CrowdStrike Falconvf.sr

listing.by · home.legend.verified

Query CrowdStrike Falcon detections, hosts, threat intel, vulnerabilities and more from your AI assistant.

state.local.long (state.local.title)listing.badge.runs_withstate.key.long

listing.install

listing.local.explain

uvx falcon-mcp

listing.local.needs listing.local.note

  • FALCON_CLIENT_ID listing.env.secret CrowdStrike API client ID
  • FALCON_CLIENT_SECRET listing.env.secret CrowdStrike API client secret
  • FALCON_BASE_URL listing.env.optional CrowdStrike API region URL
  • FALCON_MEMBER_CID listing.env.optional Child CID for Flight Control (MSSP) support
  • FALCON_MCP_MODULES listing.env.optional Comma-separated list of modules to enable
  • FALCON_MCP_TRANSPORT listing.env.optional Transport protocol to use

listing.share.h

listing.share.p_local

mcp.tc/i/crowdstrike-falcon

listing.about

Connects an AI assistant to the CrowdStrike Falcon platform through its API. Modules cover detections, hosts and host groups, threat intelligence, IOCs, Spotlight vulnerabilities, identity protection, cloud security, NG-SIEM CQL queries, Fusion SOAR workflows, policies, exclusions, quarantine and Real Time Response triage. Some modules can create, update or delete objects.

Runs locally over stdio with uvx falcon-mcp (Python package falcon-mcp). It needs a Falcon API client ID and secret, plus an optional region base URL. Modules can be limited with a module list, and a read-only option is available. The project is labeled public preview by CrowdStrike.

listing.can

  • Find and analyze detections and incidents
  • Query and manage hosts and host groups
  • Research threat actors, IOCs and intelligence reports
  • Review Spotlight vulnerability data
  • Run CQL queries against Next-Gen SIEM
  • Search cloud security findings and identity protection entities
  • Manage policies, exclusions and custom IOCs
  • Restrict access with module filters

listing.tools

listing.notools.key

listing.prompts

  • Show critical detections from the last 24 hours in Falcon

  • Find hosts in the Servers host group that have not checked in this week

  • Look up threat intel on the actor behind this indicator

  • List high severity Spotlight vulnerabilities for my Windows hosts

listing.setup.h

listing.setup.local

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport stdio crowdstrike-falcon --env "FALCON_CLIENT_ID=<YOUR_FALCON_CLIENT_ID>" --env "FALCON_CLIENT_SECRET=<YOUR_FALCON_CLIENT_SECRET>" --env "FALCON_MCP_API_KEY=<YOUR_FALCON_MCP_API_KEY>" -- uvx falcon-mcp
  1. Start Claude Code and type /mcp. crowdstrike-falcon should show as connected.

Add --scope user to make it available in every project. Replace the placeholders with your own values.

Claude Desktop

  1. Open Settings → Developer → Edit Config. It opens claude_desktop_config.json. Add:
claude_desktop_config.json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}
  1. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}

Needs uv (Python) on your computer. Replace the placeholders with your own values.

VS Code

Add it to .vscode/mcp.json. VS Code asks for the secret the first time and stores it securely:

.vscode/mcp.json
{
  "servers": {
    "crowdstrike-falcon": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "${input:falcon-client-id}",
        "FALCON_CLIENT_SECRET": "${input:falcon-client-secret}",
        "FALCON_MCP_API_KEY": "${input:falcon-mcp-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "falcon-client-id",
      "description": "FALCON_CLIENT_ID",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon-client-secret",
      "description": "FALCON_CLIENT_SECRET",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon-mcp-api-key",
      "description": "FALCON_MCP_API_KEY",
      "password": true
    }
  ]
}

Needs uv (Python) on your computer.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}
  1. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

Codex

codex mcp add crowdstrike-falcon --env "FALCON_CLIENT_ID=<YOUR_FALCON_CLIENT_ID>" --env "FALCON_CLIENT_SECRET=<YOUR_FALCON_CLIENT_SECRET>" --env "FALCON_MCP_API_KEY=<YOUR_FALCON_MCP_API_KEY>" -- uvx falcon-mcp

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.crowdstrike-falcon]
command = "uvx"
args = ["falcon-mcp"]
env = { FALCON_CLIENT_ID = "<YOUR_FALCON_CLIENT_ID>", FALCON_CLIENT_SECRET = "<YOUR_FALCON_CLIENT_SECRET>", FALCON_MCP_API_KEY = "<YOUR_FALCON_MCP_API_KEY>" }

Needs uv (Python) on your computer. Replace the placeholders with your own values.

Gemini CLI

gemini mcp add -e "FALCON_CLIENT_ID=<YOUR_FALCON_CLIENT_ID>" -e "FALCON_CLIENT_SECRET=<YOUR_FALCON_CLIENT_SECRET>" -e "FALCON_MCP_API_KEY=<YOUR_FALCON_MCP_API_KEY>" crowdstrike-falcon uvx falcon-mcp

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients that start local servers accept this shape:

{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}

Zed puts servers under context_servers in its settings, with the same command, args and env fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

listing.faq

Can I paste mcp.tc/i/crowdstrike-falcon into my MCP client?

No. CrowdStrike Falcon runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is uvx falcon-mcp.

Does CrowdStrike Falcon need an API key?

Yes. It reads FALCON_CLIENT_ID, FALCON_CLIENT_SECRET and FALCON_MCP_API_KEY from its environment, and FALCON_CLIENT_ID, FALCON_CLIENT_SECRET and FALCON_MCP_API_KEY are secrets. Put the value in your client's config on your own machine, never in a shared file.

Is CrowdStrike Falcon a remote or a local server?

Local. Your client starts it as a process on your computer with uvx falcon-mcp, which needs uv (Python).

What can CrowdStrike Falcon do?

You can find and analyze detections and incidents, query and manage hosts and host groups and research threat actors, IOCs and intelligence reports.

Which clients can use it?

Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.

Who wrote this page?

mcp.tc's robot read CrowdStrike Falcon's public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead_local listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![CrowdStrike Falcon on mcp.tc](https://mcp.tc/i/crowdstrike-falcon/badge.svg)](https://mcp.tc/i/crowdstrike-falcon)
HTML
<a href="https://mcp.tc/i/crowdstrike-falcon"><img src="https://mcp.tc/i/crowdstrike-falcon/badge.svg" alt="CrowdStrike Falcon on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/crowdstrike-falcon.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/crowdstrike-falcon" title="CrowdStrike Falcon on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json_local

https://mcp.tc/i/crowdstrike-falcon.json

listing.em.fields

listing.disclaimer_checked