CrowdStrike Falcon
CrowdStrike Falcon MCP server that provides AI assistants with direct access to CrowdStrike's cybersecurity platform through comprehensive modules covering detections, incidents, threat intelligence, host management, vulnerability scanning, cloud security, identity protection, and sensor usage analytics. Built by CrowdStrike's cloud integrations team, the implementation uses the FalconPy SDK with proper API scope management and error handling, supporting multiple transport methods (stdio, SSE, streamable-http) and featuring modular architecture with FQL query guides, retry logic for E2E testing, and Docker deployment options. Designed for security operations teams, threat hunters, and incident responders who need conversational access to their CrowdStrike environment for tasks like investigating security alerts, analyzing threat intelligence, managing endpoints, and generating security reports without switching between multiple interfaces.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-19.
Scan details: Circle-IR · 2026-09-19 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- cloud-infra
- Source
- PulseMCP
- Repository
- github.com/crowdstrike/falcon-mcp
- Author type
- human
- Last scanned
- 2026-09-19
- Updated
- 2026-09-19
Use via MCP
Resolve CrowdStrike Falcon from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.