BrickellTechnologies

Service

Endpoint Security & CrowdStrike Falcon

We deploy CrowdStrike Falcon, tune it against techniques we use on real engagements, and show you the telemetry from the attempt. Then we hand it over with runbooks so you own it.

Why an offensive shop does endpoint work

Because we spend the other half of the week trying to get past exactly this. When we tune a Falcon policy we are tuning against the tooling and the tradecraft we would use on your network next month, not against a vendor slide about what the product theoretically catches.

The gap between "the agent is installed" and "the agent would have stopped that" is where most EDR deployments quietly live. Closing it is the job.

Where engagements usually start

Migration off legacy antivirus

Signature-based products are still running in a lot of places, usually because the migration looked risky. Done in rings, with coexistence during the overlap and reporting on which hosts have which agent, it is not risky. It is a scheduling problem. The part people underestimate is the tail: the 5% of machines that are off the network, reimaged, or owned by someone who ignores every email.

Policy tuning

Out of the box, Falcon is conservative. Left alone it stays that way, and a year later you are paying for an expensive audit log. We move prevention up deliberately, ring by ring, watching for false positives and writing every exclusion down with a reason and a review date.

Detection validation

This is the part that separates a real deployment from a purchase. We run credential dumping, lateral movement, persistence and defence-evasion techniques on a controlled host and check what your console actually shows: whether it fired, what severity, whether anyone would notice at 2am, and whether the telemetry would let you reconstruct events afterwards. You get a matrix of what was blocked, what was detected, and what went by unseen.

Nobody scores 100%, and a vendor telling you otherwise is selling. The point is knowing which gaps you have, so they are decisions instead of surprises.

Beyond the base agent

Identity Protection catches the Active Directory attacks the endpoint sensor cannot see on its own, which matters given how much internal testing ends in Kerberos abuse rather than malware. Exposure management ties into the vulnerability work and cloud modules into cloud posture. We will tell you which of these you need and which you can skip.

Handover, not dependency

You get runbooks: how to triage a detection, how to add an exclusion and who signs off, what to do when a host is contained, and the escalation path when something is real. Written for whoever is actually on call, not for a security team you do not have. We would rather be your annual testing partner than your permanent console babysitter.

Questions we get asked

Do you handle CrowdStrike licensing, or only the deployment?

Either. We can source licensing through our CrowdStrike partnership, or deploy and tune alongside a reseller you already buy from. Plenty of clients come to us because they bought Falcon eighteen months ago and it is still sitting in detect-only mode.

How long does a rollout take?

The agent goes out fast; a few hundred endpoints is days, not weeks, once packaging is sorted with your deployment tooling. Tuning is the long pole and it should be. Expect two to four weeks in a phased ring before you turn prevention up everywhere, longer if you have developer machines or unusual line-of-business software that needs exclusions written carefully.

Can we run Falcon alongside our current antivirus during the migration?

Yes, and for a short window you should. Falcon coexists with most legacy AV, so you run both, confirm coverage and performance, then remove the old agent ring by ring. The dangerous version is ripping the old product out on a Friday and discovering on Monday that 12% of the fleet never got the new one.

What about Mac and Linux?

Both are supported and both get treated as first-class here, which is not always true elsewhere. Linux server policy in particular needs its own thinking; the exclusions that make sense on a developer laptop are wrong on a container host.

Do you run 24/7 monitoring for us?

We are not a SOC, and we would rather say so than sell you one. What we do is get the platform deployed, tuned and validated, then help you decide honestly between Falcon Complete, a managed provider, or your own team with a written runbook. If you already have an MSSP we will hand over to them cleanly.

Will turning prevention on break our line-of-business software?

It can, which is exactly why the rollout is phased and why exclusions get written with a documented reason attached. An undocumented exclusion is a hole nobody remembers creating; three years later it is the reason an attacker had a safe directory to work from. Every exclusion we write gets a justification and a review date.

Know what an attacker would reach first.

Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.