Some of the features of CrowdStrike:
Simplifies detection and resolution
- CrowdStrike automatically senses attacker activities: It automatically detects attacker behavior and instantly sends alerts to the Falcon UI, and thus helps avoid time-consuming research and manual searches. The CrowdStrike Threat Graph database stores event data and answers queries within less than five seconds.
- Unravels entire attacks on just one screen: An easy-to-read process tree provides complete attack details that help in quicker and easier investigations.
- Accelerates investigation workflow: It maps alerts to the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) Framework which enables understanding even the most complex detections at a glance, shortening the time required to triage alerts, and accelerate prioritization and remediation. In addition, the intuitive UI enables pivoting quickly and searching across the entire organization within seconds.
- Provides context and intelligence: Combined threat intelligence delivers the comprehensive context of an attack, including attribution.
- Responds decisively: It acts against threats in real-time, to prevent attacks before they breach the system. Its powerful response actions help examine compromised systems and Real-time Response capabilities provide direct access to endpoints under examination. This enables security responders run actions on the system and eliminate threats.
Enables full-spectrum visibility in real-time
- Observes every move in real-time: Instant visibility helps view activities in real-time.
- Captures critical details for threat hunting and forensic investigations: Falcon Insight kernel-mode driver captures over 400 raw events and related information necessary to retrace incidents.
- Answers in seconds: The CrowdStrike Threat Graph database stores event data and answers queries in less than five seconds across billions of events.
- Offers recall for up to 90 days: Falcon Insight offers a comprehensive record of endpoint activity over time, whether environment consists of fewer than 100 or more than 500,000 endpoints.
IMMEDIATE TIME-TO-VALUE
- Saves time, effort, and money: Cloud enabled Falcon Insight is delivered by the CrowdStrike Falcon platform and does not require on-premises management infrastructure.
- Deploys in minutes: CrowdStrike customers can install the cloud delivered Falcon agent to up to 70,000 endpoints in less than a day.
- Immediately operational: Falcon Insight begins the ground running, monitoring, and recording on installation without requiring reboots, fine-tuning, baselining, or complex configuration.
- Zero impact on the endpoint: Searches take place in the Threat Graph database without any performance impact on endpoints or the network through lightweight agent on the endpoint.