CrowdStrike Falcon Identity Protection vs. Exabeam Fusion

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
CrowdStrike Falcon Identity Protection
Score 0.0 out of 10
N/A
CrowdStrike Falcon Identity Protection delivers identity threat detection and response (ITDR) capabilities, protecting organizations from identity-based attacks in real time. It unifies identity and endpoint protection. Falcon® Identity Protection ensures comprehensive visibility and protection across on-premises, cloud, and hybrid identity environments. By baselining normal user behavior, it detects and prevents malicious identity activity, stopping adversaries in their tracks. It also extends…N/A
Exabeam Fusion
Score 4.2 out of 10
N/A
Exabeam headquartered in San Mateo, Exabeam Fusion, a SIEM + XDR. The vendor states the modular Exabeam platform allows analysts to collect unlimited log data, use behavioral analytics to detect attacks, and automate incident response. The Exabeam platform can be deployed on-premise or from the cloud. Exabeam can also integrate information from the Exabeam Threat Intelligence Service, or into a third-party SIEM.N/A
Pricing
CrowdStrike Falcon Identity ProtectionExabeam Fusion
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
CrowdStrike Falcon Identity ProtectionExabeam Fusion
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
CrowdStrike Falcon Identity ProtectionExabeam Fusion
User Ratings
CrowdStrike Falcon Identity ProtectionExabeam Fusion
Likelihood to Recommend
-
(0 ratings)
8.5
(0 ratings)
Usability
-
(0 ratings)
9.0
(0 ratings)
Support Rating
-
(0 ratings)
9.0
(0 ratings)
User Testimonials
CrowdStrike Falcon Identity ProtectionExabeam Fusion
Likelihood to Recommend
Identity Protection is well suited for organizations that need to be monitor AD/Entra for suspicious activity. During a Penetration Test our MDR didn't alert on some odd protocol implementations, but ITDR did. It is also simple to setup for MFA on RDP as well. There are other solutions for it, but found I got more out of ITDR than I did from Duo. ITDR is less suited for smaller organizations since it has a 250-seat minimum. They should lower it to at least 100.
Read full review
As a SIEM tool for investigations, Exabeam is the best in class. The AI assigns numeric values to observed logs them presents high scores to the analyst in a simple dashboard. We can see what is a real threat and ignore so many false positives. Exabeam is the best SIEM was used from an alert fatigue perspective. The simple interface allows other teams not just InfoSec to utilize the tool; helpdesk for asset diagnoses, HR for staffing questions, etc.
Read full review
Pros
  • The MFA component has worked great when it comes to privileged accounts accessing RDP.
  • We wanted to stop lateral movement between endpoints and with CrowdStrike Falcon Identity Protection we were able to do that.
  • Identity has done a great job at supplementing our MDR service with telemetry.
Read full review
  • Simple graphical interface
  • Plan text searching, no need to know another coding language
  • Very very fast response
  • All saved logs up to 7 years instantly searchable
  • Not cold or frozen buckets for years old logs
Read full review
Cons
  • It's not really a fault of the product, but unless you have Falcon installed on all your endpoints your visibility is limited.
  • I've yet to get MFA working on CIFS and Powershell traffic.
  • The interface could be streamlined a little. CrowdStrike Falcon Identity Protection keeps changing where things are.
Read full review
  • Improvements on top of Lucene/KQL to add more search functions.
  • Stability of the overall deployment.
  • Ability to run version upgrades quicker and without data ingestion problems afterward.
  • More documentation and examples about the API functionality available.
Read full review
Usability
While the product is solid, I do find there are an excessive number of sections you can navigate to. It takes some time getting used to, but it is a very powerful product. It's not something you'll master right off the bat.
Read full review
The system is set up to run out of the box. It has a simple easy to understand the graphical interface. Exabeam designed its SIEM from the ground up to be user-friendly and intuitive. They designed it to use plain text searches so no special training is needed. You do NOT have to learn another programming language and keep up with it daily to be proficient and productive with the tool, unlike all other SIEMs we have used before. Did I mention we love Exabeam?
Read full review
Support Rating
No answers on this topic
The engineers working to support Exabeam are very professional and competent. They always arrive prepared for troubleshooting meetings and provide helpful input to resolve most issues without requiring excessive escalation whenever possible. Their support team is good at promptly providing parsers that can be used to enhance the product's functionality and ensure fields are all populated.
Read full review
Alternatives Considered
When comparing to Cisco Duo, I felt like the product offered more than just MFA on RDP. When comparing to Silverfort, it came down to pricing. Silverfort was double the cost and I didn't like how Silverfort had separate SKUs. If you wanted MFA on everything the cost increased dramatically.
Read full review
No answers on this topic
Return on Investment
  • Being able to see right away during a Penetration Test that the product detected anomalies, but our MDR service didn't. It allowed us to go back to the MDR service to show them the results and fix the issue from slipping through the cracks.
  • By satisfying the requirements from our insurance provider, our premiums didn't go up (MFA on RDP).
Read full review
  • Reduced time to triage alerts.
  • Reduced number of alerts which need escalation to senior tiers.
  • The ability for analysts to quickly run playbooks for additional information and enrichment.
  • Ability to retain data for longer periods for forensics purposes.
  • Improved search performance compared with other SIEM solutions.
Read full review
ScreenShots