Falcon Insight for ChromeOS Adds Automated Response Actions and GovCloud Support

CrowdStrike introduces new, sensorless response actions for ChromeOS to rapidly contain compromised devices at scale, and expands availability for public sector customers with GovCloud support.

Adversaries move fast, and so must defenders. CrowdStrike is raising the bar for ChromeOS security with two major advancements in CrowdStrike Falcon® Insight for ChromeOS. New automated response actions deliver rapid device containment, and expanded support for GovCloud designed to support customers working toward meeting high compliance standards.

Falcon Insight for ChromeOS delivers a first-of-its-kind, native connector that gives organizations unified visibility and threat detection across ChromeOS devices on the CrowdStrike Falcon® platform. Built in close partnership with the Google ChromeOS team, Falcon Insight for ChromeOS eliminates the need for additional agents or mobile device management (MDM) tools by ingesting telemetry directly from the operating system.

This latest release empowers security teams to gain the powerful detection, response, and automation capabilities they rely on for other operating systems for their ChromeOS devices, all managed through the unified Falcon console, ensuring streamlined workflows, faster triage, and comprehensive protection across diverse environments.

New Response Actions Accelerate Containment

When a ChromeOS device is compromised or even shows early signs of suspicious activity, every second matters. The new response actions in Falcon Insight for ChromeOS allow security teams to quickly stop adversaries before they can move laterally. Teams can instantly disable a device to block further activity or move it into a restricted organizational unit with tighter controls until it is cleared.

By bringing containment controls directly into the Falcon platform via a prebuilt CrowdStrike Falcon® Foundry app, security teams can act immediately without juggling additional tools or consoles. This reduces response time, minimizes operational friction, and ensures ChromeOS devices are protected with the same speed and precision as other endpoints. Together with direct telemetry ingestion, these response capabilities deliver one of the most seamless protection solutions for ChromeOS environments.

Automate or Take Control

Not every incident looks the same. Some situations demand fast, automated containment to shut down adversaries immediately. Others call for human judgment and precise, hands-on action. Falcon Insight for ChromeOS delivers both. Response actions can run automatically through CrowdStrike Falcon® Fusion SOAR workflows or be executed manually from the Falcon console during an investigation. Either way, teams operate from a single platform without wasted pivots or delays.

  • Automated containment: Trigger device actions with Falcon Fusion SOAR workflows based on detections, risk signals, or other conditions
  • Manual response: Run actions directly from the Falcon console via a prebuilt Falcon Foundry app that adds the response option directly into the console where you need it, whether you are investigating a ChromeOS alert or managing hosts
Figure 1. New ChromeOS Response Actions appear directly within existing workflows Figure 1. New ChromeOS Response Actions appear directly within existing workflows
  
Figure 2. Leverage Falcon Fusion SOAR, available at no cost to all customers, to customize automated responses Figure 2. Leverage Falcon Fusion SOAR, available at no cost to all customers, to customize automated responses

Delivered Through Falcon Foundry

These new response actions leverage Falcon Foundry, a no-code automation and application development platform built on the Falcon platform. It provides a library of prebuilt apps and workflows for common use cases such as incident response, enrichment, and integrations, while also enabling security teams to create custom applications tailored to their unique environments without requiring software development skills. By combining the Falcon API ecosystem with an intuitive interface, Falcon Foundry helps organizations extend the value of their Falcon investment and adapt quickly to evolving threats and operational needs.

Getting started with the new response actions takes minutes. The new ChromeOS Device Actions app is available now in the Falcon Foundry app catalog. Just search, click to enable, and the new response actions appear instantly in the Falcon platform for use in workflows or manual response. It is included at no additional cost for all Falcon Insight for ChromeOS customers.

Figure 3. Enable ChromeOS Device Actions from the Falcon Foundry app catalog Figure 3. Enable ChromeOS Device Actions from the Falcon Foundry app catalog

Now Available in GovCloud

Falcon Insight for ChromeOS is now available in GovCloud, giving public sector organizations and companies operating under strict compliance frameworks the ability to meet higher cloud requirements for sensitive and regulated use cases. Customers can maintain the same familiar Falcon UI, workflows, and integrations across operating systems, while benefiting from faster onboarding and uniform response.

Get Started Today

With these latest enhancements, CrowdStrike strengthens ChromeOS security with the speed and precision defenders expect from the Falcon platform. By uniting native telemetry, integrated response actions, and GovCloud support, Falcon Insight for ChromeOS gives organizations greater visibility and control to detect and contain threats faster, all while simplifying operations across diverse endpoint environments.

Additional Resources

Getting started is simple: