elastic/example-mcp-app-security · Archived

generate-sample-data

Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, setting up a POC, or when the user asks for test data, demo data, or sample alerts.

First seen Apr 17, 2026

Installation

$ npx skills add elastic/example-mcp-app-security --skill generate-sample-data

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from elastic/example-mcp-app-security.

npx skills add elastic/example-mcp-app-security

Browse all from elastic/example-mcp-app-security

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 21
License LICENSE.txt
Default branch main
Open issues 11
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,610 B
  • docs SUMMARY.md 271 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 6 installs

SKILL.md

Generate Security Sample Data

Generate ECS-compliant security events and synthetic alerts using the elastic-security MCP connector.

Tools (via elastic-security MCP connector)

Tool Purpose
generate-sample-data Generate events with interactive UI. Params: scenario, count

Attack Scenarios

Scenario Description
windows-credential-theft Mimikatz, procdump, credential dumping on Windows
aws-privilege-escalation IAM policy changes, role assumption, access key creation
okta-identity-takeover MFA factor reset, password change, session hijacking
ransomware-kill-chain PowerShell execution, C2 beaconing, mass file encryption

Usage

  • To generate all scenarios: call generate-sample-data without a scenario parameter
  • To generate a specific scenario: pass scenario: "ransomware-kill-chain"
  • All data is tagged with elastic-security-sample-data for safe cleanup
  • The dashboard UI has a cleanup button to remove all generated data

After Generating

Direct the user to explore in Kibana:

  • Security > Alerts — synthetic alerts with MITRE ATT&CK mappings
  • Security > Attack Discovery — requires an LLM connector
  • Security > Hosts — host activity from sample events