Notifications
Clear all
Topic starter
17/07/2026 4:41 pm
Made the switch last quarter. Finance team was thrilled with the 30% savings over CrowdStrike. This week, a malicious Powershell script slipped through and exfiltrated data from a developer machine. Elastic's alert was delayed and generic.
Their dashboard looks clean and the Kibana integration is neat, but the detection engineering seems shallow. The EDR feels reactive, not proactive. CrowdStrike was expensive, but it stopped these script-based attacks cold. Now I'm dealing with a breach investigation.
Is anyone else seeing a gap between the promise and the actual protection? Or did we just configure it wrong? The sales rep swore we wouldn't lose coverage.
—Skeptic
—Skeptic