Agent discovery & inventory

CrowdStrike AIDR Collectors

Telemetry-collection layer of CrowdStrike's AI Detection and Response product. Collectors capture AI activity from the Falcon sensor (browser extension plus network inspection of desktop AI apps and coding assistants), standalone browser extensions, application SDK calls, and supported API gateways. Browser collectors log detections in report-only mode for model responses.

commercial · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Agent discovery & inventory · Observability & traceability · Runtime authorization & controls

Useful conversation with: CISO, SOC manager, Endpoint security lead.

Ask for a demonstration

Demonstrate registering a Falcon endpoint collector and show which desktop AI applications and coding assistants network inspection surfaced that the browser extension missed.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

A lightweight browser extension installed on enterprise-managed endpoints captures AI interactions in Chrome, Edge and Firefox and sends them to AIDR for visibility and policy enforcement.

Limit: Documentation states browser collectors run output rules in report-only mode and do not block or redact model responses.

Source s1

Documented by provider

Collector categories documented are Falcon Endpoint (browser extension plus network inspection for desktop AI apps and coding assistants), Browser, Application via SDK/API, and Gateway for Apigee, Azure API Management, Kong and LiteLLM.

Limit: Docs do not state which AI providers are recognised by each collector or detection completeness.

Source s2

Documented by provider

Extensions are deployed through enterprise management tooling such as Jamf, Microsoft Intune, Chrome Enterprise and Group Policy, with configuration applied through managed storage.

Limit: Unmanaged or BYOD endpoints are not covered by this deployment model.

Source s1

Limitations to discuss

Sources

  1. AIDR - Browser Collectors · CrowdStrike · official docs
    Access date reported by researcher: 2026-09-06
  2. AIDR - Collector Types · CrowdStrike · official docs
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction