#134 · Primary category: Cybersecurity & Decryption Tools

mcp-security

agentic-soc ai-agents blueteam chronicle-siem chronicle-soar cybersecurity google-cloud google-secops google-threat-intelligence incident-response mcp mcp-server model-context-protocol secops security-command-center security-operations siem soar threat-hunting threat-intelligence

Model Context Protocol servers enabling AI agents to access Google security operations, threat intelligence, and cloud security tools.

Project last updated:09/01/26

GitHub Stars

521

Forks

134

Contributors

42

License

Apache-2.0

Why we included this project

Security teams already invested in Google Cloud will find this a practical way to let AI assistants reach their security tooling directly. The repo bundles several Model Context Protocol servers that connect MCP-compatible clients like Claude Desktop to Google SecOps (Chronicle), SOAR, Threat Intelligence, and Security Command Center, so an analyst can run queries and hunts without leaving the chat interface. Each server installs and runs independently via pip or uv, which helps when you only need one capability, and a fully managed remote server is available for teams that prefer not to run infrastructure. Authentication uses standard Google Application Default Credentials, so setup is familiar to anyone who works with GCP. It's a good fit for blue-team engineers and SOC analysts who want to prototype agentic workflows against their existing Google security stack instead of building custom integrations from scratch.

Articles for this project

No articles for this project yet.

To suggest a topic or contribute an article, contact us.

Related projects in this category