Skip to main content

CrowdStrike Falcon

Advanced Endpoint Protection

CrowdStrike Falcon is the endpoint detection and response (EDR) platform used to monitor and protect devices, including laptops, desktops, and servers, from malware, ransomware, and other cyber threats. It runs quietly in the background, watching for suspicious activity in real time and using behavioral analysis and threat intelligence to catch attacks that traditional antivirus tools miss.

Features

CrowdStrike Falcon provides advanced defensive capabilities against modern computer and network threats. It replaces traditional signature-based antivirus with a sophisticated set of behavioral models, enabling it to detect advanced and novel threats. It has the following features/characteristics:

  • Low memory and performance impact.
  • Combines hash-based signature detections with behavioral detections based on both specific heuristics and machine learning models.
  • Includes multiple detections for and defenses against ransomware activity.

Note that CrowdStrike provides full Endpoint Detection and Response (EDR) capabilities. It uploads a transcript of system events like program launches and network connections to a cloud-based detection infrastructure, and those logs are used to detect threats. The CrowdStrike agent continues to protect systems even while they are offline.

Designed for

Current Faculty, Staff, School of Medicine Students, and Student-Staff that are managed by BigFix and/or Jamf. Devices not used for Stanford work are not eligible for CrowdStrike. See the FAQ for additional information.

Requirements

  • Supported versions of Mac OS , Windows and Linux

Data security

May be used on systems that store Low, Moderate, and High Risk Data, as defined by the Information Security Office.

Rates

Free of charge

 

Get started

Windows - Centrally deployed to BigFix managed systems. 

MacOS - Centrally deployed to Jamf managed systems.

Get help

Connect with us on the Stanford-UIT Slack instance at #iso-crowdstrike

Submit a Help request to ISO Security Operations.

Learn more

FAQ - Frequently Asked Questions

Last modified