Official agent skill

Security Detection Rule Management

by elastic in elastic/agent-skills

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

OfficialApache-2.0Auto-check: notesSecurity

Install Security Detection Rule Management

skills CLI
$ npx skills add elastic/agent-skills --skill security-detection-rule-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills security-detection-rule-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/detection-rule-management .claude/skills/security-detection-rule-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-detection-rule-management
GitHub stars
592
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
1,324 words
Files
11 (incl. scripts, references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

  • Works in 4 steps: Choose a tuning strategy → Write and test the query → Create the rule → …
  • False positives
  • SKILL.md covers Execution rules, Prerequisites, Common multi-step workflows and Workflow: Tune a rule for…, plus 8 more sections
  • Runs JavaScript scripts from its folder; calls node and npm; reaches attack.mitre.org; needs ELASTICSEARCH_API_KEY and KIBANA_API_KEY

What it does

Security Detection Rule Management is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/detection-api-reference.md`, `references/endpoint-behavior-tuning-workflow.md` and `references/endpoint-exceptions-guide.md`). Compatibility notes: Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANAURL plus KIBANAAPIKEY or KIBANAUSERNAME/KIBANAPASSWORD…

It sits in Security, covering Security operations. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • False positives
  • Rule management via Kibana API

Example prompts

  • “/security-detection-rule-management”

Requirements

  • Node.js
  • A credential in KIBANA_API_KEY
  • A credential in ELASTICSEARCH_API_KEY
  • Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Choose a tuning strategy
  2. Write and test the query
  3. Create the rule
  4. Monitor and iterate

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • attack.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ELASTICSEARCH_API_KEY
    • KIBANA_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Detection Rule Management loads about 3.9k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 1,324 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:36
    environment variables (or add them to a `.env` file in the workspace root):

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,324 words, ~3,881 tokens.

Download SKILL.mdSave it as .claude/skills/security-detection-rule-management/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
security-detection-rule-management
description
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.
compatibility
Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.
metadata.author
elastic
metadata.version
0.1.0

Detection Rule Management

Create new detection rules for emerging threats and coverage gaps, and tune existing rules to reduce false positives. All operations use the Kibana Detection Engine API via rule-manager.js.

Execution rules

  • Start executing tools immediately — do not read SKILL.md, browse the workspace, or list files first.
  • Report tool output faithfully. Copy rule IDs, names, alert counts, exception IDs, and error messages exactly as returned by the API. Do not abbreviate rule UUIDs, invent rule names, or round alert counts.
  • When a tool returns an error (rule not found, API failure), report the exact error — do not guess at alternatives.

Prerequisites

Install dependencies before first use from the skills/security directory:

bash
cd skills/security && npm install

Set the required environment variables (or add them to a .env file in the workspace root):

bash
export ELASTICSEARCH_URL="https://your-cluster.es.cloud.example.com:443"
export ELASTICSEARCH_API_KEY="your-api-key"
export KIBANA_URL="https://your-cluster.kb.cloud.example.com:443"
export KIBANA_API_KEY="your-kibana-api-key"

Common multi-step workflows

TaskTools to call (in order)
Tune noisy SIEM rulerule_manager find/noisy-rules → run_query (investigate FPs) → rule_manager patch or add-exception
Add endpoint behavior exceptionfetch_endpoint_rule (get rule definition from GitHub) → add_endpoint_exception (scoped to rule.id)
Create new detection rulerun_query (test query against data) → rule_manager create
Investigate rule alert volumerule_manager get → run_query (query alerts index)

For endpoint behavior rules, always fetch the rule definition first to understand query logic and existing exclusions before adding an exception. For SIEM rules, always investigate alert patterns with run_query before tuning.

Critical: For endpoint behavior rules, always use fetch_endpoint_rule (not shell or direct script calls) to get the rule definition, then use add_endpoint_exception to add the exception. These are dedicated tools — do not invoke the underlying scripts manually.

Workflow: Tune a rule for false positives

Steps 1–2: Identify noisy rules and analyze false positives

Find noisy rules with noisy-rules or find, then get the rule definition and investigate alerts:

bash
node skills/security/detection-rule-management/scripts/rule-manager.js noisy-rules --days 7 --top 20
node skills/security/detection-rule-management/scripts/rule-manager.js find --filter "alert.attributes.name:*Suspicious*" --brief
node skills/security/detection-rule-management/scripts/rule-manager.js get --id <rule_uuid>
node skills/security/alert-triage/scripts/run-query.js "kibana.alert.rule.name:\"<rule_name>\"" --index ".alerts-security.alerts-*" --days 7 --full

Look for patterns: same process/user/host → exception candidate; broad pattern → tighten query; legitimate software → exception; too broad → rewrite or adjust threshold.

Step 3: Choose a tuning strategy

In order of preference:

  1. Add exception — Best for specific known-good processes, users, or hosts. Does not modify the rule query. Use when the rule is correct in general but fires on known-legitimate activity.

  2. Tighten the query — Patch the rule's query to exclude the FP pattern. Best when the false positives stem from the query being too broad.

  3. Adjust threshold / alert suppression — For threshold rules, increase the threshold value. For any rule type, enable alert suppression to reduce duplicate alerts on the same entity.

  4. Reduce risk score / severity — Downgrade the rule's priority if it generates many low-value alerts but still has some detection value.

  5. Disable the rule — Last resort. Only if the rule provides no value or is completely redundant with another rule.

Steps 4–5: Apply tuning, verify, and document

Add exception (single/multi-condition, wildcard via matches):

bash
node skills/security/detection-rule-management/scripts/rule-manager.js add-exception \
  --rule-uuid <rule_uuid> \
  --entries "process.executable:is:C:\\Program Files\\SCCM\\CcmExec.exe" "process.parent.name:is:CcmExec.exe" \
  --name "Exclude SCCM" --comment "FP: SCCM deployment" --tags "tuning:fp" "source:soc" --yes

Patch query, threshold, severity, or disable:

bash
node skills/security/detection-rule-management/scripts/rule-manager.js patch --id <rule_uuid> --query "process.name:powershell.exe AND NOT process.parent.name:CcmExec.exe" --yes
node skills/security/detection-rule-management/scripts/rule-manager.js patch --id <rule_uuid> --max-signals 50 --yes
node skills/security/detection-rule-management/scripts/rule-manager.js patch --id <rule_uuid> --severity low --risk-score 21 --yes
node skills/security/detection-rule-management/scripts/rule-manager.js disable --id <rule_uuid> --yes

Write operations (patch, enable, disable, delete, add-exception, bulk-action) prompt for confirmation by default. Pass --yes to skip the prompt (required when called by an agent).

Verify with rule-manager.js get --id <rule_uuid>. Update triage cases via the case-management skill.


Workflow: Create new detection rule

Steps 1–2: Define the threat, data sources, and fields

Specify MITRE ATT&CK technique(s), required data sources (Endpoint, Network, Cloud), and malicious vs legitimate behavior. Common indexes: logs-endpoint.events.process-*, logs-endpoint.events.network-*, .alerts-security.alerts-*, logs-windows.*, logs-aws.*. Key fields: process.name, process.command_line, process.parent.name, destination.ip, winlog.event_id, event.action. Verify data with run-query.js:

bash
node skills/security/alert-triage/scripts/run-query.js "process.name:certutil.exe" --index "logs-endpoint.events.process-*" --days 30 --size 5
Step 3: Write and test the query

Rule types: query (KQL field matching), eql (event sequences), esql (aggregations), threshold (volume-based), threat_match (IOC correlation), new_terms (first-seen). Test against Elasticsearch before creating:

bash
node skills/security/alert-triage/scripts/run-query.js "process.name:certutil.exe AND process.command_line:(*urlcache* OR *decode*)" \
  --index "logs-endpoint.events.process-*" --days 30

For EQL, use --query-file to avoid shell escaping issues.

Validate query syntax before creating or patching a rule. The validate-query command catches common errors locally — escaped backslashes, mismatched parentheses, unbalanced quotes, and duplicate boolean operators:

bash
node skills/security/detection-rule-management/scripts/rule-manager.js validate-query \
  --query "process.name:taskkill.exe AND process.command_line:(*chrome.exe* OR *msedge.exe*)" --language kuery

The create and patch commands also run validation automatically and reject invalid queries. Pass --skip-validation only if you are certain the query is correct despite triggering a check.

Common KQL syntax mistakes:

  • Escaped forward-slashes — KQL wildcards use plain text. Write */IM chrome.exe*, not *\/IM chrome.exe*.
  • Mismatched parentheses — every ( must have a matching ).
  • Unbalanced quotes — every " must be paired.
  • Duplicate operators — AND AND or OR OR is always an error.
Step 4: Create the rule
bash
node skills/security/detection-rule-management/scripts/rule-manager.js create \
  --name "Certutil URL Download or Decode" \
  --description "Detects certutil.exe used to download files or decode Base64 payloads, a common LOLBin technique." \
  --type query \
  --query "process.name:certutil.exe AND process.command_line:(*urlcache* OR *decode*)" \
  --index "logs-endpoint.events.process-*" \
  --severity medium --risk-score 47 \
  --tags "OS:Windows" "Tactic:Defense Evasion" "Tactic:Command and Control" \
  --false-positives "IT administrators using certutil for legitimate certificate operations" \
  --references "https://attack.mitre.org/techniques/T1140/" \
  --interval 5m --disabled

For complex rules (EQL sequences, MITRE mappings, alert suppression), use create --from-file rule_definition.json and --threat-file. See references/detection-api-reference.md for schema.

Step 5: Monitor and iterate

Monitor alert volume with noisy-rules --days 3 --top 10 and tune false positives as needed.


Workflow: Endpoint behavior rules tuning

Tune Elastic Endpoint behavior rules by adding Endpoint exceptions scoped to specific rules. Endpoint exceptions live in Security → Exceptions → Endpoint Security Exception List, not under individual SIEM rules.

Key principles: Always fetch the rule definition from protections-artifacts first. Always scope exceptions to the rule (rule.id or rule.name). Use full paths over process names. Run the mandatory entity cross-check (Step 4b) before any exception. Simulate impact (Step 5b) and aim for ≥60% noise reduction.

Scripts: fetch-endpoint-rule-from-github.js (get rule TOML by id), add-endpoint-exception.js (add to Endpoint Exception List; rule.id/rule.name required), check-exclusion-best-practices.js.

For the full step-by-step workflow (Steps 1–6), queries, and simulation templates, see references/endpoint-behavior-tuning-workflow.md. For exclusion best practices, see references/endpoint-rule-exclusion-best-practices.md.


Show full SKILL.md (491 more words)Show less

Tool reference

rule-manager.js

All commands are run from the workspace root. All output is JSON unless noted.

CommandDescription
findSearch/list rules with optional KQL filter
getGet a rule by --id or --rule-id
createCreate a rule (inline flags or --from-file)
patchPatch specific fields on a rule
enableEnable a rule
disableDisable a rule
deleteDelete a rule
exportExport rules as NDJSON
bulk-actionBulk enable/disable/delete/duplicate/edit
add-exceptionAdd an exception item to a rule
list-exceptionsList items on an exception list
create-shared-listCreate a shared exception list
noisy-rulesFind noisiest rules by alert volume
validate-queryCheck query syntax before create/patch

Endpoint behavior tuning: fetch-endpoint-rule-from-github.js (get rule TOML by id), add-endpoint-exception.js (add to Endpoint Exception List; rule.id/rule.name required), check-exclusion-best-practices.js.

Exception entry format

Pass entries as field:operator:value. Operators: is, is_not, is_one_of, is_not_one_of, exists, does_not_exist, matches, does_not_match. Example: process.name:is:svchost.exe, file.path:matches:C:\\Program Files\\*.

Additional resources

Examples

  • "Find the noisiest detection rules from the last 7 days and help me tune one"
  • "Add an exception to exclude SCCM from the suspicious PowerShell rule"
  • "Create a new detection rule for certutil URL download or decode"

Guidelines

  • Report only tool output. When summarizing results, quote or paraphrase only what the tools returned. Do not invent IDs, hostnames, IPs, scores, process trees, or other details not present in the tool response.
  • Preserve identifiers from the request. If the user provides specific hostnames, agent IDs, case IDs, or other values, use those exact values in tool calls and responses — do not substitute different identifiers.
  • Confirm actions concisely. After executing a tool, confirm what was done using the tool's return data. Do not fabricate internal IDs, metadata, or status details unless they appear in the tool response.
  • Distinguish facts from inference. If you draw conclusions beyond what the tools returned (e.g., suggesting a MITRE technique based on observed behavior), clearly label those as your assessment rather than presenting them as tool output.
  • Start executing tools immediately. Do not read SKILL.md, browse directories, or list files before acting.
  • Report tool output verbatim. Copy rule IDs, names, alert counts, and error messages exactly as returned. Do not abbreviate UUIDs or round numbers.

Production use

  • All write operations (create, patch, enable, disable, delete, add-exception, bulk-action, add-endpoint-exception) prompt for confirmation. Pass --yes or -y to skip when called by an agent.
  • Endpoint exceptions suppress detections globally. Always scope exceptions to a specific rule using rule.id or rule.name in the entries. A broad, unscoped exception can silently reduce detection coverage.
  • Verify environment variables point to the intended cluster before running any script.
  • Use --dry-run with bulk-action to preview impact before executing bulk changes.

Environment variables

VariableRequiredDescription
ELASTICSEARCH_URLYesElasticsearch URL (for noisy-rules aggregation)
ELASTICSEARCH_API_KEYYesElasticsearch API key
KIBANA_URLYesKibana URL (for rules API)
KIBANA_API_KEYYesKibana API key

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references) in skills/security/detection-rule-management of elastic/agent-skills.

  • SKILL.md
  • references/detection-api-reference.md
  • references/endpoint-behavior-tuning-workflow.md
  • references/endpoint-exceptions-guide.md
  • references/endpoint-rule-exclusion-best-practices.md
  • scripts/add-endpoint-exception.js
  • scripts/check-exclusion-best-practices.js
  • scripts/es-client.js
  • scripts/fetch-endpoint-rule-from-github.js
  • scripts/kibana-client.js
  • scripts/rule-manager.js

Open the folder on GitHubat commit baa5111

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in elastic/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Detection Rule Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Detection Rule Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Detection Rule Management this skillelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Performing Alert Triage With Elastic Siemmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Building Threat Feed Aggregation With Mispmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0

Similar skills

  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Performing Alert Triage With Elastic Siem

    mukul975/Anthropic-Cybersecurity-Skills

    Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Threat Feed Aggregation With Misp

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    385 GitHub stars~12k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Official

    Create and manage Elastic ML anomaly detection jobs via the API.

    592 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Security Detection Rule Management

What does Security Detection Rule Management do?

Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Security Detection Rule Management is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

When should I use Security Detection Rule Management?

Security Detection Rule Management fits situations like: false positives; rule management via Kibana API.

How do I install Security Detection Rule Management in Claude Code?

Run `npx skills add elastic/agent-skills --skill security-detection-rule-management -a claude-code`. Or copy the skill folder (skills/security/detection-rule-management in elastic/agent-skills) into .claude/skills/security-detection-rule-management in your project. Claude Code loads it when a task matches its description.

How do I install Security Detection Rule Management in Codex?

Run `npx skills add elastic/agent-skills --skill security-detection-rule-management -a codex`. Or copy the skill folder (skills/security/detection-rule-management in elastic/agent-skills) into .agents/skills/security-detection-rule-management in your project. Codex loads it when a task matches its description.

Can I use Security Detection Rule Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill security-detection-rule-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-detection-rule-management, .gemini/skills/security-detection-rule-management, .github/skills/security-detection-rule-management and .opencode/skills/security-detection-rule-management in your project.

What does Security Detection Rule Management need to run?

Going by SKILL.md and its folder, Security Detection Rule Management needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named ELASTICSEARCH_API_KEY and KIBANA_API_KEY. Our summary lists: Node.js; A credential in KIBANA_API_KEY; A credential in ELASTICSEARCH_API_KEY. Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD. .

Does Security Detection Rule Management access the network?

SKILL.md names 1 domain. In commands or code: attack.mitre.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Detection Rule Management safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Detection Rule Management use?

Security Detection Rule Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Detection Rule Management use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.2k tokens, read only when the agent opens those files.

What are the alternatives to Security Detection Rule Management?

Skills that share tags, products or a category with Security Detection Rule Management: Elasticsearch Audit (aspectrr/deer, 405 stars), Performing Alert Triage With Elastic Siem (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Threat Feed Aggregation With Misp (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Detection Rule Management?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.