Keep detection coverage sharp without the alert noise.
detection engineering
Create and tune Elastic Security detection rules and exceptions to improve coverage and reduce false positives.
When to use it
Use for false positives, exceptions, coverage gaps, noisy rules, or rule management through the Kibana API.
Give it a detection-rule creation, tuning, or management request; it changes rules or exceptions in Elastic Security.
This skill
Kibana Detection Engine
Changes or deletes detection rules (irreversible)
Endpoint Security Exception List
Adds endpoint security exceptions
elastic/protections-artifacts
Fetches endpoint rules from GitHub
Elasticsearch
Queries your Elasticsearch data
Requires Node.js 22 or newer.
Requires network access to a Kibana service.
Requires network access to an Elasticsearch service.
Requires alert-triage for the mandatory alert investigation performed before tuning SIEM rules.