{
 "categories": [
  "enterprise",
  "observability"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-03",
   "fact": "homepage",
   "note": "CrowdStrike presents the Falcon platform as a commercial unified security platform covering endpoint, identity, cloud, and SIEM.",
   "source": "https://www.crowdstrike.com/en-us/platform/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "license",
   "note": "CrowdStrike sells Falcon Go, Pro, and Enterprise bundles with per-device monthly or annual pricing, plus a 15-day free trial of Falcon Prevent. Lasting access is paid.",
   "source": "https://www.crowdstrike.com/en-us/pricing/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.exists",
   "note": "CrowdStrike documents a public Falcon API that automates hosts, detections, response, intelligence, cloud, and related platform work.",
   "source": "https://developer.crowdstrike.com/api-reference/overview/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.kinds[0]",
   "note": "Falcon API operations are HTTPS routes such as POST /oauth2/token. Responses are JSON.",
   "source": "https://developer.crowdstrike.com/api-reference/collections/oauth2/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.auth[0]",
   "note": "All API requests require a bearer token from POST /oauth2/token using client_id and client_secret. Tokens have a standard 30-minute expiry. This is OAuth2 client-credentials token minting.",
   "source": "https://developer.crowdstrike.com/api-reference/collections/oauth2/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.coverage",
   "note": "The API covers endpoint security, RTR, intelligence, cloud, identity, NG-SIEM, policies, workflows, and more. Coverage is the Falcon API surface, not a claim that every console click is exposed.",
   "source": "https://developer.crowdstrike.com/api-reference/overview/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.sdk.exists",
   "note": "CrowdStrike documents six official Falcon SDKs and states they handle OAuth2 token management from an API client ID and secret.",
   "source": "https://developer.crowdstrike.com/sdks/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.sdk.languages",
   "note": "Official SDKs listed are FalconPy (Python), PSFalcon (PowerShell), goFalcon (Go), FalconJS (TypeScript), Rusty Falcon (Rust), and Crimson Falcon (Ruby).",
   "source": "https://developer.crowdstrike.com/sdks/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.sdk.official",
   "note": "The page titles the six language clients as official Falcon SDKs.",
   "source": "https://developer.crowdstrike.com/sdks/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.mcp.first_party",
   "note": "The vendor GitHub organization owns CrowdStrike/falcon-mcp. The README and SUPPORT file say CrowdStrike actively maintains it. first_party is true because the vendor owns and maintains the repo, even though the same pages say it is not an official CrowdStrike product.",
   "source": "https://github.com/CrowdStrike/falcon-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.data_access.export[0]",
   "note": "OAuth2 and other Falcon API examples return JSON bodies, including access_token and error/meta envelopes.",
   "source": "https://developer.crowdstrike.com/api-reference/collections/oauth2/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "CrowdStrike publishes a genuine developer-center llms.txt that indexes Falcon MCP, SDKs, and 128 API collections with 1468 operations.",
   "source": "https://developer.crowdstrike.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "verdict.scores.api",
   "note": "The REST API is documented, read/write across a large collection set, and paired with official SDKs and OAuth2 client-credentials auth. It is a broad production path rather than unusual completeness of every Falcon console feature.",
   "source": "https://developer.crowdstrike.com/api-reference/overview/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "verdict.scores.mcp",
   "note": "falcon-mcp is vendor-owned and useful across many Falcon modules, but the README marks public preview, asks users to avoid production, and the SUPPORT text says it is not an official CrowdStrike product. That is a limited vendor preview (5-6), not a production official server (7-8).",
   "source": "https://raw.githubusercontent.com/CrowdStrike/falcon-mcp/main/README.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[0].url",
   "note": "Opened the CrowdStrike/falcon-mcp repository page used as party evidence for vendor ownership.",
   "source": "https://github.com/CrowdStrike/falcon-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[1].url",
   "note": "Opened the current README, including the public-preview warning, module table, install/auth, and the community-driven / not-an-official-product disclaimer.",
   "source": "https://raw.githubusercontent.com/CrowdStrike/falcon-mcp/main/README.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Falcon MCP quickstart. It documents API client creation, uv/uvx install, FALCON_CLIENT_ID/SECRET/BASE_URL, and falcon_check_connectivity.",
   "source": "https://developer.crowdstrike.com/falcon-mcp/getting-started/quickstart/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as CrowdStrike's current Falcon API reference overview by domain.",
   "source": "https://developer.crowdstrike.com/api-reference/overview/",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-03",
  "volatility": "high",
  "watch": [
   {
    "type": "repo",
    "url": "https://github.com/CrowdStrike/falcon-mcp"
   },
   {
    "type": "repo",
    "url": "https://raw.githubusercontent.com/CrowdStrike/falcon-mcp/main/README.md"
   },
   {
    "type": "mcp",
    "url": "https://developer.crowdstrike.com/falcon-mcp/getting-started/quickstart/"
   },
   {
    "type": "docs",
    "url": "https://developer.crowdstrike.com/api-reference/overview/"
   }
  ]
 },
 "homepage": "https://www.crowdstrike.com/en-us/platform/",
 "id": "crowdstrike-falcon",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "oauth2-client-credentials"
   ],
   "coverage": "partial",
   "docs": "https://developer.crowdstrike.com/api-reference/overview/",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Falcon's REST API, official SDKs, and vendor-owned falcon-mcp cover practical platform automation without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "python",
    "powershell",
    "go",
    "typescript",
    "rust",
    "ruby"
   ],
   "official": true
  }
 },
 "name": "CrowdStrike Falcon",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "splunk",
   "sentry"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "CrowdStrike",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 8,
   "rpa": null
  },
  "summary": "CrowdStrike Falcon is automatable today through a public REST API. This record is the Falcon platform \u2014 detections, hosts, intel, Real Time Response, Spotlight, and the other modules reachable through the Falcon API and vendor-owned falcon-mcp. It is not Snyk. All API requests require a bearer token minted at POST /oauth2/token with an API client ID and client secret (OAuth2 client credentials). Tokens expire after 30 minutes and can be revoked at /oauth2/revoke. Official SDKs exist for Python (FalconPy), PowerShell (PSFalcon), Go (goFalcon), TypeScript (FalconJS), Rust (Rusty Falcon), and Ruby (Crimson Falcon). The developer center documents 128 service collections and 1468 operations across endpoint security, intelligence, cloud, identity, NG-SIEM, and related domains. Event Streams discovers and refreshes a data-feed connection; it is not an outbound HTTP webhook. The first-party MCP path is CrowdStrike-owned falcon-mcp at https://github.com/CrowdStrike/falcon-mcp, published on PyPI as falcon-mcp and listed as io.github.CrowdStrike/falcon-mcp. CrowdStrike's SUPPORT file and README state: \"This is a community-driven, open source project. While it is not an official CrowdStrike product, it is actively maintained by CrowdStrike and supported in collaboration with the open source developer community.\" The README marks a public preview and asks users to avoid production deployments. falcon-mcp authenticates with FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, and FALCON_BASE_URL, and supports module flags, --read-only, and dynamic discover-and-execute tools. Vendor module docs also compare this self-hosted server to a hosted Falcon MCP with a different discovery pattern; a separate hosted product page was not opened in this pass. No official Falcon management CLI was established from the opened pages. iPaaS connectors were not opened. Computer-use viability is unassessed. API scores 8 and is the best path. MCP scores 6 because it is a limited vendor preview that CrowdStrike says is not an official product and should not be used in production.\n"
 }
}