CrowdStrike Falcon is a cloud-native endpoint detection and response platform with AI-driven threat detection, automated remediation, and threat hunting. Priced per endpoint from $7.99 per month; managed detection and response available as an add-on.

Listing updated . Checked by MSP Software .

From the vendor

CrowdStrike Falcon is an endpoint detection and response platform from CrowdStrike for MSPs managing enterprise and mid-market clients who want published pricing and rapid threat response. Founded in 2011 and headquartered in Sunnyvale, California, CrowdStrike's cloud-native platform uses a single lightweight sensor to capture endpoint telemetry and applies AI-driven behavioral detection trained on frontline adversary intelligence to identify and stop threats in real-time, with automated remediation and isolation capabilities that achieve median containment in under one minute for managed response customers. Falcon operates on a per-endpoint pricing model with published tiered pricing from $7.99 per device per month billed monthly for Falcon Go, $14.99 per device per month for Falcon Pro, or $19.99 per device per month for Falcon Enterprise (checked September 2026). Annual billing offers discounts; all pricing is in USD. Falcon Go is limited to 100 devices per purchase order.

The platform includes proactive threat hunting via OverWatch, CrowdStrike's team of analysts who continuously hunt for threats across customer environments, alongside a fully managed detection and response service available as Falcon Complete Next-Gen MDR for 24/7 human-plus-machine coverage. Falcon supports Windows, macOS, and Linux endpoints with uniform sensor architecture, plus mobile device protection for iOS and Android. Additional capabilities include USB and device control to restrict removable media, firewall management for centralized host-based policy, and application allow-listing. The platform integrates with major RMMs including NinjaOne and Splashtop, SIEM platforms such as Splunk, Sumo Logic, and Datadog, and IT service management tools like ServiceNow and Jira. Falcon suits MSPs seeking analyst-led threat hunting without building an internal SOC. Before purchasing, MSPs should confirm the feature tier that meets their actual needs before comparing headline price, note that Falcon Go limits tenancy to 100 devices, and evaluate whether managed response via Falcon Complete or self-managed detection better suits their budget and technical capacity.

Our take

Falcon stands out for published per-endpoint pricing, strong threat hunting via OverWatch, and fast automated response times. It is enterprise-focused but accessible to smaller MSPs through the lower-cost Falcon Go tier. Unlike self-managed EDR competitors such as Microsoft Defender for Endpoint or Sophos Intercept X, Falcon Complete's managed MDR service achieves median containment time of under one minute with 24/7 analyst coverage. Before purchasing, confirm whether managed response via Falcon Complete MDR or self-managed detection better fits your budget and operational model, verify your RMM is on Falcon's current integration list, and check that the pricing tier you choose includes all features your operations actually need.

Read the EDR and XDR buying guide

How this listing is researched

Alternatives in EDR and XDR

All EDR and XDR software
Microsoft Defender for Endpoint Enterprise EDR bundled with Microsoft 365 E5, with multi-tenant management for MSPs via Lighthouse. No reviews yet · from £9.20 SentinelOne Autonomous endpoint detection and response with one-click rollback, per-endpoint annual pricing. No reviews yet · from US$179.99 Trend Vision One Endpoint Security Endpoint protection with EDR, XDR and threat hunting under credit-based licensing. No reviews yet FortiEDR Endpoint detection and response integrated with the Fortinet Security Fabric, quote-only pricing. No reviews yet All alternatives to CrowdStrike Falcon

Products that integrate with CrowdStrike Falcon

DNS and web filtering

Identity and access

RMM and patching

Vulnerability and compliance

Features

EDR and XDR features
FeatureSupportedNote
Behavioural detectionyesAI-driven behavioral analysis trained on frontline adversary intelligence
Automated remediationyesAutomated threat isolation and containment with median time to contain under one minute for managed response
Rollback to pre-attack stateunknown
USB and device controlyesUSB, SD card, and Thunderbolt device restrictions via policy
Application allow-listingyesApplication allow-listing and protection capabilities
Offline protectionunknown
Threat hunting consoleyesProactive hunting via OverWatch team of elite analysts, included in higher tiers and Falcon Complete MDR
Managed MDR add-onyesFalcon Complete Next-Gen MDR provides 24/7 managed detection and response with dedicated analyst oversight
SIEM and SOAR integrationyesIntegrations with Splunk, Sumo Logic, Datadog, Exabeam, and other SOAR platforms
RMM integrationyesVerified integrations with NinjaOne and Splashtop; additional RMM integrations available via marketplace
macOS supportyesFull macOS endpoint protection and detection
Linux supportyesFull Linux endpoint protection and detection
Vulnerability and compliance features
FeatureSupported
Network vulnerability scanningunknown
Authenticated scanningunknown
Missing patch detectionunknown
Compliance framework mappingunknown
Risk scoringunknown
Dark web monitoringunknown
External attack surface scanningunknown
PSA integration for remediation ticketsunknown
Scheduled recurring scansunknown
Client-facing reportsunknown
Multi-tenant consoleunknown
Automated evidence collectionunknown
MDR and SOC features
FeatureSupported
24-hour human-staffed SOCunknown
Managed threat response and isolationunknown
Own endpoint telemetry agentunknown
Identity threat detectionunknown
Network monitoringunknown
Microsoft 365 monitoringunknown
Monthly threat reportingunknown
PSA integration for ticketingunknown
Multi-tenant consoleunknown
Works with third-party EDRunknown
Dedicated incident responseunknown

FAQ

How much does CrowdStrike Falcon cost?
CrowdStrike Falcon starts at US$7.99 per endpoint per month, according to the vendor, checked September 2026.
Does CrowdStrike Falcon offer a free trial?
CrowdStrike Falcon offers a free trial. There is no free version.
What does CrowdStrike Falcon integrate with?
CrowdStrike Falcon lists integrations with NinjaOne, Splashtop, ServiceNow, Splunk, Sumo Logic and Datadog.
What integrates with CrowdStrike Falcon?
Abnormal AI, Arctic Wolf, Automox, Barracuda Managed XDR, CyberStrong and DNSSense list an integration with CrowdStrike Falcon.
Is CrowdStrike Falcon cloud or on-premises?
CrowdStrike Falcon is cloud-hosted; there is no on-premises version.
Who is CrowdStrike Falcon for?
MSPs report using CrowdStrike Falcon at sizes of 51-200 and 200+ technicians.
Is CrowdStrike Falcon priced per endpoint?

CrowdStrike Falcon is priced per endpoint per month. Falcon Go costs $7.99 per device billed monthly (or $59.99 per year), Falcon Pro is $14.99 per device monthly ($99.99 per year), and Falcon Enterprise is $19.99 per device monthly ($184.99 per year), all in USD. Falcon Go is limited to 100 devices per purchase order. Falcon Complete Next-Gen MDR pricing is available by quote.

Does Falcon include threat hunting?

CrowdStrike Falcon includes proactive threat hunting via OverWatch, the vendor's dedicated team of elite security analysts, available in mid-tier and above subscription levels and as part of Falcon Complete Next-Gen MDR. OverWatch provides continuous hunting, investigation, and remediation with a published median time-to-contain of one minute under managed response.

What operating systems does Falcon support?

CrowdStrike Falcon supports Windows, macOS, and Linux endpoints with the same single lightweight sensor architecture across all three. Mobile device protection via Falcon is also available for iOS and Android. MSPs managing heterogeneous environments can deploy Falcon uniformly across endpoint types without separate tools.

Does Falcon integrate with my RMM?

CrowdStrike Falcon has documented integrations with NinjaOne and Splashtop RMMs via the CrowdStrike Marketplace. Additional RMM integrations exist but should be verified with CrowdStrike before purchase. ServiceNow and Jira integrations support ticket automation from Falcon alerts. MSPs should confirm their specific RMM or IT service management tool is listed in the marketplace before committing.

Is there a trial available?

CrowdStrike Falcon offers a 15-day free trial accessible from the product website, allowing hands-on evaluation of detection capabilities, automated remediation, threat hunting, and RMM integrations without requiring payment or a lengthy presales process. The trial includes full access to OverWatch threat hunting features and the management console across all pricing tiers.

CrowdStrike Falcon reviews

Reviews are moderated. How reviews work.

Be the first MSP to review CrowdStrike Falcon

Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.

Write the first review

Sign in or create an account

Use your work email to review tools, share pricing and manage your vendor profile.

By continuing, you agree to our terms and acknowledge our privacy policy.