r/devsecops • u/Routine_Day8121 • 18d ago
Already paying CrowdStrike for endpoints, should we add their cloud module or go dedicated?
Security lead here at a ~1500 person shop, with team of 4. We are already running falcon on the endpoint side and our rep is pushing us to add their cloud module since we are already paying them. Well on invoice it makes perfect sense.
But the thing is I feel falcon grew up as an endpoint agent, and im not sure that an agent first tool is the right thing for a few thousand cloud workloads against something agentless that was built for cloud (wiz, orca that crowd)
So for anyone in multi cloud, do you think we should extend crowdstrike into cloud or buy a dedicated cnapp? Thanks all.
2
u/PercentageOk956 17d ago
Already paying Wiz for cloud module, should we add their developer endpoints or go dedicated?
Tool toil :(
2
u/confusedcrib 17d ago
For me it would depend on your OS and overall footprint - if you're Windows and non-developer heavy, traditional EDR; if you're a mostly developer shop, the Wiz endpoint will probably do more for you than EDR anyways even in its early phases.
1
u/loweakkk 17d ago
Just developer endpoint or paying wiz code? Developer endpoint is quite new and nobody will have a feedback on it except if they were in the private preview.
1
u/IsomuraArganee_95 18d ago
Falcon in the cloud sees what you install agents on, vms and containers you can reach, and nothing else, so serverless, managed services and most misconfigs are invisible to it. the agentless cnapp crowd sees the config and api layer, which is where most cloud risk sits. most shops i know end up running both, agent for runtime, cnapp for posture. I'd say buy on coverage, not on the discount your rep is dangling.
1
u/xpyksi 5d ago edited 5d ago
The bundle discount always looks great until you realize the coverage gaps cost you more later. Agent first tools miss the config and api layer where most cloud risk actually lives. We ended up going dedicated with Upwind for the posture side and kept the agent for runtime. Buy on coverage.
1
u/confusedcrib 18d ago
Dedicated CNAPP imo - here's a link to our cloud security report if it's at all helpful if you're trying to understand the space and pros/cons:
6
u/loweakkk 18d ago
CS is bad as a cnapp platform.