# Run RTR Command — CrowdStrike Falcon

> Initiate a Real-Time Response (RTR) session on a host and execute a read-only responder command. Calls POST /real-time-response/entities/sessions/v1 to open the session, then POST /real-time-response/entities/command/v1 to run the command…

- Key: `crowdstrike_falcon-run-rtr-command`
- Type: Action (Write)
- Version: 0.0.2
- App: CrowdStrike Falcon (`crowdstrike_falcon`) — https://pipedream.com/apps/crowdstrike-falcon.md
- This page (HTML): https://pipedream.com/apps/crowdstrike-falcon/actions/run-rtr-command
- Hints: open-world
- Source: https://github.com/PipedreamHQ/pipedream/blob/master/components/crowdstrike_falcon/actions/run-rtr-command/run-rtr-command.mjs

## Description

Initiate a Real-Time Response (RTR) session on a host and execute a read-only responder command. Calls POST /real-time-response/entities/sessions/v1 to open the session, then POST /real-time-response/entities/command/v1 to run the command; returns the session_id and cloud_request_id. Use **Get RTR Command Status** with the returned cloud_request_id to fetch results. Requires an RTR entitlement. [See the documentation](https://developer.crowdstrike.com/api-reference/collections/real-time-response/#rtr_executecommand).

## Props

| Prop | Type | Required | Description |
|---|---|---|---|
| `deviceId` | `string` | Yes | Device ID (aid) to open the RTR session against. Run Search Hosts to obtain it. |
| `baseCommand` | `string` | Yes | The RTR base command to run, e.g. ls, ps, cat. Must match the leading token of Command String. |
| `commandString` | `string` | Yes | The full command line including arguments, e.g. ls C:\Windows. |
| `queueOffline` | `boolean` | No | If true, queue the command for delivery when an offline host reconnects. Default: false. |
| `timeout` | `integer` | No | Session timeout in seconds (1-600). Default: 30. |
| `persist` | `boolean` | No | Flag indicating if this command should be executed when the host returns to service. |

## Run it

**MCP**

```ts
import { Client } from "@modelcontextprotocol/sdk/client/index.js"
import { StreamableHTTPClientTransport } from "@modelcontextprotocol/sdk/client/streamableHttp.js"
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const accessToken = await pd.rawAccessToken

const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": process.env.PIPEDREAM_PROJECT_ID!,
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "crowdstrike_falcon",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// listTools() hands your model this tool's input schema, so it can
// fill the arguments itself:
const result = await mcp.callTool({
  name: "crowdstrike_falcon-run-rtr-command",
  arguments: {
    deviceId: "Device ID",
    baseCommand: "Base Command",
  },
})
```

**TypeScript**

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-run-rtr-command",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    deviceId: "Device ID",
    baseCommand: "Base Command",
  },
})

console.log(result)
```

**cURL**

```bash
curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
  -H "Content-Type: application/json" \
  -H "X-PD-Environment: production" \
  -H "Authorization: Bearer {access_token}" \
  -d '{
    "external_user_id": "{external_user_id}",
    "id": "crowdstrike_falcon-run-rtr-command",
    "configured_props": {
      "crowdstrike_falcon": { "authProvisionId": "apn_xxxxxxx" },
      "deviceId": "Device ID",
      "baseCommand": "Base Command"
    }
  }'
```

---

- App: https://pipedream.com/apps/crowdstrike-falcon.md · All apps: https://pipedream.com/apps
