Skip to content

Falcon Foundry Samples

Build on the Falcon platform with these open-source Foundry samples. Each project demonstrates real-world patterns — from RTR automation to third-party API integration — and can be cloned, customized, and deployed to your own environment.


RepositoryLanguageCategoryDescription
foundry-sample-rapid-responseJavaScriptEndpoint SecurityPatch, upload, and remove files from hosts via RTR, SOAR, and UI extensions
foundry-sample-mitreTypeScriptDetection TriageMITRE ATT&CK-prioritized XDR detection triage view
foundry-sample-scalable-rtrTypeScriptEndpoint SecurityScalable file and registry verification across Windows
foundry-sample-anomali-threatstreamPythonThreat IntelligenceAnomali ThreatStream sample Foundry app
foundry-sample-category-blockingJavaScriptEndpoint SecurityCategory-based blocking rules for endpoint protection
foundry-sample-charlotte-toolkitTypeScriptAI SecurityCharlotte Toolkit sample Foundry app
foundry-sample-collections-toolkitTypeScriptDeveloper ReferenceCollections management toolkit and reference implementation
foundry-sample-logscalePythonData IntegrationCustom data ingestion to LogScale sample Foundry app
foundry-sample-servicenow-itsmGoIT IntegrationServiceNow ITSM and SIR sample Foundry app
foundry-sample-zscaler-internet-accessPythonNetwork SecurityZscaler Internet Access sample Foundry app
foundry-sample-insider-risk-workdayTypeScriptIdentityInsider Risk Workday sample Foundry app
foundry-sample-insider-risk-sailpointTypeScriptIdentityInsider Risk SailPoint sample Foundry app
foundry-sample-detection-translationJavaScriptDetection TriageDetection translation and context sample Foundry app
foundry-sample-foundryjs-demoTypeScriptDeveloper ReferenceFoundry-JS Demo sample Foundry app
foundry-sample-functions-pythonPythonDeveloper ReferenceFunctions with Python sample Foundry app
foundry-sample-idp-notificationsTypeScriptIdentityFalcon IdP Domain and Connector Monitoring sample Foundry app
foundry-sample-ngsiem-importerPythonData IntegrationThreat Intel Import to NG-SIEM sample Foundry app
foundry-sample-openrouter-toolkitTypeScriptAI SecurityOpenRouter Toolkit sample Foundry app
foundry-sample-servicenow-idpPythonIdentityServiceNow CMDB Ingest For Identity Protection sample Foundry app
foundry-sample-threat-intelTypeScriptThreat IntelligenceThreat Intelligence Detections Enrichment sample Foundry app
foundry-sample-templateDeveloper ReferenceTemplate repo for new Foundry samples