View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon ACTION

Manage Host Containment

Manage host containment on one or more CrowdStrike Falcon hosts via POST /devices/entities/devices-actions/v2 (action_name query param, ids body). Use Search Hosts or Get Host to find device IDs. See the documentation.
  • Action
  • Writes data
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's CrowdStrike Falcon account once, then configure and run Manage Host Containment from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-manage-host-containment",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    actionName: "Action",
    deviceIds: ["Device IDs"],
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Manage Host Containment inputs
Property Type Description
actionName Action string
Containment action to perform. One of: Contain (isolate from network), Lift Containment (restore connectivity), Detection Suppress, Detection Unsuppress, Hide Host, Unhide Host
Required
deviceIds Device IDs string[]
Device IDs to act on. Run Search Hosts to obtain these IDs. Sent as ids in the request body.
Required

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
crowdstrike_falcon-manage-host-containment
Version
0.0.2
App
CrowdStrike Falcon
Authentication
OAuth
Read-only
No
Destructive
No
Open world
Yes