{
  "markdown": "![CrowdStrike Logo (Light)](https://raw.githubusercontent.com/CrowdStrike/.github/main/assets/cs-logo-light-mode.png#gh-light-mode-only)\n![CrowdStrike Logo (Dark)](https://raw.githubusercontent.com/CrowdStrike/.github/main/assets/cs-logo-dark-mode.png#gh-dark-mode-only)\n\n<!-- mcp-name: io.github.CrowdStrike/falcon-mcp -->\n\n# falcon-mcp\n\n[![PyPI version](https://badge.fury.io/py/falcon-mcp.svg)](https://badge.fury.io/py/falcon-mcp)\n[![PyPI - Python Version](https://img.shields.io/pypi/pyversions/falcon-mcp)](https://pypi.org/project/falcon-mcp/)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![MCP Registry](https://img.shields.io/badge/MCP_Registry-falcon--mcp-blue)](https://registry.modelcontextprotocol.io/?q=io.github.CrowdStrike%2Ffalcon-mcp&all=1)\n[![GitHub MCP](https://img.shields.io/badge/GitHub_MCP-falcon--mcp-blue?logo=github)](https://github.com/mcp/CrowdStrike/falcon-mcp)\n[![Gemini CLI Extension](https://img.shields.io/badge/Gemini_CLI-falcon--mcp-blue?logo=google)](https://geminicli.com/extensions/?name=CrowdStrikefalcon-mcp)\n\n**falcon-mcp** is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilities—including detections, threat intelligence, and host management—establishing the foundation for advanced security operations and automation.\n\n> [!IMPORTANT]\n> **🚧 Public Preview**: This project is currently in public preview and under active development. Features and functionality may change before the stable 1.0 release. While we encourage exploration and testing, please avoid production deployments. We welcome your feedback through [GitHub Issues](https://github.com/crowdstrike/falcon-mcp/issues) to help shape the final release.\n\n## Documentation\n\nFull docs are available at **[developer.crowdstrike.com/falcon-mcp](https://developer.crowdstrike.com/falcon-mcp/)**.\n\n## Modules\n\n| Module | Description |\n| ------ | ----------- |\n| Core | Basic connectivity and system information |\n| [AgentWorks](https://developer.crowdstrike.com/falcon-mcp/modules/agentworks/) | Call, list, and observe Charlotte AI agents and their execution traces |\n| [Case Management](https://developer.crowdstrike.com/falcon-mcp/modules/cases/) | Case lifecycle management, evidence attachment, tagging, and templates |\n| [Cloud Security](https://developer.crowdstrike.com/falcon-mcp/modules/cloud/) | Kubernetes containers, image vulnerabilities, CSPM asset inventory, IOM findings, suppression rules, cloud risks, cloud insights, and cloud groups |\n| [Correlation Rules](https://developer.crowdstrike.com/falcon-mcp/modules/correlationrules/) | Search, create, update, and manage NG-SIEM correlation rules |\n| [Custom IOA](https://developer.crowdstrike.com/falcon-mcp/modules/custom-ioa/) | Create and manage Custom IOA behavioral detection rules and rule groups |\n| [Data Protection](https://developer.crowdstrike.com/falcon-mcp/modules/data-protection/) | Search Data Protection classifications, policies, and content patterns |\n| [Detections](https://developer.crowdstrike.com/falcon-mcp/modules/detections/) | Find, aggregate, and analyze detections to understand malicious activity |\n| [Discover](https://developer.crowdstrike.com/falcon-mcp/modules/discover/) | Search application inventory and managed/unmanaged assets, including drive encryption and system-insights posture |\n| [Exclusions](https://developer.crowdstrike.com/falcon-mcp/modules/exclusions/) | Search, create, update, and delete IOA, machine learning, sensor visibility, and certificate-based exclusions |\n| [Firewall Management](https://developer.crowdstrike.com/falcon-mcp/modules/firewall/) | Search and manage firewall rules and rule groups |\n| [Fusion SOAR](https://developer.crowdstrike.com/falcon-mcp/modules/fusion/) | Search Fusion SOAR workflow definitions and executions, read execution results, and run on-demand workflows |\n| [Guardian](https://developer.crowdstrike.com/falcon-mcp/modules/guardian/) | Monitor AI agent activity, sessions, tool usage, and inventory |\n| [Host Groups](https://developer.crowdstrike.com/falcon-mcp/modules/host-groups/) | Search, create, update, and delete host groups; manage group membership |\n| [Hosts](https://developer.crowdstrike.com/falcon-mcp/modules/hosts/) | Manage and query host/device information |\n| [Identity Protection](https://developer.crowdstrike.com/falcon-mcp/modules/idp/) | Entity investigation and identity protection analysis |\n| [Intel](https://developer.crowdstrike.com/falcon-mcp/modules/intel/) | Research threat actors, IOCs, and intelligence reports |\n| [IOC](https://developer.crowdstrike.com/falcon-mcp/modules/ioc/) | Search, create, and remove custom indicators of compromise |\n| [NGSIEM](https://developer.crowdstrike.com/falcon-mcp/modules/ngsiem/) | Execute CQL queries against Next-Gen SIEM |\n| [Policies](https://developer.crowdstrike.com/falcon-mcp/modules/policies/) | Search, create, update, and delete prevention, sensor update, firewall, device control, response, and content update policies; manage host-group assignment, enable/disable, and precedence |\n| [Quarantine](https://developer.crowdstrike.com/falcon-mcp/modules/quarantine/) | Search quarantine records, preview action counts, and release, unrelease, or delete quarantined files |\n| [Real Time Response](https://developer.crowdstrike.com/falcon-mcp/modules/rtr/) | Audit, summarize, and run read-only RTR triage workflows |\n| [Recon](https://developer.crowdstrike.com/falcon-mcp/modules/recon/) | Search and aggregate Falcon Intelligence Recon notifications (recon alerts), monitoring rules, and exposed-data records for dark web, leaked credentials, and typosquatting, and preview prospective rule noise |\n| [Scheduled Reports](https://developer.crowdstrike.com/falcon-mcp/modules/scheduled-reports/) | Manage scheduled reports and download report files |\n| [Sensor Usage](https://developer.crowdstrike.com/falcon-mcp/modules/sensor-usage/) | Access and analyze sensor usage data |\n| [Serverless](https://developer.crowdstrike.com/falcon-mcp/modules/serverless/) | Search for vulnerabilities in serverless functions |\n| [Shield](https://developer.crowdstrike.com/falcon-mcp/modules/shield/) | SaaS security posture, checks, alerts, and app inventory |\n| [Spotlight](https://developer.crowdstrike.com/falcon-mcp/modules/spotlight/) | Manage and analyze vulnerability data and security assessments |\n| [Zero Trust Assessment](https://developer.crowdstrike.com/falcon-mcp/modules/zero-trust-assessment/) | Retrieve Zero Trust Assessment posture scores and sensor and OS hardening signals for hosts |\n\nSee the [Module Overview](https://developer.crowdstrike.com/falcon-mcp/modules/overview/) for required API scopes, available tools, and FQL resources.\n\n> [!NOTE]\n> The Guardian module reads the `/aidr` API, whose route and parameter surface is not\n> yet uniform across Falcon deployments. Some tools return HTTP 400 or 404 where an\n> older surface is live. See the [Guardian module docs](https://developer.crowdstrike.com/falcon-mcp/modules/guardian/) for the details.\n\n## Quick Start\n\n### Install\n\n#### Using uv (recommended)\n\n```bash\nuv tool install falcon-mcp\n```\n\n#### Using pip\n\n```bash\npip install falcon-mcp\n```\n\n### Configure\n\nSet the required environment variables (or use a `.env` file — see the [Configuration Guide](https://developer.crowdstrike.com/falcon-mcp/getting-started/configuration/)):\n\n```bash\nexport FALCON_CLIENT_ID=\"your-client-id\"\nexport FALCON_CLIENT_SECRET=\"your-client-secret\"\nexport FALCON_BASE_URL=\"https://api.crowdstrike.com\"\n```\n\n### Run\n\n```bash\nfalcon-mcp\n```\n\nSee the [Getting Started guide](https://developer.crowdstrike.com/falcon-mcp/getting-started/installation/) for full installation and configuration details.\n\n## Editor Integration\n\n### Using `uvx` (recommended)\n\n```json\n{\n  \"mcpServers\": {\n    \"falcon-mcp\": {\n      \"command\": \"uvx\",\n      \"args\": [\n        \"--env-file\",\n        \"/path/to/.env\",\n        \"falcon-mcp\"\n      ]\n    }\n  }\n}\n```\n\n### With Module Selection\n\n```json\n{\n  \"mcpServers\": {\n    \"falcon-mcp\": {\n      \"command\": \"uvx\",\n      \"args\": [\n        \"--env-file\",\n        \"/path/to/.env\",\n        \"falcon-mcp\",\n        \"--modules\",\n        \"detections,hosts,intel\"\n      ]\n    }\n  }\n}\n```\n\n### Docker\n\n```json\n{\n  \"mcpServers\": {\n    \"falcon-mcp-docker\": {\n      \"command\": \"docker\",\n      \"args\": [\n        \"run\",\n        \"-i\",\n        \"--rm\",\n        \"--env-file\",\n        \"/full/path/to/.env\",\n        \"quay.io/crowdstrike/falcon-mcp:latest\"\n      ]\n    }\n  }\n}\n```\n\nSee the [Usage guide](https://developer.crowdstrike.com/falcon-mcp/usage/cli/) for all command line options, module configuration, and library usage.\n\n## Container Usage\n\n```bash\n# Pull the latest image\ndocker pull quay.io/crowdstrike/falcon-mcp:latest\n\n# Run with .env file (stdio transport)\ndocker run -i --rm --env-file /path/to/.env quay.io/crowdstrike/falcon-mcp:latest\n\n# Run with streamable-http transport (add --api-key when the port is reachable beyond localhost)\ndocker run --rm -p 8000:8000 --env-file /path/to/.env \\\n  quay.io/crowdstrike/falcon-mcp:latest \\\n  --transport streamable-http --host 0.0.0.0 --api-key your-secret-key\n```\n\n> [!CAUTION]\n> HTTP transports have no authentication by default. Binding to a non-loopback address (`--host 0.0.0.0`)\n> exposes an unauthenticated server that anyone who can reach the port can drive with your CrowdStrike\n> credentials. Keep the default loopback bind for local use and set `--api-key` whenever you bind wider.\n> Managed runtimes such as AWS Bedrock AgentCore and Google Cloud Run sit behind their own network\n> security layer, so this does not apply to them. See the\n> [Configuration guide](https://developer.crowdstrike.com/falcon-mcp/getting-started/configuration/#http-transport-security).\n\nSee the [Docker Deployment guide](https://developer.crowdstrike.com/falcon-mcp/deployment/docker/) for building locally, custom ports, and advanced configurations.\n\n## Dynamic Mode\n\nRunning many modules at once inflates the context window every AI client must hold. Dynamic mode\nreplaces the full tool surface with three tools — `falcon_list_enabled_tools` to see every tool the\nserver has available, `falcon_search_tools` to find candidate tools by keyword and then fetch the parameter\nschema for the one you pick, and `falcon_execute_tool` to run it — so agents only load the schemas\nthey actually need.\n\n```bash\nfalcon-mcp --dynamic\n# or: FALCON_MCP_DYNAMIC=true\n```\n\nSee the [Dynamic Mode guide](https://developer.crowdstrike.com/falcon-mcp/usage/dynamic-mode/) for\nthe full discover → execute workflow and trade-offs.\n\n## Restricting What a Server Can Do\n\n`--modules` is all-or-nothing per module: enabling one to get its search tools also exposes every\nmutating tool it carries. Three tool-level options narrow that surface.\n\n```bash\n# Investigation-only server: no tool that mutates tenant state is registered\nfalcon-mcp --read-only\n\n# Expose exactly two tools, nothing else\nfalcon-mcp --tools falcon_search_detections,falcon_search_hosts\n\n# Keep the module, drop one tool\nfalcon-mcp --modules hostgroups --exclude-tools falcon_delete_host_groups\n\n# All of detections, plus one tool from a module you did not enable\nfalcon-mcp --modules detections --tools falcon_search_applications\n```\n\n| Flag | Environment Variable | Effect |\n| --- | --- | --- |\n| `--read-only` | `FALCON_MCP_READ_ONLY` | Registers only read-only tools |\n| `--tools` | `FALCON_MCP_TOOLS` | Allow-list of tool names, added to the enabled modules |\n| `--exclude-tools` | `FALCON_MCP_EXCLUDE_TOOLS` | Deny-list of tool names |\n\nTool names are the `falcon_`-prefixed names your client displays. An unrecognized name aborts\nstartup rather than being ignored, so a typo in a deny-list cannot silently leave a tool exposed.\n\n### Composing the options\n\n`--tools` is **additive**, not a narrowing filter. It grants individual tools on top of whatever\n`--modules` already enabled, reaching across the module boundary:\n\n- `--tools X` on its own registers **only** X — no modules are loaded by default.\n- `--modules detections --tools X` registers every `detections` tool **plus** X, even when X\n  belongs to a module that is not enabled. That module contributes only X, not its whole surface,\n  and `falcon_list_enabled_modules` does not list it. `falcon_list_enabled_tools` does list X — it\n  reports the tools available on the server, so it is the reliable answer to \"is this capability\n  available here?\"\n\nTo *subtract*, use `--exclude-tools` or `--read-only`. All four knobs compose, and they resolve in\na fixed order:\n\n1. `--exclude-tools` removes a tool unconditionally, even if `--tools` names it.\n2. `--read-only` removes every mutating tool unconditionally, even if `--tools` names it.\n3. `--tools` adds the tools it names, bypassing the module gate.\n4. `--modules` decides which tools are candidates by default.\n\nBecause the first two rules always win, `--read-only` and `--exclude-tools` are safe to set as a\ndeployment-wide floor: an additive `--tools` list cannot widen past them. Combining them is how you\nexpress \"search everything, change nothing, and don't even offer that one tool\":\n\n```bash\nfalcon-mcp --read-only --exclude-tools falcon_execute_rtr_read_only_command\n```\n\nFiltering applies to dynamic mode too — a withheld tool is absent from `falcon_search_tools`\nresults and rejected by `falcon_execute_tool`. Because dynamic mode dispatches by name rather than\nregistering tools individually, that rejection spells out that the tool exists but the server's\nconfiguration withholds it, and names the one rule responsible, so an agent reports a disabled tool\nas disabled instead of telling the user the capability does not exist.\n`falcon_list_enabled_tools` carries a `filters_active` field in either mode whenever a rule is in\neffect. The startup log reports which rules are active and how many tools `--read-only` and\n`--exclude-tools` withheld, so you can confirm what you deployed. Run with `--debug` to see the\nwithheld tools by name.\n\nThese options filter tools, not resources. A withheld tool's FQL guide resource stays available —\nguides are static field documentation carrying no tenant data.\n\n## Deployment Options\n\n- [Amazon Bedrock AgentCore](https://developer.crowdstrike.com/falcon-mcp/deployment/amazon-bedrock/)\n- [Google Cloud (Agent Platform / Gemini Enterprise)](./examples/adk/README.md)\n\n## Contributing\n\n```bash\n# Clone and install\ngit clone https://github.com/CrowdStrike/falcon-mcp.git\ncd falcon-mcp\nuv sync --all-extras\n\n# Run tests\nuv run pytest\n```\n\n> [!IMPORTANT]\n> This project uses [Conventional Commits](https://www.conventionalcommits.org/) for automated releases. Please follow the commit message format outlined in our [Contributing Guide](.github/CONTRIBUTING.md).\n\n### Developer Documentation\n\n- [Documentation Guide](docs/development/docs-site.md): Architecture and maintenance guide for the documentation\n- [Module Development Guide](docs/development/module-development.md): Instructions for implementing new modules\n- [Resource Development Guide](docs/development/resource-development.md): Instructions for implementing resources\n- [Integration Testing Guide](docs/development/integration-testing.md): Guide for running integration tests with real API calls\n\n## Registries\n\nfalcon-mcp is published to public MCP catalogs for discovery and one-click setup in compatible clients:\n\n- [MCP Registry](https://registry.modelcontextprotocol.io/?q=io.github.CrowdStrike%2Ffalcon-mcp&all=1)\n- [GitHub MCP Registry](https://github.com/mcp/CrowdStrike/falcon-mcp)\n- [Gemini CLI Extensions](https://geminicli.com/extensions/?name=CrowdStrikefalcon-mcp)\n\n## License\n\nThis project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.\n\n## Support\n\nThis is a community-driven, open source project. While it is not an official CrowdStrike product, it is actively maintained by CrowdStrike and supported in collaboration with the open source developer community.\n\nFor more information, please see our [SUPPORT](SUPPORT.md) file.\n",
  "bytes": 16228,
  "sha": "851ff1f264370825573a6c986c2636fa0f022b53561ec845b9e346d82f43eb38",
  "repo_slug": "crowdstrike/falcon-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_crowdstrike_falcon_mcp_42b27c0a/readme"
}