CrowdStrike Falcon MCP Server
Connects AI agents with CrowdStrike Falcon for security analysis and automation.
257 stars12k downloads/wk
Reviews
Write oneNobody has reviewed CrowdStrike Falcon MCP Server yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
CrowdStrike Falcon MCP Server tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- Code scan80 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 3 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
What the publisher says
From the CrowdStrike Falcon MCP Server repository's README, as published. We do not edit it. Read it on GitHub
<!-- mcp-name: io.github.CrowdStrike/falcon-mcp -->
falcon-mcp
falcon-mcp is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilities—including detections, threat intelligence, and host management—establishing the foundation for advanced security operations and automation.
[!IMPORTANT]
Pre-1.0 release: falcon-mcp is under active development ahead of 1.0. Tool names, parameters, and response shapes can still change between minor releases, so pin a version and check the changelog before upgrading. The project is actively maintained by CrowdStrike and supported through GitHub Issues; CrowdStrike customers can also raise questions through their usual Technical Support channels. See SUPPORT.md for details.
Documentation
Full docs are available at developer.crowdstrike.com/falcon-mcp.
Modules
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
claude mcp add falcon-mcp -- uvx falcon-mcp
CrowdStrike Falcon MCP Server: common questions
- Is CrowdStrike Falcon MCP Server safe?
- Yes, by our scan: it is graded A (85/100). Read the CrowdStrike Falcon MCP Server safety report
- How do I install CrowdStrike Falcon MCP Server?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does CrowdStrike Falcon MCP Server need an API key?
- Yes. The registry entry asks for
FALCON_CLIENT_ID,FALCON_CLIENT_SECRET,FALCON_MCP_API_KEY. - Is CrowdStrike Falcon MCP Server maintained?
- The last commit was 3 days ago (2026-09-17). The latest release is v0.19.0.
- What can I use instead of CrowdStrike Falcon MCP Server?
- Servers from other publishers that do the same job: Reversecore MCP server, npm Registry MCP Server and Notebooklm Secure MCP server. Compare all CrowdStrike Falcon MCP Server alternatives.
Alternatives to CrowdStrike Falcon MCP Server
Same job from other publishers: the closest match first, then the best rated.
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- Notebooklm SecureSecurity-hardened NotebookLM MCP with post-quantum encryptionnot reviewedGrowingA
- CodeInspectusLocal-first MCP security scanner and CLI for AI-generated applications.not reviewedGrowingC
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB