Skip to content

API Reference

The CrowdStrike Falcon API puts the full power of the Falcon platform in your hands. Automate threat response across thousands of endpoints. Build custom detection pipelines. Integrate real-time security telemetry into your SIEM, SOAR, or data lake. Hunt adversaries programmatically with the same intelligence CrowdStrike analysts use every day.


Manage hosts, investigate detections, respond to incidents, and track sensors across your fleet.

Execute commands on live endpoints, run scripts, contain compromised hosts, and manage RTR sessions at scale.

Research adversaries, track indicators of compromise, query intelligence reports, and analyze malware.

Register cloud accounts, monitor containers and Kubernetes workloads, assess cloud posture, and track image vulnerabilities.

Pull CVE data, prioritize remediation with ExPRT ratings, and track exposure risk across your environment.

Investigate entities, assess identity risk, manage users, and operate across multi-tenant MSSP environments.

Stream events in real time, execute CQL queries against Next-Gen SIEM, and build data ingestion pipelines.

Manage firewall rules, configure IOA exclusions, control sensor visibility, and customize detection behavior.

Orchestrate security operations with scheduled reports, on-demand scans, and automated workflows.

Manage application security posture, monitor SaaS integrations, and assess API risks.

Configure data loss prevention policies and scan data at rest.

Monitor file changes, manage policies, and track deviations across your environment.

Scan networks, manage zones, discover assets, and report on scan results.

Manage cases, track escalations, and coordinate response across your SOC.

Manage knowledge bases, files, and audit events for AI-powered workflows.

Manage deployments, releases, and serverless export jobs.


The Falcon MCP Server gives AI assistants direct access to the CrowdStrike Falcon platform through the Model Context Protocol. Investigate threats, triage detections, query hosts, research adversaries, and automate security operations - all through natural language conversations with your AI tools.

Learn more about Falcon MCP →