Prepared for the Falcon team · At Bernard's request

Command and control when the device is completely offline.

Location, telemetry, and command execution — with no network connectivity, no cellular, no pairing, and no user interaction. Troverlo runs on the Wi-Fi radio already in the device.

Layer Below the network
Radio Wi-Fi frames (connectionless)
Endpoint state Off · RFM · captive portal · pre-boot

A connectionless control plane for endpoints — location and command execution over the Wi-Fi radio, without a network session.

Every laptop already has a Wi-Fi radio that emits frames whenever it's powered. Troverlo turns those frames into a control channel. Endpoints self-identify, report state, and receive commands without ever associating to an access point — no SSID, no auth, no user, no live network.

For a security stack, this means Falcon can see and act on a device that has slipped every other rail: the internet, the corporate VPN, the domain controller, MDM, cellular. If the device has power and a Wi-Fi radio, it's reachable.

RFM

Reduced Functionality Mode — the sensor's own name for the state where visibility collapses to a heartbeat. Every deployment has fleet in it, right now.

When the sensor loses the internet, it loses the platform.

The Falcon sensor is exceptional when it can reach the cloud. But when the endpoint loses internet — hotel Wi-Fi that never authenticated, an office-network segmentation event, a Secure Boot policy change, a firmware update, a July-2024-style incident that requires wired-only recovery — the sensor drops into RFM. Detections queue locally. New IOCs don't arrive. Policy changes don't apply. On Linux, it's heartbeat-only. The device is a black box until the connection comes back.

Troverlo restores visibility and control in exactly that window — with a channel Falcon does not currently have.

~20 MB
Sensor footprint · enough room for an observer to ride alongside
< 1%
CPU overhead · Troverlo adds a similar order of magnitude
Cloud-required
Falcon's operating assumption today · the assumption Troverlo relaxes
Wi-Fi radio
Present in every endpoint Falcon protects · and currently unused for C2

A Fortune‑100 PC OEM has already shipped offline C2 as a paid tier. The question isn't whether the demand exists.

HP Wolf Connect proves the demand at the PC OEM layer.

HP charges a per-device cellular BOM cost for the ability to reach a PC when it's offline — locate it, wipe it, lock it, prove it. That product line exists because HP's customers are already buying against this problem. The design decisions may be different, but the underlying need — "reach my endpoint when the network is gone" — is a shipping‑SKU commitment at a Fortune‑100 OEM.

Troverlo brings the same capability to Falcon's install base — without the cellular BOM, and on the radio already in every laptop the sensor already protects.

i.

The customer conversation has already happened.

Enterprise buyers evaluate HP Wolf Connect against Absolute, Intel vPro, Microsoft AutoPilot Reset, and other offline‑recovery paths. The decision framework is mature. Falcon is not currently in the frame — because Falcon does not currently have an offline story.

ii.

Falcon's install base is larger than HP's PC line.

Falcon protects the endpoints. HP ships some of them. The commercial gravity of putting offline C2 into the security‑agent layer — rather than the hardware layer — is meaningful. It becomes cross‑OEM, cross‑generation, and Falcon's to control.

iii.

Customers don't ask for it because they don't know it's possible without a cellular BOM.

HP taught the market to associate "offline command and control" with adding a cellular modem, a SIM, and a monthly fee. Troverlo runs on the radio that's already in the device. Once the option exists, the demand isn't latent — it's obvious.

iv.

The buy path, not the borrow path.

Falcon can partner with HP for offline reach on HP PCs. Or Falcon can own the capability across every endpoint it protects — Dell, Lenovo, HP, Apple, custom hardware, ruggedized field devices — with a single‑agent architecture. Troverlo is the mechanism for the second option.

Three concrete integration points — each in a Falcon module that already exists.

i. Falcon Identity Protection

A proximity factor for MFA and conditional access.

Falcon Identity Protection already gates access based on device posture and risk signals. Troverlo adds a physical-presence factor — the device is verifiably at the location it claims to be — without a network session, GPS, or user prompt. A connectionless MFA rail that survives internet loss, works pre-boot, and can't be phished. Natural fit in Identity, which already lives in the Falcon Elite tier.

ii. RFM recovery and remediation

A recovery channel when the sensor can't reach the cloud.

Troverlo delivers commands to an endpoint in RFM — trigger a specific action, request an updated policy, kick a re-registration attempt — without waiting for internet to come back. Complements Falcon's cached-signature and heartbeat behavior; provides the command rail that RFM currently lacks. Directly relevant to incident-recovery scenarios like the July 2024 wired-only remediation event.

iii. Offline gating and containment

Enforce policy on an endpoint that's off the grid.

A stolen laptop that never rejoins the corporate network is not currently a Falcon problem — it drops off the console. Troverlo lets Falcon lock, wipe, or gate that device based on observed location and identity signals from the Wi-Fi observation network. Extends Falcon's kill-chain into the offline window that Wolf Connect currently owns for HP hardware only.

Troverlo is the platform. HERE is one node — a strong validation, not the whole picture.

A connectionless control plane needs observers — Wi-Fi-aware infrastructure that can see the frames endpoints emit and route them back to Troverlo's cloud. The observation network is the compound of every such observer. Any Wi-Fi-aware device can participate: managed access points, cameras, sensor infrastructure, mobile handsets, purpose-built beacons. The more the network compounds, the more reliably any given endpoint is reachable.

Troverlo
Observation network
HERE Fortune-500 partner · billions of scans / week
Managed APs Enterprise Wi-Fi already in the room
Cameras Fixed observers at chokepoints
Handsets Mobile observers in motion
Sensors Purpose-built observers in the field
Beacons Troverlo-authored observers

HERE is a Fortune-500-scale validation that a global Wi-Fi observation network is a real, buildable thing. It is one component of Troverlo's platform — not the whole thing. The value grows with every additional class of observer. Troverlo owns the observation layer that unifies them.

Software-only on the sensor side. Standards-based Wi-Fi frames. Patented at the observation and control-plane layers.

Troverlo is not a hardware product for Falcon. There is no new BOM, no radio to add, no board revision. It's a lightweight capability the sensor speaks over the Wi-Fi radio the endpoint already carries. Falcon's cloud gains a new API surface — offline reach, delivered — and endpoints gain a new observation and control channel that survives every network failure mode Falcon's own architecture describes.

The observation and control-plane approach is protected by Troverlo's patent portfolio: EP granted, 8 US patents granted, 18 international grants, and 42+ pending. This is the moat.

20 minutes with the sensor or Identity team.

A concrete technical walkthrough — how the Wi-Fi frame path works, how Troverlo's cloud integrates with Falcon's, and which of the three Falcon fits above is the fastest to prove. If the read is positive, we scope a design-partner engagement from there.

Cody Catalena
Founder & CEO, Troverlo
IP Posture
EP + 8 US granted · 18 international · 42+ pending