security-full-setup

Coordinate Elastic Security deployment by discovering data sources, evaluating coverage, and provisioning rules and dashboards.

6|Updated Feb 20, 2026
One-click install
npx skills add https://github.com/patrykkopycinski/elastic-cursor-plugin --skill security-full-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-full-setup
Source: https://github.com/patrykkopycinski/elastic-cursor-plugin/tree/main/skills/security-full-setup
Command: npx skills add https://github.com/patrykkopycinski/elastic-cursor-plugin --skill security-full-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides an end-to-end workflow to configure Elastic Security by discovering available data sources, evaluating detection coverage, enabling rules, and building security dashboards.

Core Features & Use Cases

  • Data discovery: identify endpoint, audit, Windows, network, and cloud data sources.
  • Coverage assessment: measure detection rule coverage and open alert volumes.
  • Remediation orchestration: enable detection rules, configure alerting, and create dashboards to monitor security posture.
  • Use case: during deployment, run the guided setup to achieve baseline security visibility with minimal manual steps.

Quick Start

Initiate a full security setup by discovering data, evaluating gaps, and applying recommended rules and dashboards.

Frequently Asked Questions about security-full-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I set up Elastic Security end-to-end from data discovery to dashboards?

Elastic Security end-to-end setup is coordinated by discovering data sources, evaluating detection coverage gaps, enabling rules, configuring alerting, and creating Kibana dashboards via API integration.

What data sources are supported for Elastic Security detection and coverage assessment?

Elastic Security detection supports endpoint, audit, Windows, network, and cloud data sources. Coverage assessment measures detection rule coverage and open alert volumes across these discovered sources.

Do I need an API key and Kibana access to configure Elastic Security detection rules?

Configuring Elastic Security detection rules requires ES_URL, ES_API_KEY, and Kibana access. These prerequisites enable API integration to manage rules, alerts, and dashboards.

Can I use this Elastic Security deployment guide in a lab environment?

Elastic Security deployment applies to both production and lab environments. The guided setup achieves baseline security visibility with minimal manual steps by orchestrating data discovery and remediation.

What's the best way to evaluate detection coverage gaps before enabling Elastic Security rules?

Evaluating detection coverage gaps involves discovering available data sources and measuring existing detection rule coverage alongside open alert volumes, guiding which rules to enable for baseline security visibility.