security-case-management

Community

Manage and resolve security investigation cases

Authorpatrykkopycinski
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill streamlines the manual workflow of creating, tracking, and closing security investigation cases in Elastic Security by guiding analysts through case creation, alert attachment, investigation documentation, and final resolution.

Core Features & Use Cases

  • Case lifecycle management: List existing cases by status and severity, create new cases, select and retrieve case details.
  • Alert triage and attachment: Find relevant alerts, attach alert objects or references to cases, and add investigative comments.
  • Investigation documentation & closure: Record findings, enrichment results, IOCs, containment actions, and close or escalate cases with a final summary.
  • Use Case: Triage a critical detection by creating a high-severity case, attaching matching alerts, documenting evidence and remediation steps, and closing the case with recommendations for follow-up detections.

Quick Start

Create a new high-severity security case for the suspicious alert, attach matching alerts, add investigation notes, and close the case when resolved.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: security-case-management
Download link: https://github.com/patrykkopycinski/elastic-cursor-plugin/archive/main.zip#security-case-management

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.