Lightlines
Catalogue
Sign in
By elastic

security-detection-rule-management

elastic

Keep detection coverage sharp without the alert noise.

detection engineering

What it does

Create and tune Elastic Security detection rules and exceptions to improve coverage and reduce false positives.

When to use it

Use for false positives, exceptions, coverage gaps, noisy rules, or rule management through the Kibana API.

How to use it

Give it a detection-rule creation, tuning, or management request; it changes rules or exceptions in Elastic Security.

Uses


Access · 5

This skill

Kibana Detection Engine

Write

Changes or deletes detection rules (irreversible)

Endpoint Security Exception List

Write

Adds endpoint security exceptions

elastic/protections-artifacts

Read

Fetches endpoint rules from GitHub

Elasticsearch

Read

Queries your Elasticsearch data

Good to know

  • cannot be undone: Kibana Detection Engine
  • acts without asking

What you need · 10

Requires Node.js 22 or newer.

Requires network access to a Kibana service.

Requires network access to an Elasticsearch service.

Requires alert-triage for the mandatory alert investigation performed before tuning SIEM rules.


About this skill

Visibility
Public
Repository
elastic/agent-skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
11