Source: https://atomic-works-test.docs-staging.pageloop.ai/integrations/mcp-store/crowdstrike-mcp-server

# CrowdStrike MCP Server

# Connect the CrowdStrike Falcon MCP server

Connect the CrowdStrike Falcon MCP server to Atomicwork to enable secure, agentic security investigation and response.

Connecting the CrowdStrike Falcon MCP (Model Context Protocol) server to Atomicwork allows your AI Workforce, workflow builder, and coding agents to securely query and act on your Falcon platform. Once connected, your AI coworkers can investigate detections and incidents, look up host and vulnerability data, research threat intelligence, and run response actions — within the precise boundaries you define.

> \[!NOTE]
> **Note:** This integration is specifically for the CrowdStrike Falcon MCP server, which enables agentic actions and investigations. If you need the standard CrowdStrike integration instead, connect it from the App Store. See CrowdStrike: Permissions and setup.

## Before you begin

To set up the CrowdStrike Falcon MCP server, make sure you have the following permissions and information:

- **Atomicwork admin access:** You must have organization administrator permissions in Atomicwork to access the MCP tools.
- **CrowdStrike Falcon admin access:** You must have permission in Falcon to create an API client (access to Support and Resources > API Clients and Keys).
- **API base URL:** The regional base URL for your Falcon cloud (see step 4).

## Connect the CrowdStrike Falcon MCP server

Setting up the CrowdStrike Falcon MCP server involves creating an API client in the Falcon console, granting it the right scopes, and connecting it to Atomicwork. Follow these steps to complete the setup:

1. **Create the API client in Falcon:** Sign in to the Falcon console at falcon.crowdstrike.com, go to Support and Resources > API Clients and Keys, and click Add new API client. Enter a name (for example, `atomicwork-mcp`) and an optional description.

2. **Grant API scopes:** Under API scopes, select the scopes that match the tools you want Atomicwork to use (for example, read-only access to detections, incidents, and hosts, or write access for response). Narrower scopes limit the tool capabilities on the Atomicwork side.

3. **Create and save the credentials:** Click Create. Copy the Client ID and Client Secret immediately and store them securely—the Client Secret is shown only once when the API client is created.

4. **Find your API base URL:** Use the base URL for your Falcon cloud region: `https://api.crowdstrike.com` for US-1, `https://api.us-2.crowdstrike.com` for US-2, `https://api.eu-1.crowdstrike.com` for EU-1, and `https://api.laggar.gcw.crowdstrike.com` for US-GOV.

5. **Connect in Atomicwork:** In Atomicwork, navigate to AI Workforce > MCP Tools. Click the CrowdStrike Falcon tile, then click Connect. Enter your Client ID, Client Secret, and API Base URL, click Test to validate the connection, and then complete the setup.

## Managing CrowdStrike Falcon tool access

Once the setup is complete, you can control which tools your AI Coworkers can access. To configure tool access:

1. Navigate to AI Workforce > AI Coworker > Tools.

2. Select your AI Coworker from the list.

3. Grant granular or complete access to the available CrowdStrike Falcon tools based on your workspace requirements.

## Available CrowdStrike Falcon MCP tools

The CrowdStrike Falcon MCP server provides a wide range of tools grouped by category. These tools allow your AI Coworkers to retrieve information and execute tasks across your Falcon platform:

- **Aggregate and count:** Tools like falcon\_aggregate\_detections, falcon\_aggregate\_case\_slas, and falcon\_count\_kubernetes\_containers summarize and roll up data across cases, detections, and Kubernetes containers.

- **Check and connectivity:** Tools like falcon\_check\_connectivity and falcon\_check\_rtr\_command\_status verify the connection to Falcon and check whether an RTR command has finished running.

- **Download and get details:** Tools like falcon\_get\_cases, falcon\_get\_detection\_details, falcon\_get\_host\_details, and falcon\_download\_report\_execution retrieve full details for a case, detection, or host, and download completed report executions.

- **Shield (SaaS security):** Tools like falcon\_get\_shield\_posture\_metrics, falcon\_get\_shield\_activity\_monitor, and falcon\_get\_shield\_check\_compliance surface SaaS security posture, activity, and compliance checks.

- **Identity, listing, and preview:** Tools like falcon\_idp\_investigate\_entity, falcon\_list\_case\_templates, and falcon\_preview\_quarantine\_actions investigate identity entities, list case templates, and preview quarantine actions before they run.

- **Search:** Tools like falcon\_search\_hosts, falcon\_search\_detections, falcon\_search\_vulnerabilities, and falcon\_search\_cloud\_risks search across hosts, detections, vulnerabilities, and cloud, identity, and data-protection findings.

## Next steps

Now that you have connected the CrowdStrike Falcon MCP server, explore how to configure your AI coworkers and workflows to use these tools:

- **Setting up an AI Coworker** — Learn how to assign tools and set up guardrails for your AI coworkers.
- **Connect the Okta MCP server** — Learn how to connect identity provider MCP servers to your workspace.
- **Connect the Sentry MCP server** — Explore connecting other security and monitoring MCP integrations.
