Google Security Operations MCP
Five specialized servers covering the full security operations stack — from threat hunting to SOC automation — officially maintained by Google Cloud.
Official Google Cloud suite of 5 MCP servers: Chronicle SIEM, SecOps SOAR (case management and playbooks), Google Threat Intelligence, Security Command Center, and a managed remote enterprise option.
- Search your security logs for suspicious login attempts
- Get a summary of active security alerts across your cloud environment
- Investigate a potential data breach using threat intelligence
Five specialized servers covering the full security operations stack — from threat hunting to SOC automation — officially maintained by Google Cloud. Apache-2.0 license.
Security-focused consulting engagements on GCP where the client uses Chronicle, SecOps, or needs cloud security posture management.
https://github.com/google/mcp-security
By Google Cloud
How to Get It
uv tool install google-secops-mcp && uv tool install gti-mcp && uv tool install scc-mcp && uv tool install secops-soar-mcp
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Once it’s connected, paste this into Claude:
Help me search my security logs for suspicious login attempts
Trust Signals Auto-scanned
Data & Access
Community Pulse Active
Discussed on Hacker News, Reddit
- MCP Security is still Broken — Reddit · 345 pts
- MCP is a security joke — Reddit · 328 pts
- MCP Security Flaws: What Developers Need to Know — Reddit · 286 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 505 GitHub stars; 34 contributors; last commit 33d ago; license Apache-2.0.
Things to check
- Requires existing Google Cloud environment and familiarity with Chronicle, SecOps, and SCC APIs; five separate servers increase deployment and maintenance complexity. Limited value for organizations not using Google Cloud's security tooling.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 505 GitHub stars; 34 contributors; last commit 33d ago; license Apache-2.0.