Agent skill

Performing Alert Triage With Elastic Siem

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

Apache-2.0Auto-check passedSecurity

Install Performing Alert Triage With Elastic Siem

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-alert-triage-with-elastic-siem -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-alert-triage-with-elastic-siem --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-alert-triage-with-elastic-siem .claude/skills/performing-alert-triage-with-elastic-siem && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-alert-triage-with-elastic-siem
GitHub stars
34k
Token cost
~2k tokens
SKILL.md length
599 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

  • Works in 5 steps: Initial Alert Assessment (2 minutes) → Context Gathering (3 minutes) → Threat Intelligence Enrichment (2 minutes) → …
  • Triaging incoming Elastic Security detections
  • SKILL.md covers Overview, When to Use, Prerequisites and Alert Triage Workflow, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Performing Alert Triage With Elastic Siem is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows. Use when triaging incoming Elastic Security detections, prioritizing an analyst's alert queue, or investigating alerts during SOC operations.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Security operations. It works with Elasticsearch. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Triaging incoming Elastic Security detections
  • Prioritizing an analysts alert queue
  • Investigating alerts during SOC operations

Example prompts

  • “/performing-alert-triage-with-elastic-siem”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Initial Alert Assessment (2 minutes)
  2. Context Gathering (3 minutes)
  3. Threat Intelligence Enrichment (2 minutes)
  4. Classification Decision (2 minutes)
  5. Documentation and Escalation (1 minute)

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • elastic.co
    • systemweakness.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Alert Triage With Elastic Siem loads about 2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 599 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 599 words, ~2,015 tokens.

Download SKILL.mdSave it as .claude/skills/performing-alert-triage-with-elastic-siem/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-alert-triage-with-elastic-siem
description
Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows. Use when triaging incoming Elastic Security detections, prioritizing an analyst's alert queue, or investigating alerts during SOC operations.
domain
cybersecurity
subdomain
soc-operations
tags
elastic, siem, alert-triage, soc, elastic-security, detection, esql, kibana
version
1.0
author
mahipal
license
Apache-2.0
d3fend_techniques
Token Binding, Restore Access, Application Protocol Command Analysis, Password Authentication, Reissue Credential
nist_csf
DE.CM-01, DE.AE-02, RS.MA-01, DE.AE-06
mitre_attack
T1078, T1685.002, T1685.005, T1566

Performing Alert Triage with Elastic SIEM

Overview

Alert triage in Elastic Security is the systematic process of reviewing, classifying, and prioritizing security alerts to determine which represent genuine threats. Elastic's AI-driven Attack Discovery feature can triage hundreds of alerts down to discrete attack chains, but skilled analyst triage remains essential. A structured triage workflow typically takes 5-10 minutes per alert cluster using Elastic's built-in tools.

When to Use

  • When conducting security assessments that involve performing alert triage with elastic siem
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Elastic Security deployed (version 8.x or later)
  • Elastic Agent or Beats configured for endpoint and network data collection
  • Detection rules enabled and generating alerts
  • Elastic Common Schema (ECS) compliance across data sources
  • Analyst access to Kibana Security app with appropriate privileges

Alert Triage Workflow

Step 1: Initial Alert Assessment (2 minutes)

When viewing an alert in Elastic Security, review the alert details panel:

Alert Details Panel:
- Rule Name and Description
- Severity and Risk Score
- MITRE ATT&CK Mapping
- Host and User Context
- Process Tree (for endpoint alerts)
- Timeline of related events
Key Fields to Examine First
FieldPurposeECS Field
Rule severityInitial priority assessmentkibana.alert.severity
Risk scoreQuantified threat levelkibana.alert.risk_score
Host nameAffected systemhost.name
User nameAffected identityuser.name
Process nameExecuting processprocess.name
Source IPOrigin of activitysource.ip
Destination IPTarget of activitydestination.ip
MITRE tacticAttack stagethreat.tactic.name
Step 2: Context Gathering (3 minutes)
esql
FROM logs-endpoint.events.*
| WHERE host.name == "affected-host" AND @timestamp > NOW() - 1 HOUR
| STATS count = COUNT(*) BY event.category, event.action
| SORT count DESC
Find All Activity from Suspicious User
esql
FROM logs-*
| WHERE user.name == "suspicious-user" AND @timestamp > NOW() - 24 HOURS
| STATS count = COUNT(*), unique_hosts = COUNT_DISTINCT(host.name) BY event.category
| SORT count DESC
esql
FROM .alerts-security.alerts-default
| WHERE source.ip == "10.0.0.50" AND @timestamp > NOW() - 24 HOURS
| STATS alert_count = COUNT(*) BY kibana.alert.rule.name, kibana.alert.severity
| SORT alert_count DESC
Investigate Lateral Movement from Same IP
esql
FROM logs-system.auth-*
| WHERE source.ip == "10.0.0.50" AND event.outcome == "success"
| STATS login_count = COUNT(*), hosts = COUNT_DISTINCT(host.name) BY user.name
| WHERE hosts > 3
Step 3: Threat Intelligence Enrichment (2 minutes)

Check indicators against threat intelligence:

esql
FROM logs-ti_*
| WHERE threat.indicator.ip == "203.0.113.50"
| KEEP threat.indicator.type, threat.indicator.provider, threat.indicator.confidence, threat.feed.name
Check File Hash Against Known Threats
esql
FROM logs-endpoint.events.file-*
| WHERE file.hash.sha256 == "abc123..."
| STATS occurrences = COUNT(*) BY host.name, file.path, user.name
Step 4: Classification Decision (2 minutes)
ClassificationCriteriaAction
True PositiveConfirmed malicious activityEscalate to incident, begin containment
Benign True PositiveExpected behavior matching ruleDocument in alert notes, acknowledge
False PositiveRule triggered on benign activityMark as false positive, create tuning task
Needs InvestigationInsufficient data for determinationAssign for deeper investigation
Step 5: Documentation and Escalation (1 minute)

For each triaged alert, document:

  • Classification decision with rationale
  • Evidence artifacts examined
  • Related alerts or investigations
  • Recommended next steps

Detection Rules for Triage

Show full SKILL.md (245 more words)Show less
Pre-Built Detection Rules

Elastic Security includes 1000+ pre-built detection rules organized by:

  • MITRE ATT&CK Tactic: Initial Access, Execution, Persistence, etc.
  • Platform: Windows, Linux, macOS, Cloud
  • Data Source: Endpoint, Network, Cloud, Identity
Custom Alert Correlation Rule
json
{
  "name": "Multiple Failed Logins Followed by Success",
  "type": "threshold",
  "query": "event.category:authentication AND event.outcome:failure",
  "threshold": {
    "field": ["source.ip", "user.name"],
    "value": 5,
    "cardinality": [
      {
        "field": "user.name",
        "value": 3
      }
    ]
  },
  "severity": "high",
  "risk_score": 73,
  "threat": [
    {
      "framework": "MITRE ATT&CK",
      "tactic": {
        "id": "TA0006",
        "name": "Credential Access"
      },
      "technique": [
        {
          "id": "T1110",
          "name": "Brute Force"
        }
      ]
    }
  ]
}

AI-Assisted Triage

Elastic AI Assistant Integration
  1. Open alert in Elastic Security
  2. Click AI Assistant panel
  3. Use quick prompts:
    • "Summarize this alert" - Get initial assessment
    • "Generate ES|QL query to find related activity" - Expand investigation
    • "What are the recommended response actions?" - Get playbook guidance
    • "Is this likely a false positive?" - Get AI confidence assessment
Attack Discovery

Elastic's Attack Discovery automatically:

  • Groups related alerts into attack chains
  • Maps alerts to MITRE ATT&CK kill chain stages
  • Filters false positives using ML models
  • Prioritizes based on business impact
  • Provides narrative summary of the attack

Triage Prioritization Matrix

Risk ScoreSeverityAsset CriticalityResponse SLA
90-100CriticalHigh15 minutes
70-89HighHigh30 minutes
70-89HighMedium1 hour
50-69MediumAny4 hours
21-49LowAny8 hours
1-20InformationalAny24 hours

Triage Metrics and KPIs

MetricTargetMeasurement
Mean Time to Triage (MTTT)< 10 minutesTime from alert creation to classification
False Positive Rate< 30%False positives / total alerts
Escalation Rate10-20%Escalated alerts / total alerts
Alert Coverage> 80%Triaged alerts / generated alerts per shift
Reclassification Rate< 5%Changed classifications / total classified

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-alert-triage-with-elastic-siem of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Alert Triage With Elastic Siem next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Alert Triage With Elastic Siem compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Alert Triage With Elastic Siem this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli115—~15kAutomated safety check: NotesGPL-3.0

Similar skills

  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    115 GitHub stars~15k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    388 GitHub stars~12k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Performing Alert Triage With Elastic Siem

What does Performing Alert Triage With Elastic Siem do?

Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows. Performing Alert Triage With Elastic Siem is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Perform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows.

When should I use Performing Alert Triage With Elastic Siem?

Performing Alert Triage With Elastic Siem fits situations like: triaging incoming Elastic Security detections; prioritizing an analysts alert queue; investigating alerts during SOC operations.

How do I install Performing Alert Triage With Elastic Siem in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-alert-triage-with-elastic-siem -a claude-code`. Or copy the skill folder (skills/performing-alert-triage-with-elastic-siem in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-alert-triage-with-elastic-siem in your project. Claude Code loads it when a task matches its description.

How do I install Performing Alert Triage With Elastic Siem in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-alert-triage-with-elastic-siem -a codex`. Or copy the skill folder (skills/performing-alert-triage-with-elastic-siem in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-alert-triage-with-elastic-siem in your project. Codex loads it when a task matches its description.

Can I use Performing Alert Triage With Elastic Siem in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-alert-triage-with-elastic-siem -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-alert-triage-with-elastic-siem, .gemini/skills/performing-alert-triage-with-elastic-siem, .github/skills/performing-alert-triage-with-elastic-siem and .opencode/skills/performing-alert-triage-with-elastic-siem in your project.

What does Performing Alert Triage With Elastic Siem need to run?

Going by SKILL.md and its folder, Performing Alert Triage With Elastic Siem needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Alert Triage With Elastic Siem access the network?

SKILL.md names 2 domains. As links in the text: elastic.co and systemweakness.com. This is read from the text; nothing was executed.

Is Performing Alert Triage With Elastic Siem safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Alert Triage With Elastic Siem use?

Performing Alert Triage With Elastic Siem is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Alert Triage With Elastic Siem use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Performing Alert Triage With Elastic Siem?

Skills that share tags, products or a category with Performing Alert Triage With Elastic Siem: Security Detection Rule Management (elastic/agent-skills, 592 stars), Elasticsearch Audit (aspectrr/deer, 405 stars), Security Alert Triage (elastic/agent-skills, 592 stars) and Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Alert Triage With Elastic Siem?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.