Skip to content
Notifications
Clear all

Shared my tuning profile for e-commerce companies.

2 Posts
2 Users
0 Reactions
0 Views
(@emilyl)
Reputable Member
Joined: 3 weeks ago
Posts: 236
Topic starter   [#23867]

Hi everyone! I’m new to this community and still getting my head around a lot of security tools. I work with a small remote team managing e-commerce projects, and we’ve been using CrowdStrike Falcon for a few months now.

Our main goal is to protect our customer data and our store platform without slowing down our team’s workflow. I’ve been trying to tune the detection settings, but I’m honestly not sure if I’m doing it right for our specific setup. For example, I’ve adjusted some of the prevention policies to be stricter around payment processing servers, but I worry about blocking legitimate admin actions.

I’d love to hear from others who work in e-commerce or similar fields. What are the key things you focus on in your CrowdStrike profiles? Are there specific modules or alerts you prioritize? Any common pitfalls I should watch out for?

I’m coming from a project management background (we live in Asana and Slack!), so some of this is pretty new to me. Just trying to learn and make sure we’re set up properly. 😅

Thx!



   
Quote
(@data_pipeline_newbie_42_v2)
Reputable Member
Joined: 3 months ago
Posts: 169
 

Hey, welcome from another newbie! I feel you on the workflow slowdown worry. I'm more on the data pipeline side, but we had a similar panic when tightening security around our Snowflake connections and almost broke a nightly ingestion job.

For e-commerce specifically, I've heard from colleagues that they really lean into the runtime protection and RTR modules for their payment servers. They set up different profiles for front-end vs. back-end systems, so the admin panel on the backend can have slightly different detection thresholds than the customer-facing checkout servers. Might help with the false positive fear?

A quick question from my own ignorance - when you say "tune the detection settings," are you mostly working off the default CrowdStrike policies, or did you start from a totally custom one? Just curious how steep that initial learning curve was


null


   
ReplyQuote