---
# source: src/content/solutions/en/endpoint-security/crowdstrike-falcon.md
# route:  /en/solutions/endpoint-security/crowdstrike-falcon/
title: CrowdStrike Falcon
tags: [endpoint-security, security]
vendors: [crowdstrike]
summary: Endpoint detection and response from CrowdStrike. A lean sensor on the device, analysis in the cloud, and a platform that grows by module.
photoNeed: A security console on screen with real alerts in it, being triaged
stub: false
draft: false
kind: product
addon: false
status: current
practice: >
  CrowdStrike replaces Carbon Black as our EDR product. We no longer support Carbon Black.
practiceReview: false
---

## What it is

Falcon is CrowdStrike's endpoint platform. A lean sensor supplies the events from the
device; the analysis runs in the vendor's cloud. What gets judged is behaviour rather than
files: not "do I know this signature", but "why is this process reading another one's
memory".

## What it is for

Estates that choose their endpoint security independently of the rest of the stack. Falcon
ties you to no platform licence and covers Windows, macOS and Linux with the same sensor.

The second point is growth: EDR is one module of several. Identity protection, cloud
workloads and threat intelligence come out of the same console when they are needed.

## What to watch

The modules are licensed individually, and the feature set depends on the package you
bought. What a quote calls "Falcon" is therefore not always the same Falcon.

And as with any EDR: the recording is worth as much as the team looking at it. Where there
is none, managed detection and response belongs in the plan from day one.
