MCP server trust card
CrowdStrike MCP Server
CrowdStrike · recorded version or snapshot 0.1.0
CrowdStrike Falcon MCP — query threat intelligence, manage detections, investigate incidents, and query RTR sessions.
Metadata reviewed No listed warning
Source and identity
- Publisher
- CrowdStrike
- Namespace
- Not recorded
- Recorded version / snapshot
- 0.1.0
- License
- Not recorded
- Artifact SHA-256
- Not recorded — a source snapshot alone does not pin an artifact
- Canonical listing
- https://github.com/CrowdStrike/mcp-falcon
Declared access
Review every permission against your own environment and least-privilege policy.
- read:detections
- read:intel
Required secrets
Generated examples use placeholders. Never paste real secrets into ToolDix.
- CROWDSTRIKE_CLIENT_ID
- CROWDSTRIKE_CLIENT_SECRET
Compatibility and connection
Clients
- Codex
- Claude
- Cursor
- OpenClaw
Runtimes
- python
Transports
- stdio
Authentication
- oauth2
Evidence
- Canonical source
canonical · observed Jul 15, 2026