# CrowdStrike Falcon

> Use this tool when you need to access a comprehensive cybersecurity platform through AI assistants, solving problems like investigating security alerts, analyzing threat intelligence, and managing endpoints. It provides inputs such as FQL queries and outputs like detection reports, incident responses, and threat intelligence analysis. Use CrowdStrike Falcon in security operations contexts where conversational access to cybersecurity data is required, streamlining tasks for security teams, threat hunters, and incident responders.

Canonical page: https://skillsregistry.net/skills/crowdstrike-falcon  
JSON: https://api.skillsregistry.net/v1/skills/crowdstrike-falcon

## Description

CrowdStrike Falcon MCP server that provides AI assistants with direct access to CrowdStrike's cybersecurity platform through comprehensive modules covering detections, incidents, threat intelligence, host management, vulnerability scanning, cloud security, identity protection, and sensor usage analytics. Built by CrowdStrike's cloud integrations team, the implementation uses the FalconPy SDK with proper API scope management and error handling, supporting multiple transport methods (stdio, SSE, streamable-http) and featuring modular architecture with FQL query guides, retry logic for E2E testing, and Docker deployment options. Designed for security operations teams, threat hunters, and incident responders who need conversational access to their CrowdStrike environment for tasks like investigating security alerts, analyzing threat intelligence, managing endpoints, and generating security reports without switching between multiple interfaces.

## Trust

- **Trust score (0–1):** 0.47
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/crowdstrike-falcon)
- **Repository:** <https://github.com/crowdstrike/falcon-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "crowdstrike-falcon"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/crowdstrike-falcon` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/crowdstrike-falcon/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
