---
title: "google-secops"
description: "Essential Security Operations skills for Triage, Investigation, and Hunting."
canonical: https://agentpluginsdirectory.com/plugins/google-secops
last-updated: 2026-09-16
---

# google-secops
Essential Security Operations skills for Triage, Investigation, and Hunting.
- Slug: google-secops
- Publisher: Google LLC
- Repository: https://github.com/google/skills
- Manifest: plugins/cloud/google-secops/plugin.json
- Version: 1.1.0
- License: Apache-2.0
- Category (editorial): other
- Skills: 5 (secops-cases, secops-detection-engineering, secops-hunt, secops-investigate, secops-triage)
- MCP servers: 1 (google-security-operations)
- Stars: 20020
- Repository created: 2026-03-31
- Repository last pushed: 2026-09-16
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/google-secops
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What google-secops does, in the publisher's words

Agent plugin providing Security Operations capabilities for Google Security Operations (Chronicle SIEM and SOAR), packaged under the Agent Plugins 1.0.0 specification.

This plugin packages domain-specific agent skills, environment configuration rules, and remote Model Context Protocol (MCP) server definitions connecting to Google SecOps.

The Google SecOps plugin equips coding and operations agents with specialized workflows for security analytics:

- Alert Triage: Rapid evaluation, severity tuning, entity scoping, and closing recommendations.
- Investigation: UDM search, event extraction, asset/user timeline reconstruction, and lateral movement detection.
- Threat Hunting: Hypothesis-driven hunting, IoC sweeps, prevalence analysis, and outlier detection.
- Case Management: SOAR case tracking, task execution, comment documentation, and alert association.
- Detection Engineering: YARA-L 2.0 rule authoring, validation, test backtesting, deployment, and coverage evaluation.
- Credentials are read from the process environment of the CLI at launch. If you rely on direnv or a.env file, enter the project directory before starting the CLI.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/google/skills/HEAD/plugins/cloud/google-secops/README.md

## Skills

- secops-cases: Manage Google Security Operations (SecOps) SOAR cases throughout their lifecycle. Use when listing, creating, inspecting, updating, or closing SOAR cases; adding investigative comments and notes; updating case priority or description; or linking and grouping security alerts within cases. Supports b…
- secops-detection-engineering: Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps. Use when writing new detection rules, tuning existing rules, validating syntax, testing logic against historical telemetry, or evaluating detection coverage against threat…
- secops-hunt: Expert guidance for proactive threat hunting in Google SecOps. Use when proactively hunting for threats, retroactively analyzing indicators of compromise (IoCs), performing prevalence searches across enterprise events, hunting for MITRE ATT&CK techniques, or detecting behavioral and statistical out…
- secops-investigate: Expert guidance for deep security incident and entity investigations in Google SecOps. Use when investigating cases, analyzing entities (hosts, IPs, domains, hashes, users), extracting and searching UDM events, performing asset and user timeline analysis, and detecting lateral movement across enter…
- secops-triage: Expert guidance for security alert triage in Google SecOps. Use when investigating and triaging security alerts, determining false positives vs. true positives, assessing entity risk, adjusting alert severity or priority, and closing or escalating alerts and cases. Don't use for deep multi-hop inci…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- google-security-operations: transport: streamable-http; url: https://chronicle.us.rep.googleapis.com/mcp

Read from the plugin's own mcp.json. Environment variable names only, never values.
