Agent discovery & inventory
CrowdStrike AIDR Collectors
Telemetry-collection layer of CrowdStrike's AI Detection and Response product. Collectors capture AI activity from the Falcon sensor (browser extension plus network inspection of desktop AI apps and coding assistants), standalone browser extensions, application SDK calls, and supported API gateways. Browser collectors log detections in report-only mode for model responses.
commercial · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Agent discovery & inventory · Observability & traceability · Runtime authorization & controls
Useful conversation with: CISO, SOC manager, Endpoint security lead.
Ask for a demonstration
Demonstrate registering a Falcon endpoint collector and show which desktop AI applications and coding assistants network inspection surfaced that the browser extension missed.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
A lightweight browser extension installed on enterprise-managed endpoints captures AI interactions in Chrome, Edge and Firefox and sends them to AIDR for visibility and policy enforcement.
Limit: Documentation states browser collectors run output rules in report-only mode and do not block or redact model responses.
Source s1
Documented by provider
Collector categories documented are Falcon Endpoint (browser extension plus network inspection for desktop AI apps and coding assistants), Browser, Application via SDK/API, and Gateway for Apigee, Azure API Management, Kong and LiteLLM.
Limit: Docs do not state which AI providers are recognised by each collector or detection completeness.
Source s2
Documented by provider
Extensions are deployed through enterprise management tooling such as Jamf, Microsoft Intune, Chrome Enterprise and Group Policy, with configuration applied through managed storage.
Limit: Unmanaged or BYOD endpoints are not covered by this deployment model.
Source s1
Limitations to discuss
- Discovery is of AI usage/traffic, not of an enterprise agent registry
- Response blocking is unavailable in browser collectors
Sources
- AIDR - Browser Collectors · CrowdStrike · official docs
Access date reported by researcher: 2026-09-06 - AIDR - Collector Types · CrowdStrike · official docs
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction