Skip to content

feat(secops): consolidate comprehensive Chronicle 1P Case, Alert, and SOAR MCP tool suite - #319

Open
dandye wants to merge 3 commits into
mainfrom
feat/comprehensive-case-suite
Open

dandye wants to merge 3 commits into
mainfrom
feat/comprehensive-case-suite

Conversation

@dandye

@dandye dandye commented Sep 19, 2026

Copy link
Copy Markdown
Collaborator

Overview

This Pull Request consolidates all open and in-progress Case, Alert, and SOAR management workstreams across secops-mcp (google-secops-mcp) and secops-soar-mcp into a single, unified, conflict-free branch (feat/comprehensive-case-suite), while completing full API coverage across the Chronicle v1main Case and Alert proto services (126 Case/Alert/SOAR tools in secops_mcp, plus secops_soar_mcp root cause discovery).


Rolled-Up Pull Requests & Issues

This PR supersedes and unifies the following Pull Requests and Issues:

  1. PR feat(secops): add comprehensive Chronicle 1P SOAR tool suite and docs #282 (soar_trigger) (and superseded PR feat(secops): add comprehensive SOAR parity tools for Chronicle 1P (Git Stack 2/2) #290 soar_parity) — Chronicle 1P Case, CaseAlert, SOAR Reaction Triggers, Entity, Integration, Playbook & Connector Tools:
    • Core 1P CaseService (list_cases, get_case, update_case, change_case_priority, change_case_stage, assign_case, set_custom_case_fields, add_case_tag, remove_case_tag, add_case_insight, pause_case_sla, resume_case_sla, close_case, reopen_case, execute_bulk_add_case_tag, execute_bulk_assign_case, execute_bulk_change_case_priority, execute_bulk_change_case_stage, execute_bulk_close_case, execute_bulk_reopen_case)
    • Core 1P CaseAlertService (list_case_alerts, get_case_alert, update_case_alert, change_alert_priority, set_alert_custom_fields, move_case_alert, add_alert_tag, remove_alert_tag)
    • Entity Investigation (entity_investigation.py), Integration & Action Execution (integration_management.py), Playbook Management (playbook_management.py), and Connector Event Management (connector_event_management.py)
  2. PR Add MCP tools for Chronicle REST API Case Creation Endpoints #318 (add-case-creation-mcp-tools-8503933169267217566) — Chronicle REST API Case & Alert Creation Endpoints:
    • create_case (POST /v1alpha/{instance}/legacyCases:createCase — ingests LegacyCaseCasesPackage containing full alert metadata, LegacyCaseSecurityEvent UDM/CEF event telemetry, and extracted entities)
    • create_manual_case (POST /v1alpha/{instance}/legacyCases:createManualCase — creates a manual SOAR case via ApiCreateManualCaseRequest with optional alertName, entities, priority, assignedUser, tags, and playbooks)
    • create_or_update_case (POST /v1alpha/{instance}/legacy:legacyCreateOrUpdateCase — creates or updates native SIEM LegacyCase records with fixed legacy:legacyCreateOrUpdateCase custom verb routing)
    • batch_get_legacy_cases (GET /v1alpha/{instance}/legacy:legacyBatchGetCases — batch retrieval of native SIEM LegacyCase resources)
  3. PR feat: add case close root cause discovery tools (#124) #314 (feat/issue-124-case-close-root-causes) & Fixes Need case-close-root-causes in order to close cases #124 — Case Close Root Cause Discovery (secops-mcp & secops-soar-mcp):
    • list_case_close_definitions, get_case_close_definition, create_case_close_definition, update_case_close_definition, delete_case_close_definition (CaseCloseDefinitionService in server/secops/secops_mcp/tools/case_close_definitions.py)
    • list_case_close_root_causes in server/secops-soar/secops_soar_mcp/case_management.py (GET /api/external/v1/settings/case-close-root-causes)
  4. PR feat: Add SOAR MCP Case Management Tools #234 & PR fix: Update triage skill to reference new local close_case tool #281 (soar-case-management-tools) — SOAR Case Lifecycle & Triage Parity:
    • Consolidated SOAR case lifecycle management, priority/stage transitions, bulk operations, and root cause enumeration.

Full Chronicle v1main Case & Alert Service Coverage

Beyond the rolled-up PRs, this branch completes coverage across the remaining Chronicle v1main Case sub-resource services:

  • CaseService (case.proto):
    • merge_cases (POST /v1/{instance}/cases:merge with casesIds (int32[]) and caseToMergeWith (int32) to combine cases, alerts, and event telemetry into a target case)
    • get_or_create_case_summary, get_case_overview, mark_case_important, mark_case_incident, set_case_sla, attach_playbook_to_case, fetch_case_affected_Playbooks
    • list_case_tasks, get_case_task, create_case_task, update_case_task, delete_case_task
    • list_case_involved_relations, list_case_involved_events
  • CaseAlertService (case_alert.proto):
    • set_alert_sla, get_alert_overview, fetch_alert_group_events, fetch_alert_grouping_fields, import_alert_from_siem, mark_alert_important, close_case_alert, reopen_case_alert
  • CaseCloseDefinitionService, CaseStageDefinitionService & CaseTagDefinitionService (case_close_definitions.py):
    • Full CRUD (list, get, create, update, delete) for Case Close Root Cause Definitions, Case Stage Definitions (caseStageDefinitions), and Case Tag Definitions (caseTagDefinitions)
  • CaseWallService (case_wall_records.py):
    • list_case_comments, get_case_comment, create_case_comment, update_case_comment, delete_case_comment
    • list_case_wall_records, get_case_wall_record
    • list_case_external_links, create_case_external_link, update_case_external_link, delete_case_external_link
    • list_case_pinned_items, create_case_pinned_item, delete_case_pinned_item
    • list_case_chat_records, create_case_chat_record
  • CaseDetectionsService, CaseEventService & CaseInvestigationService (case_detections_and_events.py):
    • list_case_detections, get_case_detection, query_case_detections_udm_field_values
    • list_case_events, get_case_event
    • get_case_investigation, get_case_investigation_graph, update_case_investigation_graph, list_case_investigation_snapshots
  • CaseHistoryService, CaseQueueFilterService, CasesDynamicViewService, CaseAgenticReportService & CaseChatService (case_reporting_and_chat.py):
    • list_case_histories, list_case_queue_filters, get_case_queue_filter, create_case_queue_filter, update_case_queue_filter, delete_case_queue_filter
    • get_cases_dynamic_view, update_cases_dynamic_view
    • list_case_agentic_reports, get_case_agentic_report, generate_case_agentic_report
    • send_case_chat_message, list_case_chat_messages
  • LegacyCaseService (case_management.py):
    • create_case, create_manual_case, create_or_update_case, batch_get_legacy_cases
    • execute_manual_action, get_action_result_by_id, simulate_alert, get_custom_cases, is_custom_case_exists, export_custom_case, import_custom_case, delete_use_case, generate_use_cases, inject_sample_data, generate_case_collaborator, add_evidence_to_case, investigator_extend_case_graph

Verification

  1. Unit Tests (pytest):
    • server/secops/tests/test_case_close_definitions_unit.py
    • server/secops/tests/test_case_management_tools.py
    • server/secops/tests/test_secops_case_management.py
    • server/secops/tests/test_secops_soar_parity.py
    • server/secops-soar/tests/unit/test_case_management.py
    • All 32 unit tests across secops and secops-soar pass (32 passed).
  2. Live Tenant Verification (dandye-0324-chronicle / ltstrtn.backstory.chronicle.security):
    • Verified create_manual_case (legacyCases:createManualCase) creating live SOAR cases (#33288, #33289) with initial alerts (#488839) and entities (ADDRESS, HOSTNAME, USERUNIQNAME).
    • Verified create_case (legacyCases:createCase) ingesting multi-stage alerts (#488840, #488841, #488842) with full LegacyCaseSecurityEvent (PROCESS_LAUNCH, NETWORK_HTTP) telemetry and entity extraction.
    • Verified merge_cases (cases:merge) and move_case_alert (cases/{case}/caseAlerts/{alert}:move) attaching ingested alerts and events onto existing cases.
    • Verified create_case_comment, list_case_comments, add_case_tag, list_case_wall_records, list_case_close_definitions, list_case_stage_definitions, list_case_tag_definitions, create_or_update_case (legacy:legacyCreateOrUpdateCase), and batch_get_legacy_cases (legacy:legacyBatchGetCases).

… SOAR MCP tool suite

Consolidates and rolls up the full Chronicle 1P Case, CaseAlert, and SOAR MCP tool suite across secops-mcp and secops-soar-mcp:
- Rolls up PR #282 (soar_trigger): Chronicle 1P CaseService & CaseAlertService core tools, SOAR reaction triggers, Entity Investigation, Integration & Action execution, Playbook management, and Connector Event management
- Rolls up PR #318 (add-case-creation-mcp-tools): create_case (legacyCases:createCase), create_manual_case (legacyCases:createManualCase), create_or_update_case (legacy:legacyCreateOrUpdateCase), batch_get_legacy_cases (legacy:legacyBatchGetCases)
- Rolls up PR #314 (Issue #124): Case close root cause discovery (list_case_close_definitions, get_case_close_definition, create_case_close_definition, update_case_close_definition, delete_case_close_definition, list_case_close_root_causes)
- Rolls up PR #234 & PR #281 (soar-case-management-tools): SOAR case lifecycle, priority, bulk actions, and root cause enumeration
- Adds full v1main Case sub-resource parity: CaseStageDefinitionService, CaseTagDefinitionService, CaseWallService (comments, wall records, external links, pinned items, chat records, insights), CaseDetectionsService, CaseEventService, CaseInvestigationService, CaseHistoryService, CaseQueueFilterService, CasesDynamicViewService, CaseAgenticReportService, CaseChatService, and LegacyCaseService simulation/action RPCs
@dandye
dandye requested a review from a team September 19, 2026 20:45
…ha/v1 REST routes with Chronicle v1main protos

- Remove duplicate @server.tool() registrations for execute_manual_action and get_action_result_by_id in case_management.py that were shadowed by integration_management.py
- Update execute_manual_action and get_action_result_by_id in integration_management.py to use v1alpha legacyCases endpoints (legacyCases:executeManualAction and legacyCases:getActionResultById?resultIdStr=...)
- Switch add_alert_tag and remove_alert_tag in case_alert_management.py to v1alpha per case_alert.proto method_versioning restrictions
- Align list_connector_events and get_connector_event with connector_event.proto (/v1alpha/{instance}/cases/{case_id}/caseAlerts/{alert_id}/connectorEvents)
- Align get_involved_entity, list_involved_entities, get_entities_by_alert_group_identifiers, and get_entity_details with involved_entity.proto (v1alpha) and unique_entity.proto (/v1/{instance}/uniqueEntities:fetchFull)
- Align get_playbook, list_playbook_instances, and execute_playbook with legacy_playbook.proto and case.proto
- Add strict URL and query parameter assertions to test_secops_soar_parity.py
… and chat routes with v1main protos

- Fix F821 undefined name in case_alert_management.py list_events_by_alert by delegating to list_case_events (/v1alpha/{parent}/cases/{case}/events)
- Align case_alert_management.py SLA, overview, recommendation, and view routes with case_alert.proto (:setSla, :pauseSla, :resumeSla, :alertOverviewData, GET :resolveOverviewWidget, caseAlerts:fetchRecommendation, :createRecommendationLongRunning, :listAlertViews)
- Align case_detections_and_events.py routes with case_detection.proto (/detections, /detections/{id}/events), case_event.proto (/events), and case_evidence_data.proto (/caseEvidenceDatas)
- Align case_wall_records.py with case_wall_record.proto (PATCH :favorite, GET :fetchActivitiesCount, GET :queryAvailableCaseWallRecordTags)
- Align case_reporting_and_chat.py with agentic_case_report.proto (:generate, GET :download) and case_chat_message.proto (/chatMessages)
- Clean up unused imports across modified test and tool files

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Need case-close-root-causes in order to close cases

1 participant