Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ’ป Developer Tools
  3. Falcon MCP
F
Health: ActiveRecent health check succeeded.Last checked 9/8/2026, 11:46:22 AM

Falcon MCP

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe havenโ€™t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time โ€” check back soon.
View Repository

Community extension of CrowdStrike falcon-mcp with near-complete Falcon API coverage

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "falcon-mcp": {
      "command": "uvx",
      "args": [
        "directly"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing Alternatives๐Ÿ’ป More in Developer Tools

Documentation Overview

falcon-mcp-extended

License: MIT MCP Protocol Python Tools GitHub Stars CI PyPI MCP Registry

[!NOTE] This is a community extension of CrowdStrike's official falcon-mcp server (MIT licensed). It adds 106 auto-generated API wrapper modules (~904 additional tools) on top of the official curated tool set, for near-complete CrowdStrike Falcon API coverage. This project is not affiliated with, maintained by, or endorsed by CrowdStrike. If you only need the curated SOC workflows, use the official server; use this project when you need API surface the official server doesn't expose yet.

For SOC analysts and security engineers: Stop tab-switching between CrowdStrike, your ticketing system, and your notes. Ask Claude to triage the alert, pull the process tree, check if the hash ran on other hosts, and draft the IR note โ€” all in one conversation.

falcon-mcp-extended is a Model Context Protocol (MCP) server that gives AI agents โ€” including Claude โ€” direct, structured access to the CrowdStrike Falcon platform for intelligent security operations.

What It Does

This server bridges AI assistants and the CrowdStrike Falcon platform, enabling SOC analysts to ask natural-language questions and get answers backed by live Falcon data. It exposes Falcon's detection, investigation, response, and intelligence capabilities as MCP tools, so an AI agent can search detections, pivot through behaviors, contain hosts, and query threat intelligence โ€” all from a single conversation. Designed for both interactive SOC workflows and automated security pipelines, it supports MSSP Flight Control so multi-tenant environments can be queried without switching consoles.

What This Adds Over the Official Server

LayerModule countApproximate tool countEnabled by default
Curated modules (from upstream, plus additions)50~392Yes
Auto-generated API wrappers (gen_*) โ€” this project's addition106~904 additionalNo (opt-in)

The default mode exposes the curated layer (~392 tools), which covers every major SOC workflow with well-described, ergonomic tools. The full generated layer (total ~1,296 tools) can be enabled with FALCON_MCP_ENABLE_GENERATED=1 for complete API surface coverage โ€” including Message Center, ODS scans, response/content/device-control policies, installation tokens, MalQuery, FalconX Sandbox, QuickScan Pro, sample uploads, FileVantage, Falcon Complete Dashboard, cloud registration (AWS/Azure/GCP/OCI), Kubernetes admission control, container images/alerts/detections, network scanning, NGSIEM administration, knowledge bases, and much more.

Features

  • EDR Telemetry โ€” Search detections, behaviors, and incidents; drill into process execution trees and command-line activity
  • Real Time Response (RTR) โ€” Initialize RTR sessions, run read-only triage commands (ps, netstat, filehash, reg query), and execute active responder and admin commands with configurable safety gates
  • Threat Intelligence โ€” Research threat actors, query CrowdStrike indicators, retrieve MITRE ATT&CK reports, and search intelligence reports
  • Custom IOC Management โ€” Search, create, and delete custom indicators of compromise; manage IOC watchlists
  • Vulnerability Management (Spotlight) โ€” Query CVE exposure by host, filter by severity or CVE ID, and surface vulnerability assessments
  • Cloud Security โ€” Kubernetes container visibility, container image vulnerabilities, CSPM asset inventory, and serverless function vulnerability scanning
  • Identity Protection (IDP) โ€” Entity investigation and identity-based threat analysis
  • MSSP / Flight Control โ€” List and target child CIDs; pass a per-tool member_cid to scope any query to a specific managed tenant
  • Next-Gen SIEM (NGSIEM) โ€” Execute CQL queries against the Falcon NGSIEM for log-based investigation
  • Host Management โ€” Query host inventory, login history, network address history, device groups, and online state
  • Firewall & Custom IOA โ€” Search and manage firewall rules and behavioral detection rule groups
  • Incident Management โ€” Correlate incidents across hosts, update status, and annotate with investigative notes
  • Scheduled Reports โ€” List, manage, and download Falcon scheduled report outputs
  • Safety Gates โ€” Read-only mode suppresses all mutating tools at registration time; a separate destructive policy controls host containment, RTR execution, and account-level deletes

Prerequisites

  • Python 3.11 or later
  • CrowdStrike Falcon API credentials (Client ID and Client Secret) with appropriate scopes for the modules you intend to use
  • uv (recommended) or pip

Installation

[!IMPORTANT] The correct package name is falcon-mcp-extended. Do not pip install falcon-mcp โ€” that is CrowdStrike's official package, which does not include the extended module layer.

From PyPI (recommended)

Terminal
pip install falcon-mcp-extended

Or with uv:

bash
uv pip install falcon-mcp-extended

From source

bash
git clone https://github.com/rijul170/falcon-mcp.git
cd falcon-mcp
uv sync --all-extras
uv run falcon-mcp

Via uvx directly from GitHub (no clone required)

bash
uvx --from git+https://github.com/rijul170/falcon-mcp falcon-mcp

Via pip from GitHub

Terminal
pip install git+https://github.com/rijul170/falcon-mcp

Configuration

All configuration is driven by environment variables (or a .env file in the working directory). CLI flags mirror every env var and take precedence when both are set.

VariableRequiredDescriptionExample
FALCON_CLIENT_IDRequiredCrowdStrike API Client IDabc123def456
FALCON_CLIENT_SECRETRequiredCrowdStrike API Client Secretyour-client-secret
FALCON_BASE_URLRequiredAPI endpoint URL for your regionhttps://api.crowdstrike.com
FALCON_MEMBER_CIDOptionalDefault child CID for MSSP Flight Control; targets all queries at that tenantABC123DEF456GHI789
FALCON_MCP_TRANSPORTOptionalTransport protocol: stdio, sse, or streamable-http (default: stdio)streamable-http
FALCON_MCP_HOSTOptionalBind host for HTTP transports (default: 127.0.0.1)0.0.0.0
FALCON_MCP_PORTOptionalBind port for HTTP transports (default: 8000)8000
FALCON_MCP_MODULESOptionalComma-separated list of modules to enable; omit to enable alldetections,incidents,intel
FALCON_MCP_ENABLE_GENERATEDOptionalSet to 1 to load all 106 auto-generated modules (~1,296 tools total)1
FALCON_MCP_READONLYOptionalSet to true to suppress all mutating tools at startuptrue
FALCON_MCP_ALLOW_DESTRUCTIVEOptionalSet to true to enable all destructive tools, or a comma-separated list of specific tool names to allow selectivelyfalcon_perform_host_action,falcon_execute_rtr_active_responder_command
FALCON_MCP_API_KEYOptionalAPI key for x-api-key header authentication on HTTP transportsyour-api-key
FALCON_MCP_STATELESS_HTTPOptionalSet to true to enable stateless HTTP mode for horizontally-scaled deploymentstrue
FALCON_MCP_DEBUGOptionalSet to true to enable verbose debug loggingtrue

Region base URLs:

RegionBase URL
US-1https://api.crowdstrike.com
US-2https://api.us-2.crowdstrike.com
EU-1https://api.eu-1.crowdstrike.com
GOV-1https://api.laggar.gcw.crowdstrike.com

Claude Code Integration

HTTP mode (streamable-http) is recommended for Claude Code and other AI development environments that support persistent server connections.

Step 1 โ€” Start the server:

bash
FALCON_CLIENT_ID=your-client-id \
FALCON_CLIENT_SECRET=your-client-secret \
FALCON_BASE_URL=https://api.crowdstrike.com \
FALCON_MCP_TRANSPORT=streamable-http \
uv run falcon-mcp

Step 2 โ€” Add to .claude/settings.json (project) or ~/.claude/settings.json (global):

config.json
{
  "mcpServers": {
    "falcon-mcp": {
      "type": "http",
      "url": "http://localhost:8000/mcp"
    }
  }
}

For API key-protected deployments, add the header:

config.json
{
  "mcpServers": {
    "falcon-mcp": {
      "type": "http",
      "url": "http://localhost:8000/mcp",
      "headers": {
        "x-api-key": "your-api-key"
      }
    }
  }
}

Claude Desktop Integration

Stdio mode works best for Claude Desktop. Credentials are passed directly in the MCP server configuration.

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • T
    Telnyx

    Official TypeScript library for the Telnyx API

    ๐Ÿ’ป Developer Tools0 views
    Compare vs Telnyx โ†’
  • Ignite UI MCP Server logoIgnite UI MCP Server

    Unified MCP server for Ignite UI โ€” documentation, API, and CLI scaffolding

    ๐Ÿ’ป Developer Tools1 views
    Compare vs Ignite UI MCP Server โ†’
  • MCP Server Taiwan Weather logoMCP Server Taiwan Weather

    ็”จๆ–ผๅ–ๅพ—่‡บ็ฃไธญๅคฎๆฐฃ่ฑก็ฝฒ API ่ณ‡ๆ–™็š„ Model Context Protocol (MCP) Server

    ๐Ÿ’ป Developer Tools0 views
    Compare vs MCP Server Taiwan Weather โ†’
  • PraisonAI logoPraisonAI

    AI Agents Framework with Self Reflection and MCP support

    ๐Ÿ’ป Developer Tools1 views
    Compare vs PraisonAI โ†’

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Falcon MCP

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "falcon-mcp": { "command": "npx", "args": ["-y", "falcon-mcp"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewFalcon MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/falcon-mcp?style=directory)](https://allmcps.com/mcp/falcon-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/falcon-mcp"><img src="https://allmcps.com/api/badge/falcon-mcp?style=directory" alt="Falcon MCP on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ’ปDeveloper Tools
More technical detailsExpand โ–พ
TransportSTDIO
RuntimePython
Last updatedSep 1, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit7d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 1, 2026
40Quality signal: Fair ยท 40/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity4/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

โ˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server โ†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ’ป Developer Tools โ†’Best MCP servers for Developers โ†’Alternatives to Falcon MCP โ†’Install in Claude DesktopInstall in CursorInstall in VS Code