SOC on CrowdStrike Falcon: what ANOMAL delivers for existing customers
ANOMAL runs a 24/7 SOC for organisations already invested in CrowdStrike Falcon. We orchestrate detection engineering, response and threat hunting on your Falcon console, correlate signals with identity and cloud, and take over documented response. Falcon is your platform, ANOMAL is your operations team.
How this compares to neighbouring topics
This page describes how ANOMAL operates a SOC on CrowdStrike Falcon. For fundamentals see What is a SOC. For the boundary between platform and managed service, see EDR vs. MDR and SOC vs. MDR. For the Microsoft counterpart, see SOC for Microsoft 365 and Sentinel. For Elastic environments, see SOC on Elastic Security. See SOC cost Switzerland for pricing details.
Who this page is for
This page is for organisations that already licence Falcon or are actively planning a migration. It covers ANOMAL's services around the platform: operations, detection engineering, response and reporting. The Falcon platform itself falls outside this page's scope. If you have not yet chosen a platform, start with SOC provider comparison.
What ANOMAL runs on your Falcon tenant
- 24/7 monitoring of the Falcon console by our analysts
- Detection engineering: customer-specific custom IOAs, Fusion workflows, suppression tuning
- Playbook-driven response: host containment, Real Time Response, process kill, rollback coordination
- Threat hunting with Falcon LogScale and Advanced Event Search on defined hypotheses
- Correlation with Entra ID, M365 and cloud signals outside Falcon
- Monthly reporting with MTTD, MTTR, MTTC, coverage map and open detections
How ANOMAL differs from Falcon Complete
Falcon Complete is CrowdStrike's own MDR service. It is strong but limited to the Falcon platform and delivered globally. ANOMAL provides our own analysts and Swiss communication channels. We correlate signals beyond Falcon across your Microsoft, identity and cloud environments, and integrate response into your own ICT processes. Both models serve different needs.
Falcon Complete is global MDR on one platform. ANOMAL is a Swiss SOC across your full environment, with Falcon as a strong sensor.
What documented response on Falcon looks like in practice
- Host containment within minutes of a confirmed detection
- Real Time Response session with audit log for immediate forensics
- Process and network kill according to defined playbooks
- Communication with your IT via a defined channel
- Full ticket and timeline documentation for audit, revFADP and insurance
Typical pitfalls
Falcon without active detection engineering is a strong sensor running generic rules. A service that watches the console and forwards alerts without responding covers visibility, not response. Second, Falcon covers endpoints strongly. Identity Protection and Cloud Security are separate, individually licensed CrowdStrike modules, and many existing customers only hold the core EDR contract. Even with Identity licensed, correlation with M365-specific signals remains outside CrowdStrike's own ecosystem. These signals include inbox rules, OAuth consent abuse and Exchange anomalies. ANOMAL provides this correlation. Third, without documented response rights the SOC cannot act when it matters. See SOC KPIs MTTD and MTTR for alert-quality KPIs.
Cost drivers
Cost for a managed SOC with Falcon follows endpoints, identities, data sources, data volume, response scope and onboarding; vendor licences come on top. Full cost logic under SOC cost Switzerland.
Falcon without analysts is an expensive console. Falcon with a SOC is a response platform.
Placement in SOC operations
SOC as a Service Switzerland explains how ANOMAL integrates Falcon into its operations.
Frequently asked questions
Do we have to change our existing Falcon contract?
You can keep your existing Falcon contract. ANOMAL works on your existing Falcon tenant. We need defined access with documented rights. Your CrowdStrike licence agreement remains unchanged.
Why ANOMAL instead of Falcon Complete?
Falcon Complete is strong on-platform but delivered globally and Falcon-only. ANOMAL provides our analysts with German, French and English communication, correlation beyond Falcon and response processes integrated into your own IT. If your scope is Falcon endpoints only and global support is acceptable, Complete is a good fit. If you want a hybrid environment with Swiss operations, ANOMAL is the right choice.
Which response rights does ANOMAL need in Falcon?
ANOMAL needs at least host containment and Real Time Response according to the playbook catalogue, plus detection management. Optional extensions include response actions for specific cases. The contract defines all rights, and the audit log records them.
How long does onboarding a Falcon environment take?
Onboarding takes several weeks. We use this time for access setup, playbook tuning, the custom IOA baseline, connecting data sources beyond Falcon and baseline calibration. See [SOC onboarding Switzerland](/en/soc/soc-onboarding-switzerland) for details.
Can ANOMAL also incorporate Falcon LogScale and Identity Protection?
ANOMAL can incorporate both modules. Where LogScale is licensed, it becomes part of the detection and hunting layer. We correlate Identity Protection as an additional signal source, especially for compromised credential and lateral movement detections.
Related terms
- EDR Endpoint Detection and Response (EDR) monitors activities on devices like laptops and servers, enabling intervention during attacks.
- XDR Extended Detection and Response (XDR) connects security signals from endpoints, identities, email, cloud and network in one platform.
- MDR Managed Detection and Response (MDR) is a service that detects threats and actively contains them.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Threat Hunting Threat Hunting is the targeted search for attackers within a network who have not yet triggered a detection.