Query CrowdStrike Falcon Spotlight for vulnerability exposure data via the API

domain: developer.crowdstrike.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create an OAuth2 API client scoped for Spotlight vulnerabilities (read) in the Falcon console and obtain a bearer token from the token endpoint.
  2. Use the vulnerabilities search operation with an FQL filter (e.g. filtering by cve.id, severity, or host status) to page through matching vulnerability entities.
  3. Retrieve full vulnerability details, including CVE metadata and exploit/priority rating, for specific vulnerability IDs.
  4. Call the remediation details operation with remediation IDs referenced on vulnerabilities to get patch or configuration guidance.
  5. Paginate using the API's continuation-token pattern for large environments rather than offset-based paging to avoid missing results as data changes.

Known gotchas

Related routes

Query CrowdStrike Falcon API for endpoint detections
falcon.crowdstrike.com · 6 steps · unrated
Pull threat intelligence indicators from CrowdStrike Falcon Intelligence API
developer.crowdstrike.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans