BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Google Security Operations MCP

Connector Security Solid
Works inClaude Code Claude Cowork Claude Chat
Solid Scanned — metadata only

Five specialized servers covering the full security operations stack — from threat hunting to SOC automation — officially maintained by Google Cloud.

Official Google Cloud suite of 5 MCP servers: Chronicle SIEM, SecOps SOAR (case management and playbooks), Google Threat Intelligence, Security Command Center, and a managed remote enterprise option.

505 starsApache-2.0 (commercial OK)FreeNo code needed
Official tool maintained by Google Cloud.

Five specialized servers covering the full security operations stack — from threat hunting to SOC automation — officially maintained by Google Cloud. Apache-2.0 license.

Security-focused consulting engagements on GCP where the client uses Chronicle, SecOps, or needs cloud security posture management.

Claude Code Claude Cowork Claude Chat

https://github.com/google/mcp-security

By Google Cloud

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
uv tool install google-secops-mcp && uv tool install gti-mcp && uv tool install scc-mcp && uv tool install secops-soar-mcp

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me search my security logs for suspicious login attempts
PrerequisitesGoogle Cloud environment with the relevant products (Chronicle/SecOps, GTI, SCC); uv/uvx; Application Default Credentials (gcloud auth application-default login) or GOOGLE_APPLICATION_CREDENTIALS; per-server env vars such as CHRONICLE_PROJECT_ID, CHRONICLE_CUSTOMER_ID, CHRONICLE_REGION, VT_APIKEY, SOAR_URL/SOAR_APP_KEYCostFree

Trust Signals Auto-scanned

Stars505Contributors36Last updated2026-06-03LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-20 · scanner vattempted-no-data

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.Connects toGoogle Cloud servers (official integration)

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 505 GitHub stars; 34 contributors; last commit 33d ago; license Apache-2.0.

Things to check

  • Requires existing Google Cloud environment and familiarity with Chronicle, SecOps, and SCC APIs; five separate servers increase deployment and maintenance complexity. Limited value for organizations not using Google Cloud's security tooling.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
4/5
Versatility
4/5
Reliability
5/5
Security
3/5
Overall score4.10 / 5.00 SolidEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 505 GitHub stars; 34 contributors; last commit 33d ago; license Apache-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →