Falcon Endpoint Collector
The Falcon Endpoint collector monitors AI activity on endpoints through the Falcon sensor's built-in integrations.
The Falcon Endpoint collector supports two data sources:
- Falcon Browser Extension - Monitors AI activity in Chrome and Edge web browsers through the Falcon browser extension.
- Network Inspection - Monitors AI activity in desktop applications, CLIs, and any browser through network-layer traffic inspection at the sensor level.
Deploy the Falcon Endpoint collector when:
- Your endpoints run the Falcon sensor.
- You prefer sensor-managed integrations instead of standalone browser extensions and collectors.
- You want to assign AIDR policies to Falcon host groups for consistent security coverage.
If your endpoints don't run the Falcon sensor, you can use AIDR collectors that don't require it. For more information, see Collectors Overview .
Comparison
| Browser Extension | Network Inspection | |
|---|---|---|
| Monitors | Web browsers (Chrome, Edge) | Desktop applications, CLIs, and any browser |
| Platform | Windows (x64, Arm64), Mac | Windows |
| Sensor version | 7.39+ (Windows), 7.40+ (Mac) | 7.40+ |
| Input enforcement | Block, Transform, Report | Report |
| Output enforcement | Report | Not captured |
Next steps
- See overview and requirements:
- Deploy Falcon Endpoint Collector