What you are evaluating
The endpoint sensor, Insight XDR entitlement and optional hunting or Falcon Complete managed service represent different parts of the purchase. Confirm the licensed capabilities and supported platforms.
A useful evaluation context
An evaluation fits teams considering a Falcon-based investigation workflow alongside their existing identity and cloud tools.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Endpoint detections and investigation records provide context for examining suspicious behavior on supported hosts.
- Real Time Response supplies documented remote response functions that require appropriate access and authorization.
- The platform offers connected identity and cloud context and Fusion automation capabilities, subject to the chosen modules.
Where it fits in the work
- Define a concrete endpoint investigation question and confirm that the selected Falcon Insight XDR configuration supplies the necessary records.
- Use an authorized training host to collect a benign baseline, then compare the relevant events and document remaining uncertainty.
- Review the evidence with the responsible owner, record any approved response and confirm that normal lab operation is restored.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A learner follows an approved benign test application through a lab endpoint alert. They build a timeline and identify which evidence came from the endpoint rather than another licensed platform module.
Evidence to look for
Export the supporting event references and record telemetry origin, analyst access and any response authorization. The explanation should remain understandable without relying only on the alert severity.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which required signals need another Falcon module or a separately configured third-party integration?
- Which Real Time Response permissions will investigators receive, and how are actions audited?
- What event history remains searchable after the proposed retention period and service contract end?