Elastic detection-rule-management
Creates and manages Elastic Security detection rules for threat detection.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Elastic detection-rule-management, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Elastic Agent Skill for authoring and managing detection rules in Elastic Security — creating, tuning, and enabling rules. It encodes the rule schema and management API. Writes detection rules that govern security alerting in the user's deployment.
Key features and capabilities
- Detection rule authoring
- Rule tuning/enable
- Elastic Security rule API
Use cases
- Create a new detection rule
- Tune noisy security rules