Network Inspection
AIDR integrates with Network Inspection, a Falcon sensor capability that intercepts network-layer traffic on endpoints. Through this integration, AIDR monitors interactions with
supported AI applications regardless of the client type - desktop applications, CLIs, or any web browser.- Input-only - AIDR processes only input events from network traffic, such as prompts sent to AI services. Model responses are not captured.
- Report-only mode - AIDR operates in report-only mode for network events. Detections are logged but blocking and content transformations are not applied.
- Payload limit - Events exceeding 1 MiB are not sent to AIDR.
- No file attachments - AIDR doesn't process file attachments from network events.
Requirements
Requires all of these subscriptions:
- AIDR for Workforce
- Falcon Insight XDR
Sensor: Falcon sensor for Windows versions 7.40 and later
Default roles:
- AIDR Admin
- Falcon Administrator
- Falcon Host Administrator
AIDR permissions required for custom roles:
- Manage AIDR findings and workforce collectors
- Read AIDR data from LogScale
- Read AIDR findings and workforce collectors
CrowdStrike clouds: Available in US-1, US-2, and EU-1
System requirements:
-
Windows 11 version 23H2 or later, 64-bit only
note:Network inspection is not supported on Windows 11 Arm64 hosts.
-
Supported Windows 10 versions
For more information, see
Windows OS versions supported by the Falcon Sensor .
For additional information, requirements, and considerations, see Network Inspection .
Supported AI applications
AIDR integration with Network Inspection monitors traffic to the following AI applications:
ChatGPT
| Application | Surface type |
|---|---|
| ChatGPT website | Website |
| ChatGPT Classic Windows app | Windows desktop app |
Claude
| Application | Surface type |
|---|---|
| Claude | Website |
| Claude Desktop app for Windows | Windows desktop app |
| Claude Code | CLI |
| Anthropic Console | Website or developer console |
| Claude Cowork | Windows desktop app |
| Claude by Anthropic for Excel | Microsoft Excel plugin |
| Claude by Anthropic for PowerPoint | Microsoft PowerPoint plugin |
DeepSeek
| Application | Surface type |
|---|---|
| DeepSeek | Website |
Google Gemini
| Application | Surface type |
|---|---|
| Gemini | Website |
Microsoft 365 Copilot
| Application | Surface type |
|---|---|
| Microsoft 365 Copilot app for Windows | Windows desktop app |
| Microsoft 365 Copilot in Word for Windows | Windows Office desktop app |
| Microsoft 365 Copilot in Excel for Windows | Windows Office desktop app |
| Microsoft 365 Copilot in Outlook for Windows | Windows Office desktop app |
| Microsoft 365 Copilot in Teams for Windows | Windows Teams desktop app |
| Microsoft 365 Copilot in OneNote for Windows | Windows Office desktop app |
Microsoft Copilot
| Application | Surface type |
|---|---|
| Microsoft Copilot app on Windows | Windows desktop app |
| Microsoft Copilot entry point in Windows taskbar or Copilot key | Windows OS integration |
| Microsoft Copilot in Microsoft Edge | Windows browser integration |
| Microsoft Copilot website | Website |
| Microsoft Copilot Studio | Website |
-
All browsers are supported. Network Inspection works at the network layer, so the AIDR integration works with any browser accessing the supported applications.
-
Cursor, an AI code platform, is not supported at this time.
-
If your internal AI gateway uses a request structure that matches a supported provider's API, you can open a Support case to add the gateway's custom FQDN and path to monitoring.