Official agent skill

Security Generate Security Sample Data

by elastic in elastic/agent-skills

Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

OfficialApache-2.0Auto-check passedSecurity

Install Security Generate Security Sample Data

skills CLI
$ npx skills add elastic/agent-skills --skill security-generate-security-sample-data -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills security-generate-security-sample-data --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/generate-security-sample-data .claude/skills/security-generate-security-sample-data && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-generate-security-sample-data
GitHub stars
592
Token cost
~2k tokens
SKILL.md length
639 words
Files
6 (incl. scripts, references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

  • Works in 4 steps: Set environment variables → Generate sample data → Explore in Kibana → …
  • Populating dashboards
  • SKILL.md covers Quick start, Workflow, What gets generated and Continuous mode, plus 5 more sections
  • Runs JavaScript scripts from its folder; calls node; needs ELASTICSEARCH_PASSWORD and ELASTICSEARCH_API_KEY

What it does

Security Generate Security Sample Data is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, or setting up a POC.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/sample-data-reference.md`, `scripts/demo-walkthrough.js` and `scripts/es-client.js`). Compatibility notes: Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANAURL plus KIBANAAPIKEY or KIBANAUSERNAME/KIBANAPASSWORD…

It sits in Security. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Populating dashboards
  • Testing detection rules
  • Setting up a POC

Example prompts

  • “/security-generate-security-sample-data”

Requirements

  • Node.js
  • A credential in KIBANA_API_KEY
  • A credential in ELASTICSEARCH_API_KEY
  • Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Set environment variables
  2. Generate sample data
  3. Explore in Kibana
  4. Clean up when done

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ELASTICSEARCH_PASSWORD
    • ELASTICSEARCH_API_KEY
    • KIBANA_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Generate Security Sample Data loads about 2k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 639 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 639 words, ~1,984 tokens.

Download SKILL.mdSave it as .claude/skills/security-generate-security-sample-data/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
security-generate-security-sample-data
description
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, or setting up a POC.
compatibility
Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.
metadata.author
elastic
metadata.version
0.1.0

Generate Security Sample Data

Generate ECS-compliant security events, multi-step attack scenarios, and synthetic alert documents that populate Elastic Security dashboards, the Alerts tab, and Attack Discovery.

Quick start

For a zero-friction experience that generates everything and opens Kibana:

bash
node skills/security/generate-security-sample-data/scripts/demo-walkthrough.js

Workflow

text
- [ ] Step 1: Set environment variables
- [ ] Step 2: Generate sample data
- [ ] Step 3: Explore in Kibana
- [ ] Step 4: Clean up when done
Step 1: Set environment variables
bash
export ELASTICSEARCH_URL="https://your-project.es.region.aws.elastic.cloud"
export ELASTICSEARCH_USERNAME="admin"
export ELASTICSEARCH_PASSWORD="your-password"
export KIBANA_URL="https://your-project.kb.region.aws.elastic.cloud"
Step 2: Generate sample data
Generate everything at once
bash
node skills/security/generate-security-sample-data/scripts/sample-data.js \
  system endpoint okta aws windows --scenarios --alerts
Generate only events
bash
node skills/security/generate-security-sample-data/scripts/sample-data.js \
  system endpoint --count 100
Generate only attack scenarios
bash
node skills/security/generate-security-sample-data/scripts/sample-data.js --scenarios
Generate only synthetic alerts
bash
node skills/security/generate-security-sample-data/scripts/sample-data.js --alerts
Step 3: Explore in Kibana

After generating data, direct the user to these pages:

  • Security > Alerts — synthetic alerts with MITRE ATT&CK mappings
  • Security > Attack Discovery — requires an LLM connector to analyze alerts
  • Security > Hosts — host activity from sample events
  • Security > Overview — summary of all security data
  • Discover — raw events across all data streams
Step 4: Clean up when done
bash
node skills/security/generate-security-sample-data/scripts/sample-data.js --cleanup

What gets generated

Sample data spans 5 packages (system, endpoint, windows, aws, okta) and 4 focused attack scenarios covering the most common demo themes: Windows credential theft, AWS cloud privilege escalation, Okta identity takeover, and a full ransomware kill chain. Synthetic alert documents are indexed into .alerts-security.alerts-default with MITRE ATT&CK mappings, severity levels, and risk scores.

All events use RFC 5737 / RFC 2606 safe addresses. For full tables of packages, scenarios, and alerts see references/sample-data-reference.md.

Continuous mode

Stream events to simulate a live environment:

bash
node skills/security/generate-security-sample-data/scripts/sample-data.js \
  --continuous --interval 15

Every 5th batch includes an attack scenario; every 10th batch adds synthetic alerts. Press Ctrl+C to stop.

Tool reference

sample-data.js
FlagDescription
--count, -nEvents per package (default: 50)
--scenariosRun all attack simulation scenarios
--scenario NAMERun a specific scenario
--alertsGenerate synthetic alert documents
--cleanupRemove all sample data and alerts
--continuousStream live events (Ctrl+C to stop)
--interval NSeconds between continuous batches (default: 30)
--json, -jOutput results as JSON
--yes, -ySkip confirmation prompts
demo-walkthrough.js

Zero-friction runner that generates everything and opens Kibana.

FlagDescription
--cleanupRemove all sample data, alerts, case
--continuousGenerate then stream live events
--count NEvents per package (default: 50)
--interval NSeconds between batches (default: 30)

Examples

Quick demo for a stakeholder

"Set up a demo environment so I can show Attack Discovery to my VP."

bash
node skills/security/generate-security-sample-data/scripts/demo-walkthrough.js
Targeted scenario testing

"Generate only the ransomware attack chain to test our detection rules."

bash
node skills/security/generate-security-sample-data/scripts/sample-data.js \
  --scenario ransomwareChain --alerts
Simulating a live SOC

"Keep generating events so the dashboards stay active during the demo."

bash
node skills/security/generate-security-sample-data/scripts/demo-walkthrough.js --continuous
Cleaning up after a demo

"Remove all sample data from my project."

bash
node skills/security/generate-security-sample-data/scripts/sample-data.js --cleanup
Show full SKILL.md (254 more words)Show less

Guidelines

  • All generated documents are tagged with tags: ["elastic-security-sample-data"] for safe cleanup. The cleanup command only deletes documents with this marker.
  • If marker fields are not indexed in a data stream, cleanup falls back to scanning _source.tags for matching sample documents from the last 14 days.
  • Synthetic alerts are indexed directly into .alerts-security.alerts-default — they do not require detection rules to be installed or enabled.
  • Attack Discovery requires an LLM connector (OpenAI, Anthropic, Google Gemini, or similar) configured in Kibana under Stack Management > Connectors. The "Complete" project tier unlocks the feature, but the connector must be set up separately.
  • Use the case-management skill for creating investigation cases from alerts.

Production use

  • Do not run against production clusters unless you intend to inject synthetic data alongside real alerts. Sample events and alerts are tagged for cleanup but will appear in dashboards, the Alerts tab, and Attack Discovery alongside real data.
  • All write operations (generate, --cleanup, --continuous) prompt for confirmation. Pass --yes or -y to skip when called by an agent.
  • --cleanup runs deleteByQuery across all sample data indices — verify environment variables point to the intended cluster before running.
  • --continuous mode indexes events indefinitely until manually stopped with Ctrl+C.

Environment variables

VariableRequiredDescription
ELASTICSEARCH_URLYesElasticsearch URL
ELASTICSEARCH_API_KEYYes*Elasticsearch API key
ELASTICSEARCH_USERNAMEYes*Elasticsearch username (alternative)
ELASTICSEARCH_PASSWORDYes*Elasticsearch password (alternative)
KIBANA_URLNoKibana URL (for case creation and links)
KIBANA_USERNAMENoKibana username (if using Kibana features)
KIBANA_PASSWORDNoKibana password (if using Kibana features)

*Either API key or username/password is required for Elasticsearch.

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/security/generate-security-sample-data of elastic/agent-skills.

  • SKILL.md
  • references/sample-data-reference.md
  • scripts/demo-walkthrough.js
  • scripts/es-client.js
  • scripts/kibana-client.js
  • scripts/sample-data.js

Open the folder on GitHubat commit baa5111

Compare with similar skills

Security Generate Security Sample Data next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Generate Security Sample Data compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Generate Security Sample Data this skillelastic/agent-skills592—~2kAutomated safety check: PassApache-2.0
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Performing Alert Triage With Elastic Siemmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Building Threat Feed Aggregation With Mispmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Detecting Insider Threat With Uebamukul975/Anthropic-Cybersecurity-Skills34k—~738Automated safety check: PassApache-2.0
Ecs Rfc Guideelastic/ecs1.1k—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Performing Alert Triage With Elastic Siem

    mukul975/Anthropic-Cybersecurity-Skills

    Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Threat Feed Aggregation With Misp

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Insider Threat With Ueba

    mukul975/Anthropic-Cybersecurity-Skills

    Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat…

    34k GitHub stars~738 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Ecs Rfc Guide

    elastic/ecs

    Official

    Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    412 GitHub stars~1.9k tokensUpdated 13 days ago
    DevOps & CloudAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated 5 days ago
    Auto-check passed
  • Official

    Create and manage Elastic ML anomaly detection jobs via the API.

    592 GitHub stars~2.4k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Security Generate Security Sample Data

What does Security Generate Security Sample Data do?

Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Security Generate Security Sample Data is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

When should I use Security Generate Security Sample Data?

Security Generate Security Sample Data fits situations like: populating dashboards; testing detection rules; setting up a POC.

How do I install Security Generate Security Sample Data in Claude Code?

Run `npx skills add elastic/agent-skills --skill security-generate-security-sample-data -a claude-code`. Or copy the skill folder (skills/security/generate-security-sample-data in elastic/agent-skills) into .claude/skills/security-generate-security-sample-data in your project. Claude Code loads it when a task matches its description.

How do I install Security Generate Security Sample Data in Codex?

Run `npx skills add elastic/agent-skills --skill security-generate-security-sample-data -a codex`. Or copy the skill folder (skills/security/generate-security-sample-data in elastic/agent-skills) into .agents/skills/security-generate-security-sample-data in your project. Codex loads it when a task matches its description.

Can I use Security Generate Security Sample Data in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill security-generate-security-sample-data -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-generate-security-sample-data, .gemini/skills/security-generate-security-sample-data, .github/skills/security-generate-security-sample-data and .opencode/skills/security-generate-security-sample-data in your project.

What does Security Generate Security Sample Data need to run?

Going by SKILL.md and its folder, Security Generate Security Sample Data needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named ELASTICSEARCH_PASSWORD, ELASTICSEARCH_API_KEY and KIBANA_PASSWORD. Our summary lists: Node.js; A credential in KIBANA_API_KEY; A credential in ELASTICSEARCH_API_KEY. Compatibility (from SKILL.md): Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables: KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD. .

Does Security Generate Security Sample Data access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Generate Security Sample Data safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Generate Security Sample Data use?

Security Generate Security Sample Data is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Generate Security Sample Data use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 924 tokens, read only when the agent opens those files.

What are the alternatives to Security Generate Security Sample Data?

Skills that share tags, products or a category with Security Generate Security Sample Data: Elasticsearch Audit (aspectrr/deer, 405 stars), Performing Alert Triage With Elastic Siem (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Threat Feed Aggregation With Misp (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Insider Threat With Ueba (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Generate Security Sample Data?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 2, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.