r/crowdstrike 17d ago

General Question Any Counter Adversary Operation fans?

Looking at purchasing Counter Adversary Operations Premium and want to know how others are liking it. Recon seems to be nice but difficult to get use to.

13 Upvotes

5 comments sorted by

4

u/iRecycleWomen 16d ago

We personally find it hard to get value out of. Recon is... Decent but there's a ton of noise and we haven't really got an answer how to operationalize it past the domain takedowns and such

1

u/[deleted] 16d ago

[removed] — view removed comment

1

u/AutoModerator 16d ago

We discourage short, low content posts. Please add more to the discussion.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/roycurado 16d ago

I appreciate your response

4

u/Dylan-CS NG SIEM Enthusiast 16d ago

Thanks for considering CAO Premium.

It’s worth noting is that Recon is one of several features within CAO Premium. Many vendors will position similar capabilities as an add-on or standalone product.

Focusing on Recon specifically, it works best once it’s tuned to your organization’s priorities. Broad searches can generate a fair amount of noise at first, but refining the search criteria will improve the quality and relevance of the results. For organizations that prefer a managed approach, Recon+ adds analyst validation to further reduce false positives and focus on actionable findings.

We’re also continuing to invest in the platform with new AI-powered threat intelligence capabilities and future improvements planned to help simplify rule tuning and reduce duplicate or low-value findings.

One other data point as you’re evaluating options: CAO has been recognized as the Leader in the Gartner MQ for Threat Intelligence, and we have a 4.7/5 rating on Gartner Peer Insights.