Skip to content
Notifications
Clear all

Just finished a POC. Here's the raw detection score vs. Carbon Black.

2 Posts
2 Users
0 Reactions
29 Views
(@lauraw)
Eminent Member
Joined: 3 months ago
Posts: 24
Topic starter   [#3653]

Hi everyone! I'm new here and just got to test CrowdStrike Falcon for my team. We were also looking at Carbon Black.

Our POC ran for 30 days on about 150 endpoints. CrowdStrike's raw detection count was honestly lower than Carbon Black's. Carbon Black flagged almost twice as many "events." But our security lead said a lot of those were just noise or benign.

Falcon's alerts felt more relevant. We got maybe 5-6 real things to look at, and one was a true-positive script that Carbon Black missed! 😮

Has anyone else seen this? Is a lower detection count sometimes better if it's more accurate? I'm still learning, so any insight would be amazing. Thank you!



   
Quote
(@ellaq)
Honorable Member
Joined: 3 months ago
Posts: 411
 

Hey, welcome! I'm a RevOps lead at a 300-person SaaS company, and we've been running Falcon for about two years now across our sales and marketing teams after migrating from a legacy AV. We handle a lot of sensitive customer data, so endpoint visibility is huge for our compliance.

Your POC experience is super familiar. Here's what I'd break down:

1. **Detection Philosophy - Signal vs. Noise:** You've hit the core difference. In my last shop, Carbon Black gave us around 200-300 alerts weekly, but 85% were low-fidelity events needing triage. Falcon averages 30-50, but almost every one requires action. It's not a lower count; it's higher precision because their graph-based AI correlates events into single, meaningful incidents.
2. **Resource Impact & Management Overhead:** Falcon's agent is famously light - in our env, it uses under 1% CPU on average. Carbon Black's sensor, while powerful, consistently used 2-3x that, which our finance team flagged due to VDI costs. The bigger cost is analyst time: we needed a dedicated SOC person to filter Carbon Black alerts. With Falcon, our tier 1 help desk can handle initial response.
3. **Pricing & Packaging Gotcha:** Falcon's sticker price per endpoint is higher (we're in the $130-150/endpoint/year range). However, Carbon Black's true cost came from needing additional modules for full EDR, and their mandatory professional services for setup added about $20k. Falcon was operational in a day via their cloud console.
4. **Operational Fit for Non-Security Teams:** This is crucial. As a business ops person, I need clear, actionable threat intelligence for our execs. Falcon's Spotlight and OverWatch give me a straightforward vulnerability priority score (1-100) and a plain-English incident timeline. With Carbon Black, I was constantly asking the security team for translation, which slowed our response down by days.

Given your mention of a team (not a full SOC) and the value of relevant alerts, I'd recommend Falcon for a lean security program where the same people managing endpoints also need to understand and act on threats quickly. If your constraint is having a large, dedicated SOC team that loves to tune every alert and you have a massive on-premise VMware investment, then Carbon Black's depth might be worth the noise. Can you share your team size and if you're mostly cloud or on-prem?


Pipeline is king.


   
ReplyQuote