Google Security MCP Servers

repository·main·Indexed 19 days ago

https://github.com/google/mcp-security

Model Context Protocol (MCP) servers that enable AI clients, such as Claude Desktop and Cline, to interact with Google's security ecosystem. Supported services include Chronicle SecOps (google-secops-mcp), Google Threat Intelligence (gti-mcp), Security Command Center (scc-mcp), and SecOps SOAR (secops-soar-mcp).

Tokens
436.2K
Snippets
658
Records
2K
Agent score
63%

What's inside google-mcp-security

  1. Overview of Chronicle SecOps MCP Server

    main
    The Chronicle SecOps MCP Server is a Model Context Protocol (MCP) server designed to allow AI models and MCP clients to interact with Google's Chronicle Security Operations suite. It provides a standardized interface for managing security tools, log ingestion, parsers, data tables, and investigation workflows.
  2. Overview of the Endgame Integration

    main

    The Endgame integration for the SecOps SOAR MCP server enables connection to Endgame to perform security operations and threat hunting. Supported capabilities include:

    • Host Management: Isolating or unisolating hosts and managing IP subnet configurations for host isolation.
    • Threat Hunting: Hunting for users, processes, files, IPs, and registry keys.
    • System Investigation: Collecting autoruns, performing system surveys, and retrieving investigation details.
    • Endpoint Actions: Killing processes, downloading or deleting files, and listing investigations and endpoints.
  3. Overview of QRadar Integration for Chronicle SOAR

    main

    The IBM QRadar integration allows Chronicle SOAR to interact with the QRadar SIEM platform for investigation and enrichment. It provides capabilities to query event and flow data, manage reference data, and handle offenses.

    Key capabilities include:

    • AQL Query Execution: Running Ariel Query Language (AQL) searches against QRadar event and flow data.
    • Reference Data Management: Interacting with QRadar reference sets, maps, and tables used for lookups and correlation.
    • Offense Management: Retrieving offense details, updating statuses, adding notes, and assigning offenses.
    • Entity Enrichment: Querying related QRadar data to enrich SOAR entities.
    • Rule Intelligence: Retrieving QRadar rule details and MITRE ATT&CK mappings via the Use Case Manager.
  4. Overview of the Exchange Integration

    main

    The Exchange Integration enables connection to Microsoft Exchange to automate email-related security and operational tasks. Supported capabilities include:

    • Email Management: Sending emails (plain text, HTML, and vote mails), searching for emails, moving emails, and extracting EML data.
    • Inbox & Rule Management: Managing inbox rules (adding/removing domains or senders, listing, and deleting rules) and managing Out Of Facility (OOF) settings.
    • Security Actions: Blocking or unblocking senders by Message ID.
    • Communication: Sending thread replies and handling vote mail results.
    • Authentication: Managing OAuth authentication tokens.
  5. Overview of Google MCP Security Servers

    main

    The mcp-security project provides Model Context Protocol (MCP) servers that allow AI assistants (like Claude) to interact with Google's security ecosystem. There are four primary server types available:

    1. Google Security Operations (Chronicle) (google-secops-mcp): Used for threat detection, investigation, and hunting.
    2. Google Security Operations SOAR (secops-soar-mcp): Used for security orchestration, automation, and response.
    3. Google Threat Intelligence (GTI) (gti-mcp): Provides access to threat intelligence data regarding IoCs, malware, and threat actors.
    4. Security Command Center (SCC) (scc-mcp): Used for managing cloud security posture and vulnerabilities.

    Developers can choose between using a Remote MCP Server (fully managed and enterprise-ready for Google SecOps) or running the individual servers locally.

  6. Overview of the Jira integration for SecOps SOAR MCP

    main
    The Jira integration for the secops-soar-mcp server provides a set of tools to interact with a Jira instance. It enables automated or agentic management of issues, users, and attachments, facilitating seamless workflows between Security Operations and Jira ticketing.
  7. Overview of VMware Carbon Black Cloud Integration

    main

    The VMware Carbon Black Cloud integration for Chronicle SOAR enables security teams to interact with the Carbon Black Cloud platform directly from SOAR playbooks. It provides capabilities across endpoint detection and response (EDR), next-generation antivirus (NGAV), audit and remediation, and vulnerability management.

    Key capabilities include:

    • Query Endpoint Activity: Search for processes, network connections, file modifications, and other endpoint events.
    • Manage Alerts: Retrieve, update, and dismiss alerts generated by Carbon Black Cloud.
    • Endpoint Response: Quarantine/unquarantine devices, manage bypass modes, update policies, and initiate scans.
    • Reputation Management: List, create, and delete reputation overrides (block/allow lists) for hashes, certificates, and IT tools.
    • Vulnerability Management: List vulnerabilities associated with specific hosts.
    • Enrichment: Gather detailed information about endpoints (devices) and alerts.
  8. Overview of CB Response Integration

    main

    The CB Response integration connects the Chronicle SecOps SOAR platform to VMware Carbon Black EDR (formerly CB Response). It enables automated management of endpoints, processes, binaries, and alerts through the SOAR platform.

    Key capabilities include:

    • Host management (Isolate/Unisolate)
    • Hash management (Block/Unblock)
    • Entity enrichment (Process and Binary enrichment)
    • Querying (Hosts by process, Process free query)
    • Alert and watchlist management