Listing Thumbnail

    MCP Server for CrowdStrike Falcon

     Info
    Sold by: CrowdStrike 
    Deployed on AWS
    falcon-mcp enables seamless communication between AI agents and the CrowdStrike Falcon platform. Deployable directly onto Amazon Bedrock AgentCore, it provides programmatic access to Falcon data for agentic workflows and accelerating AI-native security automation.
    4.5

    Overview

    This server provides a secure, scalable bridge between AI agents and the CrowdStrike Falcon platform, bringing security telemetry and threat intelligence directly into your AWS environment. Purpose-built for deployment on Amazon Bedrock AgentCore, the falcon-mcp server enables agentic applications to programmatically access detections, incidents, behaviors, and threat intelligence from the Falcon platform. This empowers AI agents to reason over rich security context, automate response workflows, and drive proactive defense across your cloud and enterprise environments. By exposing modular Falcon capabilities through a standardized interface, the falcon-mcp server supports a wide range of use cases, from autonomous incident triage and threat enrichment to building fully agentic, context-aware security operations workflows. The falcon-mcp server gives you the data access layer to build the foundation for an AI-native SOC, backed by the power of the CrowdStrike Falcon platform. To learn more about this resource and explore its capabilities, visit the official project page at: https://github.com/crowdstrike/falcon-mcp 

    Highlights

    • The falcon-mcp server establishes a consistent and secure protocol for agents to communicate with the CrowdStrike Falcon platform, enabling - standardized integration across agentic systems.
    • It includes native support for deployment onto Amazon Bedrock AgentCore, making it easy to integrate into your AWS environment and power agentic workflows.
    • It is designed to support current and future Falcon platform capabilities, ensuring agentic workflows remain adaptive and comprehensive.

    Details

    Delivery method

    Type

    Supported services

    Delivery option
    Amazon Bedrock AgentCore

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    MCP Server for CrowdStrike Falcon

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    All orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Amazon Bedrock AgentCore

    Supported services: Learn more 
    • Amazon Bedrock AgentCore
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    0.16.1  (2026-08-10)

    Bug Fixes

    • modules/detections: chunk update_detections requests over 1000 ids (#513 ) (a9757b3 )
    • modules/exclusions: reject IOA regex zero-width assertions pre-flight (#512 ) (7f774e2 )
    • modules: return FQL guide on filter errors for hosts, spotlight, and intel searches (#507 ) (d59d4b1 ), closes #501 

    Refactoring

    Additional details

    Usage instructions

    Prerequisites

    CrowdStrike API Credentials

    Create API credentials in your CrowdStrike console:

    1. Log into your CrowdStrike console
    2. Navigate to Support > API Clients and Keys
    3. Click Add new API client
    4. Configure your API client:
      • Client Name: Choose a descriptive name (e.g., "Falcon MCP Server")
      • Description: Optional description for your records
      • API Scopes: Select scopes based on which modules you plan to use (see scope requirements )
    5. Note down these values (you cannot retrieve them later):
      • FALCON_CLIENT_ID - Your API client ID
      • FALCON_CLIENT_SECRET - Your API client secret
      • FALCON_BASE_URL - Your API base URL (region-specific)

    AWS VPC Requirements

    The MCP Server requires internet connectivity to communicate with CrowdStrike's APIs.

    • Internet Gateway or NAT Gateway - Enables outbound internet connectivity
    • Outbound HTTPS Access - Allow communication to api.crowdstrike.com on port 443
    • Security Groups - Configure appropriate rules for your network requirements

    Getting Started

    To deploy the Falcon MCP Server to Amazon Bedrock AgentCore:

    1. Visit the Falcon MCP Server on AWS Marketplace 
    2. Follow the subscription and deployment instructions
    3. Configure your CrowdStrike API credentials and environment variables as described below

    Usage Instructions

    Environment Variables

    Set the environment variables in the deployment form below; recommended AgentCore values are pre-filled. FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, and FALCON_BASE_URL are required, and FALCON_MCP_STATELESS_HTTP must remain true for AgentCore.

    Key Capabilities

    • Threat Investigation - Search detections by severity, time range, hostname, or MITRE ATT&CK technique.
    • Fleet Management - Find hosts by platform, sensor version, network segment, or containment status.
    • Vulnerability Hunting - Access Spotlight CVE data with ExPRT ratings and remediation priorities.
    • Threat Intelligence - Look up threat actors, indicators, and intelligence reports.
    • Cloud Security - Search CSPM assets, container images, and Kubernetes workloads.
    • Identity Protection - Investigate entities, analyze timelines, and map relationships.
    • Query Capabilities - Run searches against CrowdStrike Next-Gen SIEM using CQL.
    • IOC Management - Search, create, and remove custom indicators of compromise.
    • Firewall Auditing - Search and manage Falcon firewall rule groups.

    Additional modules support Real Time Response, Scheduled Reports, Shield, and more. For the full module list and required API scopes, see the Falcon MCP modules overview .

    Example tool invocation (search for recent detections):

    { "jsonrpc": "2.0", "id": "1", "method": "tools/call", "params": { "name": "falcon_search_detections", "arguments": { "filter": "status:'new'" } } }

    Additional Resources

    For full details, visit the Falcon MCP documentation .

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.5
    182 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    74%
    25%
    1%
    0%
    0%
    0 AWS reviews
    |
    182 external reviews
    External reviews are from G2 .
    Suhail D.

    Strong Cloud Security Visibility and Risk Management

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    It gives me a clear view of cloud security risks and makes it easier to identify and respond to threats from one place. I particularly like the visibility across cloud environments and the practical security insights without making the workflow unnecessarily complicated.
    What do you dislike about the product?
    The platform can feel complex at first, especially for users who are new to cloud security. Some features also require time to configure and understand properly, and the amount of information presented can sometimes make it harder to quickly identify the most important issues.
    What problems is the product solving and how is that benefiting you?
    It helps identify cloud security risks, misconfigurations, and potential threats before they become bigger problems. The main benefit is better visibility across the cloud environment, which makes it easier to prioritize risks and respond to security issues more efficiently.
    Oil & Energy

    Seamless, Lightweight Protection with Real-Time Visibility and Fast Threat Detection

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    The lightweight Falcon agent operates seamlessly without impacting endpoint performance or system resources. Its cloud-native architecture provides real-time visibility, fast threat detection, and advanced telemetry across our infrastructure. The threat hunting capabilities and centralized dashboard simplify incident response immensely.
    What do you dislike about the product?
    The granular policy configuration options and rich feature set require a brief learning curve during initial onboarding. Additionally, advanced modules and premium threat intelligence feeds can add up in cost, though the protection and peace of mind completely justify the investment."
    What problems is the product solving and how is that benefiting you?
    It eliminates visibility gaps across our endpoints and protects our environment against zero-day malware, ransomware, and fileless attacks. Having continuous monitoring and automated threat containment reduces our team's mean time to respond (MTTR) and prevents potential security breaches.
    Angélica M.

    Risk detection and multi-cloud protection on a single platform

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    Risk detection and protection of multiple cloud environments in a single platform.
    What do you dislike about the product?
    It may be more expensive than some competing options, especially for large organizations or those with many cloud resources, and although the interface is user-friendly, taking full advantage of all the advanced features requires training and experience.
    What problems is the product solving and how is that benefiting you?
    Real-time vulnerability detection allows for early action against exposure to risks.
    Blessing M.

    Top Notch Extended Endpoint Detection Plan with Real-Time Monitoring

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    It provides best security in all scale of businesses it has Extended Detect response planning, accurate real time and audit monitoring, It needs crucial management soon as it is implemented otherwise systems can be locked out and restoring them can be complex
    What do you dislike about the product?
    It sends false alerts to users, which can be alarming. It also requires hands-on administrative management. I’ve experienced disk and operating system locks that can force a machine reload and may lead to possible data loss.
    What problems is the product solving and how is that benefiting you?
    When configured correctly, unrestricted activities on the system are blocked instantly. The warnings and real-time monitoring for the endpoint detection and response plan can be helpful for immediately mitigating any issues as they arise.
    Jagan M.

    Unified Multi-Cloud Visibility with Actionable Attack Storylines

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    What impresses me most is how seamlessly it brings AWS, Azure, and GCP into a single, cohesive narrative without forcing us to choose between configuration posture and live threat protection. Instead of juggling fragmented tools across different providers, Falcon marries agentless posture management with lightweight runtime protection right inside the broader Falcon ecosystem. Being able to trace an exposed storage bucket or an overly permissive IAM role directly down to an active, running process in a Kubernetes container—and instantly correlating that with endpoint telemetry—gives our security team an unrivaled, full-spectrum view of our multi-cloud footprint.The most significant operational benefit is the drastic reduction in alert noise alongside the freedom it gives our engineering teams to move fast. Rather than drowning analysts in thousands of low-severity notifications, Falcon synthesizes scattered risk signals into prioritized, highly actionable attack storylines that drastically slash our time to detect and respond. It plugs smoothly into our CI/CD pipelines, allowing our DevOps engineers to spin up microservices and push code daily without hitting security speed bumps, as new assets are automatically discovered and guarded the moment they go live. Ultimately, it turned cloud security from a constant source of operational anxiety into a quiet, continuous advantage.
    What do you dislike about the product?
    While the platform's core visibility is top-tier, the query language and custom reporting present a noticeable learning curve. When you move beyond the out-of-the-box dashboards to build custom queries or tailored threat-hunting reports across cloud events, you run into complex syntax that takes weeks of hands-on practice to master. Additionally, the initial setup can feel overwhelming due to the sheer volume of default notifications. Until you spend dedicated time tuning policies, establishing operational baselines, and filtering out routine developer activities, Tier 1 analysts can quickly get bogged down by a flood of low-severity findings.
    What problems is the product solving and how is that benefiting you?
    Our primary challenge prior to Falcon was managing visibility across ephemeral cloud infrastructure. With developers constantly spinning up Kubernetes pods, serverless functions, and microservices across AWS and Azure, our security team was constantly playing catch-up, leading to severe coverage blind spots and configuration drift. Falcon Cloud Security solved this by providing continuous, automated asset discovery and real-time posture scanning across our entire multi-cloud estate. The tangible benefit for us has been a dramatic reduction in our Mean Time to Detect (MTTD) and Respond (MTTR); we no longer have to guess what's running in our cloud environments, and critical misconfigurations or active workload threats are caught and neutralized before they can be exploited.
    View all reviews