Tracecat

Google Cloud SecOps MCP server

Search UDM events, triage alerts and cases, and manage detection rules in Google SecOps (Chronicle SIEM) from your AI agents.

SIEM / datalake
http
Official docs

About

Connect Tracecat to Google SecOps to search Chronicle SIEM data from AI agents working alongside SOC analysts who use Google SecOps as their system of record. You can run a UDM search for the events behind an alert, pull the related case with its alerts and comments, and check which detection rule fired. From there, agents can enrich an entity, validate and create YARA-L rules, and add case comments, with access controlled by IAM roles in your Google Cloud project.

Setup

  1. 1

    Sign in with OAuth

    You'll authorize Tracecat to access Google Cloud SecOps on your behalf. No API keys to manage.

  2. 2

    Select the Google Cloud SecOps tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the Google Cloud SecOps tile, and complete the OAuth flow.

  3. 3

    Enable Google Cloud SecOps in your agent

    In your ai.agent action or Agents tools tab, select Google Cloud SecOps from the MCP integrations dropdown.

Tools

udm_search

Search security events in Chronicle SIEM with a UDM query over a time range.

translate_udm_query

Turn a natural language question into a UDM search query.

list_security_alerts

List security alerts from Chronicle SIEM, filtered by time range and status.

get_security_alert

Fetch one security alert by ID with its detection details.

list_cases

List SOAR cases in the Chronicle instance with priority, stage, and assignee.

get_case

Fetch one case with its tasks, tags, and products.

create_case_comment

Add a comment to a case.

summarize_entity

Look up an IP, domain, hash, or user in Chronicle SIEM for enrichment.

list_rules

List detection rules configured in Chronicle SIEM.

get_rule

Fetch the definition and metadata of one detection rule.

create_rule

Create a new YARA-L detection rule in Chronicle SIEM.

list_rule_errors

List execution errors for a detection rule.

Deploy the Google Cloud SecOps MCP server in minutes

Connect your security agents to 65+ hosted MCP servers.