Google Security MCP Servers
repository·main·Indexed 19 days ago
https://github.com/google/mcp-securityModel Context Protocol (MCP) servers that enable AI clients, such as Claude Desktop and Cline, to interact with Google's security ecosystem. Supported services include Chronicle SecOps (google-secops-mcp), Google Threat Intelligence (gti-mcp), Security Command Center (scc-mcp), and SecOps SOAR (secops-soar-mcp).
What's inside google-mcp-security
- The Chronicle SecOps MCP Server is a Model Context Protocol (MCP) server designed to allow AI models and MCP clients to interact with Google's Chronicle Security Operations suite. It provides a standardized interface for managing security tools, log ingestion, parsers, data tables, and investigation workflows.
Overview of the Endgame Integration
mainThe Endgame integration for the SecOps SOAR MCP server enables connection to Endgame to perform security operations and threat hunting. Supported capabilities include:
- Host Management: Isolating or unisolating hosts and managing IP subnet configurations for host isolation.
- Threat Hunting: Hunting for users, processes, files, IPs, and registry keys.
- System Investigation: Collecting autoruns, performing system surveys, and retrieving investigation details.
- Endpoint Actions: Killing processes, downloading or deleting files, and listing investigations and endpoints.
Overview of QRadar Integration for Chronicle SOAR
mainThe IBM QRadar integration allows Chronicle SOAR to interact with the QRadar SIEM platform for investigation and enrichment. It provides capabilities to query event and flow data, manage reference data, and handle offenses.
Key capabilities include:
- AQL Query Execution: Running Ariel Query Language (AQL) searches against QRadar event and flow data.
- Reference Data Management: Interacting with QRadar reference sets, maps, and tables used for lookups and correlation.
- Offense Management: Retrieving offense details, updating statuses, adding notes, and assigning offenses.
- Entity Enrichment: Querying related QRadar data to enrich SOAR entities.
- Rule Intelligence: Retrieving QRadar rule details and MITRE ATT&CK mappings via the Use Case Manager.
Overview of Microsoft Azure Sentinel Integration
mainThe Microsoft Azure Sentinel integration for the SecOps SOAR MCP server enables connection to Microsoft Azure Sentinel to perform security operations. It supports running KQL queries, managing alert and hunting rules, listing incidents, and managing incident details such as comments and labels.Overview of the Exchange Integration
mainThe Exchange Integration enables connection to Microsoft Exchange to automate email-related security and operational tasks. Supported capabilities include:
- Email Management: Sending emails (plain text, HTML, and vote mails), searching for emails, moving emails, and extracting EML data.
- Inbox & Rule Management: Managing inbox rules (adding/removing domains or senders, listing, and deleting rules) and managing Out Of Facility (OOF) settings.
- Security Actions: Blocking or unblocking senders by Message ID.
- Communication: Sending thread replies and handling vote mail results.
- Authentication: Managing OAuth authentication tokens.
Overview of Microsoft Teams Integration
mainThe Microsoft Teams integration enables interaction with Microsoft Teams to manage chats, channels, teams, users, and messages. It operates by communicating with the Microsoft Graph API.Overview of Google Cloud Compute integration
mainThe Google Cloud Compute integration provides a set of tools for interacting with Google Cloud Compute Engine. It allows for the management of virtual machine instances, firewall rules, network tags, labels, and IAM policies.Overview of Google MCP Security Servers
mainThe
mcp-securityproject provides Model Context Protocol (MCP) servers that allow AI assistants (like Claude) to interact with Google's security ecosystem. There are four primary server types available:- Google Security Operations (Chronicle) (
google-secops-mcp): Used for threat detection, investigation, and hunting. - Google Security Operations SOAR (
secops-soar-mcp): Used for security orchestration, automation, and response. - Google Threat Intelligence (GTI) (
gti-mcp): Provides access to threat intelligence data regarding IoCs, malware, and threat actors. - Security Command Center (SCC) (
scc-mcp): Used for managing cloud security posture and vulnerabilities.
Developers can choose between using a Remote MCP Server (fully managed and enterprise-ready for Google SecOps) or running the individual servers locally.
- Google Security Operations (Chronicle) (
Overview of the Jira integration for SecOps SOAR MCP
mainThe Jira integration for thesecops-soar-mcpserver provides a set of tools to interact with a Jira instance. It enables automated or agentic management of issues, users, and attachments, facilitating seamless workflows between Security Operations and Jira ticketing.Overview of VMware Carbon Black Cloud Integration
mainThe VMware Carbon Black Cloud integration for Chronicle SOAR enables security teams to interact with the Carbon Black Cloud platform directly from SOAR playbooks. It provides capabilities across endpoint detection and response (EDR), next-generation antivirus (NGAV), audit and remediation, and vulnerability management.
Key capabilities include:
- Query Endpoint Activity: Search for processes, network connections, file modifications, and other endpoint events.
- Manage Alerts: Retrieve, update, and dismiss alerts generated by Carbon Black Cloud.
- Endpoint Response: Quarantine/unquarantine devices, manage bypass modes, update policies, and initiate scans.
- Reputation Management: List, create, and delete reputation overrides (block/allow lists) for hashes, certificates, and IT tools.
- Vulnerability Management: List vulnerabilities associated with specific hosts.
- Enrichment: Gather detailed information about endpoints (devices) and alerts.
Overview of CB Live Response Integration
mainThe CB Live Response integration connects to VMware Carbon Black Cloud's Live Response feature. It enables performing remote actions directly on endpoints, specifically for file management, process management, memory dumps, and file execution.Overview of CB Response Integration
mainThe CB Response integration connects the Chronicle SecOps SOAR platform to VMware Carbon Black EDR (formerly CB Response). It enables automated management of endpoints, processes, binaries, and alerts through the SOAR platform.
Key capabilities include:
- Host management (Isolate/Unisolate)
- Hash management (Block/Unblock)
- Entity enrichment (Process and Binary enrichment)
- Querying (Hosts by process, Process free query)
- Alert and watchlist management