[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-elastic-alert-triage":3,"mdc--ve1zzc-key":40,"related-repo-elastic-alert-triage":751,"related-org-elastic-alert-triage":811},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":23,"repoUrl":24,"updatedAt":25,"license":26,"forks":27,"topics":28,"repo":35,"sourceUrl":38,"mdContent":39},"alert-triage","triage Elastic Security alerts","Triage Elastic Security alerts — fetch, investigate, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, investigating detections, reviewing security incidents, or when the user mentions ransomware, malware, lateral movement, credential theft, DLL injection, suspicious processes, or any specific threat. Also trigger for \"show me alerts\", \"what's happening on host X\", \"any critical alerts\", or any security operations question.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"elastic","Elastic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Felastic.png",[12,16,19,20],{"name":13,"slug":14,"type":15},"Security","security","tag",{"name":17,"slug":18,"type":15},"Monitoring","monitoring",{"name":9,"slug":8,"type":15},{"name":21,"slug":22,"type":15},"Triage","triage",18,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fexample-mcp-app-security","2026-07-12T07:48:26.972827",null,10,[29,30,31,8,32,33,14,34],"ai","claude","cursor","mcp","model-context-protocol","soc",{"repoUrl":24,"stars":23,"forks":27,"topics":36,"description":37},[29,30,31,8,32,33,14,34],"Reference MCP App for Elastic Security — interactive SOC dashboards inside Claude, Cursor, and other MCP hosts.","https:\u002F\u002Fgithub.com\u002Felastic\u002Fexample-mcp-app-security\u002Ftree\u002FHEAD\u002Fskills\u002Falert-triage","---\nname: alert-triage\ndescription: >\n  Triage Elastic Security alerts — fetch, investigate, classify threats, create cases,\n  and acknowledge. Use when triaging alerts, performing SOC analysis, investigating\n  detections, reviewing security incidents, or when the user mentions ransomware,\n  malware, lateral movement, credential theft, DLL injection, suspicious processes,\n  or any specific threat. Also trigger for \"show me alerts\", \"what's happening on\n  host X\", \"any critical alerts\", or any security operations question.\n---\n\n# Alert Triage\n\nYou are a senior SOC analyst. When asked to triage, you DO the triage — you investigate, classify each alert,\nand deliver a verdict. You do not just show a list and ask the user what to do.\n\n## Tools\n\n| Tool | Purpose |\n|------|---------|\n| `triage-alerts` | Fetch alerts with interactive dashboard. Params: `query`, `severity`, `days`, `limit`, `verdicts` |\n| `manage-cases` | Create\u002Fsearch cases for documenting findings |\n| `threat-hunt` | Run ES\\|QL queries for deep investigation |\n\n## How to call triage-alerts\n\nCall `triage-alerts` ONCE. Include `query` to filter and `verdicts` if you can classify based on what\nyou already know. The dashboard renders verdict badges directly on alert cards.\n\n**`query`**: Filter by threat type, hostname, process, technique:\n- \"triage ransomware\" → `query: \"ransomware\"`\n- \"alerts on SRVWIN04\" → `query: \"SRVWIN04\"`\n\n**`verdicts`**: Include when you can classify. Each verdict has:\n- `rule`: detection rule name\n- `classification`: benign \u002F suspicious \u002F malicious\n- `confidence`: low \u002F medium \u002F high\n- `summary`: 1-2 sentence reasoning\n- `action`: recommended next step\n- `hosts`: affected hostnames (optional)\n\nExample:\n```json\n{\n  \"query\": \"ransomware\",\n  \"verdicts\": [\n    {\n      \"rule\": \"Ransomware Detection Alert\",\n      \"classification\": \"malicious\",\n      \"confidence\": \"high\",\n      \"summary\": \"SHA256-named parent process sideloading MsMpEng.exe confirms active ransomware execution\",\n      \"action\": \"Isolate host, create P1 case, hunt for lateral movement\",\n      \"hosts\": [\"SRVWIN02\"]\n    }\n  ]\n}\n```\n\nDo NOT call the tool twice. One call only.\n\n## After the tool returns\n\nYou receive alert details (rule names, hosts, processes, risk scores, MITRE techniques).\nProvide your analysis in text below the dashboard:\n- Group findings by host or rule\n- Classify each as benign\u002Fsuspicious\u002Fmalicious with reasoning\n- Recommend specific actions\n\nFor detailed classification criteria, see [references\u002Fclassification-guide.md](references\u002Fclassification-guide.md).\n",{"data":41,"body":42},{"name":4,"description":6},{"type":43,"children":44},"root",[45,53,59,66,181,187,213,227,254,267,336,341,698,703,709,714,732,745],{"type":46,"tag":47,"props":48,"children":49},"element","h1",{"id":4},[50],{"type":51,"value":52},"text","Alert Triage",{"type":46,"tag":54,"props":55,"children":56},"p",{},[57],{"type":51,"value":58},"You are a senior SOC analyst. When asked to triage, you DO the triage — you investigate, classify each alert,\nand deliver a verdict. You do not just show a list and ask the user what to do.",{"type":46,"tag":60,"props":61,"children":63},"h2",{"id":62},"tools",[64],{"type":51,"value":65},"Tools",{"type":46,"tag":67,"props":68,"children":69},"table",{},[70,89],{"type":46,"tag":71,"props":72,"children":73},"thead",{},[74],{"type":46,"tag":75,"props":76,"children":77},"tr",{},[78,84],{"type":46,"tag":79,"props":80,"children":81},"th",{},[82],{"type":51,"value":83},"Tool",{"type":46,"tag":79,"props":85,"children":86},{},[87],{"type":51,"value":88},"Purpose",{"type":46,"tag":90,"props":91,"children":92},"tbody",{},[93,147,164],{"type":46,"tag":75,"props":94,"children":95},{},[96,107],{"type":46,"tag":97,"props":98,"children":99},"td",{},[100],{"type":46,"tag":101,"props":102,"children":104},"code",{"className":103},[],[105],{"type":51,"value":106},"triage-alerts",{"type":46,"tag":97,"props":108,"children":109},{},[110,112,118,120,126,127,133,134,140,141],{"type":51,"value":111},"Fetch alerts with interactive dashboard. Params: ",{"type":46,"tag":101,"props":113,"children":115},{"className":114},[],[116],{"type":51,"value":117},"query",{"type":51,"value":119},", ",{"type":46,"tag":101,"props":121,"children":123},{"className":122},[],[124],{"type":51,"value":125},"severity",{"type":51,"value":119},{"type":46,"tag":101,"props":128,"children":130},{"className":129},[],[131],{"type":51,"value":132},"days",{"type":51,"value":119},{"type":46,"tag":101,"props":135,"children":137},{"className":136},[],[138],{"type":51,"value":139},"limit",{"type":51,"value":119},{"type":46,"tag":101,"props":142,"children":144},{"className":143},[],[145],{"type":51,"value":146},"verdicts",{"type":46,"tag":75,"props":148,"children":149},{},[150,159],{"type":46,"tag":97,"props":151,"children":152},{},[153],{"type":46,"tag":101,"props":154,"children":156},{"className":155},[],[157],{"type":51,"value":158},"manage-cases",{"type":46,"tag":97,"props":160,"children":161},{},[162],{"type":51,"value":163},"Create\u002Fsearch cases for documenting findings",{"type":46,"tag":75,"props":165,"children":166},{},[167,176],{"type":46,"tag":97,"props":168,"children":169},{},[170],{"type":46,"tag":101,"props":171,"children":173},{"className":172},[],[174],{"type":51,"value":175},"threat-hunt",{"type":46,"tag":97,"props":177,"children":178},{},[179],{"type":51,"value":180},"Run ES|QL queries for deep investigation",{"type":46,"tag":60,"props":182,"children":184},{"id":183},"how-to-call-triage-alerts",[185],{"type":51,"value":186},"How to call triage-alerts",{"type":46,"tag":54,"props":188,"children":189},{},[190,192,197,199,204,206,211],{"type":51,"value":191},"Call ",{"type":46,"tag":101,"props":193,"children":195},{"className":194},[],[196],{"type":51,"value":106},{"type":51,"value":198}," ONCE. Include ",{"type":46,"tag":101,"props":200,"children":202},{"className":201},[],[203],{"type":51,"value":117},{"type":51,"value":205}," to filter and ",{"type":46,"tag":101,"props":207,"children":209},{"className":208},[],[210],{"type":51,"value":146},{"type":51,"value":212}," if you can classify based on what\nyou already know. The dashboard renders verdict badges directly on alert cards.",{"type":46,"tag":54,"props":214,"children":215},{},[216,225],{"type":46,"tag":217,"props":218,"children":219},"strong",{},[220],{"type":46,"tag":101,"props":221,"children":223},{"className":222},[],[224],{"type":51,"value":117},{"type":51,"value":226},": Filter by threat type, hostname, process, technique:",{"type":46,"tag":228,"props":229,"children":230},"ul",{},[231,243],{"type":46,"tag":232,"props":233,"children":234},"li",{},[235,237],{"type":51,"value":236},"\"triage ransomware\" → ",{"type":46,"tag":101,"props":238,"children":240},{"className":239},[],[241],{"type":51,"value":242},"query: \"ransomware\"",{"type":46,"tag":232,"props":244,"children":245},{},[246,248],{"type":51,"value":247},"\"alerts on SRVWIN04\" → ",{"type":46,"tag":101,"props":249,"children":251},{"className":250},[],[252],{"type":51,"value":253},"query: \"SRVWIN04\"",{"type":46,"tag":54,"props":255,"children":256},{},[257,265],{"type":46,"tag":217,"props":258,"children":259},{},[260],{"type":46,"tag":101,"props":261,"children":263},{"className":262},[],[264],{"type":51,"value":146},{"type":51,"value":266},": Include when you can classify. Each verdict has:",{"type":46,"tag":228,"props":268,"children":269},{},[270,281,292,303,314,325],{"type":46,"tag":232,"props":271,"children":272},{},[273,279],{"type":46,"tag":101,"props":274,"children":276},{"className":275},[],[277],{"type":51,"value":278},"rule",{"type":51,"value":280},": detection rule name",{"type":46,"tag":232,"props":282,"children":283},{},[284,290],{"type":46,"tag":101,"props":285,"children":287},{"className":286},[],[288],{"type":51,"value":289},"classification",{"type":51,"value":291},": benign \u002F suspicious \u002F malicious",{"type":46,"tag":232,"props":293,"children":294},{},[295,301],{"type":46,"tag":101,"props":296,"children":298},{"className":297},[],[299],{"type":51,"value":300},"confidence",{"type":51,"value":302},": low \u002F medium \u002F high",{"type":46,"tag":232,"props":304,"children":305},{},[306,312],{"type":46,"tag":101,"props":307,"children":309},{"className":308},[],[310],{"type":51,"value":311},"summary",{"type":51,"value":313},": 1-2 sentence reasoning",{"type":46,"tag":232,"props":315,"children":316},{},[317,323],{"type":46,"tag":101,"props":318,"children":320},{"className":319},[],[321],{"type":51,"value":322},"action",{"type":51,"value":324},": recommended next step",{"type":46,"tag":232,"props":326,"children":327},{},[328,334],{"type":46,"tag":101,"props":329,"children":331},{"className":330},[],[332],{"type":51,"value":333},"hosts",{"type":51,"value":335},": affected hostnames (optional)",{"type":46,"tag":54,"props":337,"children":338},{},[339],{"type":51,"value":340},"Example:",{"type":46,"tag":342,"props":343,"children":348},"pre",{"className":344,"code":345,"language":346,"meta":347,"style":347},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"query\": \"ransomware\",\n  \"verdicts\": [\n    {\n      \"rule\": \"Ransomware Detection Alert\",\n      \"classification\": \"malicious\",\n      \"confidence\": \"high\",\n      \"summary\": \"SHA256-named parent process sideloading MsMpEng.exe confirms active ransomware execution\",\n      \"action\": \"Isolate host, create P1 case, hunt for lateral movement\",\n      \"hosts\": [\"SRVWIN02\"]\n    }\n  ]\n}\n","json","",[349],{"type":46,"tag":101,"props":350,"children":351},{"__ignoreMap":347},[352,364,408,433,442,481,518,555,592,629,671,680,689],{"type":46,"tag":353,"props":354,"children":357},"span",{"class":355,"line":356},"line",1,[358],{"type":46,"tag":353,"props":359,"children":361},{"style":360},"--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF",[362],{"type":51,"value":363},"{\n",{"type":46,"tag":353,"props":365,"children":367},{"class":355,"line":366},2,[368,373,378,383,388,393,399,403],{"type":46,"tag":353,"props":369,"children":370},{"style":360},[371],{"type":51,"value":372},"  \"",{"type":46,"tag":353,"props":374,"children":376},{"style":375},"--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA",[377],{"type":51,"value":117},{"type":46,"tag":353,"props":379,"children":380},{"style":360},[381],{"type":51,"value":382},"\"",{"type":46,"tag":353,"props":384,"children":385},{"style":360},[386],{"type":51,"value":387},":",{"type":46,"tag":353,"props":389,"children":390},{"style":360},[391],{"type":51,"value":392}," \"",{"type":46,"tag":353,"props":394,"children":396},{"style":395},"--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D",[397],{"type":51,"value":398},"ransomware",{"type":46,"tag":353,"props":400,"children":401},{"style":360},[402],{"type":51,"value":382},{"type":46,"tag":353,"props":404,"children":405},{"style":360},[406],{"type":51,"value":407},",\n",{"type":46,"tag":353,"props":409,"children":411},{"class":355,"line":410},3,[412,416,420,424,428],{"type":46,"tag":353,"props":413,"children":414},{"style":360},[415],{"type":51,"value":372},{"type":46,"tag":353,"props":417,"children":418},{"style":375},[419],{"type":51,"value":146},{"type":46,"tag":353,"props":421,"children":422},{"style":360},[423],{"type":51,"value":382},{"type":46,"tag":353,"props":425,"children":426},{"style":360},[427],{"type":51,"value":387},{"type":46,"tag":353,"props":429,"children":430},{"style":360},[431],{"type":51,"value":432}," [\n",{"type":46,"tag":353,"props":434,"children":436},{"class":355,"line":435},4,[437],{"type":46,"tag":353,"props":438,"children":439},{"style":360},[440],{"type":51,"value":441},"    {\n",{"type":46,"tag":353,"props":443,"children":445},{"class":355,"line":444},5,[446,451,456,460,464,468,473,477],{"type":46,"tag":353,"props":447,"children":448},{"style":360},[449],{"type":51,"value":450},"      \"",{"type":46,"tag":353,"props":452,"children":454},{"style":453},"--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B",[455],{"type":51,"value":278},{"type":46,"tag":353,"props":457,"children":458},{"style":360},[459],{"type":51,"value":382},{"type":46,"tag":353,"props":461,"children":462},{"style":360},[463],{"type":51,"value":387},{"type":46,"tag":353,"props":465,"children":466},{"style":360},[467],{"type":51,"value":392},{"type":46,"tag":353,"props":469,"children":470},{"style":395},[471],{"type":51,"value":472},"Ransomware Detection Alert",{"type":46,"tag":353,"props":474,"children":475},{"style":360},[476],{"type":51,"value":382},{"type":46,"tag":353,"props":478,"children":479},{"style":360},[480],{"type":51,"value":407},{"type":46,"tag":353,"props":482,"children":484},{"class":355,"line":483},6,[485,489,493,497,501,505,510,514],{"type":46,"tag":353,"props":486,"children":487},{"style":360},[488],{"type":51,"value":450},{"type":46,"tag":353,"props":490,"children":491},{"style":453},[492],{"type":51,"value":289},{"type":46,"tag":353,"props":494,"children":495},{"style":360},[496],{"type":51,"value":382},{"type":46,"tag":353,"props":498,"children":499},{"style":360},[500],{"type":51,"value":387},{"type":46,"tag":353,"props":502,"children":503},{"style":360},[504],{"type":51,"value":392},{"type":46,"tag":353,"props":506,"children":507},{"style":395},[508],{"type":51,"value":509},"malicious",{"type":46,"tag":353,"props":511,"children":512},{"style":360},[513],{"type":51,"value":382},{"type":46,"tag":353,"props":515,"children":516},{"style":360},[517],{"type":51,"value":407},{"type":46,"tag":353,"props":519,"children":521},{"class":355,"line":520},7,[522,526,530,534,538,542,547,551],{"type":46,"tag":353,"props":523,"children":524},{"style":360},[525],{"type":51,"value":450},{"type":46,"tag":353,"props":527,"children":528},{"style":453},[529],{"type":51,"value":300},{"type":46,"tag":353,"props":531,"children":532},{"style":360},[533],{"type":51,"value":382},{"type":46,"tag":353,"props":535,"children":536},{"style":360},[537],{"type":51,"value":387},{"type":46,"tag":353,"props":539,"children":540},{"style":360},[541],{"type":51,"value":392},{"type":46,"tag":353,"props":543,"children":544},{"style":395},[545],{"type":51,"value":546},"high",{"type":46,"tag":353,"props":548,"children":549},{"style":360},[550],{"type":51,"value":382},{"type":46,"tag":353,"props":552,"children":553},{"style":360},[554],{"type":51,"value":407},{"type":46,"tag":353,"props":556,"children":558},{"class":355,"line":557},8,[559,563,567,571,575,579,584,588],{"type":46,"tag":353,"props":560,"children":561},{"style":360},[562],{"type":51,"value":450},{"type":46,"tag":353,"props":564,"children":565},{"style":453},[566],{"type":51,"value":311},{"type":46,"tag":353,"props":568,"children":569},{"style":360},[570],{"type":51,"value":382},{"type":46,"tag":353,"props":572,"children":573},{"style":360},[574],{"type":51,"value":387},{"type":46,"tag":353,"props":576,"children":577},{"style":360},[578],{"type":51,"value":392},{"type":46,"tag":353,"props":580,"children":581},{"style":395},[582],{"type":51,"value":583},"SHA256-named parent process sideloading MsMpEng.exe confirms active ransomware execution",{"type":46,"tag":353,"props":585,"children":586},{"style":360},[587],{"type":51,"value":382},{"type":46,"tag":353,"props":589,"children":590},{"style":360},[591],{"type":51,"value":407},{"type":46,"tag":353,"props":593,"children":595},{"class":355,"line":594},9,[596,600,604,608,612,616,621,625],{"type":46,"tag":353,"props":597,"children":598},{"style":360},[599],{"type":51,"value":450},{"type":46,"tag":353,"props":601,"children":602},{"style":453},[603],{"type":51,"value":322},{"type":46,"tag":353,"props":605,"children":606},{"style":360},[607],{"type":51,"value":382},{"type":46,"tag":353,"props":609,"children":610},{"style":360},[611],{"type":51,"value":387},{"type":46,"tag":353,"props":613,"children":614},{"style":360},[615],{"type":51,"value":392},{"type":46,"tag":353,"props":617,"children":618},{"style":395},[619],{"type":51,"value":620},"Isolate host, create P1 case, hunt for lateral movement",{"type":46,"tag":353,"props":622,"children":623},{"style":360},[624],{"type":51,"value":382},{"type":46,"tag":353,"props":626,"children":627},{"style":360},[628],{"type":51,"value":407},{"type":46,"tag":353,"props":630,"children":631},{"class":355,"line":27},[632,636,640,644,648,653,657,662,666],{"type":46,"tag":353,"props":633,"children":634},{"style":360},[635],{"type":51,"value":450},{"type":46,"tag":353,"props":637,"children":638},{"style":453},[639],{"type":51,"value":333},{"type":46,"tag":353,"props":641,"children":642},{"style":360},[643],{"type":51,"value":382},{"type":46,"tag":353,"props":645,"children":646},{"style":360},[647],{"type":51,"value":387},{"type":46,"tag":353,"props":649,"children":650},{"style":360},[651],{"type":51,"value":652}," [",{"type":46,"tag":353,"props":654,"children":655},{"style":360},[656],{"type":51,"value":382},{"type":46,"tag":353,"props":658,"children":659},{"style":395},[660],{"type":51,"value":661},"SRVWIN02",{"type":46,"tag":353,"props":663,"children":664},{"style":360},[665],{"type":51,"value":382},{"type":46,"tag":353,"props":667,"children":668},{"style":360},[669],{"type":51,"value":670},"]\n",{"type":46,"tag":353,"props":672,"children":674},{"class":355,"line":673},11,[675],{"type":46,"tag":353,"props":676,"children":677},{"style":360},[678],{"type":51,"value":679},"    }\n",{"type":46,"tag":353,"props":681,"children":683},{"class":355,"line":682},12,[684],{"type":46,"tag":353,"props":685,"children":686},{"style":360},[687],{"type":51,"value":688},"  ]\n",{"type":46,"tag":353,"props":690,"children":692},{"class":355,"line":691},13,[693],{"type":46,"tag":353,"props":694,"children":695},{"style":360},[696],{"type":51,"value":697},"}\n",{"type":46,"tag":54,"props":699,"children":700},{},[701],{"type":51,"value":702},"Do NOT call the tool twice. One call only.",{"type":46,"tag":60,"props":704,"children":706},{"id":705},"after-the-tool-returns",[707],{"type":51,"value":708},"After the tool returns",{"type":46,"tag":54,"props":710,"children":711},{},[712],{"type":51,"value":713},"You receive alert details (rule names, hosts, processes, risk scores, MITRE techniques).\nProvide your analysis in text below the dashboard:",{"type":46,"tag":228,"props":715,"children":716},{},[717,722,727],{"type":46,"tag":232,"props":718,"children":719},{},[720],{"type":51,"value":721},"Group findings by host or rule",{"type":46,"tag":232,"props":723,"children":724},{},[725],{"type":51,"value":726},"Classify each as benign\u002Fsuspicious\u002Fmalicious with reasoning",{"type":46,"tag":232,"props":728,"children":729},{},[730],{"type":51,"value":731},"Recommend specific actions",{"type":46,"tag":54,"props":733,"children":734},{},[735,737,743],{"type":51,"value":736},"For detailed classification criteria, see ",{"type":46,"tag":738,"props":739,"children":741},"a",{"href":740},"references\u002Fclassification-guide.md",[742],{"type":51,"value":740},{"type":51,"value":744},".",{"type":46,"tag":746,"props":747,"children":748},"style",{},[749],{"type":51,"value":750},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"items":752,"total":444},[753,760,772,785,796],{"slug":4,"name":4,"fn":5,"description":6,"org":754,"tags":755,"stars":23,"repoUrl":24,"updatedAt":25},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[756,757,758,759],{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},{"slug":761,"name":761,"fn":762,"description":763,"org":764,"tags":765,"stars":23,"repoUrl":24,"updatedAt":771},"attack-discovery-triage","triage Elastic Security attack findings","Triage Elastic Security Attack Discovery findings — fetch correlated attack narratives, assess confidence with entity risk and rule frequency signals, and present an interactive triage dashboard for approval, case creation, and acknowledgment. Use when triaging attack discoveries, reviewing correlated attacks, assessing EASE output, or when the user mentions \"attack discovery\", \"AD findings\", \"triage attacks\", \"correlated alerts\", or asks to process attack discovery results. Also trigger for \"what attacks were discovered\", \"triage my discoveries\", or \"any attack discoveries\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[766,769,770],{"name":767,"slug":768,"type":15},"Observability","observability",{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},"2026-07-12T07:48:29.539756",{"slug":773,"name":773,"fn":774,"description":775,"org":776,"tags":777,"stars":23,"repoUrl":24,"updatedAt":784},"case-management","manage Elastic Security SOC cases","Create, search, update, and manage SOC cases for Elastic Security. ALWAYS use this skill when the user mentions cases, incidents, investigations, or asks to see, show, list, open, create, update, or search cases. Trigger for: \"show me my cases\", \"open cases\", \"list cases\", \"any open cases\", \"create a case\", \"case for this alert\", \"show me case 42\", \"incident tracking\", \"investigation status\", or any case-related question.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[778,779,782,783],{"name":9,"slug":8,"type":15},{"name":780,"slug":781,"type":15},"Incident Response","incident-response",{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},"2026-07-12T07:48:24.262486",{"slug":786,"name":786,"fn":787,"description":788,"org":789,"tags":790,"stars":23,"repoUrl":24,"updatedAt":795},"detection-rule-management","manage Elastic Security detection rules","Create, tune, and manage Elastic Security detection rules. Use for false positive tuning, adding exceptions, creating new detection coverage, finding noisy rules, enabling\u002Fdisabling rules, or any detection engineering task. Also trigger for \"detection rules\", \"noisy rules\", \"false positives\", \"add exception\", \"create rule\", or \"tune rule\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[791,792,793,794],{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},"2026-07-12T07:48:28.211728",{"slug":797,"name":797,"fn":798,"description":799,"org":800,"tags":801,"stars":23,"repoUrl":24,"updatedAt":810},"generate-sample-data","generate sample Elastic Security data","Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, setting up a POC, or when the user asks for test data, demo data, or sample alerts.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[802,805,806,807],{"name":803,"slug":804,"type":15},"Dashboards","dashboards",{"name":9,"slug":8,"type":15},{"name":13,"slug":14,"type":15},{"name":808,"slug":809,"type":15},"Testing","testing","2026-07-12T07:48:25.510646",{"items":812,"total":980},[813,832,849,862,881,893,903,916,928,943,954,967],{"slug":814,"name":814,"fn":815,"description":816,"org":817,"tags":818,"stars":829,"repoUrl":830,"updatedAt":831},"accessing-benchmark-results","retrieve and analyze Rally benchmark results","Retrieve Rally benchmark results from an external Elasticsearch metrics store. Use to list past races, get a single race's overall (per-task) results, chart a metric's trend across multiple runs, compare two races, or check whether a run converged — e.g. \"show me recent geonames races\", \"what's the service_time trend for nyc_taxis over the last 30 days?\", \"compare these two race-ids\". Applies when datastore.type = elasticsearch is set in ~\u002F.rally\u002Frally.ini.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[819,822,825,826],{"name":820,"slug":821,"type":15},"Analytics","analytics",{"name":823,"slug":824,"type":15},"Data Analysis","data-analysis",{"name":9,"slug":8,"type":15},{"name":827,"slug":828,"type":15},"Performance","performance",2027,"https:\u002F\u002Fgithub.com\u002Felastic\u002Frally","2026-07-12T07:46:38.54144",{"slug":833,"name":833,"fn":834,"description":835,"org":836,"tags":837,"stars":829,"repoUrl":830,"updatedAt":848},"developing-rally","develop and debug Rally source code","Work on Rally's own codebase, not running benchmarks with it. Use when setting up the dev environment, running Rally's tests or linters, navigating its source, debugging Rally's own code, or making changes to Rally itself.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[838,841,842,845],{"name":839,"slug":840,"type":15},"Debugging","debugging",{"name":9,"slug":8,"type":15},{"name":843,"slug":844,"type":15},"Engineering","engineering",{"name":846,"slug":847,"type":15},"Local Development","local-development","2026-07-12T07:46:35.976807",{"slug":850,"name":850,"fn":851,"description":852,"org":853,"tags":854,"stars":829,"repoUrl":830,"updatedAt":861},"running-benchmarks","run Rally benchmarks against Elasticsearch","Run Rally benchmarks (races) against Elasticsearch — an existing\u002Fexternal cluster or a Rally-provisioned distribution — and read the summary report. Use when running a race (any pipeline, track, challenge, target-hosts, or auth) or when interpreting throughput, latency, and service_time results.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[855,856,859,860],{"name":9,"slug":8,"type":15},{"name":857,"slug":858,"type":15},"Elasticsearch","elasticsearch",{"name":827,"slug":828,"type":15},{"name":808,"slug":809,"type":15},"2026-07-12T07:46:37.277964",{"slug":863,"name":863,"fn":864,"description":865,"org":866,"tags":867,"stars":878,"repoUrl":879,"updatedAt":880},"cloud-access-management","manage Elastic Cloud organization access","Manage Elastic Cloud organization access: invite users, assign roles to Serverless projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[868,871,872,875],{"name":869,"slug":870,"type":15},"Cloud","cloud",{"name":9,"slug":8,"type":15},{"name":873,"slug":874,"type":15},"Operations","operations",{"name":876,"slug":877,"type":15},"Permissions","permissions",531,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fagent-skills","2026-07-12T07:46:44.946285",{"slug":882,"name":882,"fn":883,"description":884,"org":885,"tags":886,"stars":878,"repoUrl":879,"updatedAt":892},"cloud-create-project","create Elastic Cloud Serverless projects","Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[887,888,891],{"name":869,"slug":870,"type":15},{"name":889,"slug":890,"type":15},"Deployment","deployment",{"name":857,"slug":858,"type":15},"2026-07-12T07:46:42.353362",{"slug":894,"name":894,"fn":895,"description":896,"org":897,"tags":898,"stars":878,"repoUrl":879,"updatedAt":902},"cloud-manage-project","manage Elastic Cloud Serverless projects","Manages existing Elastic Cloud Serverless projects: list, get, update, delete, reset credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[899,900,901],{"name":869,"slug":870,"type":15},{"name":857,"slug":858,"type":15},{"name":873,"slug":874,"type":15},"2026-07-12T07:46:41.097412",{"slug":904,"name":904,"fn":905,"description":906,"org":907,"tags":908,"stars":878,"repoUrl":879,"updatedAt":915},"cloud-network-security","manage Elastic Cloud network security","Manage Serverless network security (traffic filters): create, update, and delete IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[909,910,911,914],{"name":869,"slug":870,"type":15},{"name":857,"slug":858,"type":15},{"name":912,"slug":913,"type":15},"Networking","networking",{"name":13,"slug":14,"type":15},"2026-07-12T07:46:43.675992",{"slug":917,"name":917,"fn":918,"description":919,"org":920,"tags":921,"stars":878,"repoUrl":879,"updatedAt":927},"cloud-setup","configure Elastic Cloud authentication","Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[922,925,926],{"name":923,"slug":924,"type":15},"Authentication","authentication",{"name":869,"slug":870,"type":15},{"name":857,"slug":858,"type":15},"2026-07-12T07:46:39.783105",{"slug":929,"name":929,"fn":930,"description":931,"org":932,"tags":933,"stars":878,"repoUrl":879,"updatedAt":942},"elasticsearch-audit","configure Elasticsearch security audit logs","Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[934,937,938,941],{"name":935,"slug":936,"type":15},"Audit","audit",{"name":857,"slug":858,"type":15},{"name":939,"slug":940,"type":15},"Logs","logs",{"name":13,"slug":14,"type":15},"2026-07-12T07:47:35.092599",{"slug":944,"name":944,"fn":945,"description":946,"org":947,"tags":948,"stars":878,"repoUrl":879,"updatedAt":953},"elasticsearch-authn","configure Elasticsearch authentication realms","Authenticate to Elasticsearch using native, file-based, LDAP\u002FAD, SAML, OIDC, Kerberos, JWT, or certificate realms. Use when connecting with credentials, choosing a realm, or managing API keys. Assumes the target realms are already configured.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[949,950,951,952],{"name":923,"slug":924,"type":15},{"name":9,"slug":8,"type":15},{"name":857,"slug":858,"type":15},{"name":13,"slug":14,"type":15},"2026-07-12T07:47:41.474547",{"slug":955,"name":955,"fn":956,"description":957,"org":958,"tags":959,"stars":878,"repoUrl":879,"updatedAt":966},"elasticsearch-authz","manage Elasticsearch RBAC and security roles","Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP\u002FSAML.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[960,961,962,965],{"name":9,"slug":8,"type":15},{"name":857,"slug":858,"type":15},{"name":963,"slug":964,"type":15},"RBAC","rbac",{"name":13,"slug":14,"type":15},"2026-07-12T07:47:36.394177",{"slug":968,"name":968,"fn":969,"description":970,"org":971,"tags":972,"stars":878,"repoUrl":879,"updatedAt":979},"elasticsearch-esql","query Elasticsearch data with ES|QL","Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[973,974,975,976],{"name":820,"slug":821,"type":15},{"name":823,"slug":824,"type":15},{"name":857,"slug":858,"type":15},{"name":977,"slug":978,"type":15},"SQL","sql","2026-07-12T07:47:40.249533",86]