PluginBench
MCP Server
Active
MIT

CrowdStrike Falcon MCP Server MCP Server

io.github.CrowdStrike/falcon-mcp

AI-powered security analysis and automation through CrowdStrike Falcon platform integration

What is the CrowdStrike Falcon MCP Server MCP server?

The CrowdStrike Falcon MCP Server connects AI agents with the CrowdStrike Falcon platform to enable intelligent security analysis and automation. It provides programmatic access to detections, threat intelligence, host management, and 20+ specialized security modules covering cloud security, identity protection, firewall management, and more.

This server bridges AI agents with CrowdStrike Falcon's comprehensive security capabilities. Use it to automate threat investigation, manage security policies, analyze detections, query threat intelligence, and orchestrate incident response workflows. It supports modular loading to keep context windows efficient and includes dynamic mode for on-demand tool discovery.

How to install CrowdStrike Falcon MCP Server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • FALCON_CLIENT_ID
    required
    secret

    CrowdStrike API client ID

  • FALCON_CLIENT_SECRET
    required
    secret

    CrowdStrike API client secret

  • FALCON_BASE_URL

    CrowdStrike API region URL

  • FALCON_MEMBER_CID

    Child CID for Flight Control (MSSP) support

  • FALCON_MCP_MODULES

    Comma-separated list of modules to enable

  • FALCON_MCP_TRANSPORT

    Transport protocol to use

  • FALCON_MCP_DEBUG

    Enable debug logging

  • FALCON_MCP_HOST

    Host to bind to for HTTP transports

  • FALCON_MCP_PORT

    Port to listen on for HTTP transports

  • FALCON_MCP_USER_AGENT_COMMENT

    Additional information to include in the User-Agent comment section

  • FALCON_MCP_STATELESS_HTTP

    Enable stateless HTTP mode for scalable deployments

  • FALCON_MCP_API_KEY
    secret

    API key for HTTP transport authentication (x-api-key header)

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "falcon-mcp": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_BASE_URL": "<YOUR_FALCON_BASE_URL>",
        "FALCON_MEMBER_CID": "<YOUR_FALCON_MEMBER_CID>",
        "FALCON_MCP_MODULES": "<YOUR_FALCON_MCP_MODULES>",
        "FALCON_MCP_TRANSPORT": "<YOUR_FALCON_MCP_TRANSPORT>",
        "FALCON_MCP_DEBUG": "<YOUR_FALCON_MCP_DEBUG>",
        "FALCON_MCP_HOST": "<YOUR_FALCON_MCP_HOST>",
        "FALCON_MCP_PORT": "<YOUR_FALCON_MCP_PORT>",
        "FALCON_MCP_USER_AGENT_COMMENT": "<YOUR_FALCON_MCP_USER_AGENT_COMMENT>",
        "FALCON_MCP_STATELESS_HTTP": "<YOUR_FALCON_MCP_STATELESS_HTTP>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Case Management — Manage case lifecycle, attach evidence, apply tags, and use case templates
  • Cloud Security — Query Kubernetes containers, image vulnerabilities, CSPM assets, IOM findings, and suppression rules
  • Correlation Rules — Search, create, update, and manage NG-SIEM correlation rules
  • Custom IOA — Create and manage Custom IOA behavioral detection rules and rule groups
  • Data Protection — Search Data Protection classifications, policies, and content patterns
  • Detections — Find and analyze detections to understand malicious activity
  • Discover — Search application inventory and discover unmanaged assets
  • Exclusions — Search, create, update, and delete IOA, ML, sensor visibility, and certificate-based exclusions
  • Firewall Management — Search and manage firewall rules and rule groups
  • Host Groups — Search, create, update, delete host groups and manage membership
  • Hosts — Manage and query host/device information
  • Identity Protection — Entity investigation and identity protection analysis
  • Intel — Research threat actors, IOCs, and intelligence reports
  • IOC — Search, create, and remove custom indicators of compromise
  • NGSIEM — Execute CQL queries against Next-Gen SIEM
  • Policies — Search, create, update, delete prevention, sensor update, firewall, device control, response, and content update policies
  • Quarantine — Search quarantine records and release, unrelease, or delete quarantined files
  • Real Time Response — Audit, summarize, and run read-only RTR triage workflows
  • Recon — Search Falcon Intelligence Recon notifications, monitoring rules, and exposed-data records
  • Scheduled Reports — Manage scheduled reports and download report files

Use cases

  • Automate threat detection analysis and investigation workflows using AI agents
  • Query and manage security policies, host groups, and firewall rules programmatically
  • Conduct threat intelligence research on threat actors, IOCs, and malicious indicators
  • Orchestrate incident response by combining detections, host data, and real-time response capabilities
  • Discover and assess vulnerabilities across cloud, serverless, and on-premises infrastructure

CrowdStrike Falcon MCP Server MCP server FAQ

What is the CrowdStrike Falcon MCP Server?

It's an MCP server that gives AI agents like Claude programmatic access to CrowdStrike Falcon's security capabilities, including detections, threat intelligence, host management, and 20+ specialized modules for security analysis and automation.

Is it free to use?

The server itself is open source (MIT licensed), but you need a CrowdStrike Falcon subscription and valid API credentials (Client ID and Secret) to connect.

How do I install it in Cursor or Claude?

Install via pip (pip install falcon-mcp) or uv (uv tool install falcon-mcp), then configure it in your editor's MCP settings with your Falcon API credentials and base URL. See the Getting Started guide for detailed editor integration steps.

What authentication is required?

You need CrowdStrike Falcon API credentials: FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, and FALCON_BASE_URL. Set these as environment variables or in a .env file.

Can I run it in Docker?

Yes, the server is available as a Docker image at quay.io/crowdstrike/falcon-mcp:latest. Run it with your .env file for stdio transport or use streamable-http transport for network access.

What is Dynamic Mode?

Dynamic Mode reduces context window overhead by replacing all tool schemas with three discovery tools (list_enabled_modules, search_tools, execute_tool), letting agents load only the tools they need on demand.

README (reference)

Source of truth, from the repository.

CrowdStrike Logo (Light) CrowdStrike Logo (Dark)

<!-- mcp-name: io.github.CrowdStrike/falcon-mcp -->

falcon-mcp

PyPI version PyPI - Python Version License: MIT MCP Registry GitHub MCP Gemini CLI Extension

falcon-mcp is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilities—including detections, threat intelligence, and host management—establishing the foundation for advanced security operations and automation.

[!IMPORTANT] 🚧 Public Preview: This project is currently in public preview and under active development. Features and functionality may change before the stable 1.0 release. While we encourage exploration and testing, please avoid production deployments. We welcome your feedback through GitHub Issues to help shape the final release.

Documentation

Full docs are available at developer.crowdstrike.com/falcon-mcp.

Modules

ModuleDescription
CoreBasic connectivity and system information
Case ManagementCase lifecycle management, evidence attachment, tagging, and templates
Cloud SecurityKubernetes containers, image vulnerabilities, CSPM asset inventory, IOM findings, and suppression rules
Correlation RulesSearch, create, update, and manage NG-SIEM correlation rules
Custom IOACreate and manage Custom IOA behavioral detection rules and rule groups
Data ProtectionSearch Data Protection classifications, policies, and content patterns
DetectionsFind and analyze detections to understand malicious activity
DiscoverSearch application inventory and discover unmanaged assets
ExclusionsSearch, create, update, and delete IOA, machine learning, sensor visibility, and certificate-based exclusions
Firewall ManagementSearch and manage firewall rules and rule groups
Host GroupsSearch, create, update, and delete host groups; manage group membership
HostsManage and query host/device information
Identity ProtectionEntity investigation and identity protection analysis
IntelResearch threat actors, IOCs, and intelligence reports
IOCSearch, create, and remove custom indicators of compromise
NGSIEMExecute CQL queries against Next-Gen SIEM
PoliciesSearch, create, update, and delete prevention, sensor update, firewall, device control, response, and content update policies; manage host-group assignment, enable/disable, and precedence
QuarantineSearch quarantine records, preview action counts, and release, unrelease, or delete quarantined files
Real Time ResponseAudit, summarize, and run read-only RTR triage workflows
ReconSearch Falcon Intelligence Recon notifications (recon alerts), monitoring rules, and exposed-data records for dark web, leaked credentials, and typosquatting
Scheduled ReportsManage scheduled reports and download report files
Sensor UsageAccess and analyze sensor usage data
ServerlessSearch for vulnerabilities in serverless functions
ShieldSaaS security posture, checks, alerts, and app inventory
SpotlightManage and analyze vulnerability data and security assessments

See the Module Overview for required API scopes, available tools, and FQL resources.

Quick Start

Install

Using uv (recommended)

uv tool install falcon-mcp

Using pip

pip install falcon-mcp

Configure

Set the required environment variables (or use a .env file — see the Configuration Guide):

export FALCON_CLIENT_ID="your-client-id"
export FALCON_CLIENT_SECRET="your-client-secret"
export FALCON_BASE_URL="https://api.crowdstrike.com"

Run

falcon-mcp

See the Getting Started guide for full installation and configuration details.

Editor Integration

Using uvx (recommended)

{
  "mcpServers": {
    "falcon-mcp": {
      "command": "uvx",
      "args": [
        "--env-file",
        "/path/to/.env",
        "falcon-mcp"
      ]
    }
  }
}

With Module Selection

{
  "mcpServers": {
    "falcon-mcp": {
      "command": "uvx",
      "args": [
        "--env-file",
        "/path/to/.env",
        "falcon-mcp",
        "--modules",
        "detections,hosts,intel"
      ]
    }
  }
}

Docker

{
  "mcpServers": {
    "falcon-mcp-docker": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "--env-file",
        "/full/path/to/.env",
        "quay.io/crowdstrike/falcon-mcp:latest"
      ]
    }
  }
}

See the Usage guide for all command line options, module configuration, and library usage.

Container Usage

# Pull the latest image
docker pull quay.io/crowdstrike/falcon-mcp:latest

# Run with .env file (stdio transport)
docker run -i --rm --env-file /path/to/.env quay.io/crowdstrike/falcon-mcp:latest

# Run with streamable-http transport
docker run --rm -p 8000:8000 --env-file /path/to/.env \
  quay.io/crowdstrike/falcon-mcp:latest --transport streamable-http --host 0.0.0.0

See the Docker Deployment guide for building locally, custom ports, and advanced configurations.

Dynamic Mode

Running many modules at once inflates the context window every AI client must hold. Dynamic mode replaces the full tool surface with three tools — falcon_list_enabled_modules to see which modules are loaded, falcon_search_tools to discover the right tool on demand, and falcon_execute_tool to run it — so agents only load the schemas they actually need.

falcon-mcp --dynamic
# or: FALCON_MCP_DYNAMIC=true

See the Dynamic Mode guide for the full discover → execute workflow and trade-offs.

Deployment Options

Contributing

# Clone and install
git clone https://github.com/CrowdStrike/falcon-mcp.git
cd falcon-mcp
uv sync --all-extras

# Run tests
uv run pytest

[!IMPORTANT] This project uses Conventional Commits for automated releases. Please follow the commit message format outlined in our Contributing Guide.

Developer Documentation

Registries

falcon-mcp is published to public MCP catalogs for discovery and one-click setup in compatible clients:

License

This project is licensed under the MIT License - see the LICENSE file for details.

Support

This is a community-driven, open source project. While it is not an official CrowdStrike product, it is actively maintained by CrowdStrike and supported in collaboration with the open source developer community.

For more information, please see our SUPPORT file.

Related MCP servers

60+ Meta Ads tools for AI agents: audits, campaign management, audiences and CAPI tracking.

9
TypeScript
MIT
View repository →

Recorded browser sessions, backend spans, and database row diffs as one ranked fix bundle.

View repository →

56+ AI tools for CRM, content, workflows, SkillForge & marketing automation.

0
JavaScript
MIT
View repository →

MCP server for full transaction and token history on EVM and UTXO addresses via Crypto APIs

0
TypeScript
View repository →

MCP server for current balance and state of EVM, UTXO, Solana, XRP, Kaspa addresses via Crypto APIs

0
TypeScript
View repository →

MCP server for AML address verification and transaction screening via Crypto APIs

0
TypeScript
View repository →