# CrowdStrike Falcon MCP server

> Query CrowdStrike Falcon detections, hosts, threat intel, vulnerabilities and more from your AI assistant.

- Listing: https://mcp.tc/i/crowdstrike-falcon
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: CrowdStrike
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://developer.crowdstrike.com/falcon-mcp/overview/>
- Repository: <https://github.com/CrowdStrike/falcon-mcp>
- Package: pypi `falcon-mcp`

## About

Connects an AI assistant to the CrowdStrike Falcon platform through its API. Modules cover detections, hosts and host groups, threat intelligence, IOCs, Spotlight vulnerabilities, identity protection, cloud security, NG-SIEM CQL queries, Fusion SOAR workflows, policies, exclusions, quarantine and Real Time Response triage. Some modules can create, update or delete objects.

Runs locally over stdio with uvx falcon-mcp (Python package falcon-mcp). It needs a Falcon API client ID and secret, plus an optional region base URL. Modules can be limited with a module list, and a read-only option is available. The project is labeled public preview by CrowdStrike.

## What it can do

- Find and analyze detections and incidents
- Query and manage hosts and host groups
- Research threat actors, IOCs and intelligence reports
- Review Spotlight vulnerability data
- Run CQL queries against Next-Gen SIEM
- Search cloud security findings and identity protection entities
- Manage policies, exclusions and custom IOCs
- Restrict access with module filters

## Example prompts

- "Show critical detections from the last 24 hours in Falcon"
- "Find hosts in the Servers host group that have not checked in this week"
- "Look up threat intel on the actor behind this indicator"
- "List high severity Spotlight vulnerabilities for my Windows hosts"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio crowdstrike-falcon --env "FALCON_CLIENT_ID=<YOUR_FALCON_CLIENT_ID>" --env "FALCON_CLIENT_SECRET=<YOUR_FALCON_CLIENT_SECRET>" --env "FALCON_MCP_API_KEY=<YOUR_FALCON_MCP_API_KEY>" -- uvx falcon-mcp
```

2. Start Claude Code and type `/mcp`. **crowdstrike-falcon** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=crowdstrike-falcon&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJmYWxjb24tbWNwIl0sImVudiI6eyJGQUxDT05fQ0xJRU5UX0lEIjoiPFlPVVJfRkFMQ09OX0NMSUVOVF9JRD4iLCJGQUxDT05fQ0xJRU5UX1NFQ1JFVCI6IjxZT1VSX0ZBTENPTl9DTElFTlRfU0VDUkVUPiIsIkZBTENPTl9NQ1BfQVBJX0tFWSI6IjxZT1VSX0ZBTENPTl9NQ1BfQVBJX0tFWT4ifX0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the secret the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "crowdstrike-falcon": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "${input:falcon-client-id}",
        "FALCON_CLIENT_SECRET": "${input:falcon-client-secret}",
        "FALCON_MCP_API_KEY": "${input:falcon-mcp-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "falcon-client-id",
      "description": "FALCON_CLIENT_ID",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon-client-secret",
      "description": "FALCON_CLIENT_SECRET",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon-mcp-api-key",
      "description": "FALCON_MCP_API_KEY",
      "password": true
    }
  ]
}
```

Needs uv (Python) on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add crowdstrike-falcon --env "FALCON_CLIENT_ID=<YOUR_FALCON_CLIENT_ID>" --env "FALCON_CLIENT_SECRET=<YOUR_FALCON_CLIENT_SECRET>" --env "FALCON_MCP_API_KEY=<YOUR_FALCON_MCP_API_KEY>" -- uvx falcon-mcp
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.crowdstrike-falcon]
command = "uvx"
args = ["falcon-mcp"]
env = { FALCON_CLIENT_ID = "<YOUR_FALCON_CLIENT_ID>", FALCON_CLIENT_SECRET = "<YOUR_FALCON_CLIENT_SECRET>", FALCON_MCP_API_KEY = "<YOUR_FALCON_MCP_API_KEY>" }
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "FALCON_CLIENT_ID=<YOUR_FALCON_CLIENT_ID>" -e "FALCON_CLIENT_SECRET=<YOUR_FALCON_CLIENT_SECRET>" -e "FALCON_MCP_API_KEY=<YOUR_FALCON_MCP_API_KEY>" crowdstrike-falcon uvx falcon-mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "crowdstrike-falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "<YOUR_FALCON_CLIENT_ID>",
        "FALCON_CLIENT_SECRET": "<YOUR_FALCON_CLIENT_SECRET>",
        "FALCON_MCP_API_KEY": "<YOUR_FALCON_MCP_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

## Details

- Server version: 0.19.0
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/crowdstrike-falcon (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
