Agent skill

Implementing Ddos Mitigation With Cloudflare

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.

Apache-2.0Auto-check passedBackend & APIs

Install Implementing Ddos Mitigation With Cloudflare

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ddos-mitigation-with-cloudflare -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ddos-mitigation-with-cloudflare --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-ddos-mitigation-with-cloudflare .claude/skills/implementing-ddos-mitigation-with-cloudflare && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-ddos-mitigation-with-cloudflare
GitHub stars
34k
Token cost
~3.6k tokens
SKILL.md length
454 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.

  • Works in 6 steps: Onboard Domain to Cloudflare → Configure DDoS Managed Rulesets → Configure Rate Limiting Rules → …
  • Tasks that involve Rate limiting
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder; calls curl; reaches api.cloudflare.com and developers.cloudflare.com; needs CF_API_TOKEN

What it does

Implementing Ddos Mitigation With Cloudflare is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Backend & APIs, covering Rate limiting. It works with Cloudflare. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Rate limiting

Example prompts

  • “/implementing-ddos-mitigation-with-cloudflare”

Requirements

  • Python 3
  • A credential in CF_API_TOKEN

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Onboard Domain to Cloudflare
  2. Configure DDoS Managed Rulesets
  3. Configure Rate Limiting Rules
  4. Configure WAF Custom Rules
  5. Configure Origin Protection
  6. Enable Under Attack Mode Automation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.cloudflare.com
    • developers.cloudflare.com
    • cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CF_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Ddos Mitigation With Cloudflare loads about 3.6k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 454 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 454 words, ~3,591 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-ddos-mitigation-with-cloudflare/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-ddos-mitigation-with-cloudflare
description
Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.
domain
cybersecurity
subdomain
network-security
tags
ddos, cloudflare, ddos-mitigation, rate-limiting, waf, bot-management, layer-7, volumetric-attack, network-security
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1046, T1040, T1557, T1071, T1078.004

Implementing DDoS Mitigation with Cloudflare

Overview

Cloudflare provides multi-layer DDoS protection across its global network of over 300 data centers with 477+ Tbps of capacity. The platform protects against L3/4 volumetric attacks (SYN floods, UDP amplification, DNS reflection), protocol attacks (Ping of Death, Smurf), and L7 application-layer attacks (HTTP floods, Slowloris, cache-busting). Cloudflare's autonomous detection systems identify and mitigate attacks within approximately 3 seconds using traffic profiling, machine learning, and adaptive rulesets. This skill covers configuring Cloudflare's DDoS protection stack including managed rulesets, WAF rules, rate limiting, Bot Management, and origin server hardening.

When to Use

  • When deploying or configuring implementing ddos mitigation with cloudflare capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Cloudflare account (Pro plan minimum for WAF, Enterprise for Advanced DDoS)
  • Domain with DNS delegated to Cloudflare nameservers
  • Origin server IP address(es)
  • Understanding of normal traffic patterns and peak volumes
  • Cloudflare API token for automation

Core Concepts

DDoS Attack Categories
LayerAttack TypeExamplesCloudflare Protection
L3/4VolumetricSYN flood, UDP flood, DNS amplificationNetwork-layer DDoS managed rules
L3/4ProtocolPing of Death, Smurf, IP fragmentationAdvanced TCP Protection
L7ApplicationHTTP flood, Slowloris, cache bustingHTTP DDoS managed rules, WAF, Rate Limiting
DNSDNS-specificDNS query flood, NXDOMAIN attackAdvanced DNS Protection
Cloudflare Protection Stack
Internet Traffic
     │
     ▼
┌─────────────────────────┐
│  Cloudflare Edge (PoP)  │
│  ┌───────────────────┐  │
│  │ L3/4 DDoS Mgd Rules│  │  ← Volumetric/Protocol mitigation
│  └───────────────────┘  │
│  ┌───────────────────┐  │
│  │ IP Access Rules    │  │  ← Country/ASN/IP blocks
│  └───────────────────┘  │
│  ┌───────────────────┐  │
│  │ Bot Management     │  │  ← Bot score, JS challenge
│  └───────────────────┘  │
│  ┌───────────────────┐  │
│  │ WAF Managed Rules  │  │  ← OWASP, Cloudflare, Custom
│  └───────────────────┘  │
│  ┌───────────────────┐  │
│  │ Rate Limiting      │  │  ← Request rate enforcement
│  └───────────────────┘  │
│  ┌───────────────────┐  │
│  │ HTTP DDoS Mgd Rules│  │  ← L7 flood detection
│  └───────────────────┘  │
└─────────────────────────┘
     │
     ▼
  Origin Server

Workflow

Step 1: Onboard Domain to Cloudflare
bash
# Add domain via API
curl -X POST "https://api.cloudflare.com/client/v4/zones" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "example.com",
    "type": "full",
    "plan": {"id": "enterprise"}
  }'

# Update DNS records (proxy enabled for DDoS protection)
curl -X POST "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "type": "A",
    "name": "example.com",
    "content": "203.0.113.50",
    "proxied": true,
    "ttl": 1
  }'
Step 2: Configure DDoS Managed Rulesets

HTTP DDoS Attack Protection override:

bash
# List HTTP DDoS managed ruleset
curl -X GET "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/rulesets/phases/ddos_l7/entrypoint" \
  -H "Authorization: Bearer $CF_API_TOKEN"

# Override HTTP DDoS sensitivity and action
curl -X PUT "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/rulesets/phases/ddos_l7/entrypoint" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "rules": [{
      "action": "execute",
      "action_parameters": {
        "id": "4d21379b4f9f4bb088e0729962c8b3cf",
        "overrides": {
          "rules": [{
            "id": "fdfdac75430c4c47a422bdc024aab531",
            "sensitivity_level": "medium",
            "action": "block"
          }],
          "sensitivity_level": "high"
        }
      },
      "expression": "true"
    }]
  }'

Network-layer DDoS Protection override:

bash
curl -X PUT "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/rulesets/phases/ddos_l4/entrypoint" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "rules": [{
      "action": "execute",
      "action_parameters": {
        "id": "3b64149bfa6e4220bbbc2bd6db7c867e",
        "overrides": {
          "sensitivity_level": "high"
        }
      },
      "expression": "true"
    }]
  }'
Step 3: Configure Rate Limiting Rules
bash
# Create rate limiting rule for login endpoint
curl -X POST "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/rulesets/phases/http_ratelimit/entrypoint" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "rules": [
      {
        "description": "Rate limit login attempts",
        "expression": "(http.request.uri.path eq \"/api/login\")",
        "action": "block",
        "ratelimit": {
          "characteristics": ["cf.colo.id", "ip.src"],
          "period": 60,
          "requests_per_period": 10,
          "mitigation_timeout": 600
        }
      },
      {
        "description": "Rate limit API endpoints",
        "expression": "(http.request.uri.path matches \"^/api/\")",
        "action": "managed_challenge",
        "ratelimit": {
          "characteristics": ["cf.colo.id", "ip.src"],
          "period": 60,
          "requests_per_period": 100,
          "mitigation_timeout": 300
        }
      },
      {
        "description": "Global rate limit per IP",
        "expression": "true",
        "action": "managed_challenge",
        "ratelimit": {
          "characteristics": ["ip.src"],
          "period": 10,
          "requests_per_period": 50,
          "mitigation_timeout": 60
        }
      }
    ]
  }'
Step 4: Configure WAF Custom Rules
bash
# Block known attack patterns
curl -X POST "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/rulesets/phases/http_request_firewall_custom/entrypoint" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "rules": [
      {
        "description": "Block requests from known bad ASNs",
        "expression": "(ip.geoip.asnum in {12345 67890})",
        "action": "block"
      },
      {
        "description": "Challenge requests without User-Agent",
        "expression": "(not http.user_agent ne \"\")",
        "action": "managed_challenge"
      },
      {
        "description": "Block high-risk countries for admin paths",
        "expression": "(http.request.uri.path contains \"/admin\" and not ip.geoip.country in {\"US\" \"CA\" \"GB\"})",
        "action": "block"
      },
      {
        "description": "Block oversized request bodies",
        "expression": "(http.request.body.size gt 10000000)",
        "action": "block"
      }
    ]
  }'
Step 5: Configure Origin Protection

Ensure the origin server only accepts traffic from Cloudflare:

bash
# Get Cloudflare IP ranges
curl https://api.cloudflare.com/client/v4/ips

# Configure origin server firewall (iptables)
# Allow only Cloudflare IPs
for ip in $(curl -s https://www.cloudflare.com/ips-v4); do
    iptables -A INPUT -p tcp --dport 443 -s $ip -j ACCEPT
    iptables -A INPUT -p tcp --dport 80 -s $ip -j ACCEPT
done

# Drop all other HTTP/HTTPS traffic
iptables -A INPUT -p tcp --dport 443 -j DROP
iptables -A INPUT -p tcp --dport 80 -j DROP

# Enable Authenticated Origin Pulls (mutual TLS)
# Download Cloudflare origin CA certificate
curl -o /etc/ssl/cloudflare-origin-pull.pem \
  https://developers.cloudflare.com/ssl/static/authenticated_origin_pull_ca.pem

# Nginx configuration for authenticated origin pulls
# ssl_client_certificate /etc/ssl/cloudflare-origin-pull.pem;
# ssl_verify_client on;
Show full SKILL.md (175 more words)Show less
Step 6: Enable Under Attack Mode Automation
python
#!/usr/bin/env python3
"""Auto-enable Cloudflare Under Attack Mode based on traffic anomalies."""

import requests
import time
import sys

CF_API_TOKEN = "your-api-token"
ZONE_ID = "your-zone-id"
HEADERS = {
    "Authorization": f"Bearer {CF_API_TOKEN}",
    "Content-Type": "application/json",
}
BASE_URL = f"https://api.cloudflare.com/client/v4/zones/{ZONE_ID}"

NORMAL_RPS_THRESHOLD = 5000  # Requests per second threshold
CHECK_INTERVAL = 30  # Seconds between checks


def get_current_security_level():
    """Get current security level setting."""
    resp = requests.get(
        f"{BASE_URL}/settings/security_level",
        headers=HEADERS
    )
    return resp.json()["result"]["value"]


def set_security_level(level: str):
    """Set security level (off, essentially_off, low, medium, high, under_attack)."""
    resp = requests.patch(
        f"{BASE_URL}/settings/security_level",
        headers=HEADERS,
        json={"value": level}
    )
    result = resp.json()
    if result["success"]:
        print(f"[+] Security level set to: {level}")
    else:
        print(f"[-] Failed to set security level: {result['errors']}")
    return result["success"]


def get_traffic_analytics():
    """Get recent traffic data from Cloudflare analytics."""
    query = """
    query {
      viewer {
        zones(filter: {zoneTag: "%s"}) {
          httpRequests1mGroups(limit: 1, orderBy: [datetime_DESC]) {
            sum {
              requests
              threats
            }
            dimensions {
              datetime
            }
          }
        }
      }
    }
    """ % ZONE_ID

    resp = requests.post(
        "https://api.cloudflare.com/client/v4/graphql",
        headers=HEADERS,
        json={"query": query}
    )
    return resp.json()


def monitor_and_respond():
    """Monitor traffic and auto-enable under attack mode."""
    current_level = get_current_security_level()
    print(f"[*] Current security level: {current_level}")
    print(f"[*] Monitoring traffic (threshold: {NORMAL_RPS_THRESHOLD} RPS)...")

    attack_mode_active = False
    consecutive_normal = 0

    while True:
        try:
            analytics = get_traffic_analytics()
            zones = analytics.get("data", {}).get("viewer", {}).get("zones", [])

            if zones and zones[0].get("httpRequests1mGroups"):
                data = zones[0]["httpRequests1mGroups"][0]["sum"]
                rps = data["requests"] / 60
                threats = data["threats"]

                print(f"[*] Current RPS: {rps:.0f}, Threats: {threats}")

                if rps > NORMAL_RPS_THRESHOLD and not attack_mode_active:
                    print(f"[!] Traffic spike detected: {rps:.0f} RPS")
                    set_security_level("under_attack")
                    attack_mode_active = True
                    consecutive_normal = 0

                elif rps <= NORMAL_RPS_THRESHOLD and attack_mode_active:
                    consecutive_normal += 1
                    if consecutive_normal >= 5:
                        print("[+] Traffic normalized, disabling under attack mode")
                        set_security_level("high")
                        attack_mode_active = False
                        consecutive_normal = 0

        except Exception as e:
            print(f"[-] Error: {e}")

        time.sleep(CHECK_INTERVAL)


if __name__ == "__main__":
    monitor_and_respond()

Monitoring and Alerting

Cloudflare Dashboard Metrics
  • Firewall Events - View blocked requests, challenged requests, rate-limited requests
  • DDoS Analytics - Attack size, duration, type, and mitigation status
  • Traffic Analytics - Request volume, bandwidth, error rates by time
  • Bot Analytics - Bot score distribution, verified bots vs automated threats
Alert Configuration
bash
# Create notification policy for DDoS attacks
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/alerting/v3/policies" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "DDoS Attack Alert",
    "alert_type": "dos_attack_l7",
    "enabled": true,
    "mechanisms": {
      "email": [{"id": "soc@example.com"}],
      "webhooks": [{"id": "webhook-id"}]
    },
    "filters": {
      "zones": ["'$ZONE_ID'"]
    }
  }'

Best Practices

  • Proxy All DNS Records - Ensure all A/AAAA/CNAME records pointing to origin are proxied (orange cloud)
  • Hide Origin IP - Never expose origin server IP; use Cloudflare Tunnel or restrict to Cloudflare IPs only
  • Start in Log Mode - Test DDoS rule overrides with "Log" action before switching to "Block"
  • Layer Defense - Combine managed rulesets, rate limiting, WAF rules, and Bot Management
  • Tune Sensitivity - Adjust DDoS rule sensitivity based on false positive rates in your traffic
  • Cache Strategy - Maximize cache hit ratio to reduce origin load during attacks
  • Waiting Room - Configure Cloudflare Waiting Room for critical pages during traffic surges
  • Authenticated Origin - Enable Authenticated Origin Pulls to prevent direct-to-origin attacks

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-ddos-mitigation-with-cloudflare of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Ddos Mitigation With Cloudflare next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Ddos Mitigation With Cloudflare compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Ddos Mitigation With Cloudflare this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Apikerhodgef/apiker127—~1.4kAutomated safety check: PassMIT
Cloudflare Kvsecondsky/claude-skills227—~2.4kAutomated safety check: PassMIT
Cloudflare Worker Devcuriositech/some_claude_skills243—~3.4kAutomated safety check: NotesMIT
Anti Bot Analyzerrevfactory/harness-1001.3k—~1.1kAutomated safety check: PassApache-2.0
Upstash Ratelimit TSupstash/ratelimit-js2k1 repos~313Automated safety check: PassMIT

Similar skills

  • Apiker

    hodgef/apiker

    Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.

    127 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Cloudflare Kv

    secondsky/claude-skills

    Cloudflare Workers KV global key-value storage. An agent skill from secondsky/claude-skills.

    227 GitHub stars~2.4k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Cloudflare Worker Dev

    curiositech/some_claude_skills

    Cloudflare Workers, KV, Durable Objects, and edge computing development.

    243 GitHub stars~3.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Data & AnalyticsAuto-check passed
  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2k GitHub starsUsed in 1 repo~313 tokens
    Backend & APIsAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.2k GitHub stars~13k tokensUpdated 4 days ago
    Backend & APIsAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Implementing Ddos Mitigation With Cloudflare

What does Implementing Ddos Mitigation With Cloudflare do?

Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks. Implementing Ddos Mitigation With Cloudflare is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configure Cloudflare DDoS protection with managed rulesets, rate limiting, WAF rules, Bot Management, and origin protection to mitigate volumetric, protocol, and application-layer attacks.

When should I use Implementing Ddos Mitigation With Cloudflare?

Implementing Ddos Mitigation With Cloudflare fits situations like: tasks that involve Rate limiting.

How do I install Implementing Ddos Mitigation With Cloudflare in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ddos-mitigation-with-cloudflare -a claude-code`. Or copy the skill folder (skills/implementing-ddos-mitigation-with-cloudflare in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-ddos-mitigation-with-cloudflare in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Ddos Mitigation With Cloudflare in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ddos-mitigation-with-cloudflare -a codex`. Or copy the skill folder (skills/implementing-ddos-mitigation-with-cloudflare in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-ddos-mitigation-with-cloudflare in your project. Codex loads it when a task matches its description.

Can I use Implementing Ddos Mitigation With Cloudflare in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ddos-mitigation-with-cloudflare -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-ddos-mitigation-with-cloudflare, .gemini/skills/implementing-ddos-mitigation-with-cloudflare, .github/skills/implementing-ddos-mitigation-with-cloudflare and .opencode/skills/implementing-ddos-mitigation-with-cloudflare in your project.

What does Implementing Ddos Mitigation With Cloudflare need to run?

Going by SKILL.md and its folder, Implementing Ddos Mitigation With Cloudflare needs Python for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named CF_API_TOKEN. Our summary lists: Python 3; A credential in CF_API_TOKEN.

Does Implementing Ddos Mitigation With Cloudflare access the network?

SKILL.md names 3 domains. In commands or code: api.cloudflare.com, developers.cloudflare.com and cloudflare.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Implementing Ddos Mitigation With Cloudflare safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Ddos Mitigation With Cloudflare use?

Implementing Ddos Mitigation With Cloudflare is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Ddos Mitigation With Cloudflare use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 397 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Ddos Mitigation With Cloudflare?

Skills that share tags, products or a category with Implementing Ddos Mitigation With Cloudflare: Apiker (hodgef/apiker, 127 stars), Cloudflare Kv (secondsky/claude-skills, 227 stars), Cloudflare Worker Dev (curiositech/some_claude_skills, 243 stars) and Anti Bot Analyzer (revfactory/harness-100, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Ddos Mitigation With Cloudflare?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.