Videos
Hi,
I know this subreddit might be a bit biased towards this question, but I'll ask anyway.
We need to decide between a managed SIEM/SOC solution and CrowdStrike's MDR, specifically the Falcon Complete solution. Unfortunately, due to budget limitations, we can't afford both.
From my perspective, after testing CrowdStrike for a month mostly the EDR and ITDR solutions and I think its amazing. I haven't tested the Falcon Complete solution yet, but I've heard very good things. However, if we choose the MDR route, we'll lose our managed SIEM/SOC solution entirely, which means we will have to find other solutions for the parts of our infrastructure that CrowdStrike doesn't cover, like network, VMware, NAC, etc.
The deal also includes the NG-SIEM, which I know is based on LogScale. This means I'll be blind to any system that doesn't have LogScale integration.
What's your opinion on this? What would you do?
I'm looking at either Crowdstrike or Sentinel One for EDR.
I'm also looking for an MDR solution. Blackpoint seems like a good option.
Does anyone have experience using Crowdstrike's MDR service?