Use CrowdStrike Falcon with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Detect threats, manage endpoints, investigate incidents, and query telemetry from CrowdStrike Falcon. the #1 endpoint detection and response platform.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 8 capabilities
The complete CrowdStrike Falcon capability set.
These are the exact actions your AI can choose when you ask it to work with CrowdStrike Falcon.
01-04
4 capabilities in this set.
Part of 8 available through CrowdStrike Falcon.
- 01
Create ioc
Types: sha256, md5, domain, ipv4, ipv6. Create a custom IOC indicator.. Actions: default
- 02
List detections
Use FQL filter syntax for precision: severity, technique, hostname, etc. Returns detection details with MITRE ATT&CK mapping. Query detection alerts
- 03
List incidents
Filter by state, severity, assigned_to, or date range using FQL syntax. Query security incidents
- 04
List vulnerabilities
Filter by CVE, severity, host, or remediation status. Query Spotlight vulnerabilities
05-08
4 capabilities in this set.
Part of 8 available through CrowdStrike Falcon.
- 05
Search hosts
Returns full device inventory details. Search endpoints
- 06
Update detection
Optionally add a triage comment. Update detection status
- 07
Contain device
Contain or lift containment on a device.. Actions: default
- 08
List iocs
Includes type, value, action, and metadata. List custom IOCs
Observed, not estimated
853ms average. Fast in production.
CrowdStrike Falcon is checked daily against the live service.
- Fastest day
- 674ms
- Slowest day
- 1065ms
- 14-day trend
- Slowing+16%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 8 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of CrowdStrike Falcon, so you can see the experience inside your AI.
It does not authenticate your account with CrowdStrike Falcon. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
CrowdStrike Falcon Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_Uam95HEcDSo3obA4xKgBdXTFdUwShAgA5MEsKr32/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — CrowdStrike Falcon capabilities are ready to use.
{
"mcpServers": {
"crowdstrike-falcon-mcp": {
"url": "https://edge.vinkius.com/vk_preview_Uam95HEcDSo3obA4xKgBdXTFdUwShAgA5MEsKr32/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions CrowdStrike Falcon owners ask.
- 01
What authentication does CrowdStrike use?
CrowdStrike uses OAuth 2.0 Client Credentials. You create an API Client in the Falcon Console under Support > API Clients and Keys. The server automatically obtains and caches Bearer tokens using your Client ID and Secret.
- 02
Which cloud regions are supported?
All CrowdStrike commercial clouds: US-1 (api.crowdstrike.com), US-2 (api.us-2.crowdstrike.com), EU-1 (api.eu-1.crowdstrike.com), and US-GOV-1. Configure the Base URL credential to match your tenant region.
- 03
Can it triage detections automatically?
Yes. The list_detections capability returns severity, tactic, technique, and device context. An AI agent can use this to auto-triage low/medium detections and escalate critical ones, reducing SOC analyst workload by 60-80%.
Explore
More in Fort Knox
Halo Security AI Connector
Automate attack surface management via Halo Security — monitor assets, scans, and vulnerabilities directly fro
ViewSecurityTrails AI Connector
Uncover IT infrastructure — access DNS history, subdomains, reverse IP lookups, WHOIS data and advanced domain
ViewIPdata AI Connector
Enrich IP addresses with geolocation, ASN, and threat intelligence data directly within your AI agent.
ViewAppDynamics (Application Performance Monitor API) AI Connector
Monitor application performance, business transactions, and infrastructure health rules directly from your AI
View
Suggestions
Cortex XSIAM AI Connector
Connect Cortex XSIAM to any AI agent via MCP.
ViewCensys AI Connector
Search internet-connected hosts, SSL certificates and attack surface — discover exposed services and vulnerabi
ViewCrowdSec AI Connector
Automate threat intelligence via CrowdSec — query local decisions, stream security updates, and check global I
ViewComplyAdvantage AI Connector
Automate AML and KYC compliance — screen entities, manage search history, and monitor risks directly from your
View
