detection-rule-management

Installation
SKILL.md

Detection Rule Management

Manage detection rules using the elastic-security MCP connector. The manage-rules tool renders an interactive rule management dashboard.

Tools (via elastic-security MCP connector)

Tool Purpose
manage-rules Browse/search rules with interactive dashboard. Params: filter (KQL)
threat-hunt Test queries against live data before creating rules

The dashboard supports searching rules, viewing details, enabling/disabling, validating queries, and viewing noisy rules.

Rule Types

Related skills
Installs
3
GitHub Stars
5
First Seen
Apr 17, 2026