Script library and runscript response action
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**What the feature is (as Title)**
**Value proposition**
Elastic Security introduces a new response action that allows security teams to execute scripts from a centralized Script Library during investigations or as automated responses. It enables fast, consistent, and repeatable actions without relying on ad-hoc commands.
**Expected outcome**
- Execute approved scripts from a managed Script Library
- Run scripts interactively from the Response Console
- Use `runscript` as an automated action in SIEM detection rules
- Reduce response time and operational friction
**Optional: Key user stories / use cases**
- As a SOC analyst, I want to run a trusted script from the Response Console during an active investigation.
- As a detection engineer, I want to automatically execute a remediation script when a high-confidence SIEM rule triggers.
- As a security team lead, I want all response scripts to come from a managed library so actions are consistent and auditable.
- As an IR analyst, I want to reuse the same script both manually and automatically without duplicating logic.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.