Official agent skill

Security Case Management

by elastic in elastic/agent-skills

Create, search, update, and manage SOC cases via the Kibana Cases API.

OfficialApache-2.0Auto-check: notesBackend & APIs

Install Security Case Management

skills CLI
$ npx skills add elastic/agent-skills --skill security-case-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills security-case-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/case-management .claude/skills/security-case-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-case-management
GitHub stars
592
Used in
1 other repo
Token cost
~2.6k tokens
SKILL.md length
951 words
Files
4 (incl. scripts, references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create, search, update, and manage SOC cases via the Kibana Cases API.

  • Works in 5 steps: State the exact total count from the… → Present each case as a compact one-line… → If the user asked for N cases, present… → …
  • Tracking incidents
  • SKILL.md covers Prerequisites, When to use, When NOT to use and Execution rules, plus 11 more sections
  • Runs JavaScript scripts from its folder; calls node and npm; needs KIBANA_API_KEY

What it does

Security Case Management is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/kibana-cases-api.md`, `scripts/case-manager.js` and `scripts/kibana-client.js`). Compatibility notes: Requires Node.js 22+, network access to Kibana. Environment variables: KIBANAURL, plus KIBANAAPIKEY or KIBANAUSERNAME/KIBANAPASSWORD.

It sits in Backend & APIs. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Tracking incidents
  • Linking alerts to cases
  • Adding investigation notes
  • Managing triage output

Example prompts

  • “/security-case-management”

Requirements

  • Node.js
  • A credential in KIBANA_API_KEY
  • Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL, plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. State the exact total count from the JSON response (e.g., "There are 12 open cases total").
  2. Present each case as a compact one-line entry: | | | . Copy the
  3. If the user asked for N cases, present exactly N entries (or fewer if fewer exist). Do not add extra columns (alerts
  4. Do not add information beyond what the API returned. If a field is null or missing, omit it.
  5. After presenting the results, stop. Do not add analysis, commentary, or observations about the cases.

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • KIBANA_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL, plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD.

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Case Management loads about 2.6k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 951 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    environment variables (or add them to a `.env` file in the workspace root):

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 951 words, ~2,601 tokens.

Download SKILL.mdSave it as .claude/skills/security-case-management/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security-case-management
description
Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.
compatibility
Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL, plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD.
metadata.author
elastic
metadata.version
0.1.0

Case Management

Manage SOC cases through the Kibana Cases API. All cases are scoped to securitySolution — this skill operates exclusively within Elastic Security. Cases appear in Kibana Security and can be assigned to analysts, linked to alerts, and pushed to external incident management systems via connectors.

Prerequisites

Install dependencies before first use from the skills/security directory:

bash
cd skills/security && npm install

Set the required environment variables (or add them to a .env file in the workspace root):

bash
export KIBANA_URL="https://your-cluster.kb.cloud.example.com:443"
export KIBANA_API_KEY="your-kibana-api-key"

When to use

  • Creating a case after alert triage (classification, IOCs, findings)
  • Searching for existing cases to correlate related alerts
  • Adding investigation comments or attaching alerts to an existing case
  • Updating case status or severity
  • Listing recent cases for review

When NOT to use

  • Do not use this skill for Observability or Elasticsearch cases — it hardcodes owner: securitySolution
  • Do not use for cases outside the Security solution space

Execution rules

  • Start executing tools immediately — do not read SKILL.md, browse the workspace, or list files first.
  • Report tool output faithfully. Copy case IDs, titles, tags, severities, and counts exactly as returned by the API. Do not abbreviate case IDs, truncate titles, invent details, or round numbers.
  • When the API returns zero results, state that explicitly — do not guess at possible results.
  • When listing or finding cases, report the exact total count from the API response and present each case with its verbatim title, severity, and status.

Quick start

All commands run from the workspace root. All output is JSON. Call the tools directly — do not read the skill file or explore the workspace first. For attach-alert/attach-alerts, --rule-id and --rule-name are required by the Kibana API (use --rule-id unknown --rule-name unknown if unknown). Use attach-alerts for batch with automatic rate-limit retry and 2-second spacing between API calls.

Common multi-step workflows

TaskTools to call (in order)
Create a casecase_manager create (title, description, tags, severity)
Find cases for a hostcase_manager find --tags "agent_id:<id>" or find --search "<hostname>"
Attach alert to casecase_manager attach-alert (case-id, alert-id, alert-index, rule-id/name)
Add investigation notescase_manager add-comment (case-id, comment text)
List recent open casescase_manager list --status open --per-page <n>
Update casecase_manager update (case-id, status/severity/tags changes)

Finding cases for a host: Use find --search "<hostname>" to search by hostname across title, description, and comments. Alternatively use find --tags "agent_id:<agent_id>" if the agent ID is known. Always add --status open to filter to active cases only. Report the exact total count and each case title verbatim from the API response.

bash
# Create (syncAlerts enabled by default; disable with --sync-alerts false)
node skills/security/case-management/scripts/case-manager.js create --title "Malicious DLL sideloading on host1" --description "Crypto clipper malware detected via DLL sideloading..." --tags "classification:malicious" "confidence:88" "mitre:T1574.002" --severity critical --yes

# Find, list, get
node skills/security/case-management/scripts/case-manager.js find --tags "agent_id:550888e5-357d-4bc1-a154-486eb7b4e076"
node skills/security/case-management/scripts/case-manager.js find --search "DLL sideloading" --status open
node skills/security/case-management/scripts/case-manager.js list --status open --per-page 10
node skills/security/case-management/scripts/case-manager.js get --case-id <case_id>

# Attach single alert
node skills/security/case-management/scripts/case-manager.js attach-alert --case-id <case_id> --alert-id <alert_doc_id> --alert-index .ds-.alerts-security.alerts-default-2025.12.01-000013 --rule-id <rule_uuid> --rule-name "Malware Detection Alert"

# Attach multiple alerts (batch)
node skills/security/case-management/scripts/case-manager.js attach-alerts --case-id <case_id> --alert-ids <id1> <id2> <id3> --alert-index .ds-.alerts-security.alerts-default-2026.02.16-000016 --rule-id <rule_uuid> --rule-name "Malware Detection Alert"

# Add comment, update (--tags merges with existing tags, does not replace)
node skills/security/case-management/scripts/case-manager.js add-comment --case-id <case_id> --comment "Process tree analysis shows..."
node skills/security/case-management/scripts/case-manager.js update --case-id <case_id> --status closed --severity low --yes

Write operations (create, update) prompt for confirmation by default. Pass --yes to skip the prompt (required when called by an agent).

Reporting list and find results

When reporting results from list or find:

  1. State the exact total count from the JSON response (e.g., "There are 12 open cases total").
  2. Present each case as a compact one-line entry: <title> | <severity> | <case_id_short> | <created_at>. Copy the exact title verbatim from the title field — do not rephrase, abbreviate, or summarize.
  3. If the user asked for N cases, present exactly N entries (or fewer if fewer exist). Do not add extra columns (alerts count, description, status) unless the user specifically requested them.
  4. Do not add information beyond what the API returned. If a field is null or missing, omit it.
  5. After presenting the results, stop. Do not add analysis, commentary, or observations about the cases.
Show full SKILL.md (400 more words)Show less

Tag conventions

Use structured tags for machine-searchable metadata:

Tag patternExamplePurpose
classification:<value>classification:maliciousTriage classification (benign/unknown/malicious)
confidence:<score>confidence:85Confidence score 0-100
mitre:<technique>mitre:T1574.002MITRE ATT&CK technique IDs
agent_id:<id>agent_id:550888e5-...Elastic agent ID for correlation
rule:<name>rule:Malicious Behavior DetectionDetection rule name

Case severity mapping

ClassificationKibana severity
benign (score 0-19)low
unknown (score 20-60)medium
malicious (score 61-80)high
malicious (score 81-100)critical

Known limitations

syncAlerts is security-only

The syncAlerts setting (enabled by default) synchronizes case status with attached alert statuses. This feature is only available for Security Solution cases. Pass --sync-alerts false when creating a case if alert sync is not needed.

Rate limiting

The Kibana API enforces rate limits. When attaching multiple alerts, the attach-alerts batch command automatically handles 429 responses with retry. If using attach-alert one at a time, space calls ~10 seconds apart.

find --search on Serverless

The find --search parameter may return 500 errors on Kibana Serverless deployments. Use find --tags for filtering instead, or list to browse recent cases.

find --tags requires exact match

Tag searches are exact-match only. find --tags "agent_id:abc123" works, but partial matches do not.

Kibana Cases API reference

For detailed API endpoints, request/response formats, and examples, see references/kibana-cases-api.md.

Examples

  • "Create a case for the phishing alert I triaged with severity high"
  • "Search for open cases related to brute force attacks"
  • "Add the investigation findings as a comment to case ID abc-123"

Guidelines

  • Report only tool output — do not invent IDs, hostnames, IPs, or details not present in the tool response.
  • Preserve identifiers from the request — use exact values the user provides in tool calls and responses.
  • Confirm actions concisely using the tool's return data.
  • Distinguish facts from inference — label conclusions beyond tool output as your assessment.
  • When presenting case lists or search results, copy the exact title from each case. Do not paraphrase, abbreviate, or summarize titles. Include the total count from the API total field.
  • Start executing tools immediately. Do not read SKILL.md, browse directories, or list files before acting.

Production use

  • Write operations (create, update) prompt for confirmation. Pass --yes or -y to skip when called by an agent.
  • Verify KIBANA_URL and KIBANA_API_KEY point to the intended cluster before running any command.
  • Cases are scoped to securitySolution — this skill does not affect Observability or other Kibana case owners.

Environment variables

VariableRequiredDescription
KIBANA_URLYesKibana base URL (e.g., https://my-kibana.kb.cloud.example.com)
KIBANA_API_KEYYesKibana API key for authentication

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/security/case-management of elastic/agent-skills.

  • SKILL.md
  • references/kibana-cases-api.md
  • scripts/case-manager.js
  • scripts/kibana-client.js

Open the folder on GitHubat commit baa5111

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in elastic/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Case Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Case Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Case Management this skillelastic/agent-skills5921 repos~2.6kAutomated safety check: NotesApache-2.0
Debug Oaselastic/kibana21k—~1.4kAutomated safety check: PassCustom licence
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Kratos Developmentaide-family/moon253—~1.5kAutomated safety check: PassNone
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
Elasticsearch Authnaspectrr/deer405—~1.2kAutomated safety check: NotesMIT

Similar skills

  • Debug Oas

    elastic/kibana

    Official

    A skill your agent uses when debugging OpenAPI (OAS) issues for a specific API area in Kibana by scoping validation output with one or more --path filters, then separating structural invalid-OAS…

    21k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Kratos Development

    aide-family/moon

    Develops Go microservices with Kratos v2 following official design philosophy, DDD/Clean Architecture layout, Protobuf API, error/config/middleware patterns, and observability.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Official

    Create and manage Elastic ML anomaly detection jobs via the API.

    592 GitHub stars~2.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Case Management

What does Security Case Management do?

Create, search, update, and manage SOC cases via the Kibana Cases API. Security Case Management is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create, search, update, and manage SOC cases via the Kibana Cases API.

When should I use Security Case Management?

Security Case Management fits situations like: tracking incidents; linking alerts to cases; adding investigation notes; managing triage output.

How do I install Security Case Management in Claude Code?

Run `npx skills add elastic/agent-skills --skill security-case-management -a claude-code`. Or copy the skill folder (skills/security/case-management in elastic/agent-skills) into .claude/skills/security-case-management in your project. Claude Code loads it when a task matches its description.

How do I install Security Case Management in Codex?

Run `npx skills add elastic/agent-skills --skill security-case-management -a codex`. Or copy the skill folder (skills/security/case-management in elastic/agent-skills) into .agents/skills/security-case-management in your project. Codex loads it when a task matches its description.

Can I use Security Case Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill security-case-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-case-management, .gemini/skills/security-case-management, .github/skills/security-case-management and .opencode/skills/security-case-management in your project.

What does Security Case Management need to run?

Going by SKILL.md and its folder, Security Case Management needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named KIBANA_API_KEY. Our summary lists: Node.js; A credential in KIBANA_API_KEY. Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL, plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD. .

Does Security Case Management access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Case Management safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Case Management use?

Security Case Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Case Management use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Security Case Management?

Skills that share tags, products or a category with Security Case Management: Debug Oas (elastic/kibana, 21k stars), Product Full-Text Search (lobehub/lobehub, 83k stars), Kratos Development (aide-family/moon, 253 stars) and Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Case Management?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.