MCP Store
CrowdStrike MCP Server
Connect the CrowdStrike Falcon MCP server
Connect the CrowdStrike Falcon MCP server to Atomicwork to enable secure, agentic security investigation and response.
Connecting the CrowdStrike Falcon MCP (Model Context Protocol) server to Atomicwork allows your AI Workforce, workflow builder, and coding agents to securely query and act on your Falcon platform. Once connected, your AI coworkers can investigate detections and incidents, look up host and vulnerability data, research threat intelligence, and run response actions — within the precise boundaries you define.
[!NOTE] Note: This integration is specifically for the CrowdStrike Falcon MCP server, which enables agentic actions and investigations. If you need the standard CrowdStrike integration instead, connect it from the App Store. See CrowdStrike: Permissions and setup.
Before you begin
To set up the CrowdStrike Falcon MCP server, make sure you have the following permissions and information:
- Atomicwork admin access: You must have organization administrator permissions in Atomicwork to access the MCP tools.
- CrowdStrike Falcon admin access: You must have permission in Falcon to create an API client (access to Support and Resources > API Clients and Keys).
- API base URL: The regional base URL for your Falcon cloud (see step 4).
Connect the CrowdStrike Falcon MCP server
Setting up the CrowdStrike Falcon MCP server involves creating an API client in the Falcon console, granting it the right scopes, and connecting it to Atomicwork. Follow these steps to complete the setup:
