Google Cloud SecOps MCP server
Search UDM events, triage alerts and cases, and manage detection rules in Google SecOps (Chronicle SIEM) from your AI agents.
About
Connect Tracecat to Google SecOps to search Chronicle SIEM data from AI agents working alongside SOC analysts who use Google SecOps as their system of record. You can run a UDM search for the events behind an alert, pull the related case with its alerts and comments, and check which detection rule fired. From there, agents can enrich an entity, validate and create YARA-L rules, and add case comments, with access controlled by IAM roles in your Google Cloud project.
Setup
- 1
Sign in with OAuth
You'll authorize Tracecat to access Google Cloud SecOps on your behalf. No API keys to manage.
- 2
Select the
Google Cloud SecOpstile in the Tracecat MCP catalogOpen the
MCP catalogin your workspace, select theGoogle Cloud SecOpstile, and complete the OAuth flow. - 3
Enable
Google Cloud SecOpsin your agentIn your
ai.agentaction orAgents→toolstab, selectGoogle Cloud SecOpsfrom theMCP integrationsdropdown.
Tools
udm_searchSearch security events in Chronicle SIEM with a UDM query over a time range.
translate_udm_queryTurn a natural language question into a UDM search query.
list_security_alertsList security alerts from Chronicle SIEM, filtered by time range and status.
get_security_alertFetch one security alert by ID with its detection details.
list_casesList SOAR cases in the Chronicle instance with priority, stage, and assignee.
get_caseFetch one case with its tasks, tags, and products.
create_case_commentAdd a comment to a case.
summarize_entityLook up an IP, domain, hash, or user in Chronicle SIEM for enrichment.
list_rulesList detection rules configured in Chronicle SIEM.
get_ruleFetch the definition and metadata of one detection rule.
create_ruleCreate a new YARA-L detection rule in Chronicle SIEM.
list_rule_errorsList execution errors for a detection rule.