Skip to content

Automate Response

Adversaries move fast - eCrime breakout times average under 30 minutes. Manual response can’t keep up. The Falcon platform gives you Real-Time Response (RTR) for live endpoint access, host containment to isolate compromised machines, and workflow orchestration to chain response actions together. Foundry samples show you working patterns. The SDKs and MCP Server let you trigger it all programmatically or through AI.

Automated Containment

Isolate compromised hosts the moment a critical detection fires.

Scale Real Time Response

Execute forensic collection, file remediation, or registry checks across thousands of endpoints.

SOAR Playbooks

Integrate Falcon response actions into your security orchestration platform.

Bulk Remediation

Push scripts, patches, or configuration changes to targeted host groups.

Response Runbooks

Execute predefined response sequences based on detection type.

Execute commands on live endpoints - run scripts, collect files, manage processes, and investigate in real time.

Contain, restore, and manage endpoint state programmatically.

Orchestrate multi-step response sequences and schedule recurring operations.

Manage quarantined files and submit samples for analysis.

Two Foundry samples demonstrate response automation patterns directly. The Rapid Response sample patches, uploads, and removes files from hosts using RTR scripts combined with Fusion SOAR workflows and a UI extension for operator control. The Scalable RTR sample orchestrates file and registry verification across Windows endpoints at scale - a pattern for any bulk remediation workflow.

The Falcon MCP supports response actions directly through AI assistants:

An analyst can contain a host, create blocking IOCs, and verify containment status without leaving their AI assistant. See editor setup for Claude Desktop, VS Code, or Gemini CLI.