Infrastructure as code for CrowdStrike — manage detections, workflows, saved searches, and more with a Terraform-like lifecycle.
-
Updated
Apr 1, 2026 - Python
Infrastructure as code for CrowdStrike — manage detections, workflows, saved searches, and more with a Terraform-like lifecycle.
A Model Context Protocol (MCP) server that provides programmatic access to CrowdStrike NGSIEM search capabilities. This server enables MCP-compatible applications to execute security event searches through a standardized interface.
Backup Crowdstrike NGSIEM correlation rules, lookups, custom parsers /AND Falcon Fusion SOAR workflows to dated folders on disk using the FalconPy.
Add a description, image, and links to the ngsiem topic page so that developers can more easily learn about it.
To associate your repository with the ngsiem topic, visit your repo's landing page and select "manage topics."