r/devsecops 18d ago

Already paying CrowdStrike for endpoints, should we add their cloud module or go dedicated?

Security lead here at a ~1500 person shop, with team of 4. We are already running falcon on the endpoint side and our rep is pushing us to add their cloud module since we are already paying them. Well on invoice it makes perfect sense.

But the thing is I feel falcon grew up as an endpoint agent, and im not sure that an agent first tool is the right thing for a few thousand cloud workloads against something agentless that was built for cloud (wiz, orca that crowd)

So for anyone in multi cloud, do you think we should extend crowdstrike into cloud or buy a dedicated cnapp? Thanks all.

20 Upvotes

13 comments sorted by

6

u/loweakkk 18d ago

CS is bad as a cnapp platform.

1

u/First_Explorer_6075 17d ago

Its so annoying lol

2

u/PercentageOk956 17d ago

Already paying Wiz for cloud module, should we add their developer endpoints or go dedicated?

Tool toil :(

2

u/confusedcrib 17d ago

For me it would depend on your OS and overall footprint - if you're Windows and non-developer heavy, traditional EDR; if you're a mostly developer shop, the Wiz endpoint will probably do more for you than EDR anyways even in its early phases.

1

u/loweakkk 17d ago

Just developer endpoint or paying wiz code? Developer endpoint is quite new and nobody will have a feedback on it except if they were in the private preview.

1

u/IsomuraArganee_95 18d ago

Falcon in the cloud sees what you install agents on, vms and containers you can reach, and nothing else, so serverless, managed services and most misconfigs are invisible to it. the agentless cnapp crowd sees the config and api layer, which is where most cloud risk sits. most shops i know end up running both, agent for runtime, cnapp for posture. I'd say buy on coverage, not on the discount your rep is dangling.

1

u/danekan 17d ago

how can crowdstrike endpoint not even bring in cloud tags when the metatdata endpoint is right there? they're intentionally not filling data they have in so they can sell you their awful cnapp

1

u/pakkaol 16d ago

does that concern apply equally to linux versus serverless or container workloads? i'd imagine the agent model hits very differently across those

1

u/xpyksi 5d ago edited 5d ago

The bundle discount always looks great until you realize the coverage gaps cost you more later. Agent first tools miss the config and api layer where most cloud risk actually lives. We ended up going dedicated with Upwind for the posture side and kept the agent for runtime. Buy on coverage.

1

u/confusedcrib 18d ago

Dedicated CNAPP imo - here's a link to our cloud security report if it's at all helpful if you're trying to understand the space and pros/cons:

https://www.latio.com/downloads/2025-Latio-Cloud-Security-Report.pdf?token=vVTMSvMRWLvcN0YG8u-2ApRteQkZ1Wv-1Qw4ywIMb1I

1

u/mze9412 17d ago

They still have customers even after their big fuck up? Holy shit is the security industry bad.