Connects AI agents with CrowdStrike Falcon for security analysis and automation.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

falcon-mcp is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilities—including detections, threat intelligence, and host management—establishing the foundation for advanced security operations and automation.
[!IMPORTANT] Pre-1.0 release: falcon-mcp is under active development ahead of 1.0. Tool names, parameters, and response shapes can still change between minor releases, so pin a version and check the changelog before upgrading. The project is actively maintained by CrowdStrike and supported through GitHub Issues; CrowdStrike customers can also raise questions through their usual Technical Support channels. See SUPPORT.md for details.
Full docs are available at developer.crowdstrike.com/falcon-mcp.
| Module | Description |
|---|---|
| Core | Basic connectivity and system information |
| AgentWorks | Call, list, and observe Charlotte AI agents and their execution traces |
| Case Management | Case lifecycle management, evidence attachment, tagging, and templates |
| Cloud Security | Kubernetes containers, image vulnerabilities, CSPM asset inventory, IOM findings, suppression rules, cloud risks, cloud insights, and cloud groups |
| Correlation Rules | Search, create, update, and manage NG-SIEM correlation rules |
| Custom IOA | Create and manage Custom IOA behavioral detection rules and rule groups |
| Data Protection | Search Data Protection classifications, policies, and content patterns |
| Detections | Find, aggregate, and analyze detections to understand malicious activity |
| Discover | Search application inventory and managed/unmanaged assets, including drive encryption and system-insights posture |
| Exclusions | Search, create, update, and delete IOA, machine learning, sensor visibility, and certificate-based exclusions |
| Firewall Management | Search and manage firewall rules and rule groups |
| Fusion SOAR | Search Fusion SOAR workflow definitions and executions, read execution results, and run on-demand workflows |
| Guardian | Monitor AI agent activity, sessions, tool usage, and inventory |
| Host Groups | Search, create, update, and delete host groups; manage group membership |
| Hosts | Manage and query host/device information |
| Identity Protection | Entity investigation and identity protection analysis |
| Intel | Research threat actors, IOCs, and intelligence reports |
| IOC | Search, create, and remove custom indicators of compromise |
| NGSIEM | Execute CQL queries against Next-Gen SIEM |
| Policies | Search, create, update, and delete prevention, sensor update, firewall, device control, response, and content update policies; manage host-group assignment, enable/disable, and precedence |
| Quarantine | Search quarantine records, preview action counts, and release, unrelease, or delete quarantined files |
| Real Time Response | Audit, summarize, and run read-only RTR triage workflows |
| Recon | Search and aggregate Falcon Intelligence Recon notifications (recon alerts), monitoring rules, and exposed-data records for dark web, leaked credentials, and typosquatting, and preview prospective rule noise |
| Scheduled Reports | Manage scheduled reports and download report files |
| Sensor Usage | Access and analyze sensor usage data |
| Serverless | Search for vulnerabilities in serverless functions |
| Shield | SaaS security posture, checks, alerts, and app inventory |
| Spotlight | Manage and analyze vulnerability data and security assessments |
| Zero Trust Assessment | Retrieve Zero Trust Assessment posture scores and sensor and OS hardening signals for hosts |
See the Module Overview for required API scopes, available tools, and FQL resources.
[!NOTE] The Guardian module reads the
/aidrAPI, whose route and parameter surface is not yet uniform across Falcon deployments. Some tools return HTTP 400 or 404 where an older surface is live. See the Guardian module docs for the details.
Set the required environment variables (or use a .env file — see the Configuration Guide):
See the Getting Started guide for full installation and configuration details.
uvx (recommended)See the Usage guide for all command line options, module configuration, and library usage.
Factual signals from GitHub, npm, and our automated checks — not a rating.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/crowdstrike-falcon-mcp-server)<a href="https://allmcps.com/mcp/crowdstrike-falcon-mcp-server"><img src="https://allmcps.com/api/badge/crowdstrike-falcon-mcp-server?style=directory" alt="CrowdStrike Falcon MCP Server on AllMCPs" /></a>