Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

Explore

  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Tags index
  • Submit a server
  • Pricing

Learn

  • Guides hub
  • What is MCP?
  • Install guide
  • Troubleshooting
  • Security
  • Blog
  • Blog RSS

Tools

  • All tools
  • Config generator
  • Config validator
  • MCP playground
  • OpenAPI β†’ MCP
  • Badge generator

For agents

  • API docs
  • Trust & traffic
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
  • Remote MCP β†— (opens in a new tab)

Company

  • About
  • Contact
  • X (@AllMCPs) β†— (opens in a new tab)
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on Buildlist
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. CrowdStrike Falcon MCP Server
C
Health: ActiveRecent health check succeeded.Last checked 8/10/2026, 11:55:17 PM

CrowdStrike Falcon MCP Server

Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository232 GitHub StarsTotal stargazers on GitHub for the source repository (232 stars).

Connects AI agents with CrowdStrike Falcon for security analysis and automation.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Install Config Generator

Choose your client
claude_desktop_config.json
{
  "mcpServers": {
    "crowdstrike-falcon-mcp-server": {
      "command": "uvx",
      "args": [
        "--env-file",
        "/path/to/.env",
        "falcon-mcp"
      ]
    }
  }
}

πŸ’‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)

Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

CrowdStrike Logo (Light) CrowdStrike Logo (Dark)

falcon-mcp

PyPI version PyPI - Python Version License: MIT MCP Registry GitHub MCP Gemini CLI Extension

falcon-mcp is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilitiesβ€”including detections, threat intelligence, and host managementβ€”establishing the foundation for advanced security operations and automation.

[!IMPORTANT] 🚧 Public Preview: This project is currently in public preview and under active development. Features and functionality may change before the stable 1.0 release. While we encourage exploration and testing, please avoid production deployments. We welcome your feedback through GitHub Issues to help shape the final release.

Documentation

Full docs are available at developer.crowdstrike.com/falcon-mcp.

Modules

ModuleDescription
CoreBasic connectivity and system information
Case ManagementCase lifecycle management, evidence attachment, tagging, and templates
Cloud SecurityKubernetes containers, image vulnerabilities, CSPM asset inventory, IOM findings, suppression rules, cloud risks, and cloud groups
Correlation RulesSearch, create, update, and manage NG-SIEM correlation rules
Custom IOACreate and manage Custom IOA behavioral detection rules and rule groups
Data ProtectionSearch Data Protection classifications, policies, and content patterns
DetectionsFind, aggregate, and analyze detections to understand malicious activity
DiscoverSearch application inventory and discover unmanaged assets
ExclusionsSearch, create, update, and delete IOA, machine learning, sensor visibility, and certificate-based exclusions
Firewall ManagementSearch and manage firewall rules and rule groups
Host GroupsSearch, create, update, and delete host groups; manage group membership
HostsManage and query host/device information
Identity ProtectionEntity investigation and identity protection analysis
IntelResearch threat actors, IOCs, and intelligence reports
IOCSearch, create, and remove custom indicators of compromise
NGSIEMExecute CQL queries against Next-Gen SIEM
PoliciesSearch, create, update, and delete prevention, sensor update, firewall, device control, response, and content update policies; manage host-group assignment, enable/disable, and precedence
QuarantineSearch quarantine records, preview action counts, and release, unrelease, or delete quarantined files
Real Time ResponseAudit, summarize, and run read-only RTR triage workflows
ReconSearch Falcon Intelligence Recon notifications (recon alerts), monitoring rules, and exposed-data records for dark web, leaked credentials, and typosquatting
Scheduled ReportsManage scheduled reports and download report files
Sensor UsageAccess and analyze sensor usage data
ServerlessSearch for vulnerabilities in serverless functions
ShieldSaaS security posture, checks, alerts, and app inventory
SpotlightManage and analyze vulnerability data and security assessments

See the Module Overview for required API scopes, available tools, and FQL resources.

Quick Start

Install

Using uv (recommended)

bash
uv tool install falcon-mcp

Using pip

Terminal
pip install falcon-mcp

Configure

Set the required environment variables (or use a .env file β€” see the Configuration Guide):

server.ts
export FALCON_CLIENT_ID="your-client-id"
export FALCON_CLIENT_SECRET="your-client-secret"
export FALCON_BASE_URL="https://api.crowdstrike.com"

Run

bash
falcon-mcp

See the Getting Started guide for full installation and configuration details.

Editor Integration

Using uvx (recommended)

config.json
{
  "mcpServers": {
    "falcon-mcp": {
      "command": "uvx",
      "args": [
        "--env-file",
        "/path/to/.env",
        "falcon-mcp"
      ]
    }
  }
}

With Module Selection

config.json
{
  "mcpServers": {
    "falcon-mcp": {
      "command": "uvx",
      "args": [
        "--env-file",
        "/path/to/.env",
        "falcon-mcp",
        "--modules",
        "detections,hosts,intel"
      ]
    }
  }
}

Docker

config.json
{
  "mcpServers": {
    "falcon-mcp-docker": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "--env-file",
        "/full/path/to/.env",
        "quay.io/crowdstrike/falcon-mcp:latest"
      ]
    }
  }
}

See the Usage guide for all command line options, module configuration, and library usage.

Container Usage

bash
# Pull the latest image
docker pull quay.io/crowdstrike/falcon-mcp:latest

# Run with .env file (stdio transport)
docker run -i --rm --env-file /path/to/.env quay.io/crowdstrike/falcon-mcp:latest

# Run with streamable-http transport (add --api-key when the port is reachable beyond localhost)
docker run --rm -p 8000:8000 --env-file /path/to/.env \
  quay.io/crowdstrike/falcon-mcp:latest \
  --transport streamable-http --host 0.0.0.0 --api-key your-secret-key

[!CAUTION] HTTP transports have no authentication by default. Binding to a non-loopback address (--host 0.0.0.0) exposes an unauthenticated server that anyone who can reach the port can drive with your CrowdStrike credentials. Keep the default loopback bind for local use and set --api-key whenever you bind wider. Managed runtimes such as AWS Bedrock AgentCore and Google Cloud Run sit behind their own network security layer, so this does not apply to them. See the Configuration guide.

See the Docker Deployment guide for building locally, custom ports, and advanced configurations.

Dynamic Mode

Running many modules at once inflates the context window every AI client must hold. Dynamic mode replaces the full tool surface with three tools β€” falcon_list_enabled_tools to see every tool the server has available, falcon_search_tools to find candidate tools by keyword and then fetch the parameter schema for the one you pick, and falcon_execute_tool to run it β€” so agents only load the schemas they actually need.

bash
falcon-mcp --dynamic
# or: FALCON_MCP_DYNAMIC=true

See the Dynamic Mode guide for the full discover β†’ execute workflow and trade-offs.

Restricting What a Server Can Do

--modules is all-or-nothing per module: enabling one to get its search tools also exposes every mutating tool it carries. Three tool-level options narrow that surface.

bash
# Investigation-only server: no tool that mutates tenant state is registered
falcon-mcp --read-only

# Expose exactly two tools, nothing else
falcon-mcp --tools falcon_search_detections,falcon_search_hosts

# Keep the module, drop one tool
falcon-mcp --modules hostgroups --exclude-tools falcon_delete_host_groups

# All of detections, plus one tool from a module you did not enable
falcon-mcp --modules detections --tools falcon_search_applications
FlagEnvironment VariableEffect
--read-onlyFALCON_MCP_READ_ONLYRegisters only read-only tools
--toolsFALCON_MCP_TOOLSAllow-list of tool names, added to the enabled modules
--exclude-toolsFALCON_MCP_EXCLUDE_TOOLSDeny-list of tool names

Tool names are the falcon_-prefixed names your client displays. An unrecognized name aborts startup rather than being ignored, so a typo in a deny-list cannot silently leave a tool exposed.

Composing the options

--tools is additive, not a narrowing filter. It grants individual tools on top of whatever --modules already enabled, reaching across the module boundary:

  • --tools X on its own registers only X β€” no modules are loaded by default.
  • --modules detections --tools X registers every detections tool plus X, even when X belongs to a module that is not enabled. That module contributes only X, not its whole surface, and falcon_list_enabled_modules does not list it. falcon_list_enabled_tools does list X β€” it reports the tools available on the server, so it is the reliable answer to "is this capability available here?"

To subtract, use --exclude-tools or --read-only. All four knobs compose, and they resolve in a fixed order:

  1. --exclude-tools removes a tool unconditionally, even if --tools names it.
  2. --read-only removes every mutating tool unconditionally, even if --tools names it.
  3. --tools adds the tools it names, bypassing the module gate.
  4. --modules decides which tools are candidates by default.

Because the first two rules always win, --read-only and --exclude-tools are safe to set as a deployment-wide floor: an additive --tools list cannot widen past them. Combining them is how you express "search everything, change nothing, and don't even offer that one tool":

bash
falcon-mcp --read-only --exclude-tools falcon_execute_rtr_read_only_command

Filtering applies to dynamic mode too β€” a withheld tool is absent from falcon_search_tools results and rejected by falcon_execute_tool. Because dynamic mode dispatches by name rather than registering tools individually, that rejection spells out that the tool exists but the server's configuration withholds it, and names the one rule responsible, so an agent reports a disabled tool as disabled instead of telling the user the capability does not exist. falcon_list_enabled_tools carries a filters_active field in either mode whenever a rule is in effect. The startup log reports which rules are active and how many tools --read-only and --exclude-tools withheld, so you can confirm what you deployed. Run with --debug to see the withheld tools by name.

These options filter tools, not resources. A withheld tool's FQL guide resource stays available β€” guides are static field documentation carrying no tenant data.

Deployment Options

  • Amazon Bedrock AgentCore
  • Google Cloud (Cloud Run / Vertex AI)

Contributing

bash
# Clone and install
git clone https://github.com/CrowdStrike/falcon-mcp.git
cd falcon-mcp
uv sync --all-extras

# Run tests
uv run pytest

[!IMPORTANT] This project uses Conventional Commits for automated releases. Please follow the commit message format outlined in our Contributing Guide.

Developer Documentation

  • Documentation Guide: Architecture and maintenance guide for the documentation
  • Module Development Guide: Instructions for implementing new modules
  • Resource Development Guide: Instructions for implementing resources
  • Integration Testing Guide: Guide for running integration tests with real API calls

Registries

falcon-mcp is published to public MCP catalogs for discovery and one-click setup in compatible clients:

  • MCP Registry
  • GitHub MCP Registry
  • Gemini CLI Extensions

License

This project is licensed under the MIT License - see the LICENSE file for details.

Support

This is a community-driven, open source project. While it is not an official CrowdStrike product, it is actively maintained by CrowdStrike and supported in collaboration with the open source developer community.

For more information, please see our SUPPORT file.

Related MCP Servers

View all in Security View all alternatives
  • Mcp Maigret logoMcp Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    πŸ”’ Security3 views
    Compare vs Mcp Maigret β†’
  • D
    Delego

    Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.

    πŸ”’ Security1 views
    Compare vs Delego β†’
  • Emilia Protocol logoEmilia Protocol

    Human sign-off + trust receipts for AI agents: requires a named human's approval before an irreversible action (payment release, record change, deploy), then mints an offline-verifiable Ed25519 Trust Receipt. Also exposes trust profiles, receipt verification, disputes, and delegation. Apache-2.0; policy engine formally verified. Install: npx -y @emilia-protocol/mcp-server.

    πŸ”’ Security1 views
    Compare vs Emilia Protocol β†’
  • H
    Haldir

    Guardian layer for AI agents: identity, secrets, audit via MCP.

    πŸ”’ Security0 views
    Compare vs Haldir β†’

Frequently Asked Questions about CrowdStrike Falcon MCP Server

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "crowdstrike-falcon-mcp-server": { "command": "npx", "args": ["-y", "CrowdStrike Falcon MCP Server"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewCrowdStrike Falcon MCP Server AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/crowdstrike-falcon-mcp-server?style=directory)](https://allmcps.com/mcp/crowdstrike-falcon-mcp-server)
HTML Embed
<a href="https://allmcps.com/mcp/crowdstrike-falcon-mcp-server"><img src="https://allmcps.com/api/badge/crowdstrike-falcon-mcp-server?style=directory" alt="CrowdStrike Falcon MCP Server on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimePython
4/4 checks healthy over the last 6h
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars232
GitHub Star CountTotal stargazers on GitHub representing community popularity (232 stars).
Last commitToday
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Aug 10, 2026
44Quality signal: Fair Β· 44/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools15/30
Adoption & activity8/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 3,181+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Free dofollow backlink: after claiming, verify your product site and place a dofollow AllMCPs badge β€” we recheck it stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to CrowdStrike Falcon MCP Server β†’Install in Claude DesktopInstall in CursorInstall in VS Code