View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon ACTION

Run RTR Command

Initiate a Real-Time Response (RTR) session on a host and execute a read-only responder command. Calls POST /real-time-response/entities/sessions/v1 to open the session, then POST /real-time-response/entities/command/v1 to run the command; returns the session_id and cloud_request_id. Use Get RTR Command Status with the returned cloud_request_id to fetch results. Requires an RTR entitlement. See the documentation.
  • Action
  • Writes data
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's CrowdStrike Falcon account once, then configure and run Run RTR Command from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-run-rtr-command",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    deviceId: "Device ID",
    baseCommand: "Base Command",
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Run RTR Command inputs
Property Type Description
deviceId Device ID string
Device ID (aid) to open the RTR session against. Run Search Hosts to obtain it.
Required
baseCommand Base Command string
The RTR base command to run, e.g. ls, ps, cat. Must match the leading token of Command String.
Required
commandString Command String string
The full command line including arguments, e.g. ls C:\Windows.
Required
queueOffline Queue Offline boolean
If true, queue the command for delivery when an offline host reconnects. Default: false.
Optional
timeout Session Timeout (seconds) integer
Session timeout in seconds (1-600). Default: 30.
Optional
persist Persist boolean
Flag indicating if this command should be executed when the host returns to service.
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
crowdstrike_falcon-run-rtr-command
Version
0.0.2
App
CrowdStrike Falcon
Authentication
OAuth
Read-only
No
Destructive
No
Open world
Yes