CrowdStrike introduced its Falcon for Defender during the RSA Conference 2024, designed to deploy OverWatch threat hunting and independent security validation on endpoints alongside Microsoft Defender security tools as the safety net to catch the breaches and detections that Microsoft missed.
“We are doing this primarily because customers, who are just purely running Microsoft, are unable to stop the breach to keep their estates safe,” CrowdStrike Head of Products Raj Rajamani told SDxCentral. “We've seen this happen numerous times and customers have come to us and say: Hey, we need something that could actually act as an eventual safety net.”
The Falcon for Defender is designed to meet that need and offers a subset of functionality from the full CrowdStrike Falcom platform with the same console, backend and sensors, according to Rajamani. While the vendor has not disclosed the exact pricing, he hinted that it would be “very attractively priced.”
Microsoft’s ongoing security issues
Despite Microsoft's extensive reach and integral role in global IT infrastructure, its security culture has faced criticism.
In a scathing 34-page report released by the U.S. Department of Homeland Security (DHS), the Cyber Safety Review Board (CSRB) has determined that Microsoft’s security culture was “inadequate,” following its investigation into the Summer 2023 Microsoft Exchange Online intrusion that impacted millions of users.
CrowdStrike revealed in April 2023 that when its incident response team investigates a Microsoft customer that has been breached, over 75% of the time Microsoft Defender has been bypassed. Rajamani noted Microsoft is one of the top vulnerable software producers.
However, he argues some security leaders use Microsoft security tools for commercial reasons. “Frequently what happens is at a CFO level, they are committing a few hundreds of millions of dollars to Microsoft. And Microsoft says: hey, I'm giving you E3 and E5 and you get all of the security products and all of the productivity tools and all a bunch of Azure credits to go with it.”
CrowdStrike’s Falcon for Defender is aimed at organizations of all sizes but is particularly appealing to these large enterprises who have committed substantial financial resources to Microsoft and are therefore hesitant or financially constrained when it comes to adopting additional security solutions such as a full CrowdStrike Falcon platform, but need to bolster their defenses immediately.
“It all comes to peace of mind,” Rajamani said. “Maybe a few years ago, you could just go with a good enough security tool, but what we are definitely seeing is that any small gap in a product, any vulnerability in a product or any weakness in a product gets immediately exploited,”
CrowdStrike offers ‘safety net’ to Microsoft Defender
The CrowdStrike Falcon for Defender ingests Microsoft Defender alert data to detect and respond to missed adversary behavior. It enables security teams to review side-by-side detections from both CrowdStrike and Microsoft Defender within the Falcon console.
“We are keeping it as lightweight and as low touch as possible,” Rajamani said. Customers only need to install and deploy CrowdStrike’s sensors to allow the integration of Microsoft Defender with CrowdStrike’s next-generation security information and event management (SIEM).
He noted the Falcon for Defender is a safety net to enhance security, instead of replacing the whole security system. “[Customers] will come to our console only if they find that something has been missed.”
Falcon for Defender users can also add Falcon OverWatch or other services from CrowdStrike for threat hunting and attack response and recovery.
“Ideally, we would have the full preventative capabilities from the full Falcon platform enabled. But we understand that in some situations for various reasons, a lot of times nontechnical reasons, customers may have to go with a different choice of products to protect,” Rajamani said.
“When those protections are enabled to keep the customer safe, we provide that safety net where we have the telemetry, make it easy for you to remediate and clean up, as well as enable the rest of the capability so that you don't end up in the same situation again,” he added.
Comments