Settings file Claude Code
Agent settings declaring 19 allowed tools.
Settings file Claude Code
Agent settings declaring 19 allowed tools.
MCP server Claude CodeCodexCursor +2
MCP server for the CrowdStrike Falcon platform. Runs locally from the crowdstrike-mcp Python package.
Plugin Claude Code
Plugin marketplace listing 10 plugins: crowdstrike-soc, crowdstrike-soc-agents, crowdstrike-logscale-security-queries, crowdstrike-detection-tuning, crowdstrike-behavioral-detections.
Plugin Claude Code
Design multi-event behavioral detection rules using CrowdStrike NG-SIEM correlate() function for attack chain detections across AWS, EntraID, and CrowdStrike data sources.
Skill Claude CodeCodex
Design multi-event behavioral detection rules using CrowdStrike NG-SIEM correlate() function. Use when building attack chain detections, correlating multiple events across time windows, or creating behavioral rules that detect complex threat patterns across AWS, EntraID, and CrowdStrike data sources.
Plugin Claude Code
Curated CQL detection engineering pattern catalog for CrowdStrike NG-SIEM — correlation, enrichment, aggregation, scoring, baselining, and more.
Skill Claude CodeCodex
CQL pattern catalog — curated detection engineering patterns for CrowdStrike NG-SIEM. Use when writing, reviewing, or debugging CQL queries.
Plugin Claude Code
Analyze and tune CrowdStrike NGSIEM detections for false positive reduction using 38 enrichment functions across AWS, EntraID, GitHub, and network data sources.
Skill Claude CodeCodex
Analyze CrowdStrike NGSIEM detections for tuning opportunities based on environmental context, recent false positives, and available enrichment functions. Use when tuning detections (including behavioral rules with correlate()), reducing false positives, enhancing detection coverage, or reviewing OOTB templates for…
Plugin Claude Code
Build CrowdStrike Falcon Fusion SOAR workflows — discover actions via live API, author YAML, validate locally, and deploy automation playbooks.
Skill Claude CodeCodex
Build CrowdStrike Falcon Fusion SOAR workflows. Discover actions via live API, author YAML using our resource schema, validate locally, and save to resources/workflows/. Use when asked to create a Fusion workflow, SOAR playbook, or automate detection response.
Plugin Claude Code
Develop, optimize, and troubleshoot CrowdStrike LogScale security detection queries using CQL — includes case statements, multi-event correlation, investigation playbooks, and hunting rules.
Skill Claude CodeCodex
Develop, optimize, and troubleshoot CrowdStrike LogScale (Humio) security detection queries using CQL syntax. Use when writing LogScale queries, building security detections, creating threat hunting rules, fixing CQL syntax errors, working with CrowdStrike EDR/Falcon security monitoring, or building behavioral rules…
Plugin Claude Code
Detection-to-response mapping and SOAR playbook design — analyzes detections, recommends tiered response actions, and produces handoff docs for Falcon Fusion workflow generation.
Skill Claude CodeCodex
Detection-to-response mapping and SOAR playbook design. Analyzes detections, recommends tiered response actions (observe, investigate, contain, remediate), and produces handoff docs for fusion-workflows to generate workflow YAML. Use when planning response automation for detections, designing SOAR playbooks, or…
Plugin Claude Code
Agent-delegated SOC workflow for CrowdStrike NGSIEM — distributes triage, investigation, and evidence collection across specialized sub-agents (Haiku for mechanical, Sonnet for substantive, Opus for judgment).
Skill Claude CodeCodex
Unified SOC analyst workflow for CrowdStrike NGSIEM — triage alerts, investigate security events, hunt threats, and tune detections. Agent-delegated architecture: Haiku for mechanical tasks, Sonnet for substantive work, Opus for judgment.
Agent
You are a mechanical alert formatting agent. You fetch CrowdStrike alerts via MCP and produce a structured summary table with triage depth tier assignments.
Agent
You are a CQL (CrowdStrike Query Language) specialist for NG-SIEM. Given an investigation intent and alert context, you write targeted CQL queries that the orchestrator will review and execute.
Agent
You are an evidence synthesis agent. You take raw investigation results and produce a structured, human-readable summary that presents the evidence objectively for the orchestrator's classification decision.
Agent
You are an evidence collection agent. You execute read-only MCP tool calls against CrowdStrike APIs and structure the raw results into organized evidence for the orchestrator.
Agent
You are a mechanical CQL syntax validation agent. You run the validate-query CLI command and report the result. Nothing more.
Plugin Claude Code
Unified SOC analyst workflow for CrowdStrike NGSIEM — triage alerts, investigate security events, hunt threats, tune detections, and manage cases through a phased lifecycle.
Command
SOC operations: $ARGUMENTS.