CrowdStrike Falcon is a cloud-native endpoint detection and response platform with AI-driven threat detection, automated remediation, and threat hunting. Priced per endpoint from $7.99 per month; managed detection and response available as an add-on.
Listing updated . Checked by MSP Software .
CrowdStrike Falcon is an endpoint detection and response platform from CrowdStrike for MSPs managing enterprise and mid-market clients who want published pricing and rapid threat response. Founded in 2011 and headquartered in Sunnyvale, California, CrowdStrike's cloud-native platform uses a single lightweight sensor to capture endpoint telemetry and applies AI-driven behavioral detection trained on frontline adversary intelligence to identify and stop threats in real-time, with automated remediation and isolation capabilities that achieve median containment in under one minute for managed response customers. Falcon operates on a per-endpoint pricing model with published tiered pricing from $7.99 per device per month billed monthly for Falcon Go, $14.99 per device per month for Falcon Pro, or $19.99 per device per month for Falcon Enterprise (checked September 2026). Annual billing offers discounts; all pricing is in USD. Falcon Go is limited to 100 devices per purchase order.
The platform includes proactive threat hunting via OverWatch, CrowdStrike's team of analysts who continuously hunt for threats across customer environments, alongside a fully managed detection and response service available as Falcon Complete Next-Gen MDR for 24/7 human-plus-machine coverage. Falcon supports Windows, macOS, and Linux endpoints with uniform sensor architecture, plus mobile device protection for iOS and Android. Additional capabilities include USB and device control to restrict removable media, firewall management for centralized host-based policy, and application allow-listing. The platform integrates with major RMMs including NinjaOne and Splashtop, SIEM platforms such as Splunk, Sumo Logic, and Datadog, and IT service management tools like ServiceNow and Jira. Falcon suits MSPs seeking analyst-led threat hunting without building an internal SOC. Before purchasing, MSPs should confirm the feature tier that meets their actual needs before comparing headline price, note that Falcon Go limits tenancy to 100 devices, and evaluate whether managed response via Falcon Complete or self-managed detection better suits their budget and technical capacity.
Falcon stands out for published per-endpoint pricing, strong threat hunting via OverWatch, and fast automated response times. It is enterprise-focused but accessible to smaller MSPs through the lower-cost Falcon Go tier. Unlike self-managed EDR competitors such as Microsoft Defender for Endpoint or Sophos Intercept X, Falcon Complete's managed MDR service achieves median containment time of under one minute with 24/7 analyst coverage. Before purchasing, confirm whether managed response via Falcon Complete MDR or self-managed detection better fits your budget and operational model, verify your RMM is on Falcon's current integration list, and check that the pricing tier you choose includes all features your operations actually need.
| Feature | Supported | Note |
|---|---|---|
| Behavioural detection | yes | AI-driven behavioral analysis trained on frontline adversary intelligence |
| Automated remediation | yes | Automated threat isolation and containment with median time to contain under one minute for managed response |
| Rollback to pre-attack state | unknown | |
| USB and device control | yes | USB, SD card, and Thunderbolt device restrictions via policy |
| Application allow-listing | yes | Application allow-listing and protection capabilities |
| Offline protection | unknown | |
| Threat hunting console | yes | Proactive hunting via OverWatch team of elite analysts, included in higher tiers and Falcon Complete MDR |
| Managed MDR add-on | yes | Falcon Complete Next-Gen MDR provides 24/7 managed detection and response with dedicated analyst oversight |
| SIEM and SOAR integration | yes | Integrations with Splunk, Sumo Logic, Datadog, Exabeam, and other SOAR platforms |
| RMM integration | yes | Verified integrations with NinjaOne and Splashtop; additional RMM integrations available via marketplace |
| macOS support | yes | Full macOS endpoint protection and detection |
| Linux support | yes | Full Linux endpoint protection and detection |
| Feature | Supported |
|---|---|
| Network vulnerability scanning | unknown |
| Authenticated scanning | unknown |
| Missing patch detection | unknown |
| Compliance framework mapping | unknown |
| Risk scoring | unknown |
| Dark web monitoring | unknown |
| External attack surface scanning | unknown |
| PSA integration for remediation tickets | unknown |
| Scheduled recurring scans | unknown |
| Client-facing reports | unknown |
| Multi-tenant console | unknown |
| Automated evidence collection | unknown |
| Feature | Supported |
|---|---|
| 24-hour human-staffed SOC | unknown |
| Managed threat response and isolation | unknown |
| Own endpoint telemetry agent | unknown |
| Identity threat detection | unknown |
| Network monitoring | unknown |
| Microsoft 365 monitoring | unknown |
| Monthly threat reporting | unknown |
| PSA integration for ticketing | unknown |
| Multi-tenant console | unknown |
| Works with third-party EDR | unknown |
| Dedicated incident response | unknown |
CrowdStrike Falcon is priced per endpoint per month. Falcon Go costs $7.99 per device billed monthly (or $59.99 per year), Falcon Pro is $14.99 per device monthly ($99.99 per year), and Falcon Enterprise is $19.99 per device monthly ($184.99 per year), all in USD. Falcon Go is limited to 100 devices per purchase order. Falcon Complete Next-Gen MDR pricing is available by quote.
CrowdStrike Falcon includes proactive threat hunting via OverWatch, the vendor's dedicated team of elite security analysts, available in mid-tier and above subscription levels and as part of Falcon Complete Next-Gen MDR. OverWatch provides continuous hunting, investigation, and remediation with a published median time-to-contain of one minute under managed response.
CrowdStrike Falcon supports Windows, macOS, and Linux endpoints with the same single lightweight sensor architecture across all three. Mobile device protection via Falcon is also available for iOS and Android. MSPs managing heterogeneous environments can deploy Falcon uniformly across endpoint types without separate tools.
CrowdStrike Falcon has documented integrations with NinjaOne and Splashtop RMMs via the CrowdStrike Marketplace. Additional RMM integrations exist but should be verified with CrowdStrike before purchase. ServiceNow and Jira integrations support ticket automation from Falcon alerts. MSPs should confirm their specific RMM or IT service management tool is listed in the marketplace before committing.
CrowdStrike Falcon offers a 15-day free trial accessible from the product website, allowing hands-on evaluation of detection capabilities, automated remediation, threat hunting, and RMM integrations without requiring payment or a lengthy presales process. The trial includes full access to OverWatch threat hunting features and the management console across all pricing tiers.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review