Skip to content

Module Overview

The Falcon MCP Server provides the following modules. Each module requires specific CrowdStrike API scopes.

ModuleAPI ScopesDescription
Cloud SecurityCloud Security API Assets:read, Falcon Container Image:readAccessing and analyzing CrowdStrike Falcon cloud resources like Kubernetes & Containers Inventory, Images Vulnerabilities, Cloud Assets
Custom IOACustom IOA Rules:read, Custom IOA Rules:writeSearching, creating, updating, and deleting Custom IOA (Indicators of Attack) behavioral rules and rule groups using Falcon Custom IOA Service Collection endpoints
DetectionsAlerts:readAccessing and analyzing CrowdStrike Falcon detections
DiscoverAssets:readAccessing and managing CrowdStrike Falcon Discover applications and unmanaged assets
Firewall ManagementFirewall Management:read, Firewall Management:writeSearching and managing firewall rules and rule groups
HostsHosts:readAccessing and managing CrowdStrike Falcon hosts/devices
Identity ProtectionIdentity Protection Assessment:read, Identity Protection Detections:read, Identity Protection Entities:read, Identity Protection Timeline:read, Identity Protection GraphQL:writeAccessing and managing CrowdStrike Falcon Identity Protection capabilities
IncidentsIncidents:readAccessing and analyzing CrowdStrike Falcon incidents
IntelActors (Falcon Intelligence):read, Indicators (Falcon Intelligence):read, Reports (Falcon Intelligence):readAccessing and analyzing CrowdStrike Falcon intelligence data
IOCIOC Management:read, IOC Management:writeSearching, creating, and deleting custom IOCs using Falcon IOC Service Collection endpoints
NGSIEMNGSIEM:read, NGSIEM:writeRunning search queries against CrowdStrike’s Next-Gen SIEM via the asynchronous job-based search API
Real Time ResponseReal time response:read, Real time response:writeInitiating and inspecting RTR sessions and for executing read-only RTR commands during host investigations
Scheduled ReportsScheduled Reports:readAccessing and managing CrowdStrike Falcon scheduled reports and scheduled searches
Sensor UsageSensor Usage:readAccessing CrowdStrike Falcon sensor usage data
ServerlessFalcon Container Image:readAccessing and managing CrowdStrike Falcon Serverless Vulnerabilities
SpotlightVulnerabilities:readAccessing and managing CrowdStrike Falcon Spotlight vulnerabilities