[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-elastic-detection-rule-management":3,"mdc-cydb9r-key":40,"related-org-elastic-detection-rule-management":555,"related-repo-elastic-detection-rule-management":727},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":23,"repoUrl":24,"updatedAt":25,"license":26,"forks":27,"topics":28,"repo":35,"sourceUrl":38,"mdContent":39},"detection-rule-management","manage Elastic Security detection rules","Create, tune, and manage Elastic Security detection rules. Use for false positive tuning, adding exceptions, creating new detection coverage, finding noisy rules, enabling\u002Fdisabling rules, or any detection engineering task. Also trigger for \"detection rules\", \"noisy rules\", \"false positives\", \"add exception\", \"create rule\", or \"tune rule\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"elastic","Elastic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Felastic.png",[12,16,19,20],{"name":13,"slug":14,"type":15},"Security","security","tag",{"name":17,"slug":18,"type":15},"Monitoring","monitoring",{"name":9,"slug":8,"type":15},{"name":21,"slug":22,"type":15},"Triage","triage",18,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fexample-mcp-app-security","2026-07-12T07:48:28.211728",null,10,[29,30,31,8,32,33,14,34],"ai","claude","cursor","mcp","model-context-protocol","soc",{"repoUrl":24,"stars":23,"forks":27,"topics":36,"description":37},[29,30,31,8,32,33,14,34],"Reference MCP App for Elastic Security — interactive SOC dashboards inside Claude, Cursor, and other MCP hosts.","https:\u002F\u002Fgithub.com\u002Felastic\u002Fexample-mcp-app-security\u002Ftree\u002FHEAD\u002Fskills\u002Fdetection-rule-management","---\nname: detection-rule-management\ndescription: >\n  Create, tune, and manage Elastic Security detection rules. Use for false positive\n  tuning, adding exceptions, creating new detection coverage, finding noisy rules,\n  enabling\u002Fdisabling rules, or any detection engineering task. Also trigger for\n  \"detection rules\", \"noisy rules\", \"false positives\", \"add exception\", \"create rule\",\n  or \"tune rule\".\n---\n\n# Detection Rule Management\n\nManage detection rules using the `elastic-security` MCP connector. The `manage-rules` tool renders an interactive\nrule management dashboard.\n\n## Tools (via elastic-security MCP connector)\n\n| Tool | Purpose |\n|------|---------|\n| `manage-rules` | Browse\u002Fsearch rules with interactive dashboard. Params: `filter` (KQL) |\n| `threat-hunt` | Test queries against live data before creating rules |\n\nThe dashboard supports searching rules, viewing details, enabling\u002Fdisabling, validating queries, and viewing noisy rules.\n\n## Rule Types\n\n| Type | Use case | Example |\n|------|----------|---------|\n| `query` (KQL) | Simple field matching | `process.name: \"mimikatz.exe\"` |\n| `eql` | Behavioral sequences | Process A spawns B within 5 minutes |\n| `esql` | Analytics\u002Faggregations | Complex joins or transformations |\n| `threshold` | Count\u002Ffrequency | >10 failed logins in 5 minutes |\n| `threat_match` | IOC correlation | Match against malicious IP indicators |\n| `new_terms` | First-time activity | User logs into host for first time |\n\n## Tuning Strategy (in order of preference)\n\n1. **Add exception** — Known-good process\u002Fuser\u002Fhost. Does not modify the rule query.\n2. **Tighten the query** — Exclude FP pattern from the rule query itself.\n3. **Adjust threshold\u002Fsuppression** — Increase threshold or enable alert suppression.\n4. **Reduce risk score\u002Fseverity** — Downgrade priority if rule has some value but is noisy.\n5. **Disable the rule** — Last resort. Only if rule provides no value.\n\n## Creating New Rules\n\n1. Define the threat (MITRE technique, data sources, malicious vs legitimate behavior)\n2. Test the query with `threat-hunt` against live data\n3. Create via the dashboard or ask Claude to help construct the rule JSON\n4. Monitor alert volume and tune false positives\n\n## Common Index Patterns\n\n| Data type | Index pattern |\n|-----------|--------------|\n| Alerts | `.alerts-security.alerts-*` |\n| Processes | `logs-endpoint.events.process-*` |\n| Network | `logs-endpoint.events.network-*` |\n| Windows | `logs-windows.*` |\n| AWS | `logs-aws.*` |\n| Okta | `logs-okta.*` |\n",{"data":41,"body":42},{"name":4,"description":6},{"type":43,"children":44},"root",[45,53,76,83,152,157,163,327,333,389,395,425,431],{"type":46,"tag":47,"props":48,"children":49},"element","h1",{"id":4},[50],{"type":51,"value":52},"text","Detection Rule Management",{"type":46,"tag":54,"props":55,"children":56},"p",{},[57,59,66,68,74],{"type":51,"value":58},"Manage detection rules using the ",{"type":46,"tag":60,"props":61,"children":63},"code",{"className":62},[],[64],{"type":51,"value":65},"elastic-security",{"type":51,"value":67}," MCP connector. The ",{"type":46,"tag":60,"props":69,"children":71},{"className":70},[],[72],{"type":51,"value":73},"manage-rules",{"type":51,"value":75}," tool renders an interactive\nrule management dashboard.",{"type":46,"tag":77,"props":78,"children":80},"h2",{"id":79},"tools-via-elastic-security-mcp-connector",[81],{"type":51,"value":82},"Tools (via elastic-security MCP connector)",{"type":46,"tag":84,"props":85,"children":86},"table",{},[87,106],{"type":46,"tag":88,"props":89,"children":90},"thead",{},[91],{"type":46,"tag":92,"props":93,"children":94},"tr",{},[95,101],{"type":46,"tag":96,"props":97,"children":98},"th",{},[99],{"type":51,"value":100},"Tool",{"type":46,"tag":96,"props":102,"children":103},{},[104],{"type":51,"value":105},"Purpose",{"type":46,"tag":107,"props":108,"children":109},"tbody",{},[110,135],{"type":46,"tag":92,"props":111,"children":112},{},[113,122],{"type":46,"tag":114,"props":115,"children":116},"td",{},[117],{"type":46,"tag":60,"props":118,"children":120},{"className":119},[],[121],{"type":51,"value":73},{"type":46,"tag":114,"props":123,"children":124},{},[125,127,133],{"type":51,"value":126},"Browse\u002Fsearch rules with interactive dashboard. Params: ",{"type":46,"tag":60,"props":128,"children":130},{"className":129},[],[131],{"type":51,"value":132},"filter",{"type":51,"value":134}," (KQL)",{"type":46,"tag":92,"props":136,"children":137},{},[138,147],{"type":46,"tag":114,"props":139,"children":140},{},[141],{"type":46,"tag":60,"props":142,"children":144},{"className":143},[],[145],{"type":51,"value":146},"threat-hunt",{"type":46,"tag":114,"props":148,"children":149},{},[150],{"type":51,"value":151},"Test queries against live data before creating rules",{"type":46,"tag":54,"props":153,"children":154},{},[155],{"type":51,"value":156},"The dashboard supports searching rules, viewing details, enabling\u002Fdisabling, validating queries, and viewing noisy rules.",{"type":46,"tag":77,"props":158,"children":160},{"id":159},"rule-types",[161],{"type":51,"value":162},"Rule Types",{"type":46,"tag":84,"props":164,"children":165},{},[166,187],{"type":46,"tag":88,"props":167,"children":168},{},[169],{"type":46,"tag":92,"props":170,"children":171},{},[172,177,182],{"type":46,"tag":96,"props":173,"children":174},{},[175],{"type":51,"value":176},"Type",{"type":46,"tag":96,"props":178,"children":179},{},[180],{"type":51,"value":181},"Use case",{"type":46,"tag":96,"props":183,"children":184},{},[185],{"type":51,"value":186},"Example",{"type":46,"tag":107,"props":188,"children":189},{},[190,217,239,261,283,305],{"type":46,"tag":92,"props":191,"children":192},{},[193,203,208],{"type":46,"tag":114,"props":194,"children":195},{},[196,202],{"type":46,"tag":60,"props":197,"children":199},{"className":198},[],[200],{"type":51,"value":201},"query",{"type":51,"value":134},{"type":46,"tag":114,"props":204,"children":205},{},[206],{"type":51,"value":207},"Simple field matching",{"type":46,"tag":114,"props":209,"children":210},{},[211],{"type":46,"tag":60,"props":212,"children":214},{"className":213},[],[215],{"type":51,"value":216},"process.name: \"mimikatz.exe\"",{"type":46,"tag":92,"props":218,"children":219},{},[220,229,234],{"type":46,"tag":114,"props":221,"children":222},{},[223],{"type":46,"tag":60,"props":224,"children":226},{"className":225},[],[227],{"type":51,"value":228},"eql",{"type":46,"tag":114,"props":230,"children":231},{},[232],{"type":51,"value":233},"Behavioral sequences",{"type":46,"tag":114,"props":235,"children":236},{},[237],{"type":51,"value":238},"Process A spawns B within 5 minutes",{"type":46,"tag":92,"props":240,"children":241},{},[242,251,256],{"type":46,"tag":114,"props":243,"children":244},{},[245],{"type":46,"tag":60,"props":246,"children":248},{"className":247},[],[249],{"type":51,"value":250},"esql",{"type":46,"tag":114,"props":252,"children":253},{},[254],{"type":51,"value":255},"Analytics\u002Faggregations",{"type":46,"tag":114,"props":257,"children":258},{},[259],{"type":51,"value":260},"Complex joins or transformations",{"type":46,"tag":92,"props":262,"children":263},{},[264,273,278],{"type":46,"tag":114,"props":265,"children":266},{},[267],{"type":46,"tag":60,"props":268,"children":270},{"className":269},[],[271],{"type":51,"value":272},"threshold",{"type":46,"tag":114,"props":274,"children":275},{},[276],{"type":51,"value":277},"Count\u002Ffrequency",{"type":46,"tag":114,"props":279,"children":280},{},[281],{"type":51,"value":282},">10 failed logins in 5 minutes",{"type":46,"tag":92,"props":284,"children":285},{},[286,295,300],{"type":46,"tag":114,"props":287,"children":288},{},[289],{"type":46,"tag":60,"props":290,"children":292},{"className":291},[],[293],{"type":51,"value":294},"threat_match",{"type":46,"tag":114,"props":296,"children":297},{},[298],{"type":51,"value":299},"IOC correlation",{"type":46,"tag":114,"props":301,"children":302},{},[303],{"type":51,"value":304},"Match against malicious IP indicators",{"type":46,"tag":92,"props":306,"children":307},{},[308,317,322],{"type":46,"tag":114,"props":309,"children":310},{},[311],{"type":46,"tag":60,"props":312,"children":314},{"className":313},[],[315],{"type":51,"value":316},"new_terms",{"type":46,"tag":114,"props":318,"children":319},{},[320],{"type":51,"value":321},"First-time activity",{"type":46,"tag":114,"props":323,"children":324},{},[325],{"type":51,"value":326},"User logs into host for first time",{"type":46,"tag":77,"props":328,"children":330},{"id":329},"tuning-strategy-in-order-of-preference",[331],{"type":51,"value":332},"Tuning Strategy (in order of preference)",{"type":46,"tag":334,"props":335,"children":336},"ol",{},[337,349,359,369,379],{"type":46,"tag":338,"props":339,"children":340},"li",{},[341,347],{"type":46,"tag":342,"props":343,"children":344},"strong",{},[345],{"type":51,"value":346},"Add exception",{"type":51,"value":348}," — Known-good process\u002Fuser\u002Fhost. Does not modify the rule query.",{"type":46,"tag":338,"props":350,"children":351},{},[352,357],{"type":46,"tag":342,"props":353,"children":354},{},[355],{"type":51,"value":356},"Tighten the query",{"type":51,"value":358}," — Exclude FP pattern from the rule query itself.",{"type":46,"tag":338,"props":360,"children":361},{},[362,367],{"type":46,"tag":342,"props":363,"children":364},{},[365],{"type":51,"value":366},"Adjust threshold\u002Fsuppression",{"type":51,"value":368}," — Increase threshold or enable alert suppression.",{"type":46,"tag":338,"props":370,"children":371},{},[372,377],{"type":46,"tag":342,"props":373,"children":374},{},[375],{"type":51,"value":376},"Reduce risk score\u002Fseverity",{"type":51,"value":378}," — Downgrade priority if rule has some value but is noisy.",{"type":46,"tag":338,"props":380,"children":381},{},[382,387],{"type":46,"tag":342,"props":383,"children":384},{},[385],{"type":51,"value":386},"Disable the rule",{"type":51,"value":388}," — Last resort. Only if rule provides no value.",{"type":46,"tag":77,"props":390,"children":392},{"id":391},"creating-new-rules",[393],{"type":51,"value":394},"Creating New Rules",{"type":46,"tag":334,"props":396,"children":397},{},[398,403,415,420],{"type":46,"tag":338,"props":399,"children":400},{},[401],{"type":51,"value":402},"Define the threat (MITRE technique, data sources, malicious vs legitimate behavior)",{"type":46,"tag":338,"props":404,"children":405},{},[406,408,413],{"type":51,"value":407},"Test the query with ",{"type":46,"tag":60,"props":409,"children":411},{"className":410},[],[412],{"type":51,"value":146},{"type":51,"value":414}," against live data",{"type":46,"tag":338,"props":416,"children":417},{},[418],{"type":51,"value":419},"Create via the dashboard or ask Claude to help construct the rule JSON",{"type":46,"tag":338,"props":421,"children":422},{},[423],{"type":51,"value":424},"Monitor alert volume and tune false positives",{"type":46,"tag":77,"props":426,"children":428},{"id":427},"common-index-patterns",[429],{"type":51,"value":430},"Common Index Patterns",{"type":46,"tag":84,"props":432,"children":433},{},[434,450],{"type":46,"tag":88,"props":435,"children":436},{},[437],{"type":46,"tag":92,"props":438,"children":439},{},[440,445],{"type":46,"tag":96,"props":441,"children":442},{},[443],{"type":51,"value":444},"Data type",{"type":46,"tag":96,"props":446,"children":447},{},[448],{"type":51,"value":449},"Index pattern",{"type":46,"tag":107,"props":451,"children":452},{},[453,470,487,504,521,538],{"type":46,"tag":92,"props":454,"children":455},{},[456,461],{"type":46,"tag":114,"props":457,"children":458},{},[459],{"type":51,"value":460},"Alerts",{"type":46,"tag":114,"props":462,"children":463},{},[464],{"type":46,"tag":60,"props":465,"children":467},{"className":466},[],[468],{"type":51,"value":469},".alerts-security.alerts-*",{"type":46,"tag":92,"props":471,"children":472},{},[473,478],{"type":46,"tag":114,"props":474,"children":475},{},[476],{"type":51,"value":477},"Processes",{"type":46,"tag":114,"props":479,"children":480},{},[481],{"type":46,"tag":60,"props":482,"children":484},{"className":483},[],[485],{"type":51,"value":486},"logs-endpoint.events.process-*",{"type":46,"tag":92,"props":488,"children":489},{},[490,495],{"type":46,"tag":114,"props":491,"children":492},{},[493],{"type":51,"value":494},"Network",{"type":46,"tag":114,"props":496,"children":497},{},[498],{"type":46,"tag":60,"props":499,"children":501},{"className":500},[],[502],{"type":51,"value":503},"logs-endpoint.events.network-*",{"type":46,"tag":92,"props":505,"children":506},{},[507,512],{"type":46,"tag":114,"props":508,"children":509},{},[510],{"type":51,"value":511},"Windows",{"type":46,"tag":114,"props":513,"children":514},{},[515],{"type":46,"tag":60,"props":516,"children":518},{"className":517},[],[519],{"type":51,"value":520},"logs-windows.*",{"type":46,"tag":92,"props":522,"children":523},{},[524,529],{"type":46,"tag":114,"props":525,"children":526},{},[527],{"type":51,"value":528},"AWS",{"type":46,"tag":114,"props":530,"children":531},{},[532],{"type":46,"tag":60,"props":533,"children":535},{"className":534},[],[536],{"type":51,"value":537},"logs-aws.*",{"type":46,"tag":92,"props":539,"children":540},{},[541,546],{"type":46,"tag":114,"props":542,"children":543},{},[544],{"type":51,"value":545},"Okta",{"type":46,"tag":114,"props":547,"children":548},{},[549],{"type":46,"tag":60,"props":550,"children":552},{"className":551},[],[553],{"type":51,"value":554},"logs-okta.*",{"items":556,"total":726},[557,576,593,608,627,639,649,662,674,689,700,713],{"slug":558,"name":558,"fn":559,"description":560,"org":561,"tags":562,"stars":573,"repoUrl":574,"updatedAt":575},"accessing-benchmark-results","retrieve and analyze Rally benchmark results","Retrieve Rally benchmark results from an external Elasticsearch metrics store. Use to list past races, get a single race's overall (per-task) results, chart a metric's trend across multiple runs, compare two races, or check whether a run converged — e.g. \"show me recent geonames races\", \"what's the service_time trend for nyc_taxis over the last 30 days?\", \"compare these two race-ids\". Applies when datastore.type = elasticsearch is set in ~\u002F.rally\u002Frally.ini.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[563,566,569,570],{"name":564,"slug":565,"type":15},"Analytics","analytics",{"name":567,"slug":568,"type":15},"Data Analysis","data-analysis",{"name":9,"slug":8,"type":15},{"name":571,"slug":572,"type":15},"Performance","performance",2027,"https:\u002F\u002Fgithub.com\u002Felastic\u002Frally","2026-07-12T07:46:38.54144",{"slug":577,"name":577,"fn":578,"description":579,"org":580,"tags":581,"stars":573,"repoUrl":574,"updatedAt":592},"developing-rally","develop and debug Rally source code","Work on Rally's own codebase, not running benchmarks with it. Use when setting up the dev environment, running Rally's tests or linters, navigating its source, debugging Rally's own code, or making changes to Rally itself.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[582,585,586,589],{"name":583,"slug":584,"type":15},"Debugging","debugging",{"name":9,"slug":8,"type":15},{"name":587,"slug":588,"type":15},"Engineering","engineering",{"name":590,"slug":591,"type":15},"Local Development","local-development","2026-07-12T07:46:35.976807",{"slug":594,"name":594,"fn":595,"description":596,"org":597,"tags":598,"stars":573,"repoUrl":574,"updatedAt":607},"running-benchmarks","run Rally benchmarks against Elasticsearch","Run Rally benchmarks (races) against Elasticsearch — an existing\u002Fexternal cluster or a Rally-provisioned distribution — and read the summary report. Use when running a race (any pipeline, track, challenge, target-hosts, or auth) or when interpreting throughput, latency, and service_time results.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[599,600,603,604],{"name":9,"slug":8,"type":15},{"name":601,"slug":602,"type":15},"Elasticsearch","elasticsearch",{"name":571,"slug":572,"type":15},{"name":605,"slug":606,"type":15},"Testing","testing","2026-07-12T07:46:37.277964",{"slug":609,"name":609,"fn":610,"description":611,"org":612,"tags":613,"stars":624,"repoUrl":625,"updatedAt":626},"cloud-access-management","manage Elastic Cloud organization access","Manage Elastic Cloud organization access: invite users, assign roles to Serverless projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[614,617,618,621],{"name":615,"slug":616,"type":15},"Cloud","cloud",{"name":9,"slug":8,"type":15},{"name":619,"slug":620,"type":15},"Operations","operations",{"name":622,"slug":623,"type":15},"Permissions","permissions",531,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fagent-skills","2026-07-12T07:46:44.946285",{"slug":628,"name":628,"fn":629,"description":630,"org":631,"tags":632,"stars":624,"repoUrl":625,"updatedAt":638},"cloud-create-project","create Elastic Cloud Serverless projects","Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[633,634,637],{"name":615,"slug":616,"type":15},{"name":635,"slug":636,"type":15},"Deployment","deployment",{"name":601,"slug":602,"type":15},"2026-07-12T07:46:42.353362",{"slug":640,"name":640,"fn":641,"description":642,"org":643,"tags":644,"stars":624,"repoUrl":625,"updatedAt":648},"cloud-manage-project","manage Elastic Cloud Serverless projects","Manages existing Elastic Cloud Serverless projects: list, get, update, delete, reset credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[645,646,647],{"name":615,"slug":616,"type":15},{"name":601,"slug":602,"type":15},{"name":619,"slug":620,"type":15},"2026-07-12T07:46:41.097412",{"slug":650,"name":650,"fn":651,"description":652,"org":653,"tags":654,"stars":624,"repoUrl":625,"updatedAt":661},"cloud-network-security","manage Elastic Cloud network security","Manage Serverless network security (traffic filters): create, update, and delete IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[655,656,657,660],{"name":615,"slug":616,"type":15},{"name":601,"slug":602,"type":15},{"name":658,"slug":659,"type":15},"Networking","networking",{"name":13,"slug":14,"type":15},"2026-07-12T07:46:43.675992",{"slug":663,"name":663,"fn":664,"description":665,"org":666,"tags":667,"stars":624,"repoUrl":625,"updatedAt":673},"cloud-setup","configure Elastic Cloud authentication","Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[668,671,672],{"name":669,"slug":670,"type":15},"Authentication","authentication",{"name":615,"slug":616,"type":15},{"name":601,"slug":602,"type":15},"2026-07-12T07:46:39.783105",{"slug":675,"name":675,"fn":676,"description":677,"org":678,"tags":679,"stars":624,"repoUrl":625,"updatedAt":688},"elasticsearch-audit","configure Elasticsearch security audit logs","Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[680,683,684,687],{"name":681,"slug":682,"type":15},"Audit","audit",{"name":601,"slug":602,"type":15},{"name":685,"slug":686,"type":15},"Logs","logs",{"name":13,"slug":14,"type":15},"2026-07-12T07:47:35.092599",{"slug":690,"name":690,"fn":691,"description":692,"org":693,"tags":694,"stars":624,"repoUrl":625,"updatedAt":699},"elasticsearch-authn","configure Elasticsearch authentication realms","Authenticate to Elasticsearch using native, file-based, LDAP\u002FAD, SAML, OIDC, Kerberos, JWT, or certificate realms. Use when connecting with credentials, choosing a realm, or managing API keys. Assumes the target realms are already configured.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[695,696,697,698],{"name":669,"slug":670,"type":15},{"name":9,"slug":8,"type":15},{"name":601,"slug":602,"type":15},{"name":13,"slug":14,"type":15},"2026-07-12T07:47:41.474547",{"slug":701,"name":701,"fn":702,"description":703,"org":704,"tags":705,"stars":624,"repoUrl":625,"updatedAt":712},"elasticsearch-authz","manage Elasticsearch RBAC and security roles","Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP\u002FSAML.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[706,707,708,711],{"name":9,"slug":8,"type":15},{"name":601,"slug":602,"type":15},{"name":709,"slug":710,"type":15},"RBAC","rbac",{"name":13,"slug":14,"type":15},"2026-07-12T07:47:36.394177",{"slug":714,"name":714,"fn":715,"description":716,"org":717,"tags":718,"stars":624,"repoUrl":625,"updatedAt":725},"elasticsearch-esql","query Elasticsearch data with ES|QL","Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[719,720,721,722],{"name":564,"slug":565,"type":15},{"name":567,"slug":568,"type":15},{"name":601,"slug":602,"type":15},{"name":723,"slug":724,"type":15},"SQL","sql","2026-07-12T07:47:40.249533",86,{"items":728,"total":785},[729,740,752,765,772],{"slug":730,"name":730,"fn":731,"description":732,"org":733,"tags":734,"stars":23,"repoUrl":24,"updatedAt":739},"alert-triage","triage Elastic Security alerts","Triage Elastic Security alerts — fetch, investigate, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, investigating detections, reviewing security incidents, or when the user mentions ransomware, malware, lateral movement, credential theft, DLL injection, suspicious processes, or any specific threat. Also trigger for \"show me alerts\", \"what's happening on host X\", \"any critical alerts\", or any security operations question.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[735,736,737,738],{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},"2026-07-12T07:48:26.972827",{"slug":741,"name":741,"fn":742,"description":743,"org":744,"tags":745,"stars":23,"repoUrl":24,"updatedAt":751},"attack-discovery-triage","triage Elastic Security attack findings","Triage Elastic Security Attack Discovery findings — fetch correlated attack narratives, assess confidence with entity risk and rule frequency signals, and present an interactive triage dashboard for approval, case creation, and acknowledgment. Use when triaging attack discoveries, reviewing correlated attacks, assessing EASE output, or when the user mentions \"attack discovery\", \"AD findings\", \"triage attacks\", \"correlated alerts\", or asks to process attack discovery results. Also trigger for \"what attacks were discovered\", \"triage my discoveries\", or \"any attack discoveries\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[746,749,750],{"name":747,"slug":748,"type":15},"Observability","observability",{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},"2026-07-12T07:48:29.539756",{"slug":753,"name":753,"fn":754,"description":755,"org":756,"tags":757,"stars":23,"repoUrl":24,"updatedAt":764},"case-management","manage Elastic Security SOC cases","Create, search, update, and manage SOC cases for Elastic Security. ALWAYS use this skill when the user mentions cases, incidents, investigations, or asks to see, show, list, open, create, update, or search cases. Trigger for: \"show me my cases\", \"open cases\", \"list cases\", \"any open cases\", \"create a case\", \"case for this alert\", \"show me case 42\", \"incident tracking\", \"investigation status\", or any case-related question.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[758,759,762,763],{"name":9,"slug":8,"type":15},{"name":760,"slug":761,"type":15},"Incident Response","incident-response",{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},"2026-07-12T07:48:24.262486",{"slug":4,"name":4,"fn":5,"description":6,"org":766,"tags":767,"stars":23,"repoUrl":24,"updatedAt":25},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[768,769,770,771],{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},{"name":13,"slug":14,"type":15},{"name":21,"slug":22,"type":15},{"slug":773,"name":773,"fn":774,"description":775,"org":776,"tags":777,"stars":23,"repoUrl":24,"updatedAt":784},"generate-sample-data","generate sample Elastic Security data","Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, setting up a POC, or when the user asks for test data, demo data, or sample alerts.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[778,781,782,783],{"name":779,"slug":780,"type":15},"Dashboards","dashboards",{"name":9,"slug":8,"type":15},{"name":13,"slug":14,"type":15},{"name":605,"slug":606,"type":15},"2026-07-12T07:48:25.510646",5]