Chronicle SecOps MCP Server
Provides tools for interacting with Google Chronicle Security Operations, including searching security events, retrieving security alerts, looking up entities (IP, domain, hash), listing security detection rules, and getting Indicators of Compromise (IoC) matches.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Chronicle SecOps MCP Serversearch for security events from IP 10.0.0.5 in the last 24 hours"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
This is a personal project.
Chronicle SecOps MCP Server
This is an MCP (Model Context Protocol) server for interacting with Google's Chronicle Security Operations suite. MCP Info
Installing in Claude Desktop
To use this MCP server with Claude Desktop:
Install Claude Desktop
Open Claude Desktop and select "Settings" from the Claude menu
Click on "Developer" in the lefthand bar, then click "Edit Config"
Update your
claude_desktop_config.jsonwith the following configuration (replace paths with your actual paths):
{
"mcpServers": {
"secops-mcp": {
"command": "/path/to/your/uv",
"args": [
"--directory",
"/path/to/your/mcp-secops-v3",
"run",
"secops_mcp.py"
],
"env": {
"CHRONICLE_PROJECT_ID": "your-google-cloud-project-id",
"CHRONICLE_CUSTOMER_ID": "your-chronicle-customer-id",
"CHRONICLE_REGION": "us"
}
}
}
}Make sure to update:
The path to
uv(usewhich uvto find it)The directory path to where this repository is cloned
Your Chronicle credentials (project ID, customer ID, and region)
Save the file and restart Claude Desktop
You should now see the hammer icon in the Claude Desktop interface, indicating the MCP server is active
Related MCP server: Google Search Console + GA4 MCP Server
Features
Security Tools
search_security_events: Search for security events in Chronicle with customizable queriesget_security_alerts: Get security alerts from Chroniclelookup_entity: Look up information about an entity (IP, domain, hash)list_security_rules: List security detection rules from Chronicleget_ioc_matches: Get Indicators of Compromise (IoCs) matches from Chronicle
Installation
Installing via Smithery
To install mcp-secops-v3 for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @emeryray2002/mcp-secops-v3 --client claudeManual Installation
Install the package:
pip install -e .Set up your environment variables:
export CHRONICLE_PROJECT_ID="your-google-cloud-project-id"
export CHRONICLE_CUSTOMER_ID="your-chronicle-customer-id"
export CHRONICLE_REGION="us" # or your regionRequirements
Python 3.11+
A Google Cloud account with Chronicle Security Operations enabled
Proper authentication configured
Usage
Running the MCP Server
python main.pyAPI Capabilities
The MCP server provides the following capabilities:
Search Security Events: Search for security events in Chronicle
Get Security Alerts: Retrieve security alerts
Lookup Entity: Look up entity information (IP, domain, hash, etc.)
List Security Rules: List detection rules
Get IoC Matches: Get Indicators of Compromise matches
Example
See example.py for a complete example of using the MCP server.
Authentication
The server uses Google's authentication. Make sure you have either:
Set up Application Default Credentials (ADC)
Set a GOOGLE_APPLICATION_CREDENTIALS environment variable
Used
gcloud auth application-default login
License
Apache 2.0
Development
The project is structured as follows:
secops_mcp.py: Main MCP server implementationexample.py: Example usage of the MCP server
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityBmaintenanceEnables interaction with Arcanna's AI-powered security use cases, allowing users to manage jobs and integrations, query security events, provide feedback for model training, and generate/execute Python code for security automation.
- Flicense-quality-maintenanceEnables querying Google Search Console and Google Analytics 4 data to retrieve search performance and site analytics. It provides tools for listing web properties and running detailed reports using secure Google OAuth authentication.
- Flicense-qualityDmaintenanceProvides threat intelligence tools like IoC lookups, event backtracking, and IP enrichment via MCP, enabling automated triage and evidence queries.1
- AlicenseBqualityBmaintenanceEnables LLM agents to access Google Threat Intelligence data, including IOC search, file/domain/IP/URL analysis, and threat hunting rulesets, for security investigations.36Apache 2.0
Related MCP Connectors
Query and retrieve information about various adversarial tactics and techniques used in cyber atta…
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Search and analyze global news coverage and US TV transcripts via the GDELT Project APIs.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mcpflow/mcp-secops-v3'
If you have feedback or need assistance with the MCP directory API, please join our Discord server