Investigate CrowdStrike Falcon alerts and telemetry through falcon-mcp

Use falcon-mcp when an agent needs CrowdStrike Falcon detections, incidents, behaviors, threat intel, or read-only response context to triage a security event without leaving an MCP workflow.

Investigate CrowdStrike Falcon alerts and telemetry through falcon-mcp

Use falcon-mcp when an agent needs CrowdStrike Falcon detections, incidents, behaviors, threat intel, or read-only response context to triage a security event without leaving an MCP workflow.

Installation

Method 1, Agent Skill Exchange

Method 2, Git clone

git clone https://github.com/agentskillexchange/skills.git && cd skills/skills/investigate-crowdstrike-falcon-alerts-and-telemetry-through-falcon-mcp

Method 3, Download ZIP

  • Download the repository ZIP and extract skills/investigate-crowdstrike-falcon-alerts-and-telemetry-through-falcon-mcp.

Method 4, Manual copy

  • Copy this skill folder into your local skills directory, then reload your agent tooling.

Method 5, Fork and sync

  • Fork the repository if you want to maintain local edits while syncing upstream changes.

Source