TrustRadius: an HG Insights company

CrowdStrike Falcon Device Control

What is CrowdStrike Falcon Device Control?

CrowdStrike Falcon Device Control is a cloud-managed endpoint peripheral security module that provides real-time visibility, policy enforcement, and audit tracking for USB devices and removable storage connected to corporate endpoints.

Key Capabilities
  • Single-Agent Architecture: Operates natively within the core CrowdStrike Falcon lightweight sensor, eliminating the need for separate agent installations, additional endpoint drivers, or secondary management consoles.
  • Granular Policy Enforcement: Regulates peripheral access using rule sets defined by VID, PID, device serial numbers, interface classes, or user and group assignments to enforce read-only, full access, or complete block policies.
  • USB Activity & File Write Auditing: Captures detailed telemetry on device insertion events, connection timestamps, drive mounting, and file copy operations to removable storage for forensic auditing and compliance reporting.
  • Integrated Endpoint Detection and Response (EDR): Streams peripheral event data directly into Falcon Insight, enabling Security Operations Center (SOC) analysts to correlate USB insertions with process execution, file modifications, and potential malware deployment.
  • Customizable End-User Notifications: Displays contextual desktop notifications when a peripheral device is blocked or restricted, informing users of policy restrictions and corporate guidelines.
  • Cross-Platform Support: Applies consistent device control policy frameworks across Windows, macOS, and Linux host operating systems.

Audience & Use Cases
  • Audience: Chief Information Security Officers (CISOs), SOC Analysts, Endpoint Security Administrators, and IT Compliance Officers.
  • Use Case: Preventing unauthorized data exfiltration via USB flash drives, mitigating malware introduction through infected removable media, enforcing hardware access controls in high-security environments, and auditing file transfers for regulatory compliance.

Technical Specifications
  • Deployment Model: Cloud-managed via the Falcon Console; executed at the endpoint level through the single CrowdStrike Falcon sensor.
  • Supported Operating Systems: Microsoft Windows (desktop and server editions), macOS, and major Linux distributions.
  • Policy Control Granularity: VID, PID, device serial number, device class (e.g., mass storage, human interface device), user/group identity, and host group.
  • Access Enforcement Options: Full Access, Read-Only, Block, or Custom Exception.
  • Platform Integrations: CrowdStrike Falcon Insight (EDR), Falcon Data Protection, Falcon Fusion (automated workflow orchestration), and RESTful Falcon APIs.

Categories & Use Cases

Technical Details

Technical Details
Mobile ApplicationNo

FAQs

What is CrowdStrike Falcon Device Control?
CrowdStrike Falcon Device Control is a cloud-managed endpoint peripheral security module that provides real-time visibility, policy enforcement, and audit tracking for USB devices and removable storage connected to corporate endpoints.