Enhanced Network Visibility for Falcon macOS Sensor
🔍 The Falcon macOS sensor (v7.29+) delivers Enhanced Network Visibility, an opt-in capability that augments process telemetry with protocol and TLS-inspection attributes. It parses plaintext HTTP, extracts TLS Client Hello details including JA4 fingerprints, and identifies application protocols across ports while minimizing impact via Apple content filter APIs. New Next‑Gen SIEM events (HttpRequest, HttpResponse, TlsClientHello, AppProtocolDetected) expose the telemetry for detection and hunting workflows, and the feature can be enabled from Mac Prevention Policies in the Falcon UI.
