TechValidate Research on CrowdStrike Threat Intelligence

8 Case Studies


CrowdStrike Threat Intelligence Case Study

Medium Enterprise Pharmaceuticals Company

Introduction

This case study of a medium enterprise pharmaceuticals company is based on a November 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“One more step closer to validating the exposed data and threat actor.”

“Pre-filter results with follow-up calls with analysts are helpful.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select CrowdStrike Threat Intelligence:

  • What challenges did you or your team experience before using Falcon Intelligence Recon+?
    • Our current detection capabilities were mostly internal and we were concerned about underground threats
    • We were concerned about brand abuse on social media or forums
    • We were concerned about risks to VIPs or executives mentioned on forums

Use Case

The key features and functionalities of CrowdStrike Threat Intelligence that the surveyed company uses:

  • The surveyed user is part of the Cyber Security Oversight & Risk Team.
  • Which features of Falcon Intelligence Recon+ do you find most useful?
    • Assistance from CrowdStrike experts pre-filtering alerts
    • Domain “take-down” reports and assistance

Results

The surveyed company achieved the following results with CrowdStrike Threat Intelligence:

  • Why did you choose CrowdStrike Falcon Intel Recon + over others?
    • Assistance from CrowdStrike analysts
    • Recon + covers multiple use cases, valuable to multiple teams without an increase in costs
  • Please rate the following capabilities of CrowdStrike Falcon Intel Recon+ compared to the competition:
    • Continuous coverage of underground forums, marketplaces, etc: Better
    • Discovery of typo squatted domains: Better
    • Monitoring assistance from CrowdStrike Experts: Significantly Better
    • User Experience via Falcon Portal: Better
    • Notification capabilities to other members inside our outside the team: Better
    • Vulnerability Intelligence: Better
  • What benefits did your organization realize following the deployment of CrowdStrike Falcon Intelligence Recon+?
    • Improved awareness of key eCrime trends (Ransomware campaigns, Access Broker trends …)
    • We can inform our leadership more reliably about emerging threats as they unfold
  • In your best estimate, by what percent did CrowdStrike improve the following?
    • Improved our threat risk awareness: 50-75%
    • Increased depth of incident investigations: 50-75%
    • Helped to mitigate external threats before they became a problem: 25-50%
    • Reduced our global risk posture: 25-50%
    • Improved effectiveness of our patching efforts: 50-75%

CrowdStrike Threat Intelligence Case Study

Large Enterprise Hospitality Company

Introduction

This case study of a large enterprise hospitality company is based on a November 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“Turnkey, quick response from CrowdStrike managed team.”

“Things matter outside of the big-breaches. 1,000,000 cuts can still slowly kill.”

Challenges

What challenges did you or your team experience before using Falcon Intelligence Recon+?

  • Our current detection capabilities were mostly internally and we were concerned about underground threats
  • We were concerned about brand abuse on social media or forums
  • Day-to-day value is from retail-specific use cases (fraud, abuse techniques, non-breach things)

Which other vendors did you consider before selecting CrowdStrike Threat Intelligence?

  • Recorded Future
  • Mandiant / Google
  • ZeroFox

Use Case

Which features of Falcon Intelligence Recon+ do you find most useful?

  • Assistance from CrowdStrike experts pre-filtering alerts
  • Searching across different forums

The surveyed user is part of relative small security team ( 5 – 10 members) covering many security areas.

Results

Why did you choose CrowdStrike Falcon Intel Recon + over others?

  • Assistance from CrowdStrike analysts
  • We use the Falcon platform already for other security offerings and want to keep our consoles consolidated
  • Cost / Value was substantially higher compared to other vendors

CrowdStrike Threat Intelligence Case Study

Medium Enterprise Pharmaceuticals Company

Introduction

This case study of a medium enterprise pharmaceuticals company is based on a November 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“We have more visibility of external threats and breaches.”

“Filters false positives, help in prioritizing incidents.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select CrowdStrike Threat Intelligence:

  • What challenges did you or your team experience before using Falcon Intelligence Recon+?
    • Our current detection capabilities were mostly internal and we were concerned about underground threats
    • We were uncertain about the impact of security incidents and couldn’t verify if data was leaked
    • We were concerned about brand abuse on social media or forums
    • Our organization is often hit by phishing campaigns and needs to verify credential theft
    • We were concerned about risks to VIPs or executives mentioned on forums
  • Which other vendors did you consider before selecting CrowdStrike Threat Intelligence?
    • Mandiant / Google

Use Case

The key features and functionalities of CrowdStrike Threat Intelligence that the surveyed company uses:

  • The surveyed user is part of relatively small security team ( 5 – 10 members) covering many security areas.
  • Which features of Falcon Intelligence Recon+ do you find most useful?
    • Notifications on exposed data, compromised identities, brand abuse, typo-squatting
    • Assistance from CrowdStrike experts pre-filtering alerts
    • Domain “take-down” reports and assistance
    • Vulnerability Intelligence (CVSS scores enriched with exploit rating, actors, technologies, etc)

Results

The surveyed company achieved the following results with CrowdStrike Threat Intelligence:

  • Why did you choose CrowdStrike Falcon Intel Recon + over others?
    • Assistance from CrowdStrike analysts
    • CrowdStrike’s expertise in threat intelligence
    • Recon + covers multiple use cases, valuable to multiple teams without an increase in costs
  • Please rate the following capabilities of CrowdStrike Falcon Intel Recon+ compared to the competition:
    • Continuous coverage of underground forums, marketplaces, etc: Significantly Better
    • Discovery of typo squatted domains: Best In Class
    • Monitoring assistance from CrowdStrike Experts: Significantly Better
    • Advise on how to mitigate discovered threats: Significantly Better
    • User Experience via Falcon Portal: Better
    • Notification capabilities to other members inside our outside the team: Significantly Better
  • What benefits did your organization realize following the deployment of CrowdStrike Falcon Intelligence Recon+?
    • We now receive early warnings on digital threats not known before
    • Improved risk mitigation post incident by searching for leaked credentials or exposed data
    • We are better prepared to stop threats from criminals or malicious infrastructure targeting our organization
    • Prioritize mitigation of attack surface exposures with vulnerability intelligence
    • We can inform our leadership more reliably about emerging threats as they unfold
  • In your best estimate, by what percent did CrowdStrike improve the following?
  • Increased depth of incident investigations: 25-50%
  • Helped to mitigate external threats before they became a problem: +100%
  • Reduced our global risk posture: 50-75%

CrowdStrike Threat Intelligence Case Study

Large Enterprise Consumer Products Company

Introduction

This case study of a large enterprise consumer products company is based on a November 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“We use the final product intelligence for briefings to executive and risk teams on wider implications of business activity as it relates to cyber threats. We were able to gain insight into actors targeting our ecommerce platforms for fraud.”

Challenges

What challenges did you or your team experience before using Falcon Intelligence Recon+?

  • Our current detection capabilities were mostly internal and we were concerned about underground threats
  • We were concerned about brand abuse on social media or forums
  • Our organization is often hit by phishing campaigns and needed to verify credential theft
  • We often see fake websites impersonating our organization and going after customers.
  • We were concerned about risks to VIPs or executives mentioned on forums

Which other vendors did you consider before selecting CrowdStrike Threat Intelligence?

  • ZeroFox
  • Digital Shadows / Reliaquest
  • Microsoft

Use Case

Which features of Falcon Intelligence Recon+ do you find most useful?

  • Notifications on exposed data, compromised identities, brand abuse, typo-squatting
  • Assistance from CrowdStrike experts pre-filtering alerts
  • Searching across different forums
  • Weekly reports about ransomware families, access brokers, vulnerability exploits

Surveyed user: “I’m part of the security planning team (Info Sec).”

Results

Why did you choose CrowdStrike Falcon Intel Recon + over others?

  • Assistance from CrowdStrike analysts
  • We use the Falcon platform already for other security offerings and want to keep our consoles consolidated
  • CrowdStrike’s expertise in threat intelligence
  • Recon + covers multiple use cases, valuable to multiple teams without increase in costs

Please rate the following capabilities of CrowdStrike Falcon Intel Recon+ compared to the competition:

  • Continuous coverage of underground forums, marketplaces etc: Significantly Better
  • Discovery of typosquatted domains: Better
  • Monitoring assistance from CrowdStrike Experts: Best In Class
  • Advise on how to mitigate discovered threats: Significantly Better
  • User Experience via Falcon Portal: Significantly Better
  • Vulnerability Intelligence: Better

What benefits did your organization realize following the deployment of CrowdStrike Falcon Intelligence Recon+?

  • We now receive early warnings on digital threats not know before
  • We are better prepared to stop threats from criminals or malicious infrastructure targeting our organization
  • Improved awareness of key eCrime trends (Ransomware campaigns, Access Broker trends …)
  • We can inform our leadership more reliable on emerging threats as they unfold

In your best estimate, by what percent did CrowdStrike improve the following?

  • Improved our threat risk awareness: 50-75%
  • Increased depth of incident investigations: 25-50%
  • Helped to mitigate external threats before they became a problem: 75-100%
  • Reduced our global risk posture: 75-100%
  • Improved effectiveness of our patching efforts: 25-50%

CrowdStrike Threat Intelligence Case Study

Minter Ellison

Introduction

This case study of MinterEllison is based on a November 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service.

“We can now accurately validate leakage of credentials or any mentions of our brand name on the dark web. It also helps us consolidate or rather look at one source of information and focus our efforts there rather than multiple threat intel alerts which takes time and is inconsistent.

The TI feed into other parts of Falcon also helps us prioritize our proactive work on improving security posture."

“The main value for us is the simplicity of it and the data information flow across to other Falcon modules. This helps our team to focus on what’s important and quickly address the issue. ie no need to skill up on yet another platform or do more research on multiple forums etc.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select CrowdStrike Threat Intelligence:

  • What challenges did you or your team experience before using Falcon Intelligence Recon+?
    • Our current detection capabilities were mostly internal and we were concerned about underground threats
    • Consolidation of threat intel. we had a few sources that we were referring to but they were a bit generic. CERT alerts etc were a bit delayed too.
  • Which other vendors did you consider before selecting CrowdStrike Threat Intelligence?
    • Recorded Future
    • Mandiant / Google
    • Microsoft
    • Secureworks, Anomaly

Use Case

The key features and functionalities of CrowdStrike Threat Intelligence that the surveyed company uses:

  • I’m part of a relatively small security team ( 5 – 10 members) covering many security areas.
  • Which features of Falcon Intelligence Recon+ do you find most useful?
    • Notifications on exposed data, compromised identities, brand abuse, typo-squatting
    • Assistance from CrowdStrike experts pre-filtering alerts
    • Searching across different forums
    • It is part of the Falcon platform which we already use for other use cases
    • Weekly reports about ransomware families, access brokers, vulnerability exploits
    • Vulnerability Intelligence (CVSS scores enriched with exploit rating, actors, technologies, etc)
    • Dedicated analyst who sends the intel, the very rich/detailed alert which helps us a lot in quickly determining whether we escalate it immediately.

Results

The surveyed company achieved the following results with CrowdStrike Threat Intelligence:

  • Why did you choose CrowdStrike Falcon Intel Recon + over others?
    • Assistance from CrowdStrike analysts
    • We use the Falcon platform already for other security offerings and want to keep our consoles consolidated
    • CrowdStrike’s expertise in threat intelligence
    • Recon + covers multiple use cases, valuable to multiple teams without an increase in costs
  • Please rate the following capabilities of CrowdStrike Falcon Intel Recon+ compared to the competition:
    • Continuous coverage of underground forums, marketplaces, etc: Best In Class
    • Monitoring assistance from CrowdStrike Experts: Best In Class
    • Advise on how to mitigate discovered threats: Best In Class
    • User Experience via Falcon Portal: Best In Class
    • Notification capabilities to other members inside and outside the team: Best In Class
    • Vulnerability Intelligence: Better
  • What benefits did your organization realize following the deployment of CrowdStrike Falcon Intelligence Recon+?
    • We now receive early warnings on digital threats not known before
    • Improved risk mitigation post incident by searching for leaked credentials or exposed data
    • We are better prepared to stop threats from criminals or malicious infrastructure targeting our organization
    • Improved awareness of key eCrime trends (Ransomware campaigns, Access Broker trends …)
    • Prioritize mitigation of attack surface exposures with vulnerability intelligence
    • We can inform our leadership more reliably about emerging threats as they unfold
  • In your best estimate, by what percent did CrowdStrike improve the following?
    • Improved our threat risk awareness: 75-100%
    • Increased depth of incident investigations: +100%
    • Helped to mitigate external threats before they became a problem: 75-100%
    • Reduced our global risk posture: +100%
    • Improved effectiveness of our patching efforts: 75-100%

CrowdStrike Threat Intelligence Case Study

Small Business Retail Company

Introduction

This case study of a small business retail company is based on a November 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“Notified us of leaked credentials.”

Challenges

What challenges did you or your team experience before using Falcon Intelligence Recon+?

  • We were concerned about brand abuse on social media or forums
  • Our organization is often hit by phishing campaigns and needed to verify credential theft
  • We were concerned about risks to VIPs or executives mentioned on forums

Which other vendors did you consider before selecting CrowdStrike Threat Intelligence?

  • Mandiant / Google
  • LookingGlass

Use Case

Which features of Falcon Intelligence Recon+ do you find most useful?

  • Notifications on exposed data, compromised identities, brand abuse, typo-squatting
  • Domain “take-down” reports and assistance
  • Searching across different forums
  • Custom monthly Recon + reports

They said “I’m part of an advanced hunting team looking for actors targeting our organization.”

Results

Why did you choose CrowdStrike Falcon Intel Recon + over others?

  • CrowdStrike’s expertise in threat intelligence
  • Recon + covers multiple use cases, valuable to multiple teams without increase in costs

Please rate the following capabilities of CrowdStrike Falcon Intel Recon+ compared to the competition:

  • Continuous coverage of underground forums, marketplaces etc: Significantly Better
  • Discovery of typosquatted domains: Significantly Better
  • Monitoring assistance from CrowdStrike Experts: Significantly Better
  • Advise on how to mitigate discovered threats: Significantly Better
  • User Experience via Falcon Portal: Significantly Better
  • Notification capabilities to other members inside our outside the team: Significantly Better
  • Vulnerability Intelligence: Significantly Better

What benefits did your organization realize following the deployment of CrowdStrike Falcon Intelligence Recon+?

  • Improved risk mitigation post-incident by searching for leaked credentials or exposed data
  • We can inform our leadership more reliable on emerging threats as they unfold

In your best estimate, by what percent did CrowdStrike improve the following?

  • Improved our threat risk awareness: 75-100%
  • Increased depth of incident investigations: 75-100%
  • Helped to mitigate external threats before they became a problem: 75-100%
  • Reduced our global risk posture: 75-100%
  • Improved effectiveness of our patching efforts: 75-100%

CrowdStrike Threat Intelligence Case Study

Medium Enterprise Computer Software Company

Introduction

This case study of a medium enterprise computer software company is based on a February 2023 survey of CrowdStrike Threat Intelligence customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“Alerts to staff when their credentials have been exposed identified typosquat domains and similar scams.”

“Solid response to incidents on multiple occasions.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select CrowdStrike Threat Intelligence:

  • Which of the following represented the biggest security challenge(s) for your organization before implementing CrowdStrike?
    • Day-to-day SOC tactical tasks (ie investigations or IR) taking too much time
  • Which other vendors did you consider before choosing CrowdStrike Threat Intelligence?
    • Recorded Future
    • Zerofox

Use Case

The key features and functionalities of CrowdStrike Threat Intelligence that the surveyed company uses:

  • What features of CrowdStrike Threat Intelligence are you using?
    • Threat Alerts
    • Recon Feeds (Deep Dark Web, Criminal Market Places, Forums)
  • Why did you choose CrowdStrike Threat Intelligence over other threat intelligence solutions?
    • Threat Collection & Visibility that CrowdStrike Owns
    • Actionability of provided threat intelligence (indicators, rules, actors)

Results

The surveyed company achieved the following results with CrowdStrike Threat Intelligence:

  • CrowdStrike threat intelligence compared to the competition:
    • Threat Coverage: Significantly Better
    • Integration Capabilities: Significantly Better
    • Actionability of Provided Intelligence: Better
  • What benefits did your organization realize following the deployment of CrowdStrike Threat Intelligence?
    • It has improved our global threat risk awareness
    • It has improved the efficiency of our security operations
    • We have found new threats that we had no prior knowledge of

CrowdStrike Cloud Security Case Study

Independent Living Association, Inc.

Introduction

This case study of Independent Living Association, Inc. is based on a February 2023 survey of CrowdStrike Cloud Security customers by TechValidate, a 3rd-party research service.

“Crowdstrike caught more infections and other threats in the first 6 months compared to the vendor we were using.”

Challenges

Which of the following represented the biggest security challenge(s) for your organization before implementing CrowdStrike?

  • A changing/evolving nature of threat landscape
  • A Lack of threat Visibility (ie what threats are active outside our organization)
  • Existing Threat Intelligence being too tactical and not reliable
  • A lack of expertise

Which other vendors did you consider before choosing CrowdStrike Threat Intelligence?

  • Artic Wolf, Fortinet, Dell Secureworks

Use Case

What features of CrowdStrike Threat Intelligence are you using?

  • Threat Alerts
  • Periodic Reports
  • Recon Feeds (Deep Dark Web, Criminal Markert Places, Forums)

Why did you choose CrowdStrike Threat Intelligence over other threat intelligence solutions?

  • Threat Collection & Visibility that CrowdStrike Owns
  • Depth of Threat Research
  • Workflow via Falcon Platform

Results

How they rated CrowdStrike Threat Intelligence compared to the competition:

  • Threat Coverage: Significantly Better
  • Integration Capabilities: Significantly Better
  • Actionability of Provided Intelligence: Best in Class
  • Depth of Research: Best in Class
  • Custom Research: Best in Class

What benefits did your organization realize following the deployment of CrowdStrike Threat Intelligence?

  • It has improved our global Threat Risk Awareness
  • We have found new threats that we had no prior knowledge of
  • It has helped us understand the impact of global cybersecurity events on our organization
  • It has improved data protection of critical information protection practices

In your best estimate, by what percent did CrowdStrike improve the following?

  • Improve their risk posture: 75-99%
  • Reduce alert investigation time & efforts: 100% +
  • Increase efficiency to threat detection & prevention: 100% +
  • Reduce threat research efforts: 100% +
  • Increase efficiency of risk mitigation efforts (Vulnerability Management): 100% +



More Research on CrowdStrike Threat Intelligence