Tracecat

CrowdStrike Falcon MCP server

Triage detections, contain hosts, and query Falcon intel across CrowdStrike's EDR and XDR modules.

Endpoint
stdio
Official docs

About

Connect Tracecat to CrowdStrike Falcon to triage detections and contain hosts from agents working alongside SOC analysts and incident responders. You can pick up a Falcon detection, pivot to the affected host, and run Real Time Response commands the same way an analyst would in the console. From there, agents can look up the related threat actor in CrowdStrike intel, query NGSIEM with CQL, and pull Spotlight or Identity Protection signals so a single connection covers endpoint, cloud, and identity investigations.

Setup

  1. 1

    Create an API key

    The Falcon MCP server authenticates with a Falcon API client ID and secret. Credentials are issued from the Falcon console under API Clients and Keys and scoped to the specific Falcon modules the agent needs.

  2. 2

    Select the CrowdStrike Falcon tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the CrowdStrike Falcon tile, and paste your API key.

  3. 3

    Enable CrowdStrike Falcon in your agent

    In your ai.agent action or Agents tools tab, select CrowdStrike Falcon from the MCP integrations dropdown.

Tools

falcon_search_detections

Search Falcon detections for alert triage.

falcon_get_detection_details

Retrieve details for specific Falcon detections.

falcon_search_hosts

Search Falcon host inventory.

falcon_get_host_details

Retrieve host details for selected device IDs.

falcon_init_session

Start a Real Time Response session.

falcon_execute_read_only_command

Run a read-only Real Time Response command.

falcon_check_command_status

Check Real Time Response command status.

falcon_get_session_details

Retrieve Real Time Response session details.

falcon_list_session_files

List files available in a Real Time Response session.

falcon_pulse_session

Keep a Real Time Response session active.

falcon_search_sessions

Search Real Time Response sessions.

falcon_delete_session

Delete a Real Time Response session.

falcon_query_actor_entities

Retrieve CrowdStrike intel actor entities.

falcon_query_indicator_entities

Retrieve CrowdStrike intel indicator entities.

falcon_query_report_entities

Retrieve CrowdStrike intel report entities.

falcon_get_mitre_report

Retrieve a MITRE report from CrowdStrike intel.

falcon_search_iocs

Search custom indicators of compromise.

falcon_add_ioc

Add a custom indicator of compromise.

falcon_remove_iocs

Remove custom indicators of compromise.

falcon_search_ngsiem

Run searches against CrowdStrike NGSIEM.

falcon_search_vulnerabilities

Search Spotlight vulnerability findings.

falcon_investigate_entity

Investigate an Identity Protection entity.

falcon_search_cspm_assets

Search Cloud Security Posture Management assets.

falcon_search_cspm_suppression_rules

Search CSPM suppression rules.

falcon_create_cspm_suppression_rule

Create a CSPM suppression rule.

falcon_delete_cspm_suppression_rules

Delete CSPM suppression rules.

falcon_search_images_vulnerabilities

Search container image vulnerabilities.

falcon_search_iom_findings

Search Indicators of Misconfiguration findings.

falcon_search_kubernetes_containers

Search Kubernetes containers.

falcon_count_kubernetes_containers

Count Kubernetes containers.

falcon_search_serverless_vulnerabilities

Search serverless vulnerability findings.

falcon_create_ioa_rule

Create a custom IOA rule.

falcon_update_ioa_rule

Update a custom IOA rule.

falcon_delete_ioa_rules

Delete custom IOA rules.

falcon_create_ioa_rule_group

Create a custom IOA rule group.

falcon_update_ioa_rule_group

Update a custom IOA rule group.

falcon_delete_ioa_rule_groups

Delete custom IOA rule groups.

falcon_search_ioa_rule_groups

Search custom IOA rule groups.

falcon_get_ioa_platforms

List supported custom IOA platforms.

falcon_get_ioa_rule_types

List supported custom IOA rule types.

falcon_search_applications

Search discovered applications.

falcon_search_unmanaged_assets

Search unmanaged assets.

falcon_create_firewall_rule_group

Create a firewall rule group.

falcon_delete_firewall_rule_groups

Delete firewall rule groups.

falcon_search_firewall_policy_rules

Search firewall policy rules.

falcon_search_firewall_rule_groups

Search firewall rule groups.

falcon_search_firewall_rules

Search firewall rules.

falcon_create_case

Create a Falcon case.

falcon_update_case

Update a Falcon case.

falcon_search_cases

Search Falcon cases.

falcon_get_cases

Retrieve Falcon cases.

falcon_list_case_templates

List case templates.

falcon_manage_case_tags

Manage case tags.

falcon_add_case_alert_evidence

Add alert evidence to a case.

falcon_add_case_event_evidence

Add event evidence to a case.

falcon_search_scheduled_reports

Search scheduled reports.

falcon_search_report_executions

Search report executions.

falcon_launch_scheduled_report

Launch a scheduled report.

falcon_download_report_execution

Download a report execution.

falcon_search_sensor_usage

Search sensor usage records.

falcon_search_shield_alerts

Search Falcon Shield alerts.

falcon_search_shield_apps

Search Falcon Shield apps.

falcon_search_shield_checks

Search Falcon Shield checks.

falcon_search_shield_data_shares

Search Falcon Shield data shares.

falcon_search_shield_devices

Search Falcon Shield devices.

falcon_search_shield_users

Search Falcon Shield users.

falcon_get_shield_activity_monitor

Retrieve Falcon Shield activity monitor data.

falcon_get_shield_app_users

Retrieve Falcon Shield app users.

falcon_get_shield_check_affected_entities

Retrieve affected entities for a Shield check.

falcon_get_shield_check_compliance

Retrieve compliance data for a Shield check.

falcon_get_shield_integrations

Retrieve Falcon Shield integrations.

falcon_get_shield_posture_metrics

Retrieve Falcon Shield posture metrics.

falcon_get_shield_supported_saas

Retrieve supported SaaS apps for Falcon Shield.

falcon_get_shield_system_logs

Retrieve Falcon Shield system logs.

falcon_get_shield_system_users

Retrieve Falcon Shield system users.

falcon_dismiss_shield_check

Dismiss a Falcon Shield check.

Deploy the CrowdStrike Falcon MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.

Self-host free