Skip to content

Falcon Foundry Samples

Build on the Falcon platform with these open-source Foundry samples. Each project demonstrates real-world patterns — from RTR automation to third-party API integration — and can be cloned, customized, and deployed to your own environment.


RepositoryCategoryDescription
foundry-sample-rapid-responseEndpoint SecurityPatch, upload, and remove files from hosts via RTR, SOAR, and UI extensions
foundry-sample-mitreDetection TriageMITRE ATT&CK-prioritized XDR detection triage view
foundry-sample-scalable-rtrEndpoint SecurityScalable file and registry verification across Windows
foundry-sample-anomali-threatstreamThreat IntelligenceAnomali ThreatStream sample Foundry app
foundry-sample-category-blockingEndpoint SecurityCategory-based blocking rules for endpoint protection
foundry-sample-charlotte-toolkitAI SecurityCharlotte Toolkit sample Foundry app
foundry-sample-collections-toolkitDeveloper ReferenceCollections management toolkit and reference implementation
foundry-sample-logscaleData IntegrationCustom data ingestion to LogScale sample Foundry app
foundry-sample-servicenow-itsmIT IntegrationServiceNow ITSM and SIR sample Foundry app
foundry-sample-zscaler-internet-accessNetwork SecurityZscaler Internet Access sample Foundry app
foundry-sample-insider-risk-workdayIdentityInsider Risk Workday sample Foundry app
foundry-sample-insider-risk-sailpointIdentityInsider Risk SailPoint sample Foundry app
foundry-sample-detection-translationDetection TriageDetection translation and context sample Foundry app
foundry-sample-foundryjs-demoDeveloper ReferenceFoundry-JS Demo sample Foundry app
foundry-sample-functions-pythonDeveloper ReferenceFunctions with Python sample Foundry app
foundry-sample-idp-notificationsIdentityFalcon IdP Domain and Connector Monitoring sample Foundry app
foundry-sample-ngsiem-importerData IntegrationThreat Intel Import to NG-SIEM sample Foundry app
foundry-sample-openrouter-toolkitAI SecurityOpenRouter Toolkit sample Foundry app
foundry-sample-servicenow-idpIdentityServiceNow CMDB Ingest For Identity Protection sample Foundry app
foundry-sample-threat-intelThreat IntelligenceThreat Intelligence Detections Enrichment sample Foundry app
foundry-sample-templateDeveloper ReferenceTemplate repo for new Foundry samples