Tracecat

CrowdStrike Falcon MCP server

Triage detections, contain hosts, and query Falcon intel across CrowdStrike's EDR and XDR modules.

Endpoint
stdio
Official docs

About

Connect Tracecat to CrowdStrike Falcon to triage detections and contain hosts from agents working alongside SOC analysts and incident responders. You can pick up a Falcon detection, pivot to the affected host, and run Real Time Response commands the same way an analyst would in the console. From there, agents can look up the related threat actor in CrowdStrike intel, query NGSIEM with CQL, and pull Spotlight or Identity Protection signals so a single connection covers endpoint, cloud, and identity investigations.

Setup

  1. 1

    Create an API key

    The Falcon MCP server authenticates with a Falcon API client ID and secret. Credentials are issued from the Falcon console under API Clients and Keys and scoped to the specific Falcon modules the agent needs.

  2. 2

    Select the CrowdStrike Falcon tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the CrowdStrike Falcon tile, and paste your API key.

  3. 3

    Enable CrowdStrike Falcon in your agent

    In your ai.agent action or Agents tools tab, select CrowdStrike Falcon from the MCP integrations dropdown.

Tools

detectionsList, search, and update Falcon detections to drive alert triage.
hostsQuery host inventory, look up host details, and run containment actions.
real_time_responseExecute Real Time Response commands on Falcon-managed endpoints.
intelLook up threat actors, indicators, and CrowdStrike intel reports.
spotlightRetrieve Spotlight vulnerability findings and remediation status for assets.
iocCreate, update, and remove custom indicators of compromise.
ngsiemRun CQL queries against CrowdStrike NGSIEM data.
identity_protectionInvestigate identity entities and risk signals from Falcon Identity Protection.
cloud_securityPull CSPM findings, image vulnerabilities, and Kubernetes posture data.
custom_ioaManage behavioral Indicators of Attack rules across Falcon prevention policies.

Deploy the CrowdStrike Falcon MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.

Self-host free