health Care

    Great EDR solution for any OS with helpful telemetry and nice interface

    Reviewed on Sep 14, 2026
    Review provided by G2
    What do you like best about the product?
    detections provided by crowdstrike are very insightful and clear
    What do you dislike about the product?
    until you tune up the alerts, it can be noisy
    What problems is the product solving and how is that benefiting you?
    helped with alert fatigue and provides cleaner interface with endpoint management and detections
    Financial Services

    Cloud-Native Endpoint Protection with Powerful EDR and Rapid Response

    Reviewed on Sep 13, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about CrowdStrike Falcon is its cloud-native, unified approach to endpoint protection. It combines strong prevention, EDR visibility, managed threat hunting options, and rapid response capabilities in a single platform with a lightweight endpoint agent.
    What do you dislike about the product?
    The licensing and entitlement management is complex. It would be nice if that were much simpler to understand and manage.
    What problems is the product solving and how is that benefiting you?
    CrowdStrike Falcon helps address endpoint threats such as malware and ransomware by providing real-time prevention, endpoint detection and response, and centralized visibility across the environment. This benefits us by improving detection and investigation speed, reducing the likelihood and impact of security incidents, and strengthening incident-response capabilities.
    Non-Profit Organization Management

    One of the best EDR platform on the market

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    Falcon sensor supports multiple systems—Windows, MacOS, and Linux—under the same management. I’m able to drill down into the process chain to understand what triggered an event. Since everything is delivered from the cloud, there’s no on-premise infrastructure required, which made deployment fast. It’s one sensor and one platform, with more and more features built into the same sensor over time, so there’s no need for additional deployments. Sensor update management is also straightforward and easy.
    What do you dislike about the product?
    At times, it can generate a lot of false-positive alerts, although this seems to depend on how aggressively your detection/prevention policy is configured. I also wish the on-demand scan supported more file types.
    What problems is the product solving and how is that benefiting you?
    We migrated from a traditional AV vendor to CrowdStrike Falcon EDR. Falcon EDR gives us a centralized view and management across our entire fleet, spanning multiple types of operating systems. It also helps us use it as an asset inventory management system, so we can cross-reference it with other systems. We’re able to view all alerts in one central place and then drill down into the details when needed.
    Enes A.

    Strong endpoint protection with excellent detection and visibility

    Reviewed on Sep 05, 2026
    Review provided by G2
    What do you like best about the product?
    CrowdStrike provides strong endpoint protection, excellent threat detection, and good visibility across the environment. The Falcon platform is easy to manage from a centralized console, and its detection and investigation capabilities help security teams respond to threats quickly. I also find the lightweight endpoint agent and the overall quality of telemetry very useful for day-to-day security operations.
    What do you dislike about the product?
    The platform has a broad range of capabilities, which can make the initial configuration and tuning somewhat complex. Some advanced features also require additional time and experience to configure effectively. The amount of information available can occasionally be overwhelming for teams that are new to the platform, so having clearly defined use cases and policies from the beginning is helpful.
    What problems is the product solving and how is that benefiting you?
    CrowdStrike helps us improve endpoint security by providing centralized visibility, real-time threat detection, and investigation capabilities across our environment. It reduces the time required to identify and investigate suspicious activity and helps the security team respond to incidents more efficiently. The platform also helps reduce the risk associated with malware, endpoint compromise, and other security threats.
    KC P.

    A Powerful Security Platform Backed by an Exceptional Customer Partnership

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    CrowdStrike has been an excellent partner for our organization. Their team has taken the time to understand our environment, along with the security, regulatory, and operational challenges that are unique to the tribal gaming and hospitality industry. That industry awareness has made their recommendations more applicable and their support more effective.

    Throughout our partnership, they have stayed attentive to our needs. They respond quickly to questions, take our concerns seriously, and remain engaged well beyond implementation. When we have needed guidance or expressed interest in expanding our CrowdStrike services, their team has worked with us to clarify what we are trying to accomplish and to identify a practical path forward.

    The Falcon platform has exceeded our expectations. It gives our team strong visibility across our endpoints and provides the detection, investigation, and response capabilities we need to act quickly when suspicious activity occurs. As we continue to expand our use of its capabilities, the platform keeps adding value.

    Overall, CrowdStrike has delivered an exceptional product backed by a consistently positive customer experience. That level of service is becoming increasingly difficult to find, and it is a key reason CrowdStrike has become a trusted partner for our organization.
    What do you dislike about the product?
    The biggest drawback is the complexity and cost of expanding across the Falcon platform. CrowdStrike provides a broad set of valuable capabilities, but many of them are licensed as separate modules. As a result, it can be hard to tell exactly what’s included, where features overlap, and how to plan a predictable long-term roadmap. Clearer packaging and more flexible licensing would make it easier for customers to add services over time and take fuller advantage of the platform.
    What problems is the product solving and how is that benefiting you?
    CrowdStrike Falcon is helping us tackle several challenges, including limited endpoint visibility, complex incident investigations, and the need to detect and contain threats quickly across a large, diverse environment.

    The platform gives our security team centralized visibility into endpoint activity and the context needed to understand what happened, which systems were affected, and what actions to take next. Its behavioral detection capabilities help identify suspicious activity that traditional signature-based tools may miss, and its response features let us isolate systems and start containment without waiting for physical access to a device.

    Falcon has also improved both the speed and the quality of our investigations. Our analysts can work from a single platform rather than pulling information from multiple disconnected sources. This reduces manual effort, supports faster decision-making, and helps us respond to potential incidents before they grow into larger problems.

    Overall, Falcon has strengthened our endpoint security posture, increased our team’s efficiency, and given us greater confidence that suspicious activity can be identified, investigated, and contained quickly.
    Dave S.

    Falcon Endpoint Protection

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    The sensor is light and it captures everything
    What do you dislike about the product?
    It can be difficult at times to deploy through Microsoft intune.
    What problems is the product solving and how is that benefiting you?
    It’s giving us data on our endpoints with AIDR
    Pavel S.

    Comprehensive Protection, Easy Management

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    I really like how much of the endpoint protection stack is consolidated into one platform with CrowdStrike Falcon Endpoint Protection Platform. It's very easy to manage, and it runs lightly on user devices and servers. The initial deployment was very easy, and even though configuring all its features can be a bit challenging, once it's set up, it runs smoothly. I also think it protects better, works well, and offers easier management compared to others like SentinelOne, Bitdefender, and Kaspersky.
    What do you dislike about the product?
    I wish CrowdStrike had DNS filtering capabilities. The initial setup was easy-ish; it was very easy to deploy, but a little harder to fully configure due to its massive amount of features. However, once it's configured, it runs very well.
    What problems is the product solving and how is that benefiting you?
    CrowdStrike Falcon Endpoint Protection Platform provides on-endpoint protection, consolidates protection stacks, and runs smoothly and efficiently on devices. It's easy to manage, making it an efficient solution for protecting our customers' environments.
    Joseph G.

    Helpful Policy Creation and Asset Monitoring

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    The ability to create policies and monitor our assets is very helpful.
    What do you dislike about the product?
    Not sure. Fairly new to the product, at least from my position.
    What problems is the product solving and how is that benefiting you?
    It does better than any other product out there at the moment.
    Anonymous

    Strong USB Protection, Effortless Setup

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    I really like that one sensor in CrowdStrike Falcon Endpoint Protection Platform provides multiple services. It makes the platform incredibly efficient because different modules can be handled with just one sensor installed on endpoints. Additionally, the initial setup was really easy, which was a big plus. I also appreciate the strong protection and visibility it offers on USB devices. Overall, I find it quite effective.
    What do you dislike about the product?
    URL whitelisting could be improved.
    What problems is the product solving and how is that benefiting you?
    CrowdStrike Falcon Endpoint Protection Platform enforces strong protection and visibility for USB devices, enhancing security with a single sensor offering multiple services across endpoints.
    reviewer2895273

    Platform has unified threat visibility and delivers lightweight protection for every endpoint

    Reviewed on Sep 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    CrowdStrike Falcon is primarily used because we are a system integrator that sells a solution to our customers, so most of it is endpoint security.

    We are not the one operating CrowdStrike Falcon, but when we do an implementation, once we install the agent and complete the implementation, we see what it has detected from day one of the implementation until the turnover to the operations team. The Falcon Complete dashboard is intuitive, especially OverWatch, which highlights every risk that we need to manage, and also the detection field and incident field where we can see the entire timeline and all the things that happened. There is also a network map where you can see, for example, if there is one detection on a workstation, which other users or other devices it communicated with.

    We are primarily utilizing Charlotte AI within CrowdStrike Falcon platform. We use it extensively on CrowdStrike Falcon EDR, plus also NG-SIEM, because with Charlotte, it can help us create queries without doing it manually.

    What is most valuable?

    One of the key advantages of CrowdStrike Falcon is its lightweight sensor, so it is easy to deploy compared to other security solutions.

    CrowdStrike Falcon provides results because, until now, no customer of ours has gotten ransomware or been infected.

    The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of the companies that I mentioned earlier had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.

    There is no impact on endpoint performance. On some of the other products that I compared CrowdStrike Falcon with, some of them cause high utilization. We have not experienced that with CrowdStrike Falcon.

    For me as the one who implements CrowdStrike Falcon, it has a real impact because it is easy to deploy. Even though the customer does not have software deployment tools, you can deploy CrowdStrike Falcon by having a simple GPO, a Group Policy Object, load it there, and then you can install it easily.

    For endpoint performance, it is great because it is very lightweight. It is not the traditional antivirus from before where when you do a scan and install it, the CPU and memory will spike up and the user cannot do anything about it. CrowdStrike Falcon is very lightweight. With that, users do not need to balance between usability and security because with CrowdStrike Falcon, you can have both.

    What needs improvement?

    CrowdStrike Falcon can improve their supportability of legacy devices. This is where CrowdStrike Falcon has been edged out by other cybersecurity vendors because some of them support legacy operating systems, unlike CrowdStrike Falcon that primarily uses one level higher of operating system than others.

    For how long have I used the solution?

    In the cybersecurity field, I have been working for more than ten years. We have been working with CrowdStrike Falcon since 2022 to now.

    What do I think about the stability of the solution?

    In terms of reliability, ever since I used CrowdStrike Falcon platform, I think it is still okay because the GUI, the dashboard, and the console are easy to use because all of their solutions are in one platform, so you will not get lost. They have OverWatch and a detection incident where all the detection is already consolidated there. Once you click it, you are going to see all the details.

    What do I think about the scalability of the solution?

    The most common solutions that I compare CrowdStrike Falcon to in my country are Trend Micro, Sophos, and Palo Alto and SentinelOne. The really key advantage of CrowdStrike Falcon is its lightweight sensor. Some of those companies that I mentioned had a hard time deploying because they have 400 to 500 MB of sensor, which if you deploy it on 3,000 or 4,000 endpoints, it will really slow down their network. Unlike with CrowdStrike Falcon, we can deploy, for example, 2,000 endpoints a day.

    How are customer service and support?

    When we had an issue, for example, on an agent installation because of one legacy device or when we were installing it with another endpoint application, we had CrowdStrike Falcon support come in with us. They are very helpful because they were able to resolve our issue.

    Which solution did I use previously and why did I switch?

    We had one experience with one of our customers where at first, they were not a CrowdStrike Falcon user. They had a ransomware with a different solution, not CrowdStrike Falcon. After that, we asked them to try CrowdStrike Falcon and install it, then we could see other detections that their previous vendor or solution did not see. After we were able to help them clean their environment, they transitioned to CrowdStrike Falcon with Falcon Complete, with the managed detection and response of CrowdStrike Falcon.

    The most common solution right now in my country is NG-SIEM. Before, they used a different SIEM, like Splunk, Rapid7, Exabeam, or QRadar, but now that they see the value of CrowdStrike Falcon XDR and they want it to work together, most of them are trying to move to NG-SIEM so that you can have your XDR and your SIEM in one platform, plus the telemetry that CrowdStrike Falcon endpoint provides. This will really help them secure their environment.

    What other advice do I have?

    I think it is very great that we have a solution as CrowdStrike Falcon which has many different security functionalities because threats are evolving. As the defender, we need to evolve as well. We are fortunate to have CrowdStrike Falcon that is continuing to evolve, even now in the AI era because threats are more complex than before. Before you just needed to worry about the zero-day and the signature. Now it is different with AI. We are fortunate we have CrowdStrike Falcon with us.

    I am confident that CrowdStrike Falcon is up to par to protect you and your customers from AI threats.

    Most of our customers in my country use CrowdStrike Falcon, and ever since then, they do not have serious incidents, such as a ransomware that has taken effect on all their critical infrastructures, including servers.

    One value or benefit that customers can have from CrowdStrike Falcon is not having their solutions in silos. If it works in silos, it is going to be hard to keep track of threats, especially now that AI is moving at AI speed. If we are working in silos or have different solutions, it is going to be hard to catch up. Did they get anything on the identity solution? Did they get anything on the cloud solution? With CrowdStrike Falcon, it is all in a single sensor and a single platform. Customers are going to have a single pane of glass that they can look at.

    The impact of AI features such as Charlotte AI on our security operations makes our lives easier, not only for us but also for our customers. Before, when they were going to do a query, they needed to drill down multiple times before they got to the one event that they wanted to see. Now, if you ask Charlotte, it is one click of a button and enter, and Charlotte will give you everything. It is much faster than drilling down to all the events and all the reports.

    Customers usually get Falcon EDR first, Falcon Pro. After that, they expand to Falcon Complete, meaning adding the MDR services, and now they are trying to go to NG-SIEM plus the identity. Now that they have heard about Falcon Guardian, they might look into that as well.

    If I were to give advice for someone who is evaluating or considering CrowdStrike Falcon platform, I think they need to try it so they can feel the experience and the protection and the security that CrowdStrike Falcon provides. I rate this solution a ten out of ten.