Skip to main content

Network Inspection

AIDR integrates with Network Inspection, a Falcon sensor capability that intercepts network-layer traffic on endpoints. Through this integration, AIDR monitors interactions with

supported AI applications regardless of the client type - desktop applications, CLIs, or any web browser.

Considerations:
  • Input-only - AIDR processes only input events from network traffic, such as prompts sent to AI services. Model responses are not captured.
  • Report-only mode - AIDR operates in report-only mode for network events. Detections are logged but blocking and content transformations are not applied.
  • Payload limit - Events exceeding 1 MiB are not sent to AIDR.
  • No file attachments - AIDR doesn't process file attachments from network events.

Requirements

Requires all of these subscriptions:

  • AIDR for Workforce
  • Falcon Insight XDR

Sensor: Falcon sensor for Windows versions 7.40 and later

Default roles:

  • AIDR Admin
  • Falcon Administrator
  • Falcon Host Administrator

AIDR permissions required for custom roles:

  • Manage AIDR findings and workforce collectors
  • Read AIDR data from LogScale
  • Read AIDR findings and workforce collectors

CrowdStrike clouds: Available in US-1, US-2, and EU-1

System requirements:

For additional information, requirements, and considerations, see Network Inspection .

Supported AI applications

AIDR integration with Network Inspection monitors traffic to the following AI applications:

ChatGPT

ApplicationSurface type
ChatGPT websiteWebsite
ChatGPT Classic Windows appWindows desktop app

Claude

ApplicationSurface type
ClaudeWebsite
Claude Desktop app for WindowsWindows desktop app
Claude CodeCLI
Anthropic ConsoleWebsite or developer console
Claude CoworkWindows desktop app
Claude by Anthropic for ExcelMicrosoft Excel plugin
Claude by Anthropic for PowerPointMicrosoft PowerPoint plugin

DeepSeek

ApplicationSurface type
DeepSeekWebsite

Google Gemini

ApplicationSurface type
GeminiWebsite

Microsoft 365 Copilot

ApplicationSurface type
Microsoft 365 Copilot app for WindowsWindows desktop app
Microsoft 365 Copilot in Word for WindowsWindows Office desktop app
Microsoft 365 Copilot in Excel for WindowsWindows Office desktop app
Microsoft 365 Copilot in Outlook for WindowsWindows Office desktop app
Microsoft 365 Copilot in Teams for WindowsWindows Teams desktop app
Microsoft 365 Copilot in OneNote for WindowsWindows Office desktop app

Microsoft Copilot

ApplicationSurface type
Microsoft Copilot app on WindowsWindows desktop app
Microsoft Copilot entry point in Windows taskbar or Copilot keyWindows OS integration
Microsoft Copilot in Microsoft EdgeWindows browser integration
Microsoft Copilot websiteWebsite
Microsoft Copilot StudioWebsite

Next steps

©2026 CrowdStrike. All rights reserved.

PrivacyTerms of UseLegal Notices