Skip to content
Cybersecurity CrowdStrike

CrowdStrike Falcon Prevent

Falcon Prevent: Next-Generation Antivirus (NGAV) with AI. Replaces traditional antivirus, detects malware without signatures, blocks exploits and ransomware.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Key Features

  • Machine Learning detection - detection without signatures
  • Behavioral analysis - process behavior analysis
  • Exploit blocking - 0-day protection
  • Ransomware protection - encryption blocking
  • Script control - PowerShell, WMI control
Available now
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Send inquiry
Table of Contents

What is Falcon Prevent?

Falcon Prevent is Next-Generation Antivirus (NGAV) - a modern alternative to traditional antivirus. Instead of virus signatures, it uses machine learning and behavioral analysis to detect threats.

Why NGAV instead of traditional AV:

  • Traditional AV detects only known threats (needs signature)
  • NGAV detects unknown threats through behavior analysis
  • 350,000+ new malware variants daily - signatures can’t keep up

How does Falcon Prevent work?

1. Machine Learning Detection

Falcon uses multiple ML layers to detect malware:

[File] --> [Pre-execution ML] --> Known malware? --> BLOCK
              |
              v
         [Execution] --> [Behavioral ML] --> Suspicious behavior? --> BLOCK
              |
              v
         [Cloud ML] --> Seen at others? --> BLOCK/ALERT

ML Models:

  • On-sensor ML - works locally, even offline
  • Cloud ML - analysis in Threat Graph
  • Behavioral ML - runtime behavior analysis

2. Behavioral Analysis

Falcon monitors process behavior in real-time:

Detected patterns:

  • Process injection
  • Credential dumping (LSASS access)
  • Suspicious parent-child relationships
  • Registry persistence
  • Scheduled task creation

Example:

Word.exe --> PowerShell.exe --> Download malware
    ^                ^              ^
  Normal       SUSPICIOUS     MALICIOUS

3. Exploit Blocking

Protection against 0-day exploits:

  • Memory protection (DEP, ASLR enforcement)
  • Return-Oriented Programming (ROP) detection
  • Heap spray detection
  • Shellcode detection

4. Ransomware Protection

Special mechanisms against ransomware:

  • Volume shadow copy protection - blocks backup deletion
  • MBR protection - protects Master Boot Record
  • Rapid encryption detection - detects mass encryption
  • Automatic rollback - restores encrypted files

What does Falcon Prevent detect?

Malware

  • Trojans, viruses, worms
  • Cryptominers
  • Adware, PUPs
  • Rootkits

Ransomware

  • WannaCry, NotPetya
  • Ryuk, Conti, LockBit
  • Ransomware-as-a-Service

Exploits

  • 0-day exploits
  • Memory corruption
  • Privilege escalation
  • Browser exploits

Fileless Attacks

  • PowerShell attacks
  • WMI abuse
  • Living-off-the-land binaries (LOLBins)
  • Script-based malware

Falcon Prevent vs Traditional AV

FeatureTraditional AVFalcon Prevent
DetectionSignaturesML + Behavioral
Unknown threatsWeakStrong
UpdatesDailyReal-time (cloud)
Performance impactHighLow (25MB agent)
ManagementOn-prem consoleCloud console
Fileless attacksLimitedFull

USB Device Control

Falcon Prevent includes USB device control:

  • Allow/Block - allowed device list
  • Read-only - read only, no write
  • Per-policy - different policies for different groups
  • Audit mode - logging without blocking

Script Control

Script control:

  • PowerShell
  • WMI
  • VBScript
  • JavaScript
  • Python

Modes:

  • Block all scripts
  • Block unsigned scripts
  • Audit only
  • Custom policies

Implementation

Requirements

  • Windows 7+ / macOS 10.14+ / Linux
  • 512MB RAM
  • 25MB agent
  • Internet connection (optional for offline protection)

Deployment

  1. Download agent from console
  2. Deploy via GPO/SCCM/Intune
  3. Agent automatically connects to cloud
  4. Protection active immediately

Implementation time: Hours, not weeks

Inquire about CrowdStrike Falcon Prevent

Contact your product specialist and get a custom quote.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist