CrowdStrike Falcon MCP Server
CrowdStrike publishes falcon-mcp, a first-party open-source MCP server that connects agents to the Falcon platform. It is a LOCAL STDIO product: installed with uv/pip/uvx and run by the operator, authenticating with the operator's own Falcon OAuth2 client credentials. CrowdStrike also operates a separate HOSTED Falcon MCP (discovery-shaped: search_tools then execute_tool) which its own docs compare against this one, but publishes no anonymous endpoint URL for it — so no remote endpoint is recorded here.
One-click install for Cursor, VS Code, Claude, and 20+ other MCP clients, powered by API Commons MCP Install — visit install.apicommons.org for more information.
Documentation
Documentation link · transport
Tools
falcon_search_agentworks_agents— Search for AgentWorks (Charlotte AI) agents in your CrowdStrike environment.falcon_search_agentworks_agent_versions— Search for versions of AgentWorks agents.falcon_search_agentworks_spans— Search AgentWorks execution spans (traces) for observability.falcon_get_agentworks_agent_invocation— Get the current state of an AgentWorks agent invocation by ID.falcon_invoke_agentworks_agent— Invoke an AgentWorks (Charlotte AI) agent and return its reply.falcon_search_cases— Find cases by criteria and return their complete details.falcon_get_cases— Retrieve details for case IDs you already have.falcon_create_case— Create a new case in CrowdStrike.falcon_update_case— Update an existing case's fields.falcon_add_case_alert_evidence— Attach alert evidence to an existing case.falcon_add_case_event_evidence— Attach LogScale event evidence to an existing case.falcon_manage_case_tags— Add or remove tags on a case.falcon_list_case_templates— List available case templates.falcon_aggregate_case_slas— Count case SLA definitions grouped by a field.falcon_aggregate_case_templates— Count case templates grouped by a field.falcon_aggregate_case_access_tags— Count case access tags grouped by a field.falcon_aggregate_case_notification_groups— Count case notification groups grouped by a field.falcon_aggregate_case_file_details— Report the files attached to cases, grouped and counted by a field.falcon_search_cloud_insights— Search for cloud security insights using FQL.falcon_get_cloud_asset_insights— Retrieve the full insight detail for one or more cloud ASSET IDs.falcon_list_cloud_insight_definitions— Return all available cloud insight definitions, deduplicated by insight_id.falcon_search_cspm_assets— Search for cloud assets in your CrowdStrike CSPM inventory.falcon_search_kubernetes_containers— Search for Kubernetes containers in your CrowdStrike container inventory.falcon_count_kubernetes_containers— Count Kubernetes containers matching filter criteria.falcon_search_images_vulnerabilities— Search for container image vulnerabilities in CrowdStrike Image Assessments.falcon_search_iom_findings— Search for CSPM Indicators of Misconfiguration (IOM) findings.falcon_search_cspm_suppression_rules— Search for CSPM IOM suppression rules.falcon_create_cspm_suppression_rule— Create a CSPM IOM suppression rule to hide matching findings.falcon_delete_cspm_suppression_rules— Delete CSPM IOM suppression rules by ID.falcon_search_cloud_risks— Search for cloud risks in your CrowdStrike environment.falcon_search_cloud_groups— List cloud groups in your CrowdStrike environment.falcon_get_cloud_groups— Get detailed information for cloud groups by ID.falcon_search_correlation_rules— Search NG-SIEM Correlation Rules and return full rule details.falcon_create_correlation_rule— Create a new NG-SIEM Correlation Rule.falcon_update_correlation_rule— Update an existing NG-SIEM Correlation Rule.falcon_delete_correlation_rules— Permanently delete NG-SIEM Correlation Rules by rule ID.falcon_search_ioa_rule_groups— Search Custom IOA rule groups and return full details including their rules.falcon_get_ioa_platforms— Get all available platforms for Custom IOA rule groups.falcon_get_ioa_rule_types— Get all available Custom IOA rule types.falcon_create_ioa_rule_group— Create a new Custom IOA rule group.falcon_update_ioa_rule_group— Update an existing Custom IOA rule group.falcon_delete_ioa_rule_groups— Delete Custom IOA rule groups by ID.falcon_create_ioa_rule— Create a new Custom IOA behavioral detection rule within a rule group.falcon_update_ioa_rule— Update an existing Custom IOA behavioral detection rule.falcon_delete_ioa_rules— Delete Custom IOA behavioral detection rules from a rule group.falcon_search_data_protection_classifications— Search for Data Protection classifications in your CrowdStrike environment.falcon_search_data_protection_policies— Search for Data Protection policies in your CrowdStrike environment.falcon_search_data_protection_content_patterns— Search for Data Protection content patterns in your CrowdStrike environment.falcon_search_detections— Find detections (also called alerts) by criteria and return their complete details.falcon_get_detection_details— Retrieve details for detection IDs you already have.falcon_aggregate_detections— Count and summarize detections (also called alerts) without retrieving each record.falcon_update_detections— Update the status, assignment, visibility, comments, and tags of one or more detections.falcon_search_applications— Search for applications discovered in your CrowdStrike environment.falcon_search_unmanaged_assets— Search for unmanaged assets (hosts without Falcon sensor) in your environment.falcon_search_managed_assets— Search hosts by asset and configuration posture: drive encryption status, encrypted/unencrypted drives, OS security settings (Secure Boot, Credential Guard, IOMMU), disk/memory/CPU usage, asset criticality, and internet exposure.falcon_search_exclusions— Search exclusions of a given type and return full exclusion records.falcon_create_exclusion— Create an exclusion of the given type.falcon_update_exclusion— Update an existing exclusion of the given type.falcon_delete_exclusions— Delete one or more exclusions of the given type.falcon_get_certificate_details— Retrieve the code-signing certificate metadata for a file by SHA256.falcon_search_firewall_rules— Search firewall rules and return full rule details.falcon_search_firewall_rule_groups— Search firewall rule groups and return full rule group details.falcon_search_firewall_policy_rules— Search firewall rules within a specific policy container.falcon_create_firewall_rule_group— Create a firewall rule group.falcon_delete_firewall_rule_groups— Delete firewall rule groups by ID.falcon_search_workflow_definitions— Search Fusion SOAR workflow definitions in your CrowdStrike environment.falcon_search_workflow_executions— Search Fusion SOAR workflow execution history in your CrowdStrike environment.falcon_get_workflow_execution_results— Read what one or more Fusion SOAR workflow executions produced.falcon_execute_workflow— Start a Fusion SOAR workflow by definition ID.falcon_search_guardian_agents— List AI agents from the AIAgent entity store.falcon_get_guardian_agent— Get a specific AI agent's record from the AIAgent entity store.falcon_search_guardian_mcp_servers— List MCP server names observed across the fleet (MCPServerName entity).falcon_get_guardian_agent_sessions— List AI agent sessions across the fleet, filtered by product.falcon_get_guardian_session_detail— Get detailed information about a specific AI session.falcon_get_guardian_session_activity— Get activity for one or more AI sessions.falcon_search_guardian_tools— List AI tools from the AITool entity store — the inventory of which tools exist.falcon_search_guardian_tool_usage— List AI tool usage from LogScale AgenticToolRequest events.falcon_search_guardian_executions— List AI agent process executions, with the model and token counts for each.falcon_search_guardian_prompts— Search for AI prompts within a session (LogScale AgenticUserPromptSubmit).falcon_get_guardian_inventory— Get a summary overview of AI activity in your environment.falcon_search_guardian_skills— List AI skill frontmatters (AISkillFrontmatterView entity).falcon_search_guardian_skill_usage— List per-invocation AI skill events (LogScale AgenticToolRequest).falcon_get_guardian_fleet_skill_inventory— Get a fleet-wide skill usage rollup by name (AISkill aggregate).falcon_search_guardian_os_users— List OS users that have run AI agents (AIAgentOSUser entity).falcon_pivot_on_guardian_attribute— Pivot from a known attribute value to the agents or activity carrying it.falcon_get_guardian_process_tree— Get the spawned process tree for an AI session.falcon_get_guardian_network_events— Get outbound network connections from an AI session's processes.falcon_get_guardian_file_events— Get file activity for processes spawned from an AI session.falcon_get_guardian_classified_file_access— Get classified/sensitive file access for an AI agent process.falcon_generate_guardian_report— Generate a structured Guardian report.falcon_search_guardian_detections— List detections involving AI agent processes.falcon_get_guardian_detection_scores— Get the Agentic Threat Score for each agent.falcon_search_guardian_installs— List AI agent installations (AIAgentInstallationView entity).falcon_search_guardian_models— List AI model names (AIModelName entity).falcon_search_host_groups— Search for host groups in your CrowdStrike environment.falcon_search_host_group_members— Search for the host members of a specific host group.falcon_create_host_group— Create a host group.falcon_update_host_group— Update an existing host group.falcon_delete_host_groups— Delete one or more host groups.falcon_perform_host_group_action— Add or remove hosts from one or more host groups.falcon_search_hosts— Search hosts and their sensor state: filter by hostname, platform, IP, sensor version, containment (network-quarantine) status, assigned policies, or grouping tags.falcon_get_host_details— Retrieve detailed information for one or more host device IDs.falcon_manage_host_grouping_tags— Add or remove Falcon Grouping Tags on one or more hosts.falcon_idp_investigate_entity— Investigate one or more Identity Protection entities by ID, name, email, IP, or domain.falcon_search_actors— Research threat actors and adversary groups tracked by CrowdStrike intelligence.falcon_search_indicators— Search for threat indicators and IOCs from CrowdStrike intelligence.falcon_search_reports— Search CrowdStrike intelligence publications and threat reports.falcon_get_mitre_report— Generate a MITRE ATT&CK report for a given threat actor.falcon_search_iocs— Search custom IOCs and return full IOC details.falcon_add_ioc— Create one or more custom IOCs.falcon_remove_iocs— Remove custom IOCs by IDs or FQL filter.falcon_search_ngsiem— Execute a CQL (CrowdStrike Query Language) query against CrowdStrike Next-Gen SIEM.falcon_search_policies— Search host-based policies of a given type and return full policy records.falcon_search_policy_members— Search for the host members governed by a specific policy.falcon_create_policy— Create a host-based policy of the given type.falcon_update_policy— Update an existing host-based policy of the given type.falcon_delete_policies— Delete one or more host-based policies of the given type.falcon_perform_policy_action— Perform an action on one or more policies of the given type.falcon_set_policy_precedence— Set the precedence (evaluation order) of policies for a platform.falcon_search_quarantined_files— Search quarantined files and return full quarantine metadata.falcon_preview_quarantine_actions— Estimate how many quarantine records each action would affect for a given filter.falcon_update_quarantined_files— Apply a reversible quarantine action to records selected by IDs or filter.falcon_delete_quarantined_files— Delete quarantine records selected by IDs or filter.falcon_search_recon_notifications— Search Falcon Intelligence Recon notifications (also called recon alerts) and return their full details.falcon_search_recon_rules— Search Falcon Intelligence Recon monitoring rules and return their full details.falcon_search_recon_exposed_data_records— Search Falcon Intelligence Recon exposed-data records and return their full details.falcon_aggregate_recon_notifications— Count and group Falcon Intelligence Recon notifications into summary buckets.falcon_aggregate_recon_exposed_data_records— Count and group Falcon Intelligence Recon exposed-data records into summary buckets.falcon_preview_recon_rule— Estimate how many notifications a prospective Recon monitoring rule would generate.falcon_search_rtr_sessions— Search RTR sessions and return full session details.falcon_search_rtr_audit_sessions— Search RTR audit sessions for accountability and timeline evidence.falcon_aggregate_rtr_sessions— Summarize RTR session activity with Falcon aggregation buckets.falcon_get_rtr_session_details— Retrieve detailed metadata for one or more RTR sessions.falcon_init_rtr_session— Initialize or reuse an RTR session for a single host.falcon_pulse_rtr_session— Refresh an RTR session timeout for a single host.falcon_execute_rtr_read_only_command— Execute a read-only RTR command on a single host.falcon_run_rtr_read_only_command_and_wait— Execute a read-only RTR command and poll until completion.falcon_check_rtr_command_status— Get the status and output for an RTR command execution.falcon_list_rtr_session_files— List files extracted during an RTR session.falcon_delete_rtr_session— Close an RTR session and release the host connection.falcon_search_scheduled_reports— Search for scheduled reports and searches in your CrowdStrike environment.falcon_launch_scheduled_report— Launch a scheduled report or search on demand.falcon_search_report_executions— Search for report/search execution history.falcon_download_report_execution— Download the results of a completed report execution.falcon_search_sensor_usage— Search for weekly sensor usage data in your CrowdStrike environment.falcon_search_serverless_vulnerabilities— Search for vulnerabilities in serverless functions across all cloud providers.falcon_search_shield_checks— Search individual Falcon Shield (SaaS Security) posture checks with filtering.falcon_get_shield_check_affected_entities— Retrieve the specific entities (users, apps, or devices) that are violating a given Falcon Shield posture check.falcon_get_shield_posture_metrics— Get aggregated Falcon Shield (SaaS Security) posture metrics for a dashboard or summary view.falcon_get_shield_check_compliance— Retrieve the compliance framework mappings for a specific Falcon Shield posture check.falcon_search_shield_alerts— Search Falcon Shield (SaaS Security) alerts for monitored SaaS applications.falcon_get_shield_activity_monitor— Get events from the Falcon Shield (SaaS Security) activity monitor; data is retained for 180 days.falcon_search_shield_users— List end-users discovered across Falcon Shield (SaaS Security) connected SaaS applications.falcon_search_shield_devices— List devices registered to users in Falcon Shield (SaaS Security) connected SaaS applications.falcon_search_shield_apps— List third-party applications (OAuth apps, API tokens, browser extensions, service principals) with access to Falcon Shield (SaaS Security) monitored platforms.falcon_get_shield_app_users— Retrieve the users who have authorized or are associated with a specific third-party app in Falcon Shield.falcon_search_shield_data_shares— List files and resources shared externally across Falcon Shield (SaaS Security) monitored applications.falcon_get_shield_integrations— List all SaaS integrations connected to Falcon Shield and their current connection status.falcon_get_shield_system_users— List Falcon Shield (SaaS Security) platform administrators.falcon_get_shield_supported_saas— List SaaS platforms supported by Falcon Shield for integration.falcon_get_shield_system_logs— Retrieve Falcon Shield (SaaS Security) system audit logs; data is retained for 90 days.falcon_dismiss_shield_check— Dismiss a Falcon Shield (SaaS Security) posture check to suppress it from the failed checks list.falcon_search_vulnerabilities— Search for vulnerabilities in your CrowdStrike environment.falcon_search_zta_assessments— Search Zero Trust Assessment scores and return full assessment details.falcon_get_zta_assessments— Get Zero Trust Assessment details for specific hosts by agent ID (AID).falcon_get_zta_audit— Get the tenant-wide Zero Trust Assessment summary.
About MCP
The Model Context Protocol (MCP) is an open protocol Anthropic introduced for connecting LLM-based agents to external tools and data sources. Providers publish MCP servers that expose their API surface as structured, discoverable tools — an MCP-compatible client (Claude Desktop, Cursor, Cline, Continue, etc.) can connect to the server and call its tools without any per-provider integration code.
Browse every MCP server on the APIs.io network or compare with the broader Agent Skill surfaces of the same providers.
Work with this as data
Every MCP server here is available over the APIs.io API and to AI agents over MCP.