Endpoint Agentic AI Skills
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**Value proposition**
Enable security analysts, responders, and endpoint administrators to work with Elastic Defend through natural language by shipping a curated set of agentic AI skills in Elastic Security. These skills help users investigate host activity, contain threats, troubleshoot endpoint health, manage policies, and work with endpoint artifacts without navigating multiple consoles or memorizing workflows — reducing time-to-action while keeping human confirmation and auditability for sensitive operations.
**Expected outcome**
- Analysts can investigate endpoints conversationally — reconstruct attacker activity, identify patient zero, and gather forensic context without chaining Osquery, Discover, and response consoles manually.
- Responders can request containment and remediation actions (for example isolate host, terminate process, retrieve file) in natural language, with clear confirmation before execution.
- Administrators and support users can diagnose endpoint and agent health issues through guided troubleshooting in chat.
- Policy owners can understand, compare, and update Elastic Defend policies through natural-language assistance instead of only form-driven configuration.
- Security teams can create, review, and manage endpoint artifacts (exceptions, trusted apps, blocklists, and related controls) from the same agentic experience.
- All skills return structured, actionable results in-product and remain aligned with existing Elastic Security permissions and response controls.
**Key user stories / use cases**
- As a DFIR analyst, I want to ask forensic investigation questions in natural language, so that I can identify patient zero and reconstruct attacker activity without switching tools.
- As an incident responder, I want to describe containment actions in chat, so that I can reduce dwell time without leaving the investigation context.
- As a SOC analyst, I want guided endpoint troubleshooting in natural language, so that I can diagnose agent or host health issues faster.
- As an endpoint administrator, I want to manage Elastic Defend policies through conversational assistance, so that I can apply the right protections with less configuration friction.
- As a security engineer, I want to manage endpoint artifacts through the agent, so that I can tune exceptions and prevention controls without navigating every artifact UI.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.