Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.
---
name: security-case-management
description: >
Create, search, update, and manage SOC cases via the Kibana Cases API. Use when
tracking incidents, linking alerts to cases, adding investigation notes, or managing
triage output.
compatibility: >
Requires Node.js 22+, network access to Kibana. Environment variables: KIBANA_URL,
plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD.
metadata:
author: elastic
version: 0.1.0
---
# Case Management
Manage SOC cases through the Kibana Cases API. All cases are scoped to `securitySolution` — this skill operates
exclusively within Elastic Security. Cases appear in Kibana Security and can be assigned to analysts, linked to alerts,
and pushed to external incident management systems via connectors.
## Prerequisites
Install dependencies before first use from the `skills/security` directory:
```bash… install to load the full skillIt activates automatically in your next session.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp