> Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.
npx skills add https://github.com/elastic/agent-skills --skill security-case-management
Manage SOC cases through the Kibana Cases API. All cases are scoped to securitySolution — this skill operates
exclusively within Elastic Security. Cases appear in Kibana Security and can be assigned to analysts, linked to alerts,
and pushed to external incident management systems via connectors.
Install dependencies before first use from the skills/security directory:
cd skills/security && npm install
Set the required environment variables (or add them to a .env file in the workspace root):
export KIBANA_URL="https://your-cluster.kb.cloud.example.com:443"
export KIBANA_API_KEY="your-kibana-api-key"
owner: securitySolutionnot abbreviate case IDs, truncate titles, invent details, or round numbers.
verbatim title, severity, and status.
All commands run from the workspace root. All output is JSON. Call the tools directly — do not read the skill file or
explore the workspace first. For attach-alert/attach-alerts, --rule-id and --rule-name are required by the Kibana
API (use --rule-id unknown --rule-name unknown if unknown). Use attach-alerts for batch with automatic rate-limit
retry and 2-second spacing between API calls.
| Task | Tools to call (in order) |
| --------------------------- | ---------------------------------------------------------------------------- |
| Create a case | case_manager create (title, description, tags, severity) |
| Find cases for a host | case_manager find --tags "agent_id:\<id\>" or find --search "\<hostname\>" |
| Attach alert to case | case_manager attach-alert (case-id, alert-id, alert-index, rule-id/name) |
| Add investigation notes | case_manager add-comment (case-id, comment text) |
| List recent open cases | case_manager list --status open --per-page \<n\> |
| Update case | case_manager update (case-id, status/severity/tags changes) |
Finding cases for a host: Use find --search "<hostname>" to search by hostname across title, description, and
comments. Alternatively use find --tags "agent_id:<agent_id>" if the agent ID is known. Always add --status open to
filter to active cases only. Report the exact total count and each case title verbatim from the API response.
# Create (syncAlerts enabled by default; disable with --sync-alerts false)
node skills/security/case-management/scripts/case-manager.js create --title "Malicious DLL sideloading on host1" --description "Crypto clipper malware detected via DLL sideloading..." --tags "classification:malicious" "confidence:88" "mitre:T1574.002" --severity critical --yes
# Find, list, get
node skills/security/case-management/scripts/case-manager.js find --tags "agent_id:550888e5-357d-4bc1-a154-486eb7b4e076"
node skills/security/case-management/scripts/case-manager.js find --search "DLL sideloading" --status open
node skills/security/case-management/scripts/case-manager.js list --status open --per-page 10
node skills/security/case-management/scripts/case-manager.js get --case-id <case_id>
# Attach single alert
node skills/security/case-management/scripts/case-manager.js attach-alert --case-id <case_id> --alert-id <alert_doc_id> --alert-index .ds-.alerts-security.alerts-default-2025.12.01-000013 --rule-id <rule_uuid> --rule-name "Malware Detection Alert"
# Attach multiple alerts (batch)
node skills/security/case-management/scripts/case-manager.js attach-alerts --case-id <case_id> --alert-ids <id1> <id2> <id3> --alert-index .ds-.alerts-security.alerts-default-2026.02.16-000016 --rule-id <rule_uuid> --rule-name "Malware Detection Alert"
# Add comment, update (--tags merges with existing tags, does not replace)
node skills/security/case-management/scripts/case-manager.js add-comment --case-id <case_id> --comment "Process tree analysis shows..."
node skills/security/case-management/scripts/case-manager.js update --case-id <case_id> --status closed --severity low --yes
Write operations (create, update) prompt for confirmation by default. Pass --yes to skip the prompt (required when
called by an agent).
When reporting results from list or find:
total count from the JSON response (e.g., "There are 12 open cases total").<title> | <severity> | <case_id_short> | <created_at>. Copy theexact title verbatim from the title field — do not rephrase, abbreviate, or summarize.
count, description, status) unless the user specifically requested them.
Use structured tags for machine-searchable metadata:
| Tag pattern | Example | Purpose |
| ------------------------ | ----------------------------------- | ------------------------------------------------ |
| classification:<value> | classification:malicious | Triage classification (benign/unknown/malicious) |
| confidence:<score> | confidence:85 | Confidence score 0-100 |
| mitre:<technique> | mitre:T1574.002 | MITRE ATT&CK technique IDs |
| agent_id:<id> | agent_id:550888e5-... | Elastic agent ID for correlation |
| rule:<name> | rule:Malicious Behavior Detection | Detection rule name |
| Classification | Kibana severity |
| ------------------------ | --------------- |
| benign (score 0-19) | low |
| unknown (score 20-60) | medium |
| malicious (score 61-80) | high |
| malicious (score 81-100) | critical |
The syncAlerts setting (enabled by default) synchronizes case status with attached alert statuses. This feature is
only available for Security Solution cases. Pass --sync-alerts false when creating a case if alert sync is not needed.
The Kibana API enforces rate limits. When attaching multiple alerts, the attach-alerts batch command automatically
handles 429 responses with retry. If using attach-alert one at a time, space calls ~10 seconds apart.
find --search on ServerlessThe find --search parameter may return 500 errors on Kibana Serverless deployments. Use find --tags for filtering
instead, or list to browse recent cases.
find --tags requires exact matchTag searches are exact-match only. find --tags "agent_id:abc123" works, but partial matches do not.
For detailed API endpoints, request/response formats, and examples, see
references/kibana-cases-api.md.
or summarize titles. Include the total count from the API total field.
create, update) prompt for confirmation. Pass --yes or -y to skip when called by an agent.KIBANA_URL and KIBANA_API_KEY point to the intended cluster before running any command.securitySolution — this skill does not affect Observability or other Kibana case owners.| Variable | Required | Description |
| ---------------- | -------- | ---------------------------------------------------------------- |
| KIBANA_URL | Yes | Kibana base URL (e.g., https://my-kibana.kb.cloud.example.com) |
| KIBANA_API_KEY | Yes | Kibana API key for authentication |
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple output formats (XML, Markdown, plain text), preserve file structure and context, optimize for AI consumption with token counting, filter by file types and directories, add custom headers and summaries. Use when packaging codebases for AI analysis, creating repository snapshots for LLM context, analyzing third-party libraries, preparing for security audits, generating documentation context, or evaluating unfamiliar codebases.
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects. Covers Node.js and Python SDKs.
Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help. Supports Python, JavaScript/TypeScript, and Go. Do NOT use for general code review, debugging, threat modeling (use security-threat-model), or non-security tasks.
Configures API gateways for routing, authentication, rate limiting, and request transformation in microservice architectures. Use when setting up Kong, Nginx, AWS API Gateway, or Traefik for centralized API management.
Take elastic/security-case-management from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.
The instructions reference npm.
Without those the skill loads but fails at the first command.