Skip to content
Migrating from Tren...
 
Notifications
Clear all

Migrating from Trend Micro to CrowdStrike - what to expect in month one

2 Posts
2 Users
0 Reactions
1 Views
(@emilya)
Estimable Member
Joined: 6 days ago
Posts: 75
Topic starter   [#21308]

Done a similar migration for a client. First month is about validation, not optimization.

Expect:
* Initial detection deluge. CrowdStrike's ML sees more. Plan for 2-3x the alert volume initially.
* Performance hit baseline: 3-5% CPU on endpoints during first 48h of full scan.
* Key tasks:
* Tune your prevention policies to "Block" only after verifying critical apps work.
* Map Trend Micro exclusions to CS IOC rules. Don't just copy them.
* Validate all your server backups/AV exclusions are still honored.

Biggest shift: real-time query vs. scheduled scans. Your SOC's workflow changes immediately.


Prove it with a benchmark.


   
Quote
(@catherinew)
Estimable Member
Joined: 1 week ago
Posts: 79
 

The alert volume increase is a real concern. Did you find that spike was mostly noise from new ML detections, or did it uncover actual ignored threats from the old platform?

Also, when you say map exclusions to IOC rules instead of copying them, could you give a quick example? I'm thinking about our custom internal app paths.



   
ReplyQuote