detection-rule-management
Installation
SKILL.md
Detection Rule Management
Manage detection rules using the elastic-security MCP connector. The manage-rules tool renders an interactive
rule management dashboard.
Tools (via elastic-security MCP connector)
| Tool | Purpose |
|---|---|
manage-rules |
Browse/search rules with interactive dashboard. Params: filter (KQL) |
threat-hunt |
Test queries against live data before creating rules |
The dashboard supports searching rules, viewing details, enabling/disabling, validating queries, and viewing noisy rules.
Rule Types
Related skills