SecOps-MCP-Server
Google SecOps (Chronicle) MCP Server (Streamable HTTP)
エンタープライズ向けModel Context Protocol (MCP)サーバーで、Google SecOps (Chronicle) SIEM/SOARテレメトリ、アラートトリアージ、Universal Data Model (UDM)検索、YARA-L検出ルール管理を提供します。トランスポートにはStreamable HTTP(streamable-http)を使用しています。これは現在のMCP仕様標準です。
🌟 概要: Streamable HTTP Transport
統合エンドポイント(
/mcp): クライアントからサーバーへのメッセージング、ツールの検出、双方向通信のための単一エンドポイント。本番スケーラビリティ: Google Cloud Runのようなステートレスおよびコンテナ化プラットフォームにシームレスにデプロイ可能。
コンテナヘルスプローブ: 組み込みの
/healthzlivenessプローブおよびreadinessプローブ。エンタープライズセキュリティ: OAuth2/OIDCトークンサポートによるネイティブなGoogle Cloud IAM認証(
roles/run.invoker)。
Related MCP server: openobserve-community-mcp
🛠️ 実装済みのSecOpsツール(全29の公式ツール)
1. セキュリティ調査およびアラートツール
search_security_events: 自然言語またはUDMクエリを使用してSecOpsイベントを検索します。get_security_alerts: 重大度(CRITICAL、HIGHなど)とステータスでフィルタリングされたアラートを取得します。get_security_alert_by_id: 詳細なアラートメタデータとMITRE ATT&CKマッピングを取得します。do_update_security_alert: トリアージステータスを更新し、アナリストノートを追加します。lookup_entity: IP、ドメイン、ホスト名、ユーザー、ハッシュの360度リスクテレメトリプロファイル。get_ioc_matches: ルックバックウィンドウ内の侵害指標(IoC)マッチを取得します。get_threat_intel: SecOps SecLM脅威インテリジェンスインサイトをクエリします。
2. 検出ルール管理
list_security_rules: カスタムおよびキュレーションされたYARA-L検出ルールを一覧表示します。search_security_rules: 正規表現パターンまたはキーワードを使用して検出ルールを検索します。get_rule_detections: 特定のルールによってトリガーされた検出結果を取得します。list_rule_errors: ルールの実行エラーまたはコンパイルエラーを一覧表示します。create_rule: 新しいYARA-L 2.0検出ルールを作成します。test_rule: 過去のテレメトリに対して検出ルールをバックテストします。validate_rule: YARA-L定義の構文と構造を検証します。
3. ログ取り込みツール
ingest_raw_log: 生のログペイロード(JSON、XML、CEF、syslog)を取り込みます。ingest_udm_events: 構造化されたUniversal Data Modelイベントを取り込みます。get_available_log_types: サポートされているログタイプ(Cloud Audit、EDR、Okta、Zscalerなど)を列挙します。
4. パーサー管理ツール
create_parser: カスタムログパーサー(CBN構文)を作成します。get_parser: パーサー設定とフィルタリングコードを取得します。activate_parser: ライブ取り込み処理のためにパーサーをアクティブ化します。deactivate_parser: アクティブなパーサーを非アクティブ化します。run_parser_against_sample_logs: サンプルログ文字列に対してパーサールールをテストします。
5. データテーブルと参照リスト
create_data_table/add_rows_to_data_table/list_data_table_rows/delete_data_table_rowscreate_reference_list/get_reference_list/update_reference_list
🚀 クイックスタート: ローカルで実行
1. 依存関係のインストール
pip install -r requirements.txt2. サーバーの起動
export PORT=8080
export HOST=0.0.0.0
python server.pyStreamable HTTPサーバーは以下のURLでアクセス可能です:
Streamable HTTPエンドポイント:
http://localhost:8080/mcpヘルスプローブ:
http://localhost:8080/healthz
☁️ Google Cloud Runへのワンクリックデプロイ
自動デプロイスクリプトを使用して直接デプロイ:
chmod +x deploy.sh
./deploy.sh実行されるデプロイ手順:
[Step 1/5] カスタム変数:
.envファイルを読み込み、カスタム変数をマージします。[Step 2/5] APIの有効化: Cloud Run、Cloud Build、Chronicle APIを有効化します。
[Step 3/5] Cloud Runデプロイ: Streamable HTTPトランスポートを使用してコンテナをデプロイします。
[Step 4/5] IAMポリシーバインディング: エージェントランナーサービスアカウントとアクティブユーザーに
roles/run.invokerを付与します。[Step 5/5] 検証:
/healthzプローブをチェックし、エンドポイントURLを出力します。
🧪 テストと検査
オプションA: テストスイートの実行
python3 test_client.pyオプションB: MCPインスペクターUIの使用
公式のModel Context Protocolインスペクターを起動:
npx -y @modelcontextprotocol/inspectorHTTPトランスポートを使用してhttp://localhost:8080/mcpに接続します。
オプションC: Google ADK / GenAIエージェント経由で接続
エージェント設定で環境変数を設定:
export SECOPS_MCP_URL="https://<your-cloud-run-service-url>/mcp"This server cannot be deployed
Maintenance
Related MCP Connectors
Syslog receiver and MCP server for homelab log intelligence.
Syslog receiver and MCP server for homelab log intelligence.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
MCP server for Statsig API - interact with Statsig's feature flags, experiments, and analytics
Related MCP Servers
- AlicenseCqualityDmaintenanceMCP server for Microsoft Sentinel. Enables access to Sentinel logs, incidents, analytics, and Entra ID data via a modular, queryable interface. Strictly non-production. Designed for use with Claude and other LLMs.4918MIT
- AlicenseBqualityCmaintenanceA read-only MCP server for OpenObserve Community Edition that works over the REST API. Provides tools for searching logs, traces, stream schemas, and dashboards - no Enterprise license required.894 PyPI16GPL 3.0
- AlicenseAqualityBmaintenanceComprehensive MITRE ATT\&CK MCP server with SOC integration for technique lookup, alert mapping, and coverage analysis.2619 npm4MIT
- AlicenseAqualityAmaintenanceMCP server for Malcolm (Zeek/Suricata/Arkime/OpenSearch/NetBox): full read surface plus opt-in, audited write tools.5192 PyPI3MIT