Enables querying and analyzing Falco security events from Falcosidekick UI through MCP tools. Supports filtering events by time windows and retrieving full event details for security monitoring and incident investigation.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.FALCO_BASE_URL— e =http://falcosidekick-ui.default.svc.cluster.local:2802 \FALCO_EVENTS_PATH— /api/v1/events/search Override the events endpoint path if neededFALCO_USERNAME— / FALCO_PASSWORD admin / admin Basic Auth credentialsFALCO_PASSWORD— FALCO_USERNAME / admin / admin Basic Auth credentialsFALCO_HTTP_TIMEOUT— 15 HTTP timeout in secondsMCP_HOSTPORT— 8080 MCP HTTP listener portMCP_HTTP_PATH— /mcp Streamable HTTP mount pathMCP_TRANSPORT— streamable-http Set to stdio if your MCP client expects stdio transport[](https://m8ven.ai/mcp/maratsal-falco-mcp-m9lvo6)