$ timeahead_
← mcp scores
87
falcon-mcp

Connect AI agents to CrowdStrike Falcon for automated security analysis and threat hunting

overview

What it does

Falcon-mcp is an MCP server that integrates CrowdStrike Falcon capabilities into AI agent workflows. It provides modular access to security operations including threat detection analysis, intelligence research, host and endpoint management, firewall administration, vulnerability assessment, and Real Time Response (RTR) for endpoint triage. Agents interact with 16+ modules spanning cloud security, identity protection, SIEM querying, and more.

Who it's for

Security operations teams automating incident response, threat analysts building agentic investigation workflows, and platform engineers integrating Falcon into security orchestration systems.

Common use cases

  • Analyze detections to understand attack activity and malware behavior
  • Research threat actors, IOCs, and threat intelligence reports
  • Query endpoint inventory and discover unmanaged assets
  • Execute read-only forensic commands on endpoints via Real Time Response
  • Query security events in Next-Gen SIEM using CQL
  • Assess vulnerabilities in Kubernetes clusters and serverless functions
  • Manage firewall rules and custom behavioral detection rules

Setup pitfalls

  • Requires CrowdStrike Falcon API credentials (FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, FALCON_BASE_URL); each module requires specific API scopes
  • Public preview status—features and module availability may change before 1.0 release
  • Writes to local filesystem for state and configuration; verify directory permissions before deploying
  • No passing CI; module and integration testing is the caller's responsibility
install
add to your claude desktop / cursor / windsurf mcp config:
{
  "mcpServers": {
    "falcon": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ]
    }
  }
}
per-client install guide (claude desktop · cursor · windsurf · vscode · claude code) →
owner of this server? claim your listing to get a verified badgeclaim →
score breakdown
security (35%)100
freshness (25%)100
adoption (20%)64
quality (10%)90
trust (10%)50
score history (5 updates)
5/10/20265/14/2026
capabilities · what this server can do
tool list unavailable — permissions from static analysis·auth: API key
high risk
● active   ○ not requested  ·  hover each badge for details
fs read fs write network exec eval secrets
why high risk: fs read + fs write + network + exec + secrets active — can execute code, access credentials, and make external network calls.
raw data
weekly downloads3k
github stars156
forks47
open issues32
license✓ present
readme length37775 chars
last commit2d ago
last updated4h ago
install verified✓ pass · 5d ago
score drop alerts
get notified by email when this server's score drops 5+ points