CrowdStrike Falcon ACTION
Run RTR Command
Initiate a Real-Time Response (RTR) session on a host and execute a read-only responder command. Calls POST /real-time-response/entities/sessions/v1 to open the session, then POST /real-time-response/entities/command/v1 to run the command; returns the session_id and cloud_request_id. Use Get RTR Command Status with the returned cloud_request_id to fetch results. Requires an RTR entitlement. See the documentation.
- Action
- Writes data
- OAuth
- SDK
- MCP
IMPLEMENTATION
Call this tool
Connect a user's CrowdStrike Falcon account once, then configure and run Run RTR Command from your backend or agent.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "crowdstrike_falcon-run-rtr-command",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
deviceId: "Device ID",
baseCommand: "Base Command",
},
})
console.log(result)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "crowdstrike_falcon-run-rtr-command",
"configured_props": {
"crowdstrike_falcon": { "authProvisionId": "apn_xxxxxxx" },
"deviceId": "Device ID",
"baseCommand": "Base Command"
}
}'// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "crowdstrike_falcon",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// listTools() hands your model this tool's input schema, so it can
// fill the arguments itself:
const result = await mcp.callTool({
name: "crowdstrike_falcon-run-rtr-command",
arguments: {
deviceId: "Device ID",
baseCommand: "Base Command",
},
})SCHEMA
Inputs
Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.
| Property | Type | Description |
|---|---|---|
deviceId Device ID | string | Device ID (aid) to open the RTR session against. Run Search Hosts to obtain it. Required |
baseCommand Base Command | string | The RTR base command to run, e.g. ls, ps, cat. Must match the leading token of Command String. Required |
commandString Command String | string | The full command line including arguments, e.g. ls C:\Windows. Required |
queueOffline Queue Offline | boolean | If true, queue the command for delivery when an offline host reconnects. Default: false. Optional |
timeout Session Timeout (seconds) | integer | Session timeout in seconds (1-600). Default: 30. Optional |
persist Persist | boolean | Flag indicating if this command should be executed when the host returns to service. Optional |
REFERENCE
Tool details
Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.
- Registry key
- crowdstrike_falcon-run-rtr-command
- Version
- 0.0.2
- App
- CrowdStrike Falcon
- Authentication
- OAuth
- Read-only
- No
- Destructive
- No
- Open world
- Yes
- Source
- View on GitHub ↗