secops
Python SDK for wrapping the Google SecOps API for common use cases
Decision gist · record as of 2026-08-14
Yes, if you are already using Google Security Operations (Chronicle) and need programmatic access from Python. The low install friction, active maintenance, permissive license, and comprehensive authentication options make it a practical choice for integrating Chronicle into automation and orchestration workflows. The alpha status and requirement for pre-configured Google Cloud infrastructure are not blockers for teams already committed to the Chronicle platform.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a Google Cloud project linked to a Google SecOps instance, Chronicle API enabled, and appropriate IAM permissions (Chronicle API Admin role recommended).
- Authentication via Application Default Credentials or explicit service account credentials is mandatory.
- Low install friction with a pure-Python wheel.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in commercial and proprietary projects with minimal restrictions beyond attribution.
last release 2026-05-22 (84 days) · last repo commit 2026-07-22 · 89 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 278,981 downloads/mo, #8,127 on PyPI
Alternatives
Verify before relying
pip install secops
from secops import SecOpsClient
client = SecOpsClient()
chronicle = client.chronicle(
customer_id="your-instance-id",
project_id="your-project-id",
region="us"
)- Whether the SDK supports all Chronicle API endpoints or only a subset of common use cases.
- Performance characteristics and rate-limiting behavior under high-volume query loads.
- Backward compatibility guarantees given alpha status (Development Status :: 3).
What it is and what it does
The secops package is a Python wrapper around the Google Security Operations (Chronicle) API, designed to simplify interaction with Google's SIEM platform. It abstracts away low-level API details and provides a client-based interface for common security operations workflows: searching Unified Data Model (UDM) events, looking up entities, managing indicators of compromise, handling alerts, managing cases, and administering detection rules. The SDK supports multiple authentication methods—Application Default Credentials for local development and cloud environments, explicit service account files, and service account impersonation—making it flexible for different deployment scenarios.
The package depends on google-api-python-client, google-auth-httplib2, and google-auth to handle API communication and credential management. It includes built-in retry logic for transient failures and a command-line interface for terminal-based operations. The SDK is actively maintained, supports Python 3.10 through 3.13, and carries an Apache-2.0 license. Setup requires a pre-configured Google Cloud project linked to your SecOps instance and appropriate IAM roles; without this infrastructure, authentication will fail regardless of SDK installation.
Use it for
- Automate UDM event searches and threat hunting workflows within Chronicle without writing raw API calls.
- Build security orchestration scripts that query entities, manage alerts, and update cases programmatically.
- Integrate Chronicle SIEM data into custom dashboards or incident response automation platforms.
- Manage detection rules and IoC indicators at scale via Python scripts or scheduled jobs.
- Develop CLI tools or terminal-based security operations workflows using the built-in command interface.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using Google Security Operations (Chronicle) and need programmatic access from Python.
The low install friction, active maintenance, permissive license, and comprehensive authentication options make it a practical choice for integrating Chronicle into automation and orchestration workflows. The alpha status and requirement for pre-configured Google Cloud infrastructure are not blockers for teams already committed to the Chronicle platform.
Install
secops on PyPI
Before you install
Low install friction with a pure-Python wheel. Actively maintained as of 2026-07-22 with recent releases; marked alpha status but in the top 15000 PyPI packages by downloads. Depends on three Google authentication and API client libraries.
Requires a Google Cloud project linked to a Google SecOps instance, Chronicle API enabled, and appropriate IAM permissions (Chronicle API Admin role recommended). Authentication via Application Default Credentials or explicit service account credentials is mandatory.
License in practice
Licensed under Apache-2.0 (permissive), allowing use in commercial and proprietary projects with minimal restrictions beyond attribution.
Quickstart
pip install secops
from secops import SecOpsClient
client = SecOpsClient()
chronicle = client.chronicle(
customer_id="your-instance-id",
project_id="your-project-id",
region="us"
)
Verify before relying
- Whether the SDK supports all Chronicle API endpoints or only a subset of common use cases.
- Performance characteristics and rate-limiting behavior under high-volume query loads.
- Backward compatibility guarantees given alpha status (Development Status :: 3).
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesgoogle-api-python-clientgoogle-auth-httplib2google-auth |
| Maintenance | Actively maintained 84 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 278,981 / month, #8,127 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: Security |
Evidence: secops-0.44.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “google chronicle siem api”
- secopsA Python SDK for interacting with Google Security Operations…
- google-cloud-securitycenterPython client library for Google Cloud Security Command Center API,…
- sumologic-sdkPython interface to the Sumo Logic REST API, enabling programmatic…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also google-cloud-iam · sumologic-sdk · google-cloud-os-login · google-nest-sdm · grpc-google-iam-v1 · analytics-mcp · pyfcm · boto_session_manager · onelogin · google-cloud-access-context-manager