I've been tasked with evaluating our endpoint protection and the team is pushing hard for CrowdStrike. The intel and threat search capabilities are a big part of the sales pitch. So I took the trial for a spin, expecting something... I don't know, on par with a modern SIEM or even a decent log analytics tool?
What I found feels like a glorified grep on a slow day. Am I using it wrong, or is the search functionality genuinely this cumbersome?
My main gripes so far:
* The query language seems arbitrarily restrictive. Want to combine multiple IOCs with a time range and filter out a specific process? Prepare for a nested mess of parentheses that may or may not return what you expect.
* The performance is inconsistent. A broad search hangs, but a narrow one returns instantly. There's no transparency into why, which makes building investigative workflows a guessing game.
* The results presentation is awful. It's a flat list where crucial context (like the relationship between a file write and a subsequent network call) is buried. You have to manually piece the timeline together.
I've used open-source tools that, while less polished, offer more powerful and transparent search capabilities. With CrowdStrike's pricing, I expected the search to be a standout feature, not a liability.
Before I go back to the team and rain on their parade, I need a reality check.
* Are these known limitations that shops just work around?
* Is there a secret handshake to crafting performant queries?
* Or is the real value elsewhere, and we're supposed to accept that the search is just a basic entry point?
I'm trying to build a TCO model that includes analyst efficiency, and this feels like a major drag on productivity. If I'm missing something, please enlighten me.
- skeptic_sam
The real cost is in the fine print.