{
 "categories": [
  "enterprise",
  "observability"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-15",
   "fact": "homepage",
   "note": "Google presents Security Operations as a cloud-native SIEM, SOAR, and threat-intelligence platform sold in Standard, Enterprise, and Enterprise Plus packages.",
   "source": "https://cloud.google.com/security/products/security-operations",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "license",
   "note": "Pricing is package-based and listed as contact sales. SecOps is a commercial Google Cloud security product.",
   "source": "https://cloud.google.com/security/products/security-operations",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "platforms",
   "note": "Google documents SecOps as a hosted analyst console for detection, investigation, and response. The opened page is a web product, not a desktop agent.",
   "source": "https://cloud.google.com/security/products/security-operations",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.api.exists",
   "note": "Google publishes the Chronicle API as REST resources that help analysts investigate and mitigate security threats.",
   "source": "https://cloud.google.com/chronicle/docs/reference/rest",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.api.kinds[0]",
   "note": "The reference lists REST resources under v1beta, including instances, cases, alerts, events, feeds, and integrations.",
   "source": "https://cloud.google.com/chronicle/docs/reference/rest",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.api.auth[0]",
   "note": "Google documents Application Default Credentials and Authorization: Bearer access tokens for the hosted SecOps MCP endpoint, with curl using gcloud auth application-default print-access-token. The ADK sample uses google.auth.default with the chronicle OAuth scope.",
   "source": "https://google.github.io/mcp-security/remote_server.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.api.coverage",
   "note": "REST coverage includes cases, alerts, events, feeds, rules-related resources, and SOAR integrations. The page does not claim the entire SecOps UI.",
   "source": "https://cloud.google.com/chronicle/docs/reference/rest",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.api.docs",
   "note": "Opened Google's current Chronicle API REST reference landing page.",
   "source": "https://cloud.google.com/chronicle/docs/reference/rest",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.mcp.first_party",
   "note": "Google lists Google Security Operations as its own remote MCP product at https://chronicle.REGION.rep.googleapis.com/mcp, separate from Cloud Logging and Cloud Monitoring.",
   "source": "https://docs.cloud.google.com/mcp/supported-products",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.mcp.verdict",
   "note": "Google documents a fully managed remote MCP server for SecOps that uses Chronicle REST APIs (OneMCP). SIEM tools are available immediately; SOAR tools require Chronicle API migration.",
   "source": "https://google.github.io/mcp-security/remote_server.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Google documents custom detection authoring in YARA-L and playbook automation for SOAR response actions.",
   "source": "https://cloud.google.com/security/products/security-operations",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.extensibility.scripting[1]",
   "note": "The same product page documents SOAR playbooks that orchestrate response actions across integrations.",
   "source": "https://cloud.google.com/security/products/security-operations",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "modalities.data_access.export[0]",
   "note": "The hosted MCP curl example calls tools/call list_rules and accepts application/json. Chronicle REST resources return JSON resource documents.",
   "source": "https://google.github.io/mcp-security/remote_server.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "verdict.scores.api",
   "note": "Chronicle REST is a documented v1beta management and investigation surface. Beta resource paths and tenant customer-id/region context keep the path below unusual completeness.",
   "source": "https://cloud.google.com/chronicle/docs/reference/rest",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "verdict.scores.mcp",
   "note": "The official hosted server is useful for SIEM search, rules, alerts, and feeds. SOAR tools need API migration, and callers need roles/mcp.toolUser plus customer id. That is official-useful rather than unusually complete.",
   "source": "https://google.github.io/mcp-security/remote_server.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as Google's current remote SecOps MCP setup page, including chronicle.REGION.rep.googleapis.com/mcp and SIEM versus SOAR migration notes.",
   "source": "https://google.github.io/mcp-security/remote_server.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current supported MCP products table with the Google Security Operations row, last updated 2026-09-14 UTC.",
   "source": "https://docs.cloud.google.com/mcp/supported-products",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current Chronicle API REST reference.",
   "source": "https://cloud.google.com/chronicle/docs/reference/rest",
   "tier": "declared"
  },
  {
   "date": "2026-09-15",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as the current google/mcp-security README. It recommends the remote SecOps server and also documents local SecOps, SOAR, GTI, and SCC servers.",
   "source": "https://raw.githubusercontent.com/google/mcp-security/main/README.md",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-15",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://google.github.io/mcp-security/remote_server.html"
   },
   {
    "type": "mcp",
    "url": "https://docs.cloud.google.com/mcp/supported-products"
   },
   {
    "type": "docs",
    "url": "https://cloud.google.com/chronicle/docs/reference/rest"
   },
   {
    "type": "mcp",
    "url": "https://raw.githubusercontent.com/google/mcp-security/main/README.md"
   }
  ]
 },
 "homepage": "https://cloud.google.com/security/products/security-operations",
 "id": "google-security-operations",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "oauth2"
   ],
   "coverage": "partial",
   "docs": "https://cloud.google.com/chronicle/docs/reference/rest",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "yara-l",
    "soar-playbooks"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Chronicle REST, the hosted SecOps MCP endpoint, and playbook automation cover SIEM and SOAR work without browser control of the SecOps console. This record is not Google Cloud as a whole-cloud identity.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Google Security Operations",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "microsoft-sentinel",
   "ibm-qradar",
   "crowdstrike-falcon"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Google",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "Google Security Operations is automatable today through Chronicle REST APIs and a Google-hosted remote MCP server. This record is SecOps SIEM and SOAR (formerly Chronicle), not Cloud Logging, Cloud Monitoring, Microsoft Sentinel, IBM QRadar, or CrowdStrike Falcon. The Chronicle API publishes REST resources under v1beta for instances, cases, alerts, events, feeds, rules, integrations, and related SOAR objects. The hosted MCP server is enabled with gcloud beta services mcp enable chronicle.googleapis.com/mcp and reached at https://chronicle.REGION.rep.googleapis.com/mcp. Callers authenticate with Application Default Credentials and a Bearer access token, need roles/mcp.toolUser, and must send customer id, region, and project id on requests. SIEM tools are available without migration. SOAR tools require Chronicle API migration away from legacy SOAR APIs. The google/mcp-security repository also ships local SecOps, SOAR, Threat Intelligence, and Security Command Center servers; Google recommends the remote server. Connector catalogs were not opened. Computer-use viability is unassessed. API scores 8 and is the best path because Chronicle REST does not depend on MCP enablement. MCP scores 7: official hosted coverage with IAM and SOAR-migration gates.\n"
 }
}