Skip to content

Commit a408fc5

Browse files
committed
Merge branch 'main' into bug-fix-tool-test-rule
2 parents a90f7c0 + e38909a commit a408fc5

466 files changed

Lines changed: 5272 additions & 3090 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/publish-packages.yml‎

Lines changed: 515 additions & 0 deletions
Large diffs are not rendered by default.

‎README.md‎

Lines changed: 155 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,136 @@ The server uses Google's authentication. Make sure you have either:
3232
2. Set a GOOGLE_APPLICATION_CREDENTIALS environment variable
3333
3. Used `gcloud auth application-default login`
3434

35+
## Standalone Usage
36+
37+
Each MCP server can be installed and used as a standalone package.
38+
39+
### Installation
40+
41+
You can install the packages using `uv tool install` (recommended):
42+
43+
```bash
44+
# Install packages
45+
uv tool install google-secops-mcp
46+
uv tool install gti-mcp
47+
uv tool install scc-mcp
48+
uv tool install secops-soar-mcp
49+
```
50+
51+
Alternatively, you can use pip:
52+
53+
```bash
54+
pip install google-secops-mcp
55+
pip install gti-mcp
56+
pip install scc-mcp
57+
pip install secops-soar-mcp
58+
```
59+
60+
### Running Standalone
61+
62+
After installation, you can run the servers directly using uvx:
63+
64+
```bash
65+
# Run SecOps MCP server
66+
uvx --from google-secops-mcp secops_mcp
67+
68+
# Run GTI MCP server
69+
uvx gti_mcp
70+
71+
# Run SCC MCP server
72+
uvx scc_mcp
73+
74+
# Run SecOps SOAR MCP server (with optional integrations)
75+
uvx secops_soar_mcp --integrations CSV,OKTA
76+
```
77+
78+
With environment variables:
79+
80+
```bash
81+
CHRONICLE_PROJECT_ID="your-project-id" \
82+
CHRONICLE_CUSTOMER_ID="01234567-abcd-4321-1234-0123456789ab" \
83+
CHRONICLE_REGION="us" \
84+
uvx secops_mcp
85+
```
86+
87+
### Using with MCP Clients (Recommended)
88+
89+
You can configure MCP clients to use the installed packages with uvx. Here's an example configuration:
90+
91+
```json
92+
{
93+
"mcpServers": {
94+
"secops": {
95+
"command": "uvx",
96+
"args": [
97+
"--from",
98+
"google-secops-mcp",
99+
"secops_mcp"
100+
],
101+
"env": {
102+
"CHRONICLE_PROJECT_ID": "your-project-id",
103+
"CHRONICLE_CUSTOMER_ID": "01234567-abcd-4321-1234-0123456789ab",
104+
"CHRONICLE_REGION": "us"
105+
},
106+
"disabled": false,
107+
"autoApprove": []
108+
},
109+
"gti": {
110+
"command": "uvx",
111+
"args": [
112+
"gti_mcp"
113+
],
114+
"env": {
115+
"VT_APIKEY": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"
116+
},
117+
"disabled": false,
118+
"autoApprove": []
119+
},
120+
"scc-mcp": {
121+
"command": "uvx",
122+
"args": [
123+
"scc_mcp"
124+
],
125+
"env": {},
126+
"disabled": false,
127+
"autoApprove": []
128+
},
129+
"secops-soar": {
130+
"command": "uvx",
131+
"args": [
132+
"secops_soar_mcp",
133+
"--integrations",
134+
"CSV,OKTA"
135+
],
136+
"env": {
137+
"SOAR_URL": "https://yours-here.siemplify-soar.com:443",
138+
"SOAR_APP_KEY": "01234567-abcd-4321-1234-0123456789ab"
139+
},
140+
"disabled": false,
141+
"autoApprove": []
142+
}
143+
}
144+
}
145+
```
146+
147+
You can also use environment files with uvx:
148+
149+
```json
150+
{
151+
"mcpServers": {
152+
"secops": {
153+
"command": "uvx",
154+
"args": [
155+
"--env-file",
156+
"/path/to/.env",
157+
"secops_mcp"
158+
],
159+
"disabled": false
160+
}
161+
}
162+
}
163+
```
164+
35165
## Client Configurations
36166
The MCP servers from this repo can be used with the following clients
37167
1. Cline, Claude Desktop, and other MCP supported clients
@@ -43,6 +173,31 @@ The configuration for Claude Desktop and Cline is the same (provided below for [
43173

44174
Please refer to the [README file](./run-with-google-adk/README.md) for both - locally running the prebuilt agent and [Cloud Run](https://cloud.google.com/run) deployment.
45175

176+
## MCP Client Config Locations
177+
178+
MCP clients all use the same JSON configuration format (see the [MCP Server Configuration Reference](https://google.github.io/mcp-security/usage_guide.html#mcp-server-configuration-reference)), but they expect the file in different locations.
179+
180+
| Client Application | Scope | macOS / Linux Location | Windows Location | Notes |
181+
| ------------------------ | --------- | ------------------------------------- | ----------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
182+
| **Gemini CLI** | Global | `~/.gemini/settings.json` | `%USERPROFILE%\.gemini\settings.json` | File must include `mcpServers`. Confirmed in [Google Security Ops post](https://security.googlecloudcommunity.com/google-security-operations-2/google-cloud-security-mcp-servers-in-gemini-cli-922). |
183+
| **Claude Desktop** | Global | `~/Claude/claude_desktop_config.json` | `%USERPROFILE%\Claude\claude_desktop_config.json` | Config accessible via *Claude > Settings > Developer > Edit Config*. |
184+
| **Claude Code** | Global | `~/.claude.json` | `%USERPROFILE%\.claude.json` | Primary config file for Claude Code CLI and extensions. |
185+
| **Cursor IDE (Global)** | Global | `~/.cursor/mcp.json` | `%USERPROFILE%\.cursor\mcp.json` | Enables MCP servers globally across all projects. |
186+
| **Cursor IDE (Project)** | Project | `<project-root>/.cursor/mcp.json` | `<project-root>/.cursor/mcp.json` | Workspace/project-specific config file. |
187+
| **VS Code (Workspace)** | Workspace | `<project-root>/.vscode/mcp.json` | `<project-root>/.vscode/mcp.json` | Workspace-level config used when an MCP extension (like **Cline**) is installed. Overrides global config if present. |
188+
| **Cline (VS Code Ext.)** | Global | Inside VS Code extension data | `%APPDATA%\Code\User\globalStorage\<extension-id>\settings\cline_mcp_settings.json` | Exact path varies by VS Code variant and platform. `<extension-id>` corresponds to the installed extension folder (e.g., `saoudrizwan.claude-dev`). |
189+
190+
### Additional Notes for Windows
191+
192+
- `%USERPROFILE%` → `C:\Users\<username>`
193+
- `%APPDATA%` → `C:\Users\<username>\AppData\Roaming`
194+
- `<project-root>` → folder opened in VS Code or IDE for the project
195+
- `<extension-id>` → name of the installed extension folder (e.g., `saoudrizwan.claude-dev` for Claude/Cline)
196+
197+
### Tip: Single Config with Symlinks
198+
199+
If you use multiple MCP clients, you can maintain a **single config file** and symlink it into each expected location. This avoids drift and keeps your server definitions consistent.
200+
46201

47202
### Using uv (Recommended)
48203

‎docs/soar_integrations/active_directory.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ Get the members list of the provided group name in Active Directory
1313
* `case_id` (str, required): The ID of the case.
1414
* `alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
1515
* `group_name` (str, required): Specify whether the name of the group of which you would like to list down the group members.
16-
* `members_type` (List[Any], required): Specify the member type of the group.
16+
* `members_type` (List[str], required): Specify the member type of the group.
1717
* `perform_nested_search` (bool, required): Specify whether the action should fetch additional details regarding groups found in the main group.
1818
* `limit` (str, required): Specify the maximum number of listings to fetch from Active Directory
1919
* `target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.

‎docs/soar_integrations/algo_sec.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ List available templates in AlgoSec.
1212

1313
* `case_id` (str, required): The ID of the case.
1414
* `alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
15-
* `filter_logic` (Optional[List[Any]], optional, default=None): Specify what filter logic should be applied.
15+
* `filter_logic` (Optional[List[str]], optional, default=None): Specify what filter logic should be applied.
1616
* `filter_value` (Optional[str], optional, default=None): Specify what value should be used in the filter. If "Equal" is selected, action will try to find the exact match among record types and if "Contains" is selected, action will try to find items that contain that substring. If nothing is provided in this parameter, the filter will not be applied.
1717
* `max_templates_to_return` (Optional[str], optional, default=None): Specify how many templates to return. Default: 50.
1818
* `target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.

‎docs/soar_integrations/amazon_macie.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ List Amazon Macie findings based on the specified action input parameters. Note
3030
* `include_archived_findings` (Optional[bool], optional, default=None): Specify whether to include archived findings in results or not.
3131
* `record_limit` (Optional[str], optional, default=None): Specify how many records can be returned by the action.
3232
* `sort_by` (Optional[str], optional, default=None): Specify a parameter for sorting the data, eg updatedAt
33-
* `sort_order` (Optional[List[Any]], optional, default=None): Sort order.
33+
* `sort_order` (Optional[List[str]], optional, default=None): Sort order.
3434
* `target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.
3535
* `scope` (str, optional, default="All entities"): Defines the scope for the action.
3636

‎docs/soar_integrations/anomali.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ Enrich entities using information from Anomali ThreatStream. Supported entities:
1313
* `case_id` (str, required): The ID of the case.
1414
* `alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
1515
* `limit` (str, required): Specify how many records to return per entity.
16-
* `severity_threshold` (Optional[List[Any]], optional, default=None): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
16+
* `severity_threshold` (Optional[List[str]], optional, default=None): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
1717
* `confidence_threshold` (Optional[str], optional, default=None): Specify what should be the confidence threshold for the entity, in order to mark it as suspicious. Note: Maximum is 100. If multiple records are found for the entity, action will take the average. Active records have priority. Default: 50.
1818
* `ignore_false_positive_status` (Optional[bool], optional, default=None): If enabled, action will ignore the false positive status and mark the entity as suspicious based on the "Severity Threshold" and "Confidence Threshold". If disabled, action will never label false positive entities as suspicious, regardless, if they pass the "Severity Threshold" and "Confidence Threshold" conditions or not.
1919
* `target_entities` (List[TargetEntity], optional, default=[]): Optional list of specific target entities (Identifier, EntityType) to run the action on.

‎docs/soar_integrations/anomali_threat_stream.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -75,12 +75,12 @@ Submit an observable to Anomali ThreatStream based on IP, URL, Hash, Email entit
7575

7676
* `case_id` (str, required): The ID of the case.
7777
* `alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
78-
* `classification` (List[Any], required): Specify the classification of the observable.
79-
* `threat_type` (List[Any], required): Specify the threat type of the observables.
78+
* `classification` (List[str], required): Specify the classification of the observable.
79+
* `threat_type` (List[str], required): Specify the threat type of the observables.
8080
* `source` (Optional[str], optional, default=None): Specify the intelligence source for the observable.
8181
* `expiration_date` (Optional[str], optional, default=None): Specify the expiration date in days for the observable. If nothing is specified here, action will create an observable that will never expire.
8282
* `trusted_circle_i_ds` (Optional[str], optional, default=None): Specify the comma-separated list of trusted circle ids. Observables will be shared with those trusted circles.
83-
* `tlp` (Optional[List[Any]], optional, default=None): Specify the TLP for your observables.
83+
* `tlp` (Optional[List[str]], optional, default=None): Specify the TLP for your observables.
8484
* `confidence` (Optional[str], optional, default=None): Specify what should be the confidence for the observable. Note: this parameter will only work, if you create observables in your organization and requires 'Override System Confidence' to be enabled.
8585
* `override_system_confidence` (Optional[bool], optional, default=None): If enabled, created observables will have the confidence specified in the 'Confidence' parameter. Note: you can't share observables in trusted circles and publicly, when this parameter is enabled.
8686
* `anonymous_submission` (Optional[bool], optional, default=None): If enabled, action will make an anonymous submission.
@@ -141,7 +141,7 @@ Retrieve information about entities from Anomali ThreatStream. Supported entitie
141141

142142
* `case_id` (str, required): The ID of the case.
143143
* `alert_group_identifiers` (List[str], required): Identifiers for the alert groups.
144-
* `severity_threshold` (List[Any], required): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
144+
* `severity_threshold` (List[str], required): Specify what should be the severity threshold for the entity, in order to mark it as suspicious. If multiple records are found for the same entity, action will take the highest severity out of all available records.
145145
* `confidence_threshold` (str, required): Specify what should be the confidence threshold for the entity, in order to mark it as suspicious. Note: Maximum is 100. If multiple records are found for the entity, action will take the average. Active records have priority.
146146
* `create_insight` (bool, required): If enabled, action will add an insight per processed entity.
147147
* `only_suspicious_entity_insight` (bool, required): If enabled, action will create insight only for entities that exceeded the "Severity Threshold" and "Confidence Threshold".

0 commit comments

Comments
 (0)