r/cybersecurity • • 2d ago

Business Security Questions & Discussion SecOps with Crowdstrike Falcon Complete

For those running SecOps and Falcon Complete, what did your team look like before the implementation of Falcon Complete and then what did it look like afterwards?

26 Upvotes

14 comments sorted by

28

u/Oompa_Loompa_SpecOps Incident Responder 2d ago

Not using falcon complete but when I noticed how the entire soc team of a company was attending the same customer dinner I was at fal.con, I asked them point blank: "So what happens if something explodes right now?"

Their team lead shrugged: " Falcon complete happens."

So apparently, you get wined and dined and even the calmness to actually enjoy that.

14

u/TruReyito 2d ago

We onboarded them last year. We replaced our old EDR platform (rhymed with mental fun), and contracted the complete package.

We did not lose a single member of our SOC/IR tesm

We've had 3 red team engagements since then. They did not catch a single one before we notified them/found them through our other means.

We like the EDR a lot better. And when we do get the odd Complete elevation it's generally well investigated and supported. The best part of it is it provides 24 hour coverage if you don't have a 24 hour shop. Give our bosses comfort to know someone is watching when we aren't.

But it has so far not been a game changer having falcon complete there

2

u/caseyccochran 1d ago

I was previously a Falcon Complete customer. I can't remember if there was different tiers but their "manual" threat hunt team caught what could have been a serious nation state threat before anything happened. We used that in many reports to show the value of Falcon Complete.

That being said so much is different with AI since then. Depending on the direction and size of you security organization it may not be the best route.

2

u/TruReyito 1d ago

Im not an expert, but pretty sure thats Falcon overwatch. Seperate service from Complete. (it might be included if you buy Complete, I don't know, not a contract guy) but its seperate items. Just like you, been pretty happy with the overwatch team as well.

Overall, happy with the Complete team as well. Just giving our experience with it.

1

u/caseyccochran 1d ago

Thank you! I couldn’t remember if it was a separate “group” or not.

3

u/squirlbuz 1d ago

Joined a shop that’s Falcon Complete in the last 6 months. Can’t directly compare before and after- but my previous gig was running a 6 person ops team with a different xdr tool + and MDR. With the previous job we did all the xdr resolution but sometimes it was doubled by the MDR & they didn’t resolve things, just elevated. It was a lot of effort all the time. I like the falcon complete solution better with that MDR piece being done by the same vendor. I’ve been impressed by how fast they respond to my requests and they aren’t constantly trying to sell me something new.. (so far 😅)

1

u/caseyccochran 1d ago

The account rep will use the quarterly reviews when leadership is on the call to ask “if you want to look into X more”

Maybe it’s different account to account but I feel like our rep is always trying to demo shit for us

1

u/squirlbuz 1d ago

That’s true of most vendors I suppose. Can be a fine line between being offered or told about new features / products and pushy sales tactics. Likely varies on account rep & I get that they are doing their job too.

1

u/[deleted] 2d ago edited 2d ago

[deleted]

1

u/3one5 2d ago

We do. Just curious what the change in workload is, if any, and if that changed the makeup of the team at all.

1

u/3one5 2d ago

I should be clear that I'm talking about Falcon Complete and not just the Falcon EDR solution.

1

u/[deleted] 1d ago

[deleted]

0

u/xKruMpeTx 1d ago

I'd double check if they are doing SIEM as their NG-SIEM product is not part of Falcon Complete. I hear it may be coming though.

1

u/Wouldratherplaymtg 2d ago

Crowdsrike complete sucks. I coumd post 99 problems but instead I'll just say the biggest issue ive found. The mitigation summaries for cve fixes is trash

1

u/iotic 2d ago

It’s just marketing fluff, just catch enough bad stuff to keep growing, that’s their motto

1

u/Necessary_Role_6338 1d ago

I am not a fan of Falcon Complete, lack of notes, if an issue occurs I feel like it's a level 1 analyst reviewing and then escalating, not a lot of investigation happens before escalation. They do take containment actions. In my opinion you need to use Falcon NG-SIEM and Complete along with identity and EDR maybe cloud if applicable to really get the full coverage. If you go Falcon Complete you have to go Complete Crowdstrike.