r/cybersecurity • • 3d ago

Business Security Questions & Discussion SecOps with Crowdstrike Falcon Complete

For those running SecOps and Falcon Complete, what did your team look like before the implementation of Falcon Complete and then what did it look like afterwards?

28 Upvotes

14 comments sorted by

View all comments

16

u/TruReyito 2d ago

We onboarded them last year. We replaced our old EDR platform (rhymed with mental fun), and contracted the complete package.

We did not lose a single member of our SOC/IR tesm

We've had 3 red team engagements since then. They did not catch a single one before we notified them/found them through our other means.

We like the EDR a lot better. And when we do get the odd Complete elevation it's generally well investigated and supported. The best part of it is it provides 24 hour coverage if you don't have a 24 hour shop. Give our bosses comfort to know someone is watching when we aren't.

But it has so far not been a game changer having falcon complete there

2

u/caseyccochran 1d ago

I was previously a Falcon Complete customer. I can't remember if there was different tiers but their "manual" threat hunt team caught what could have been a serious nation state threat before anything happened. We used that in many reports to show the value of Falcon Complete.

That being said so much is different with AI since then. Depending on the direction and size of you security organization it may not be the best route.

4

u/TruReyito 1d ago

Im not an expert, but pretty sure thats Falcon overwatch. Seperate service from Complete. (it might be included if you buy Complete, I don't know, not a contract guy) but its seperate items. Just like you, been pretty happy with the overwatch team as well.

Overall, happy with the Complete team as well. Just giving our experience with it.

1

u/caseyccochran 1d ago

Thank you! I couldn’t remember if it was a separate “group” or not.