MCPLow riskUnclaimed
CrowdStrike Falcon MCP Server
Connects AI agents with CrowdStrike Falcon for security analysis and automation.
CrowdStrikecrowdstrike/falcon-mcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.CrowdStrike/falcon-mcp",
"description": "Connects AI agents with CrowdStrike Falcon for security analysis and automation.",
"title": "CrowdStrike Falcon MCP Server",
"repository": {
"url": "https://github.com/CrowdStrike/falcon-mcp",
"source": "github",
"id": "999737146"
},
"version": "0.19.0",
"packages": [
{
"registryType": "pypi",
"identifier": "falcon-mcp",
"version": "0.19.0",
"runtimeHint": "uvx",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "CrowdStrike API client ID",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "FALCON_CLIENT_ID"
},
{
"description": "CrowdStrike API client secret",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "FALCON_CLIENT_SECRET"
},
{
"description": "CrowdStrike API region URL",
"format": "string",
"default": "https://api.crowdstrike.com",
"placeholder": "https://api.crowdstrike.com",
"name": "FALCON_BASE_URL"
},
{
"description": "Child CID for Flight Control (MSSP) support",
"format": "string",
"name": "FALCON_MEMBER_CID"
},
{
"description": "Comma-separated list of modules to enable",
"format": "string",
"placeholder": "detections,incidents,hosts",
"name": "FALCON_MCP_MODULES"
},
{
"description": "Transport protocol to use",
"format": "string",
"default": "stdio",
"choices": [
"stdio",
"sse",
"streamable-http"
],
"name": "FALCON_MCP_TRANSPORT"
},
{
"description": "Enable debug logging",
"format": "boolean",
"default": "false",
"name": "FALCON_MCP_DEBUG"
},
{
"description": "Host to bind to for HTTP transports",
"format": "string",
"default": "127.0.0.1",
"name": "FALCON_MCP_HOST"
},
{
"description": "Port to listen on for HTTP transports",
"format": "number",
"default": "8000",
"name": "FALCON_MCP_PORT"
},
{
"description": "Additional information to include in the User-Agent comment section",
"format": "string",
"name": "FALCON_MCP_USER_AGENT_COMMENT"
},
{
"description": "Enable stateless HTTP mode for scalable deployments",
"format": "boolean",
"default": "false",
"name": "FALCON_MCP_STATELESS_HTTP"
},
{
"description": "API key for HTTP transport authentication (x-api-key header)",
"format": "string",
"isSecret": true,
"name": "FALCON_MCP_API_KEY"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
pythonInstalls—
pypi:falcon-mcp@0.19.0Runs install scripts—None
NetworkNoneNone
Needs credentials
FALCON_CLIENT_IDFALCON_CLIENT_SECRETFALCON_MCP_API_KEYFALCON_CLIENT_IDFALCON_CLIENT_SECRETFALCON_MCP_API_KEYOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #10.19.0latestOct 7, 2026
CrowdStrike Falcon MCP ServerOpen in Codeg