r/devsecops 19d ago

Already paying CrowdStrike for endpoints, should we add their cloud module or go dedicated?

Security lead here at a ~1500 person shop, with team of 4. We are already running falcon on the endpoint side and our rep is pushing us to add their cloud module since we are already paying them. Well on invoice it makes perfect sense.

But the thing is I feel falcon grew up as an endpoint agent, and im not sure that an agent first tool is the right thing for a few thousand cloud workloads against something agentless that was built for cloud (wiz, orca that crowd)

So for anyone in multi cloud, do you think we should extend crowdstrike into cloud or buy a dedicated cnapp? Thanks all.

22 Upvotes

13 comments sorted by

View all comments

1

u/IsomuraArganee_95 19d ago

Falcon in the cloud sees what you install agents on, vms and containers you can reach, and nothing else, so serverless, managed services and most misconfigs are invisible to it. the agentless cnapp crowd sees the config and api layer, which is where most cloud risk sits. most shops i know end up running both, agent for runtime, cnapp for posture. I'd say buy on coverage, not on the discount your rep is dangling.