Falcon Foundry Samples
Build on the Falcon platform with these open-source Foundry samples. Each project demonstrates real-world patterns — from RTR automation to third-party API integration — and can be cloned, customized, and deployed to your own environment.
Featured Samples
Section titled “Featured Samples”Rapid Response
Patch, upload, and remove files from hosts using RTR scripts, Fusion SOAR workflows, and Foundry UI extensions.
MITRE ATT&CK Triage
Provides a MITRE-prioritized view of XDR detections for faster triage and investigation workflows.
Scalable RTR
Orchestrate file and registry verification across Windows endpoints at scale with automated RTR workflows.
All Foundry Samples
Section titled “All Foundry Samples”| Repository | Language | Category | Description |
|---|---|---|---|
| foundry-sample-rapid-response | JavaScript | Endpoint Security | Patch, upload, and remove files from hosts via RTR, SOAR, and UI extensions |
| foundry-sample-mitre | TypeScript | Detection Triage | MITRE ATT&CK-prioritized XDR detection triage view |
| foundry-sample-scalable-rtr | TypeScript | Endpoint Security | Scalable file and registry verification across Windows |
| foundry-sample-anomali-threatstream | Python | Threat Intelligence | Anomali ThreatStream sample Foundry app |
| foundry-sample-category-blocking | JavaScript | Endpoint Security | Category-based blocking rules for endpoint protection |
| foundry-sample-charlotte-toolkit | TypeScript | AI Security | Charlotte Toolkit sample Foundry app |
| foundry-sample-collections-toolkit | TypeScript | Developer Reference | Collections management toolkit and reference implementation |
| foundry-sample-logscale | Python | Data Integration | Custom data ingestion to LogScale sample Foundry app |
| foundry-sample-servicenow-itsm | Go | IT Integration | ServiceNow ITSM and SIR sample Foundry app |
| foundry-sample-zscaler-internet-access | Python | Network Security | Zscaler Internet Access sample Foundry app |
| foundry-sample-insider-risk-workday | TypeScript | Identity | Insider Risk Workday sample Foundry app |
| foundry-sample-insider-risk-sailpoint | TypeScript | Identity | Insider Risk SailPoint sample Foundry app |
| foundry-sample-detection-translation | JavaScript | Detection Triage | Detection translation and context sample Foundry app |
| foundry-sample-foundryjs-demo | TypeScript | Developer Reference | Foundry-JS Demo sample Foundry app |
| foundry-sample-functions-python | Python | Developer Reference | Functions with Python sample Foundry app |
| foundry-sample-idp-notifications | TypeScript | Identity | Falcon IdP Domain and Connector Monitoring sample Foundry app |
| foundry-sample-ngsiem-importer | Python | Data Integration | Threat Intel Import to NG-SIEM sample Foundry app |
| foundry-sample-openrouter-toolkit | TypeScript | AI Security | OpenRouter Toolkit sample Foundry app |
| foundry-sample-servicenow-idp | Python | Identity | ServiceNow CMDB Ingest For Identity Protection sample Foundry app |
| foundry-sample-threat-intel | TypeScript | Threat Intelligence | Threat Intelligence Detections Enrichment sample Foundry app |
| foundry-sample-template | — | Developer Reference | Template repo for new Foundry samples |