Skip to main content
Has your work email already leaked?Run the 10-second check
Who does what

Falcon Complete runs the MDR. Someone still has to build it.

The first thing a CrowdStrike-aware buyer asks us is what we do that Falcon Complete does not. The answer is in CrowdStrike's own onboarding: look at which column the work falls in.

Not a comparison. Vijilan is a CrowdStrike Powered Service Provider. Falcon Complete is a strong service and where a client runs it we do not duplicate it. This page is about the boundary, because the boundary is where the surprises live.

The short answer

CrowdStrike Falcon® Complete is managed detection and response: CrowdStrike triages, tunes and remediates on the Falcon estate around the clock, with Security Advisors, front-line Analysts and Falcon Adversary OverWatch behind it. CrowdStrike reports it is on average fully deployed and operational within five business days.

What its onboarding hands to the customer is the engineering. Deploying sensors until coverage is actually complete, identifying and connecting data sources, writing parsers for the sources with no purpose-built connector, wiring MFA, IDaaS and SOAR. That work is real, and it is the customer's unless somebody does it for them.

That is most of what an implementation partner does, and it is why the two sit together rather than against each other.

The boundary

Four stages. Three columns.

CrowdStrike's and the customer's columns are drawn from CrowdStrike's own deployment material. The third is what we take off your side of it.

Getting started
CrowdStrike

Welcome pack, operating model, onboarding guide and weekly webinar access.

Yours

Log into the Falcon portal, begin sensor deployment, work the onboarding wizard, nominate contacts, security postures and escalation paths.

Where we come in

We run the rollout and the wizard with you, and we are the escalation contact if you would rather not staff one.

Configure
CrowdStrike

Host groups and prevention policies. For identity, MFA and SOAR and traffic inspection. For Next-Gen SIEM, correlation rules.

Yours

Keep the sensor rollout moving until coverage is complete. Register cloud accounts. Configure MFA connectors, IDaaS and SOAR actions.

Where we come in

This is the engineering block. Connector and parser work, identity plumbing, cloud account onboarding, and chasing the last unmanaged hosts.

Connect and ingest
CrowdStrike

Purpose-built connectors and ingestion guides. CrowdStrike validates and tunes the correlation rules.

Yours

Identify the data sources and get them flowing.

Where we come in

Deciding what to send, what it costs and how it parses. The sources that have no purpose-built connector are the ones that take the time.

Go live and ongoing
CrowdStrike

Triage, tuning, remediation, 24/7 monitoring and threat hunting. Security Advisors on health checks, Analysts on the front line, Adversary OverWatch hunting across the data.

Yours

Receive remediation notifications, confirm false positives, escalate when asked.

Where we come in

Everything outside the Falcon estate, and the sources Falcon Complete does not watch. Where you already have Falcon Complete, we do not duplicate it.

It has already happened

CrowdStrike recommended us for exactly this.

At Practising Law Institute, CrowdStrike recommended and assigned Vijilan as the implementation partner. Falcon Complete continued to own PLI's 24/7 managed detection and response throughout. Vijilan stood up Falcon Next-Gen SIEM alongside it, on a tight timeline with a team new to the platform.

  • Roughly 80 percent tuned to PLI's needs by the end of knowledge transfer, PLI's own estimate.
  • Later confirmed by an independently hired lead security engineer, who found only minor tuning left.
  • One view across endpoint, network, cloud and identity, with Falcon Complete still running the MDR.
Read the case study
"Having those capabilities integrated into a single platform has simplified operations, improved our security posture, and allowed us to focus on strategic initiatives rather than day-to-day monitoring and management."
— Liang Chen, Director, Network Operations, Practising Law InstituteRead the case study

Common questions

CrowdStrike already sells Falcon Complete. What does Vijilan do that they do not?

Falcon Complete is managed detection and response: CrowdStrike triages, tunes and remediates on the Falcon estate around the clock. What its onboarding hands to the customer is the engineering. Deploying sensors to full coverage, identifying and connecting data sources, writing parsers for the sources with no purpose-built connector, wiring MFA and IDaaS and SOAR. That work is real and it is yours unless somebody does it for you. It is also most of what we do.

Do you replace Falcon Complete?

No, and we would usually advise against it if it is working. We are a CrowdStrike Powered Service Provider and Falcon Complete is a strong service. Where a client already runs it, we do not duplicate the MDR: we take the implementation work, the sources outside the Falcon estate, and the parts of the environment Falcon Complete was never scoped to watch.

Has that actually happened, or is it a diagram?

It has happened. CrowdStrike recommended and assigned Vijilan as the implementation partner at Practising Law Institute. Falcon Complete continued to own PLI’s 24/7 managed detection and response throughout. Vijilan stood up Falcon Next-Gen SIEM alongside it, and PLI estimated the environment was roughly 80 percent tuned by the end of knowledge transfer, later confirmed by an independently hired lead security engineer who found only minor tuning left.

How long does Falcon Complete take to deploy?

CrowdStrike reports that Falcon Complete is, on average, fully deployed and operational within five business days. That figure describes CrowdStrike’s side of the work. The sensor rollout, data source onboarding and connector engineering on the customer side run to whatever your estate and your team make them, which is the part worth planning for.

What if we do not have Falcon Complete?

Then the question is which model fits. ThreatDefend™ is managed CrowdStrike Falcon run by our SOC, license included. ThreatRespond™ wraps a 24/7 SOC around whatever endpoint tooling you already own, Falcon or otherwise. NextDefend™ is managed Falcon Next-Gen SIEM. None of them requires you to have bought anything from CrowdStrike first.

We are an MSP. Can we put our own name on this?

Yes. Every tier ships white-label, and we never compete with our partners for their clients. If your client runs Falcon Complete and needs the implementation and the non-Falcon coverage around it, that engagement can be delivered entirely under your brand.

Already running Falcon Complete?

Then you do not need MDR from us. You may need the rollout finished, the sources that never got connected, or coverage of the estate Falcon Complete was not scoped to watch. Start by measuring which of those is actually true.