SecOps-MCP-Server
Google SecOps (Chronicle) MCP 服务器(可流式 HTTP)
企业级模型上下文协议(MCP)服务器,使用可流式 HTTP(streamable-http)传输——当前 MCP 规范标准——提供 Google SecOps (Chronicle) SIEM/SOAR 遥测、告警分类、通用数据模型(UDM)搜索和 YARA-L 检测规则管理。
🌟 概述:可流式 HTTP 传输
可流式 HTTP 是模型上下文协议(MCP)服务器的标准远程传输方式:
统一端点(
/mcp):用于客户端到服务器消息传递、工具发现和双向通信的单一端点。生产级可扩展性:无缝部署到无状态和容器化平台,如 Google Cloud Run。
容器健康检查:内置
/healthz存活和就绪探针。企业级安全:原生 Google Cloud IAM 认证(
roles/run.invoker),支持 OAuth2/OIDC 令牌。
Related MCP server: openobserve-community-mcp
🛠️ 已实现的 SecOps 工具(全部 29 个官方工具)
1. 安全调查与告警工具
search_security_events:通过自然语言或 UDM 查询搜索 SecOps 事件。get_security_alerts:按严重级别(CRITICAL、HIGH等)和状态检索告警。get_security_alert_by_id:获取详细的告警元数据和 MITRE ATT&CK 映射。do_update_security_alert:更新分类状态并附加分析人员备注。lookup_entity:针对 IP、域名、主机名、用户或哈希的 360 度风险遥测配置文件。get_ioc_matches:在回看窗口内检索入侵指标匹配项。get_threat_intel:查询 SecOps SecLM 威胁情报洞察。
2. 检测规则管理
list_security_rules:列出自定义和预置的 YARA-L 检测规则。search_security_rules:使用正则表达式模式或关键词搜索检测规则。get_rule_detections:检索由特定规则触发的检测结果。list_rule_errors:列出规则的执行或编译错误。create_rule:创建新的 YARA-L 2.0 检测规则。test_rule:针对历史遥测数据回测检测规则。validate_rule:验证 YARA-L 定义的语法和结构。
3. 日志接入工具
ingest_raw_log:接入原始日志负载(JSON、XML、CEF、syslog)。ingest_udm_events:接入结构化通用数据模型事件。get_available_log_types:枚举支持的日志类型(Cloud Audit、EDR、Okta、Zscaler 等)。
4. 解析器管理工具
create_parser:创建自定义日志解析器(CBN 语法)。get_parser:检索解析器配置和过滤代码。activate_parser:激活解析器以进行实时接入处理。deactivate_parser:停用已激活的解析器。run_parser_against_sample_logs:针对示例日志字符串测试解析器规则。
5. 数据表与参考列表
create_data_table/add_rows_to_data_table/list_data_table_rows/delete_data_table_rowscreate_reference_list/get_reference_list/update_reference_list
🚀 快速入门:本地运行
1. 安装依赖项
pip install -r requirements.txt2. 启动服务器
export PORT=8080
export HOST=0.0.0.0
python server.py现在可流式 HTTP 服务器可通过以下地址访问:
可流式 HTTP 端点:
http://localhost:8080/mcp健康检查探针:
http://localhost:8080/healthz
☁️ 一键部署到 Google Cloud Run
使用自动化部署脚本直接部署:
chmod +x deploy.sh
./deploy.sh执行的部署步骤:
【步骤 1/5】自定义变量:加载
.env文件并合并自定义变量。【步骤 2/5】启用 API:启用 Cloud Run、Cloud Build 和 Chronicle API。
【步骤 3/5】Cloud Run 部署:部署带有可流式 HTTP 传输的容器。
【步骤 4/5】IAM 策略绑定:向代理运行器服务账号和当前用户授予
roles/run.invoker角色。【步骤 5/5】验证:检查
/healthz探针并打印端点 URL。
🧪 测试与检查
选项 A:运行测试套件
python3 test_client.py选项 B:使用 MCP 检查器 UI
启动官方模型上下文协议检查器:
npx -y @modelcontextprotocol/inspector通过 HTTP 传输连接到 http://localhost:8080/mcp。
选项 C:通过 Google ADK / GenAI 代理连接
在代理配置中设置环境变量:
export SECOPS_MCP_URL="https://<your-cloud-run-service-url>/mcp"This server cannot be deployed
Maintenance
Related MCP Connectors
Syslog receiver and MCP server for homelab log intelligence.
Syslog receiver and MCP server for homelab log intelligence.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
MCP server for Statsig API - interact with Statsig's feature flags, experiments, and analytics
Related MCP Servers
- AlicenseCqualityDmaintenanceMCP server for Microsoft Sentinel. Enables access to Sentinel logs, incidents, analytics, and Entra ID data via a modular, queryable interface. Strictly non-production. Designed for use with Claude and other LLMs.4918MIT
- AlicenseBqualityCmaintenanceA read-only MCP server for OpenObserve Community Edition that works over the REST API. Provides tools for searching logs, traces, stream schemas, and dashboards - no Enterprise license required.894 PyPI16GPL 3.0
- AlicenseAqualityBmaintenanceComprehensive MITRE ATT\&CK MCP server with SOC integration for technique lookup, alert mapping, and coverage analysis.2619 npm4MIT
- AlicenseAqualityAmaintenanceMCP server for Malcolm (Zeek/Suricata/Arkime/OpenSearch/NetBox): full read surface plus opt-in, audited write tools.5192 PyPI3MIT