Home Solutions CrowdStrike
Endpoint · EDR/XDR · Authorized partner: CYBER BOOST
CrowdStrike logo

Falcon is a platform that stops attacks early.

CrowdStrike Falcon is a cloud platform. One lightweight agent protects endpoints, identities and cloud workloads. NGAV, EDR/XDR, threat intelligence and 24/7 OverWatch managed hunting are all in one console. CYBER BOOST officially supplies and supports Falcon in Uzbekistan.

#1
A Leader in the Gartner Magic Quadrant for Endpoint Protection Platforms.
29,000+
organizations worldwide use Falcon every day.
1 agent
for Windows, macOS, Linux, servers, VMs, containers and the cloud.
100%
visibility and prevention in the MITRE ATT&CK Evaluations (Enterprise).
Why Falcon

The attacker leaves no files behind.
Antivirus has nothing to catch.

80% of modern attacks are fileless, use stolen credentials to take over accounts or rely on living-off-the-land techniques. Signature-based protection can’t see them. Falcon is built on a behavioral model, ML models and CrowdStrike Threat Graph cloud analytics.

  • Cloud architecture. No on-prem management servers, no maintenance windows.
  • One agent. Less than 1% CPU, <40 MB of RAM, no reboot required.
  • Threat Graph. Event correlation across 270M+ endpoints in real time.
  • OverWatch 24/7. A team of threat hunters tracks targeted APTs in your environment.
What Falcon covers
One agent for the whole attack surface
NGAV: prevention of known and unknown threats
ML models, IOAs, exploit prevention, ransomware blocking.
FALCON PREVENT
EDR/XDR: investigation and response
Full telemetry of processes, network and registry; graph visualization of the incident.
FALCON INSIGHT
Threat intelligence on 230+ APT groups
Attribution, IOC feeds, technical profiles, the threat picture for your region.
FALCON INTEL
Identity Protection: protecting accounts
Pass-the-Hash, Kerberoasting, AD threats, user behavior analytics.
FALCON IDENTITY
Cloud Security: CWP, CSPM, containers
AWS, Azure, GCP, Kubernetes, Linux workloads, serverless functions.
FALCON CLOUD
The Falcon platform

18 modules under one agent and one console.

Connect only what you need now and scale as your SOC matures. Falcon Complete is available as a fully managed service.

FALCON 01Prevent (NGAV)ML/AI and behavioral prevention of malware and fileless attacks.
FALCON 02Insight (EDR/XDR)Extended telemetry, real-time response, graph analysis.
FALCON 03OverWatch24/7 managed threat hunting by the CrowdStrike team.
FALCON 04IntelligenceA threat intelligence portal, profiles of 230+ APTs, IOC feeds.
FALCON 05DiscoverIT hygiene: inventory of assets, applications and accounts.
FALCON 06SpotlightReal-time vulnerability management without a scanner.
FALCON 07Identity ProtectionProtection for AD and IdPs, detection of Pass-the-Hash and Kerberoasting.
FALCON 08Cloud SecurityCWP, CSPM, CIEM, protection for Kubernetes and serverless workloads.
FALCON 09SandboxDynamic analysis of samples in a cloud sandbox.
FALCON 10ForensicsDeep artifact analysis without an on-site visit.
FALCON 11LogScale (SIEM)A next-gen SIEM with search across petabyte-scale indexes.
FALCON 12Complete (MDR)A fully managed service: prevention, investigation, response.
+ Device Control, Firewall Management, Surface (EASM), FileVantage, Horizon (CSPM), Counter Adversary Operations.
The 1-10-60 rule

1 minute to detect.
10 to investigate.
60 to contain.

CrowdStrike based this benchmark on real breakout times observed for 230+ APT groups. With Falcon, a SOC can meet it without hiring more staff.

Average eCrime breakout time
79 minutes is all you have.
1 min
Detect
Falcon Prevent ML models and IOA engines stop the attack before the process gains a foothold.
10 min
Investigate
Falcon Insight rebuilds the graph of processes, network connections and the registry in real time.
60 min
Respond
Real-Time Response: host isolation, artifact collection, remote execution of playbooks.
Source: CrowdStrike Global Threat Report. CYBER BOOST sets your 1-10-60 SLA targets to match the maturity of your SOC.
MITRE ATT&CK

14 tactics and 200+ techniques covered by Falcon telemetry.

In the 2024 Enterprise Evaluations, Falcon demonstrated 100% visibility and 99% analytic coverage. Below is a simplified coverage map by ATT&CK Enterprise tactics.

ReconResourceInitialExecutionPersistencePriv-EscDefenseCredentialDiscoveryLateralCollectionC2ExfilImpact
Full analytics
Detection
Telemetry
Out of scope
Source: MITRE Engenuity ATT&CK Evaluations · Enterprise.
Falcon OverWatch
24/7 Managed Threat Hunting
01
Analysis of attacker behavior
based on the tactics, techniques and procedures (TTPs) of 230+ APT groups, not on signatures.
02
Only real incidents are escalated
no false positives to triage, only confirmed threats.
03
Clear recommendations
on containment, remediation and hardening for every alert.
04
Quarterly hunt reports
a summary of detections, SOC metrics and industry trends.
Service · OverWatch

Without threat hunters, EDR is just log storage.

OverWatch is a CrowdStrike team that hunts for stealthy threats 24/7 on top of Falcon Insight. These include living-off-the-land, insider and low-and-slow APT attacks that no ML model can see.

The average time from compromise to escalation is under 5 minutes. The team covers every time zone and writes in Russian and English.

Get OverWatch
Use cases

Where Falcon gives measurable results.

Replacing outdated AV

Falcon first runs alongside your current antivirus. Then the old product is switched off, with no maintenance window.

Ransomware protection

Behavior-based blocking of ransomware such as Conti, LockBit, BlackCat and Akira, without signatures.

Protecting remote workers

Cloud architecture: the agent needs no VPN or internal management server and works from anywhere.

Incident response

Falcon Forensics + Real-Time Response. Isolation, artifact collection and remote investigation without sending a team on site.

Compliance: PCI DSS, ISO 27001, STB

Falcon covers the requirements for EDR and operations auditing, with reports and ready-to-use playbooks for auditors.

Cloud workloads & Kubernetes

Protection for AWS/Azure/GCP, runtime protection for containers and admission control in Kubernetes clusters.

CYBER BOOST × CrowdStrike

Falcon in Uzbekistan, through a local partner.

CYBER BOOST supplies, licenses and supports Falcon. We adapt the processes to your policies and translate the console and alerts. We also provide first-line support and connect you with CrowdStrike engineers.

5 years
is the average length of our clients’ Falcon projects, from pilot to a mature SOC.
RU/UZ
local engineering support and contracts in soums and US dollars.
14 days
typical time for a pilot deployment on 1,000 endpoints.
L1–L3
all support goes through CYBER BOOST: policy configuration, alert analysis, retesting.
FAQ

Frequently asked questions about CrowdStrike Falcon.

How is CrowdStrike Falcon different from classic antivirus?
Falcon is a cloud platform built on one lightweight agent. It uses behavioral analysis, machine learning and the OverWatch managed threat hunting service. Unlike signature-based antivirus, Falcon detects fileless attacks, attacks with stolen credentials and living-off-the-land techniques.
How long does it take to deploy Falcon?
Basic coverage of 2,000-10,000 workstations takes 2-4 weeks. The agent is installed through group policies and needs no reboot. It runs alongside your existing antivirus, so you can migrate without a maintenance window.
Does CrowdStrike support Linux and macOS servers?
Yes. The same agent covers Windows, macOS, Linux (RHEL, Ubuntu, SUSE, Amazon Linux, Oracle Linux), ARM and x86 architectures, virtual machines, Kubernetes containers and serverless workloads in AWS, Azure and Google Cloud.
Can Falcon be connected to our SIEM?
Yes. Falcon streams telemetry through the Streaming API and integrates with Splunk, Microsoft Sentinel, IBM QRadar, Elastic and ArcSight. The platform has an open REST API and Falcon LogScale as its own next-gen SIEM if you don’t have one yet.
What does the OverWatch service include?
OverWatch is a team of CrowdStrike threat hunters who work 24/7. They search your environment for traces of targeted attacks, escalate suspicious activity and advise on how to respond. The service works on top of EDR and does not replace a SOC.
Where is customer data stored?
CrowdStrike offers several cloud regions: EU, US and AU. You can choose a data center in the European Union to host your telemetry. All communications are encrypted with TLS 1.3, and access follows a zero-trust model.
Request · Falcon

A Falcon pilot on your assets in 2 weeks.

For qualified customers we cover up to 1,000 endpoints in a pilot project free of charge. Fill in the form and our engineer will contact you within one business day.