Connect your own CrowdStrike Falcon tenant (OAuth2 API Client) to manage Hosts, Detections, Alerts, Incidents, custom IOCs, Prevention Policies, and Real Time Response sessions across your endpoint...
What this app can do
25 tools registered
Connect CrowdstrikeFree
Connect your own CrowdStrike Falcon tenant by saving its cloud region and an OAuth2 API Client (Client ID + Secret), after checking they actually work.
Disconnect CrowdstrikeFree
Disconnect a CrowdStrike Falcon tenant: deletes the saved OAuth2 Client ID/Secret. Nothing in CrowdStrike itself is changed.
List ConnectionsFree
List the connected CrowdStrike Falcon tenants (region + masked Client ID).
List Hosts8 tok
List endpoints (hosts/sensors) in the connected Falcon tenant, optionally filtered by an FQL expression.
Get Host8 tok
Read one endpoint (host/sensor) in full by its Falcon device id.
Contain Hosts20 tok
Network-contain one or more hosts -- isolates them from the network except for traffic to the Falcon cloud. The core incident-response 'stop the bleeding' action.
Lift Containment20 tok
Lift network containment on one or more hosts, restoring normal network access.
Hide Hosts16 tok
Hide one or more hosts from the Falcon console (does not uninstall the sensor).
Unhide Hosts16 tok
Unhide one or more previously hidden hosts.
List Detections8 tok
List sensor-visibility Detections in the connected Falcon tenant, optionally filtered by an FQL expression (e.g. "status:'new'").
Get Detection8 tok
Read one Detection in full by its detection id.
Update Detection Status16 tok
Update a Detection's triage status (new/in_progress/true_positive/false_positive/ignored), optionally with a comment and/or assignee.
List Incidents8 tok
List correlated Incidents (CrowdScore groupings of related detections) in the connected Falcon tenant.
Get Incident8 tok
Read one Incident in full by its incident id.
Update Incident16 tok
Update an Incident's status and/or add a tag/comment.
List Iocs8 tok
List custom IOCs (Indicators of Compromise) configured on the connected Falcon tenant.
Create Ioc16 tok
Create a new custom IOC (hash/domain/IP) with a detect/prevent/allow action applied fleet-wide (or to selected platforms).
Delete Ioc16 tok
Permanently delete a custom IOC. Cannot be undone.
List Prevention Policies8 tok
List Prevention Policies configured on the connected Falcon tenant, optionally filtered by an FQL expression.
Get Prevention Policy8 tok
Read one Prevention Policy in full by its id.
Set Prevention Policy Enabled16 tok
Enable or disable a Prevention Policy without deleting it.
Start Rtr Session20 tok
Start a Real Time Response (RTR) session on a host, for live read-only investigation (ls, ps, netstat, etc. via run_rtr_command).
Run Rtr Command20 tok
Run a read-only RTR command (e.g. 'ls', 'ps', 'netstat', 'ifconfig') in an active RTR session and return its output.
List Vulnerabilities8 tok
List Spotlight Vulnerabilities (CVE exposure) across the fleet, optionally filtered by an FQL expression (e.g. "cve.severity:'CRITICAL'").
Audit Falcon Estate40 tok
Build one aggregated health report across the connected Falcon tenant: stale hosts, open critical incidents, new detections, and disabled prevention policies.