CrowdStrike Falcon Device Control
What is CrowdStrike Falcon Device Control?
CrowdStrike Falcon Device Control is a cloud-managed endpoint peripheral security module that provides real-time visibility, policy enforcement, and audit tracking for USB devices and removable storage connected to corporate endpoints.
Key Capabilities
- Single-Agent Architecture: Operates natively within the core CrowdStrike Falcon lightweight sensor, eliminating the need for separate agent installations, additional endpoint drivers, or secondary management consoles.
- Granular Policy Enforcement: Regulates peripheral access using rule sets defined by VID, PID, device serial numbers, interface classes, or user and group assignments to enforce read-only, full access, or complete block policies.
- USB Activity & File Write Auditing: Captures detailed telemetry on device insertion events, connection timestamps, drive mounting, and file copy operations to removable storage for forensic auditing and compliance reporting.
- Integrated Endpoint Detection and Response (EDR): Streams peripheral event data directly into Falcon Insight, enabling Security Operations Center (SOC) analysts to correlate USB insertions with process execution, file modifications, and potential malware deployment.
- Customizable End-User Notifications: Displays contextual desktop notifications when a peripheral device is blocked or restricted, informing users of policy restrictions and corporate guidelines.
- Cross-Platform Support: Applies consistent device control policy frameworks across Windows, macOS, and Linux host operating systems.
Audience & Use Cases
- Audience: Chief Information Security Officers (CISOs), SOC Analysts, Endpoint Security Administrators, and IT Compliance Officers.
- Use Case: Preventing unauthorized data exfiltration via USB flash drives, mitigating malware introduction through infected removable media, enforcing hardware access controls in high-security environments, and auditing file transfers for regulatory compliance.
Technical Specifications
- Deployment Model: Cloud-managed via the Falcon Console; executed at the endpoint level through the single CrowdStrike Falcon sensor.
- Supported Operating Systems: Microsoft Windows (desktop and server editions), macOS, and major Linux distributions.
- Policy Control Granularity: VID, PID, device serial number, device class (e.g., mass storage, human interface device), user/group identity, and host group.
- Access Enforcement Options: Full Access, Read-Only, Block, or Custom Exception.
- Platform Integrations: CrowdStrike Falcon Insight (EDR), Falcon Data Protection, Falcon Fusion (automated workflow orchestration), and RESTful Falcon APIs.
Categories & Use Cases
Technical Details
| Mobile Application | No |
|---|
FAQs
What is CrowdStrike Falcon Device Control?
CrowdStrike Falcon Device Control is a cloud-managed endpoint peripheral security module that provides real-time visibility, policy enforcement, and audit tracking for USB devices and removable storage connected to corporate endpoints.