Skip to main content

Network Inspection

AIDR integrates with Network Inspection, a Falcon sensor capability that intercepts network-layer traffic on endpoints. Through this integration, AIDR monitors user prompts and provider responses for

supported AI applications regardless of the client type - desktop applications, CLIs, or any web browser.

Considerations:
  • Report-only mode - AIDR logs detections for network events but doesn't apply blocking or content transformations.
  • Payload limit - Events exceeding 1 MiB are not sent to AIDR.
  • No file attachments - AIDR doesn't process file attachments from network events.

Requirements

Requires all of these subscriptions:

  • AIDR for Workforce
  • Falcon Insight XDR

Sensor:

  • Falcon sensor for Windows version 7.40 and later

  • Falcon sensor for Windows version 8.10 and later adds these capabilities:

    • Provider response visibility
    • Coverage for additional AI applications
    • Windows 11 Arm64 support

Default roles:

  • AIDR Admin
  • Falcon Administrator
  • Endpoint Manager

AIDR permissions required for custom roles:

  • Manage AIDR findings and workforce collectors
  • Manage AIDR policy settings of workforce collectors
  • Manage AIDR workforce collectors
  • Read AIDR data from LogScale
  • Read AIDR data from LogScale via AIDR
  • Read AIDR findings and workforce collectors
  • Read AIDR metadata from LogScale
  • Read AIDR metadata from LogScale via AIDR
  • Read AIDR policy settings of workforce collectors
  • Read AIDR workforce collectors

CrowdStrike clouds: Available in US-1, US-2, and EU-1

System requirements:

  • Windows 11 version 23H2 and later

    note:

    Network Inspection support on Windows 11 Arm64 hosts requires Falcon sensor for Windows version 8.10 and later.

  • Supported 64-bit versions of Windows 10

    For more info, see

    Windows OS versions supported by the Falcon Sensor .

For more info, see Network Inspection .

Supported AI applications

Anthropic

ApplicationSurface typeSensor version
Claude.ai websiteWebsite7.40+
Claude DesktopWindows desktop app7.40+
Claude CodeCLI7.40+
Anthropic ConsoleWebsite or developer console7.40+
Claude CoworkWindows desktop app7.40+
Claude Microsoft Excel PluginMicrosoft Excel plugin7.40+
Claude Powerpoint PluginMicrosoft PowerPoint plugin7.40+

AWS

ApplicationSurface typeSensor version
KiroWindows desktop app8.10+

DeepSeek

ApplicationSurface typeSensor version
DeepSeek websiteWebsite7.40+

GitHub

ApplicationSurface typeSensor version
GitHub CopilotIDE extension8.10+
GitHub Copilot extensionIDE extension8.10+

Google

ApplicationSurface typeSensor version
GeminiWebsite7.40+

Microsoft 365 Copilot

ApplicationSurface typeSensor version
Microsoft 365 Copilot app for WindowsWindows desktop app7.40+
Microsoft 365 Copilot in Word for WindowsWindows Office desktop app7.40+
Microsoft 365 Copilot in Excel for WindowsWindows Office desktop app7.40+
Microsoft 365 Copilot in Outlook for WindowsWindows Office desktop app7.40+
Microsoft 365 Copilot in Teams for WindowsWindows Teams desktop app7.40+
Microsoft 365 Copilot in OneNote for WindowsWindows Office desktop app7.40+

Microsoft Copilot

ApplicationSurface typeSensor version
Microsoft CopilotWindows desktop app7.40+
Microsoft Copilot entry point in Windows taskbar or Copilot keyWindows OS integration7.40+
Microsoft Copilot in Microsoft EdgeWindows browser integration7.40+
Microsoft Copilot websiteWebsite7.40+
Microsoft Copilot StudioWebsite7.40+

OpenAI

ApplicationSurface typeSensor version
ChatGPT websiteWebsite7.40+
ChatGPT Desktop (Chat tab)Windows desktop app7.40+
ChatGPT Desktop (Work tab / Codex)Windows desktop app8.10+
OpenAI CodexCLI8.10+

Next steps

©2026 CrowdStrike. All rights reserved.

PrivacyTerms of UseLegal Notices