SOAR / MDR / CrowdStrike

Falcon Complete

Falcon Complete is CrowdStrike's native-platform managed detection and response service. Provider analysts detect, investigate, and, when contracted, remediate using Falcon telemetry across endpoint, identity, cloud, SaaS, and optional third-party sources through Next-Gen SIEM.

Managed detection and responseResearch reviewed

What you are evaluating

This is a staffed service on Falcon, not Falcon Insight endpoint detection and response and not Next-Gen SIEM as a product buy. Warranty language is a separate legal instrument, not unlimited incident response.

A useful evaluation context

Evaluation is for teams already on Falcon who want a staffed detect-and-remediate service rather than only the endpoint or SIEM products.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Around-the-clock expert-led detect, investigate, and remediate on in-scope Falcon telemetry.
  • Humans in the loop for response rather than unattended containment of every alert.
  • Coverage can include endpoint, identity, cloud, SaaS, and optional third-party telemetry via Next-Gen SIEM when those domains are in the order form.

Where it fits in the work

  1. Onboard the Falcon domains and contacts that the statement of work actually covers.
  2. Investigate provider-raised cases and confirm which containment acts the service will execute versus customer IT.
  3. Hand remaining patching, identity recovery, and business communication to the customer after contracted response.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In an authorized Falcon test tenant, use the provider's supported validation method to raise a harmless test detection, then time acknowledge, investigate, and the recommended or executed action.

Evidence to look for

The investigation record shows time to acknowledge, the action taken or recommended, and that production hosts outside the test tenant were untouched.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which Falcon domains are in-scope, and which remain customer-monitored?
  2. Who executes host isolation, and what work remains with customer IT after the service acts?
  3. Where does Falcon Complete stop and a separate incident-response engagement begin?

Find your next idea.

Tip: press / to open search. Escape closes this window.