Triage Elastic Security Attack Discovery findings — fetch correlated attack narratives, assess confidence with entity risk and rule frequency signals, and present an interactive triage dashboard for approval, case creation, and acknowledgment. Use when triaging attack discoveries, reviewing correlated attacks, assessing EASE output, or when the user mentions "attack discovery", "AD findings", "triage attacks", "correlated alerts", or asks to process attack discovery results. Also trigger for "what attacks were discovered", "triage my discoveries", or "any attack discoveries".
$npx -y skills add elastic/example-mcp-app-security --skill attack-discovery-triageInstalls into the current project.
Run `npx skills use "https://github.com/elastic/example-mcp-app-security" --skill "elastic/example-mcp-app-security/attack-discovery-triage"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/elastic/example-mcp-app-security" that are relevant to the current task. Run `npx skills add "https://github.com/elastic/example-mcp-app-security"` and select the relevant skills, then follow their instructions.