Listing Thumbnail

    MCP Server for CrowdStrike Falcon

     Info
    Sold by: CrowdStrike 
    Deployed on AWS
    falcon-mcp enables seamless communication between AI agents and the CrowdStrike Falcon platform. Deployable directly onto Amazon Bedrock AgentCore, it provides programmatic access to Falcon data for agentic workflows and accelerating AI-native security automation.
    4.5

    Overview

    This server provides a secure, scalable bridge between AI agents and the CrowdStrike Falcon platform, bringing security telemetry and threat intelligence directly into your AWS environment. Purpose-built for deployment on Amazon Bedrock AgentCore, the falcon-mcp server enables agentic applications to programmatically access detections, incidents, behaviors, and threat intelligence from the Falcon platform. This empowers AI agents to reason over rich security context, automate response workflows, and drive proactive defense across your cloud and enterprise environments. By exposing modular Falcon capabilities through a standardized interface, the falcon-mcp server supports a wide range of use cases, from autonomous incident triage and threat enrichment to building fully agentic, context-aware security operations workflows. The falcon-mcp server gives you the data access layer to build the foundation for an AI-native SOC, backed by the power of the CrowdStrike Falcon platform. To learn more about this resource and explore its capabilities, visit the official project page at: https://github.com/crowdstrike/falcon-mcp 

    Highlights

    • The falcon-mcp server establishes a consistent and secure protocol for agents to communicate with the CrowdStrike Falcon platform, enabling - standardized integration across agentic systems.
    • It includes native support for deployment onto Amazon Bedrock AgentCore, making it easy to integrate into your AWS environment and power agentic workflows.
    • It is designed to support current and future Falcon platform capabilities, ensuring agentic workflows remain adaptive and comprehensive.

    Details

    Delivery method

    Type

    Supported services

    Delivery option
    Amazon Bedrock AgentCore

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    MCP Server for CrowdStrike Falcon

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    All orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Amazon Bedrock AgentCore

    Supported services: Learn more 
    • Amazon Bedrock AgentCore
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    0.17.0  (2026-08-22)

    Features

    • modules/agentworks: add AgentWorks module for calling and observing Charlotte AI agents (#538 ) (7919f50 )
    • modules/cases: add description_format to create/update case (#531 ) (fa52750 )
    • modules/discover: add falcon_search_managed_assets (#537 ) (5148e3c )
    • modules/fusion: add Fusion SOAR module for running and observing workflows (#543 ) (1b76e26 )
    • modules/recon: add aggregation and rule-preview tools (#527 ) (ecf8813 )
    • modules/zero-trust-assessment: add Zero Trust Assessment module (#542 ) (a3267e6 )

    Bug Fixes

    • modules/firewall: drop ignored q param and fix name-glob filter docs (#528 ) (a9da031 ), closes #525 
    • modules/ngsiem: reject repository values that break path construction (#544 ) (e8b649f )
    • modules/ngsiem: return job metadata so a zero-row result is provably one (#539 ) (1ff6323 )
    • modules/policies: reject settings for firewall policies (#529 ) (c92c69f ), closes #526 
    • modules/policies: send rule_group_id for rule-group actions (#540 ) (42aafb1 )

    Additional details

    Usage instructions

    Prerequisites

    CrowdStrike API Credentials

    Create API credentials in your CrowdStrike console:

    1. Log into your CrowdStrike console
    2. Navigate to Support > API Clients and Keys
    3. Click Add new API client
    4. Configure your API client:
      • Client Name: Choose a descriptive name (e.g., "Falcon MCP Server")
      • Description: Optional description for your records
      • API Scopes: Select scopes based on which modules you plan to use (see scope requirements )
    5. Note down these values (you cannot retrieve them later):
      • FALCON_CLIENT_ID - Your API client ID
      • FALCON_CLIENT_SECRET - Your API client secret
      • FALCON_BASE_URL - Your API base URL (region-specific)

    AWS VPC Requirements

    The MCP Server requires internet connectivity to communicate with CrowdStrike's APIs.

    • Internet Gateway or NAT Gateway - Enables outbound internet connectivity
    • Outbound HTTPS Access - Allow communication to api.crowdstrike.com on port 443
    • Security Groups - Configure appropriate rules for your network requirements

    Getting Started

    To deploy the Falcon MCP Server to Amazon Bedrock AgentCore:

    1. Visit the Falcon MCP Server on AWS Marketplace 
    2. Follow the subscription and deployment instructions
    3. Configure your CrowdStrike API credentials and environment variables as described below

    Usage Instructions

    Environment Variables

    Set the environment variables in the deployment form below; recommended AgentCore values are pre-filled. FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, and FALCON_BASE_URL are required, and FALCON_MCP_STATELESS_HTTP must remain true for AgentCore.

    Key Capabilities

    • Threat Investigation - Search detections by severity, time range, hostname, or MITRE ATT&CK technique.
    • Fleet Management - Find hosts by platform, sensor version, network segment, or containment status.
    • Vulnerability Hunting - Access Spotlight CVE data with ExPRT ratings and remediation priorities.
    • Threat Intelligence - Look up threat actors, indicators, and intelligence reports.
    • Cloud Security - Search CSPM assets, container images, and Kubernetes workloads.
    • Identity Protection - Investigate entities, analyze timelines, and map relationships.
    • Query Capabilities - Run searches against CrowdStrike Next-Gen SIEM using CQL.
    • IOC Management - Search, create, and remove custom indicators of compromise.
    • Firewall Auditing - Search and manage Falcon firewall rule groups.

    Additional modules support Real Time Response, Scheduled Reports, Shield, and more. For the full module list and required API scopes, see the Falcon MCP modules overview .

    Example tool invocation (search for recent detections):

    { "jsonrpc": "2.0", "id": "1", "method": "tools/call", "params": { "name": "falcon_search_detections", "arguments": { "filter": "status:'new'" } } }

    Additional Resources

    For full details, visit the Falcon MCP documentation .

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.5
    192 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    76%
    23%
    1%
    0%
    0%
    0 AWS reviews
    |
    192 external reviews
    External reviews are from G2 .
    Mahesh S.

    Strong Network Security with Fast Bug and Port Error Detection

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    security about network and fast detection about bugs and port error issues.
    What do you dislike about the product?
    unnecessary port Block sometimes then need to open that again
    What problems is the product solving and how is that benefiting you?
    its resolved issue related to network Block when remote connection while using software and licensing error, it helps good...
    Islam M.

    Seamless Multi-Cloud Security with Powerful Threat Intelligence

    Reviewed on Aug 24, 2026
    Review provided by G2
    What do you like best about the product?
    I love the seamless integration and the intuitive dashboard of CrowdStrike Falcon Cloud Security. Its powerful threat intelligence provides real-time visibility across multi-cloud environments without slowing down our infrastructure. The product streamlines our security workflows and reduces reaction time to critical alerts. It saves significant team effort by eliminating the need to manage multiple disconnected security tools across our clouds. The initial setup was very straightforward and easy to deploy, thanks to the cloud-native agent and automated integration templates that made the initial setup fast with minimal hassle.
    What do you dislike about the product?
    I find the licensing cost to be relatively high, and the documentation for advanced custom configurations could be more streamlined and easier to navigate. Adding step-by-step configuration templates, more real-world use cases, and short video walkthroughs would make the documentation much easier to search and implement.
    What problems is the product solving and how is that benefiting you?
    I use CrowdStrike Falcon Cloud Security for real-time protection of our multicloud environments, preventing cloud misconfiguration, and streamlining compliance monitoring. It reduces alert fatigue, enhances threat detection, integrates seamlessly, and saves team effort by consolidating security tools.
    Consumer Electronics

    Meets data security purpose and protecting against cyber threats

    Reviewed on Aug 23, 2026
    Review provided by G2
    What do you like best about the product?
    Data security is the main purpose, and the software fully meets that purpose.
    What do you dislike about the product?
    So far, I haven’t found any major issues. If anything comes up, I can report it.
    What problems is the product solving and how is that benefiting you?
    The main problem it solves is protecting against cyber threats.
    Information Services

    Unified Falcon Agent and Strong Visibility, but Pricing and Licensing Feel Complex

    Reviewed on Aug 21, 2026
    Review provided by G2
    What do you like best about the product?
    The unified, single-agent architecture is the biggest advantage for me: the same Falcon sensor extends from endpoints to cloud workloads and containers, which removes the overhead of deploying and managing separate agents. Threat Graph then correlates endpoint, identity, and cloud telemetry into unified detections, giving a clearer view across the entire attack surface.
    What do you dislike about the product?
    Pricing is my biggest issue. It’s noticeably higher than many competitors, and the costs for individual modules add up fast, which can make it hard for smaller organizations to justify or afford. On top of that, the licensing feels overly complex, and the lack of clear, transparent pricing for enterprise tiers only adds to the frustration.
    What problems is the product solving and how is that benefiting you?
    Falcon Cloud Security addresses the critical issue of fragmented cloud security tools by bringing CSPM, CWPP, CDR, and CIEM together in a single CNAPP platform. By consolidating these capabilities, it reduces the complexity and cost of managing multiple point products
    Amos S.

    Helps Security Teams Identify Vulnerabilities and Respond to Threats Fast

    Reviewed on Aug 20, 2026
    Review provided by G2
    What do you like best about the product?
    It helps security teams quickly identify vulnerabilities, monitor activity, and respond to threats in a timely, effective way.
    What do you dislike about the product?
    It feels complex to use, and I get a high number of security notifications and alerts.
    What problems is the product solving and how is that benefiting you?
    It reduces the time I spend investigating risks and improves my ability to respond quickly to threats.
    View all reviews