Vibe Coding Discover

MCP

falcon-mcp

View on GitHub

Connect AI agents to CrowdStrike Falcon for automated security analysis and threat hunting

★ 25888 forksPythonMITCrowdStrike

CrowdStrike Falcon MCP server exposing Falcon security APIs (detections, hosts, intel, SIEM, cloud, identity, RTR) as tools for AI agents. Supports stdio/HTTP transports, module selection, read-only and dynamic modes; Python, MIT licensed, pre-1.0.

Use Cases

Automate CrowdStrike Falcon detection search and analysis from an AI agentThreat hunting via natural-language queries over Falcon telemetryHost and asset inventory lookup and management for triageIOC creation, search, and removal during incident responseVulnerability and Spotlight exposure analysisNG-SIEM CQL query execution for security investigationsIdentity protection entity investigationCloud security posture, container, and K8s vulnerability reviewCase management with evidence attachment for incident workflowsFirewall, prevention, and exclusion policy managementQuarantine record review and file releaseRead-only RTR triage workflow executionThreat intelligence and dark web recon monitoringTriggering Fusion SOAR workflows on demandMonitoring AI agent activity and tool usage via GuardianReducing MCP context usage with dynamic tool discovery mode

Built With

Language
Python
Frameworks
Model Context Protocol (MCP) · MCP Python SDK · FastMCP · FalconPy · AnyIO · Starlette · SSE-Starlette · Pydantic · uv · Docker · pytest · Gemini CLI Extension

Tags

mcp · mcp-server · crowdstrike · falcon · security · threat-hunting · soc · cybersecurity · detections · siem · streamable-http · sse · docker · read-only-mode · dynamic-tools · devsecops