Prepared for the Falcon team · At Bernard's request

Command and control when the device is completely offline.

Location, telemetry, and command execution — with no network connectivity, no cellular, no pairing, and no user interaction. Troverlo runs on the Wi-Fi radio already in the device.

Layer Below the network
Radio Wi-Fi frames (connectionless)
Endpoint state Off · RFM · captive portal · pre-boot

A connectionless control plane for endpoints — location and command execution over the Wi-Fi radio, without a network session.

Every laptop already has a Wi-Fi radio that emits frames whenever it's powered. Troverlo turns those frames into a control channel. Endpoints self-identify, report state, and receive commands without ever associating to an access point — no SSID, no auth, no user, no live network.

For a security stack, this means Falcon can see and act on a device that has slipped every other rail: the internet, the corporate VPN, the domain controller, MDM, cellular. If the device has power and a Wi-Fi radio, it's reachable.

RFM

Reduced Functionality Mode — the sensor's own name for the state where visibility collapses to a heartbeat. Every deployment has fleet in it, right now.

When the sensor loses the internet, it loses the platform.

The Falcon sensor is exceptional when it can reach the cloud. But when the endpoint loses internet — hotel Wi-Fi that never authenticated, an office-network segmentation event, a Secure Boot policy change, a firmware update, a July-2024-style incident that requires wired-only recovery — the sensor drops into RFM. Detections queue locally. New IOCs don't arrive. Policy changes don't apply. On Linux, it's heartbeat-only. The device is a black box until the connection comes back.

Troverlo restores visibility and control in exactly that window — with a channel Falcon does not currently have.

~20 MB
Sensor footprint · enough room for an observer to ride alongside
< 1%
CPU overhead · Troverlo adds a similar order of magnitude
Cloud-required
Falcon's operating assumption today · the assumption Troverlo relaxes
Wi-Fi radio
Present in every endpoint Falcon protects · and currently unused for C2

A Fortune‑100 PC OEM has already shipped offline C2 as a paid tier. The question isn't whether the demand exists.

HP Wolf Connect proves the demand at the PC OEM layer.

HP charges a per-device cellular BOM cost for the ability to reach a PC when it's offline — locate it, wipe it, lock it, prove it. That product line exists because HP's customers are already buying against this problem. The design decisions may be different, but the underlying need — "reach my endpoint when the network is gone" — is a shipping‑SKU commitment at a Fortune‑100 OEM.

Troverlo brings the same capability to Falcon's install base — without the cellular BOM, and on the radio already in every laptop the sensor already protects.

i.

The customer conversation has already happened.

Enterprise buyers evaluate HP Wolf Connect against Absolute, Intel vPro, Microsoft AutoPilot Reset, and other offline‑recovery paths. The decision framework is mature. Falcon is not currently in the frame — because Falcon does not currently have an offline story.

ii.

Falcon's install base is larger than HP's PC line.

Falcon protects the endpoints. HP ships some of them. The commercial gravity of putting offline C2 into the security‑agent layer — rather than the hardware layer — is meaningful. It becomes cross‑OEM, cross‑generation, and Falcon's to control.

iii.

Customers don't ask for it because they don't know it's possible without a cellular BOM.

HP taught the market to associate "offline command and control" with adding a cellular modem, a SIM, and a monthly fee. Troverlo runs on the radio that's already in the device. Once the option exists, the demand isn't latent — it's obvious.

iv.

The buy path, not the borrow path.

Falcon can partner with HP for offline reach on HP PCs. Or Falcon can own the capability across every endpoint it protects — Dell, Lenovo, HP, Apple, custom hardware, ruggedized field devices — with a single‑agent architecture. Troverlo is the mechanism for the second option.

Three concrete integration points — each in a Falcon module that already exists.

i. Falcon Identity Protection

A proximity factor for MFA and conditional access.

Falcon Identity Protection already gates access based on device posture and risk signals. Troverlo adds a physical-presence factor — the device is verifiably at the location it claims to be — without a network session, GPS, or user prompt. A connectionless MFA rail that survives internet loss, works pre-boot, and can't be phished. Natural fit in Identity, which already lives in the Falcon Elite tier.

ii. RFM recovery and remediation

A recovery channel when the sensor can't reach the cloud.

Troverlo delivers commands to an endpoint in RFM — trigger a specific action, request an updated policy, kick a re-registration attempt — without waiting for internet to come back. Complements Falcon's cached-signature and heartbeat behavior; provides the command rail that RFM currently lacks. Directly relevant to incident-recovery scenarios like the July 2024 wired-only remediation event.

iii. Offline gating and containment

Enforce policy on an endpoint that's off the grid.

A stolen laptop that never rejoins the corporate network is not currently a Falcon problem — it drops off the console. Troverlo lets Falcon lock, wipe, or gate that device based on observed location and identity signals from the Wi-Fi observation network. Extends Falcon's kill-chain into the offline window that Wolf Connect currently owns for HP hardware only.

Troverlo is the platform. HERE is one node — a strong validation, not the whole picture.

A connectionless control plane needs observers — Wi-Fi-aware infrastructure that can see the frames endpoints emit and route them back to Troverlo's cloud. The observation network is the compound of every such observer. Any Wi-Fi-aware device can participate: managed access points, cameras, sensor infrastructure, mobile handsets, purpose-built beacons. The more the network compounds, the more reliably any given endpoint is reachable.

Troverlo
Observation network
HERE Fortune-500 partner · billions of scans / week
Managed APs Enterprise Wi-Fi already in the room
Cameras Fixed observers at chokepoints
Handsets Mobile observers in motion
Sensors Purpose-built observers in the field
Beacons Troverlo-authored observers

HERE is a Fortune-500-scale validation that a global Wi-Fi observation network is a real, buildable thing. It is one component of Troverlo's platform — not the whole thing. The value grows with every additional class of observer. Troverlo owns the observation layer that unifies them.

Software-only on the sensor side. Standards-based Wi-Fi frames. Patented at the observation and control-plane layers.

Troverlo is not a hardware product for Falcon. There is no new BOM, no radio to add, no board revision. It's a lightweight capability the sensor speaks over the Wi-Fi radio the endpoint already carries. Falcon's cloud gains a new API surface — offline reach, delivered — and endpoints gain a new observation and control channel that survives every network failure mode Falcon's own architecture describes.

The observation and control-plane approach is protected by Troverlo's patent portfolio: EP granted, 8 US patents granted, 18 international grants, and 42+ pending. This is the moat.

Find My · side by side

Two devices. One moment.
Microsoft's Find my device and Troverlo, captured 60 seconds apart.

A first-party comparison. Two devices signed into the same Microsoft account and instrumented with Troverlo. Both actually sitting at Lucky Goat Coffee, 3345 University Dr E, Bryan, TX. Screenshots captured on August 19, 2026 between 9:37 and 9:44 AM CDT. Nothing staged, nothing recreated.

The setup

Same two devices. Same account. Same moment.

Cody-XPS
Dell XPS-13 running Windows, signed into cody@catalena.com Microsoft account, currently online, 99% battery, sitting on a table at the coffee shop.
CodySurface
Microsoft Surface running Windows, same Microsoft account, but has been offline, disconnected, and moving around for several days before arriving at the coffee shop this morning.
Both instrumented
Both devices are enrolled in Microsoft's Find my device (Location on) and both are also tagged in the Troverlo Observation Network. Same devices, two different location systems, checked at the same time.
Microsoft's result

What Microsoft's Find my device returns.

From account.microsoft.com/devices, signed into the same account that owns both devices, captured between 9:41 and 9:43 AM CDT on August 19, 2026.

Cody-XPS online now
Microsoft Find my device showing Cody-XPS with address 815 Texas Ave, College Station, TX, last updated 8/17/2026, and a map pin that does not correspond to that address
  • Last updated8/17/2026 · 48 hours ago
  • Address shown815 Texas Ave, College Station, TX 77840
  • Map pinDoes not correspond to the address shown — appears dropped roughly in central College Station
  • Actual location3345 University Dr E, Bryan, TX
  • Distance from actual~5.5 miles
CodySurface offline & mobile for days
Microsoft Find my device showing CodySurface with address 1650 Bird Pond Rd College Station TX, battery 100 percent, and a map pin that does not correspond to that address
  • Address shown1650 Bird Pond Rd, College Station, TX 77845
  • Reality of that addressDevice has not been at this address in over a year
  • Map pinDoes not correspond to the address shown — appears dropped roughly in central College Station
  • Battery shown100% · stale telemetry, not a current reading
  • Actual location3345 University Dr E, Bryan, TX
  • Distance from actual~10 miles
  • Update location (offline)Cannot fetch a fix — device is off-network

Refreshing the panel and selecting Microsoft's "Update location" control did not correct either address or either map pin during the capture window. Both devices are shown with addresses and pins that do not match each other and do not match the devices' actual location.

Troverlo's result

What Troverlo returns for the same two devices.

From portal.find.troverlo.com, the same Microsoft account owner, captured at 9:37–9:38 AM CDT on August 19, 2026 — inside the same two-minute window as the Microsoft screenshots.

Cody-XPS-HGVVYK4 Dell XPS-13
Troverlo dashboard showing Cody-XPS-HGVVYK4 at 3345 University Dr E, Bryan TX with 7.5 meter accuracy, observed at 9:38:04 AM CDT
  • Observation timestamp2026-08-19 9:38:04 AM CDT · < 6 min old
  • Address3345 University Dr E, Bryan, TX 77802
  • Map pinMatches the address
  • Accuracy7.5 meters
CodySurface-0F0184J23063BF offline for days
Troverlo dashboard showing CodySurface-0F0184J23063BF at 3345 University Dr E, Bryan TX with 0.16 meter accuracy, observed at 9:37:07 AM CDT
  • Observation timestamp2026-08-19 9:37:07 AM CDT · < 7 min old
  • Address3345 University Dr E, Bryan, TX 77802
  • Map pinMatches the address
  • Accuracy0.16 meters · sub-meter
  • Located while offlineYes — off-network, mobile for days prior
Objective comparison

Side by side, one row per fact.

Microsoft Find my device Troverlo
Freshness — online device (XPS) 48 hours Less than 6 minutes
Freshness — offline device (Surface) Stale — device has not been at the address shown in over a year Less than 7 minutes
Locates a device that is off-network No — shows a stale last-known location instead Yes — observed within the last 7 minutes
Address ↔ map pin alignment Mismatch Consistent
XPS location error vs. actual ~5.5 miles 7.5 meters
Surface location error vs. actual ~10 miles 0.16 meters
Requires the device to be online Yes No
Requires a cellular modem No No
Requires new hardware on the PC No No — uses the Wi-Fi radio already in the device
Location source IP address and cached Wi-Fi / cell fingerprints Direct observation of the device by a third-party Wi-Fi radio
Can be fooled by VPN or corporate egress rewrites Yes No — observation happens in the physical environment

Location error compares Microsoft's returned address (Cody-XPS card) and displayed map pin to the actual physical location of the device (3345 University Dr E, Bryan TX). Troverlo's accuracy figure is the value reported on the observation record.

Why the difference

Two different mechanisms produce two different results.

Microsoft Find my device

The PC reports its own location to Microsoft over the PC's own network connection. When the PC last checked in, Microsoft resolved that check-in against IP-geolocation databases and cached Wi-Fi and cell-tower fingerprints. The result is a location the PC says it is at, not a location a third party observed it at. When the device is off-network the last-known value stays put; when it is online the value can still be wrong by miles because the underlying IP or fingerprint lookup was imprecise or stale.

  • Location is derived from IP address and cached Wi-Fi / cell fingerprints, not a scan of what is physically nearby
  • Can be fooled by a VPN, a corporate egress node, or a stale fingerprint database
  • Device must be powered on and have a working network path to Microsoft for any refresh
  • Feature must be enabled before the device is lost
  • Not available on all Windows devices — several devices on this account show "Location disabled"
Troverlo

The device beacons a small identifier over standard Wi-Fi frames without associating to any network. Any Wi-Fi radio nearby — an access point, a vehicle, a partner device, another PC — observes the beacon and reports it back through the Troverlo Observation Network with the observer's own GPS-grade position. The location is where a third party actually saw the device, in the physical Wi-Fi environment around it. There is no IP address to look up and no fingerprint to guess. That is why CodySurface was located at sub-meter accuracy while it was offline and moving.

  • Location is an observation of the device's real physical environment, not an inference from network metadata
  • Cannot be fooled by VPNs, egress rewrites, or outdated fingerprint databases
  • Device does not need a network connection or to be booted into the operating system
  • Any nearby Wi-Fi radio can be the observer — infrastructure or peer
  • Works on the Wi-Fi radio already in every commercial PC

20 minutes with the sensor or Identity team.

A concrete technical walkthrough — how the Wi-Fi frame path works, how Troverlo's cloud integrates with Falcon's, and which of the three Falcon fits above is the fastest to prove. If the read is positive, we scope a design-partner engagement from there.

Cody Catalena
Founder & CEO, Troverlo
IP Posture
EP + 8 US granted · 18 international · 42+ pending