elastic / elastic/roadmap

Script library and runscript response action

Open
#211 0 comments 0 reactions 1 assignee Claimed by @raqueltabuyo View on GitHub
Component: Elastic Cloud Hosted Component: Elastic Cloud Serverless product-area:security
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**What the feature is (as Title)**

**Value proposition**
Elastic Security introduces a new response action that allows security teams to execute scripts from a centralized Script Library during investigations or as automated responses. It enables fast, consistent, and repeatable actions without relying on ad-hoc commands.

**Expected outcome**
- Execute approved scripts from a managed Script Library
- Run scripts interactively from the Response Console
- Use `runscript` as an automated action in SIEM detection rules
- Reduce response time and operational friction

**Optional: Key user stories / use cases**
- As a SOC analyst, I want to run a trusted script from the Response Console during an active investigation.
- As a detection engineer, I want to automatically execute a remediation script when a high-confidence SIEM rule triggers.
- As a security team lead, I want all response scripts to come from a managed library so actions are consistent and auditable.
- As an IR analyst, I want to reuse the same script both manually and automatically without duplicating logic.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.