CrowdStrike Falcon Fusion

CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.

Play video

Build CrowdStrike Falcon Fusion SOAR workflows directly from Claude Code. Six skills cover the full workflow lifecycle: discover available Fusion actions live from your CID's API, author workflow YAML validated against the Charlotte JSON schema, import and release workflow versions, trigger executions and monitor or debug them, and manage Falcon Next-Gen SIEM lookup files for CQL match() queries. A setup skill walks through Falcon API credential configuration on first run.

The plugin ships fifteen grounded use-case patterns the orchestrator matches your request against — enriching a detection's indicators with VirusTotal and tagging the case, gating device containment behind analyst approval on high-severity detections, paging through REST APIs inside a workflow, deduplicating Next-Gen SIEM detections, sending workflow notifications to a chat channel, and invoking a published Charlotte AI agent when a detection fires. Each pattern cites the CrowdStrike Tech Hub article or bundled example workflow it is grounded in.

How to use: Try prompts like "Create a Fusion workflow that enriches new detections with VirusTotal and comments the case", "Import this workflow into my CID and release it", "Run my containment workflow and tail the execution", or "Create a lookup file of known-bad domains for my CQL match() queries".

Requires a CrowdStrike Falcon subscription with API access; a companion plugin, crowdstrike-falcon-foundry, covers Falcon Foundry app development.