elastic/example-mcp-app-security · Archived

detection-rule-management

Create, tune, and manage Elastic Security detection rules. Use for false positive tuning, adding exceptions, creating new detection coverage, finding noisy rules, enabling/disabling rules, or any detection engineering task. Also trigger for "detection rules", "noisy rules", "false positives", "add exception", "create rule", or "tune rule".

First seen Apr 17, 2026

Installation

$ npx skills add elastic/example-mcp-app-security --skill detection-rule-management

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from elastic/example-mcp-app-security.

npx skills add elastic/example-mcp-app-security

Browse all from elastic/example-mcp-app-security

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 21
License LICENSE.txt
Default branch main
Open issues 11
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,519 B
  • docs SUMMARY.md 374 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 7 installs

SKILL.md

Detection Rule Management

Manage detection rules using the elastic-security MCP connector. The manage-rules tool renders an interactive rule management dashboard.

Tools (via elastic-security MCP connector)

Tool Purpose
manage-rules Browse/search rules with interactive dashboard. Params: filter (KQL)
threat-hunt Test queries against live data before creating rules

The dashboard supports searching rules, viewing details, enabling/disabling, validating queries, and viewing noisy rules.

Rule Types

Type Use case Example
query (KQL) Simple field matching process.name: "mimikatz.exe"
eql Behavioral sequences Process A spawns B within 5 minutes
esql Analytics/aggregations Complex joins or transformations
threshold Count/frequency >10 failed logins in 5 minutes
threat_match IOC correlation Match against malicious IP indicators
new_terms First-time activity User logs into host for first time

Tuning Strategy (in order of preference)

  1. Add exception — Known-good process/user/host. Does not modify the rule query.
  2. Tighten the query — Exclude FP pattern from the rule query itself.
  3. Adjust threshold/suppression — Increase threshold or enable alert suppression.
  4. Reduce risk score/severity — Downgrade priority if rule has some value but is noisy.
  5. Disable the rule — Last resort. Only if rule provides no value.

Creating New Rules

  1. Define the threat (MITRE technique, data sources, malicious vs legitimate behavior)
  2. Test the query with threat-hunt against live data
  3. Create via the dashboard or ask Claude to help construct the rule JSON
  4. Monitor alert volume and tune false positives

Common Index Patterns

Data type Index pattern
Alerts .alerts-security.alerts-*
Processes logs-endpoint.events.process-*
Network logs-endpoint.events.network-*
Windows logs-windows.*
AWS logs-aws.*
Okta logs-okta.*