Can AI agents automate Google Security Operations?
Google · saas · enterpriseobservability
Google Security Operations is automatable today through Chronicle REST APIs and a Google-hosted remote MCP server. This record is SecOps SIEM and SOAR (formerly Chronicle), not Cloud Logging, Cloud Monitoring, Microsoft Sentinel, IBM QRadar, or CrowdStrike Falcon. The Chronicle API publishes REST resources under v1beta for instances, cases, alerts, events, feeds, rules, integrations, and related SOAR objects. The hosted MCP server is enabled with gcloud beta services mcp enable chronicle.googleapis.com/mcp and reached at https://chronicle.REGION.rep.googleapis.com/mcp. Callers authenticate with Application Default Credentials and a Bearer access token, need roles/mcp.toolUser, and must send customer id, region, and project id on requests. SIEM tools are available without migration. SOAR tools require Chronicle API migration away from legacy SOAR APIs. The google/mcp-security repository also ships local SecOps, SOAR, Threat Intelligence, and Security Command Center servers; Google recommends the remote server. Connector catalogs were not opened. Computer-use viability is unassessed. API scores 8 and is the best path because Chronicle REST does not depend on MCP enablement. MCP scores 7: official hosted coverage with IAM and SOAR-migration gates.
Best path today: api · Overall automatability: 8/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | restoauth2 coverage: partial · docs |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | yes | yara-lsoar-playbooks webhooks: unknown |
| Data access | export: json · import: unknown | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. Chronicle REST, the hosted SecOps MCP endpoint, and playbook automation cover SIEM and SOAR work without browser control of the SecOps console. This record is not Google Cloud as a whole-cloud identity.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 8 | 7 | — | — | — | — | 8 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-15 |
license | declared | source | 2026-09-15 |
platforms | declared | source | 2026-09-15 |
modalities.api.exists | declared | source | 2026-09-15 |
modalities.api.kinds[0] | declared | source | 2026-09-15 |
modalities.api.auth[0] | declared | source | 2026-09-15 |
modalities.api.coverage | declared | source | 2026-09-15 |
modalities.api.docs | declared | source | 2026-09-15 |
modalities.mcp.first_party | declared | source | 2026-09-15 |
modalities.mcp.verdict | declared | source | 2026-09-15 |
modalities.extensibility.scripting[0] | declared | source | 2026-09-15 |
modalities.extensibility.scripting[1] | declared | source | 2026-09-15 |
modalities.data_access.export[0] | declared | source | 2026-09-15 |
verdict.scores.api | declared | source | 2026-09-15 |
verdict.scores.mcp | declared | source | 2026-09-15 |
freshness.watch[0].url | declared | source | 2026-09-15 |
freshness.watch[1].url | declared | source | 2026-09-15 |
freshness.watch[2].url | declared | source | 2026-09-15 |
freshness.watch[3].url | declared | source | 2026-09-15 |
Related tools
Other products in this database that share a category with Google Security Operations.
Last verified 2026-09-15 · volatility high · JSON record