A modular, multi-transport Model Context Protocol server that connects AI assistants to the CrowdStrike Falcon platform. Query NG-SIEM logs, triage alerts, inspect endpoints, manage detection rules, and audit cloud security posture — all through natural language.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.FALCON_CLIENT_ID— 1 Environment variables , FALCON_CLIENT_SECRET, FALCON_BASE_URLFALCON_CLIENT_SECRET— 1 Environment variables FALCON_CLIENT_ID, , FALCON_BASE_URLFALCON_BASE_URL— 1 Environment variables FALCON_CLIENT_ID, FALCON_CLIENT_SECRET,CASE_DEFAULT_ASSIGNEEFALCON_MCP_NGSIEM_TIMEOUT— 300 Max seconds to poll for an ngsiem_query search job before timing outFALCON_MCP_NGSIEM_POLL_INTERVAL— 2 Seconds between ngsiem_query search-status pollsCROWDSTRIKE_MCP_RTR_EXTRA_ALLOWED— env var (comma-separated) — deny list alwaysFALCON_MCP_TRANSPORT— transport stdio Transport: stdio, sse, streamable-httpFALCON_MCP_MODULES— modules all Comma-separated module listFALCON_MCP_DEBUG— debug false Enable debug loggingFALCON_MCP_HOST— host 127.0.0.1 HTTP bind addressFALCON_MCP_PORT— port 8000 HTTP portFALCON_MCP_API_KEY— api-key — API key for HTTP authFALCON_MCP_ALLOW_WRITES— true crowdstrike-mcpMCP_LARGE_RESPONSE_THRESHOLD[](https://m8ven.ai/mcp/willwebster5-crowdstrike-mcp-h4fbwy)