Skip to main content

Falcon Endpoint Collector

The Falcon Endpoint collector monitors AI activity on endpoints through the Falcon sensor's built-in integrations.

The Falcon Endpoint collector supports two data sources:

  • Falcon Browser Extension - Monitors AI activity in Chrome and Edge web browsers through the Falcon browser extension.
  • Network Inspection - Monitors AI activity in desktop applications, CLIs, and any browser through network-layer traffic inspection at the sensor level.

Deploy the Falcon Endpoint collector when:

  • Your endpoints run the Falcon sensor.
  • You prefer sensor-managed integrations instead of standalone browser extensions and collectors.
  • You want to assign AIDR policies to Falcon host groups for consistent security coverage.

If your endpoints don't run the Falcon sensor, you can use AIDR collectors that don't require it. For more information, see Collectors Overview .

Comparison

Browser ExtensionNetwork Inspection
MonitorsWeb browsers (Chrome, Edge)Desktop applications, CLIs, and any browser
PlatformWindows (x64, Arm64), MacWindows
Sensor version7.39+ (Windows), 7.40+ (Mac)7.40+
Input enforcementBlock, Transform, ReportReport
Output enforcementReportNot captured

Next steps

©2026 CrowdStrike. All rights reserved.

PrivacyTerms of UseLegal Notices