dt-sec-insights

Analyze Dynatrace security events using DQL queries.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/mf-dynatrace/dt-mcp-workspace --skill dt-sec-insights
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dt-sec-insights
Source: https://github.com/mf-dynatrace/dt-mcp-workspace/tree/main/skills/dt-sec-insights
Command: npx skills add https://github.com/mf-dynatrace/dt-mcp-workspace --skill dt-sec-insights

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides comprehensive access and analysis of Dynatrace security data, empowering users to monitor, analyze, and mitigate security risks efficiently.

Core Features & Use Cases

  • Security Event Analysis: Query and analyze security events using DQL, covering vulnerabilities, threat detections, compliance posture, and scan coverage.
  • Vulnerability Management: Identify and manage vulnerabilities with detailed insights into CVEs, reachability, exposure, and exploit availability.
  • Compliance Posture: Assess and track compliance posture with KSPM/CSPM and external compliance tools.
  • Runtime Attacks and Threats: Detect and respond to runtime attacks and threats using Dynatrace-native and external detection providers.
  • Scan Coverage Analysis: Analyze scan coverage for k8s workloads, hosts, and processes.
  • Entity Enrichment: Map external findings to Dynatrace entities (hosts, K8s workloads, cloud resources).
  • Dashboards/KPIs: Generate dashboards and KPIs for security monitoring and reporting.
  • Use Case: If you have a large number of security events in Dynatrace and need to quickly identify and prioritize critical vulnerabilities, this Skill can help you do so efficiently.

Quick Start

Use the dt-sec-insights skill to find all critical vulnerabilities within the last 30 minutes.

Frequently Asked Questions about dt-sec-insights

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I query critical security vulnerabilities in Dynatrace using DQL?

To query security vulnerabilities in Dynatrace using DQL, you analyze security events to monitor and mitigate risks. You can identify and prioritize critical vulnerabilities by evaluating CVEs, reachability, exposure, and exploit availability.

What is the best way to monitor runtime attacks and threats in Dynatrace?

Monitoring runtime attacks in Dynatrace involves analyzing security events with DQL. You can detect and respond to runtime threats using both Dynatrace-native and external detection providers mapped to specific entities.

Can I assess compliance posture and KSPM/CSPM findings using Dynatrace DQL?

Yes, you can assess compliance posture in Dynatrace using DQL. This allows you to track KSPM/CSPM findings and integrate external compliance tools to maintain your security standards.

How do I analyze scan coverage for Kubernetes workloads and hosts in Dynatrace?

Analyzing scan coverage in Dynatrace uses DQL to evaluate k8s workloads, hosts, and processes. This identifies gaps in your vulnerability scanning to ensure all infrastructure is monitored.

Do I need prior DQL knowledge to analyze Dynatrace security events?

Yes, analyzing Dynatrace security events requires knowledge of DQL and access to Dynatrace data. This allows you to effectively query vulnerabilities, compliance posture, and runtime threats.

Why map external security findings to Dynatrace entities?

Mapping external security findings to Dynatrace entities enriches your analysis. It correlates external vulnerabilities and threats with specific hosts, K8s workloads, and cloud resources for targeted mitigation.