Chronicle Security Operations

by emeryray2002

4 stars
Not rated
GitHub

About

Integrates with Google's Chronicle Security Operations suite to enable security analysis tasks including event searches, alert retrieval, entity lookups, detection rule listing, and IoC matching for threat hunting and incident investigation.

Details

Author
emeryray2002
GitHub stars
4
Categories
Cloud Service, Security, Other, Infrastructure, Productivity, Developer Tools, Design, AI, Search, Frontend
Tags
#integration

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Chronicle Security Operations
    Command (node, npx, python, etc.) npx
    Arguments
    • Argument 1 -y
    • Argument 2 @highlight/mcp-server

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "chronicle security operations": {
            "env": {},
            "args": [
                "-y",
                "@highlight/mcp-server"
            ],
            "command": "npx"
        }
    }
}

Linux

{
    "env": [],
    "args": [
        "-y",
        "@highlight/mcp-server"
    ],
    "command": "npx"
}

Macos

{
    "env": [],
    "args": [
        "-y",
        "@highlight/mcp-server"
    ],
    "command": "npx"
}

Windows

{
    "env": [],
    "args": [
        "/c",
        "npx",
        "-y",
        "@highlight/mcp-server"
    ],
    "command": "cmd"
}

Access Google's security products and services, including Chronicle, SOAR, Threat Intelligence (GTI), and Security Command Center (SCC).

Interact with Binalyze AIR's digital forensics and incident response capabilities using natural language.

AI-powered security operations with Wazuh SIEM + Claude Desktop. Natural language threat detection, automated incident response & compliance.

This AWS Labs Model Context Protocol (MCP) server for CloudTrail enables your AI agents to query AWS account activity for security investigations, compliance auditing, and operational troubleshooting.

Interact with the RAD Security platform which provides AI-powered security insights for Kubernetes and cloud environments.

Provides a unified interface to AWS services for security investigations and incident response.

Behavioral trust scoring for MCP servers and AI agents. Live registry tracking 4,500+ servers with trust scores based on interaction history, success rates, and latency.

Enables AI assistants to interact with Fleet Device Management for device management, security monitoring, and compliance enforcement.

Administer Google Workspace using the GAM command-line tool.

An MCP server for accessing Google Cloud Logging data and services.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.