Agent skill

Securing Azure With Microsoft Defender

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring…

Apache-2.0Auto-check passedDevOps & Cloud

Install Securing Azure With Microsoft Defender

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-azure-with-microsoft-defender -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills securing-azure-with-microsoft-defender --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/securing-azure-with-microsoft-defender .claude/skills/securing-azure-with-microsoft-defender && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
securing-azure-with-microsoft-defender
GitHub stars
34k
Token cost
~3k tokens
SKILL.md length
722 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring…

  • Works in 6 steps: Enable Defender for Cloud Plans → Configure Environment Connectors for… → Review and Prioritize Secure Score… → …
  • Onboarding workloads to Defender for Cloud
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls az and aws

What it does

Securing Azure With Microsoft Defender is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring recommendations, and managing Secure Score via the unified Defender portal. Use when onboarding workloads to Defender for Cloud or setting up cloud workload protection and threat monitoring.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Cloud architecture and Cloud security. It works with Microsoft Defender, Microsoft Azure and Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Onboarding workloads to Defender for Cloud
  • Setting up cloud workload protection and threat monitoring

Example prompts

  • “Use the securing-azure-with-microsoft-defender skill to deploy and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and…”
  • “/securing-azure-with-microsoft-defender”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Enable Defender for Cloud Plans
  2. Configure Environment Connectors for Multi-Cloud
  3. Review and Prioritize Secure Score Recommendations
  4. Configure Adaptive Application Controls and JIT Access
  5. Set Up Security Alerts and Workflow Automation
  6. Enable Cloud Security Graph and Attack Path Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • az
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az and aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Securing Azure With Microsoft Defender loads about 3k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 722 words, ~2,993 tokens.

Download SKILL.mdSave it as .claude/skills/securing-azure-with-microsoft-defender/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
securing-azure-with-microsoft-defender
description
Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring recommendations, and managing Secure Score via the unified Defender portal. Use when onboarding workloads to Defender for Cloud or setting up cloud workload protection and threat monitoring.
domain
cybersecurity
subdomain
cloud-security
tags
microsoft-defender, azure-security, cnapp, secure-score, cloud-workload-protection
version
1.0.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580, T1610

Securing Azure with Microsoft Defender

When to Use

  • When deploying cloud workload protection across Azure subscriptions and resource groups
  • When establishing a Secure Score baseline and prioritizing security recommendations
  • When extending threat protection to multi-cloud environments including AWS and GCP
  • When enabling container security for AKS clusters and Azure Container Registry
  • When integrating AI workload security with the Data and AI security dashboard

Do not use for AWS-only environments (see implementing-aws-security-hub), for identity provider configuration (see managing-cloud-identity-with-okta), or for network-level firewall rule management (see implementing-cloud-waf-rules).

Prerequisites

  • Azure subscription with Security Admin or Contributor role
  • Azure Policy initiative for Defender for Cloud enabled at the management group level
  • Log Analytics workspace provisioned for security data collection
  • Microsoft Defender for Cloud plans licensed (P1 or P2 for server protection)

Workflow

Step 1: Enable Defender for Cloud Plans

Activate Defender plans for each workload type: Servers, Containers, App Service, Storage, Databases, Key Vault, Resource Manager, and DNS. Each plan provides specialized threat detection and vulnerability assessment.

powershell
# Enable Defender for Servers Plan 2
az security pricing create --name VirtualMachines --tier Standard --subplan P2

# Enable Defender for Containers
az security pricing create --name Containers --tier Standard

# Enable Defender for Storage with malware scanning
az security pricing create --name StorageAccounts --tier Standard \
  --extensions '[{"name":"OnUploadMalwareScanning","isEnabled":"True",
  "additionalExtensionProperties":{"CapGBPerMonthPerStorageAccount":"5000"}}]'

# Enable Defender for Databases
az security pricing create --name SqlServers --tier Standard
az security pricing create --name CosmosDbs --tier Standard

# Enable Defender for Key Vault
az security pricing create --name KeyVaults --tier Standard

# Verify all enabled plans
az security pricing list --query "[?pricingTier=='Standard'].{Plan:name, Tier:pricingTier, SubPlan:subPlan}" -o table
Step 2: Configure Environment Connectors for Multi-Cloud

Connect AWS accounts and GCP projects to Defender for Cloud for unified security posture management across cloud providers.

powershell
# Create AWS connector for CSPM
az security security-connector create \
  --name aws-production-connector \
  --resource-group security-rg \
  --environment-name AWS \
  --hierarchy-identifier "123456789012" \
  --offerings '[{
    "offeringType": "CspmMonitorAws",
    "nativeCloudConnection": {"cloudRoleArn": "arn:aws:iam::123456789012:role/DefenderForCloudRole"}
  }]'

# Create GCP connector
az security security-connector create \
  --name gcp-production-connector \
  --resource-group security-rg \
  --environment-name GCP \
  --hierarchy-identifier "my-gcp-project-id" \
  --offerings '[{"offeringType": "CspmMonitorGcp"}]'
Step 3: Review and Prioritize Secure Score Recommendations

Analyze the Secure Score across all subscriptions. Each recommendation includes a risk priority based on asset exposure, internet exposure, and threat intelligence context.

powershell
# Get current Secure Score
az security secure-score list \
  --query "[].{Name:displayName, Score:current, Max:max, Percentage:percentage}" -o table

# List unhealthy recommendations sorted by severity
az security assessment list \
  --query "[?properties.status.code=='Unhealthy'].{Name:properties.displayName, Severity:properties.metadata.severity, Resources:properties.resourceDetails.id}" \
  --output table

# Get specific recommendation details
az security assessment show \
  --assessment-name "4fb67663-9ab9-475d-b026-8c544cced439" \
  --query "{Name:properties.displayName, Description:properties.metadata.description, Remediation:properties.metadata.remediationDescription}"
Step 4: Configure Adaptive Application Controls and JIT Access

Enable Just-In-Time VM access to reduce the attack surface by opening management ports only when needed, and deploy adaptive application controls to whitelist approved executables.

powershell
# Enable JIT VM access policy
az security jit-policy create \
  --resource-group production-rg \
  --location eastus \
  --name default \
  --virtual-machines '[{
    "id": "/subscriptions/sub-id/resourceGroups/production-rg/providers/Microsoft.Compute/virtualMachines/web-server-01",
    "ports": [
      {"number": 22, "protocol": "TCP", "allowedSourceAddressPrefix": "10.0.0.0/8", "maxRequestAccessDuration": "PT3H"},
      {"number": 3389, "protocol": "TCP", "allowedSourceAddressPrefix": "10.0.0.0/8", "maxRequestAccessDuration": "PT1H"}
    ]
  }]'

# Request JIT access
az security jit-policy initiate \
  --resource-group production-rg \
  --location eastus \
  --name default \
  --virtual-machines '[{
    "id": "/subscriptions/sub-id/resourceGroups/production-rg/providers/Microsoft.Compute/virtualMachines/web-server-01",
    "ports": [{"number": 22, "duration": "PT1H", "allowedSourceAddressPrefix": "203.0.113.10"}]
  }]'
Step 5: Set Up Security Alerts and Workflow Automation

Configure workflow automation to trigger Logic Apps or Azure Functions when security alerts are generated. Set up email notifications for Critical and High severity alerts.

powershell
# Create workflow automation for high severity alerts
az security automation create \
  --name high-severity-alert-automation \
  --resource-group security-rg \
  --scopes '[{"description": "Production subscription", "scopePath": "/subscriptions/<sub-id>"}]' \
  --sources '[{
    "eventSource": "Alerts",
    "ruleSets": [{"rules": [{"propertyJPath": "Severity", "propertyType": "String", "expectedValue": "High", "operator": "Equals"}]}]
  }]' \
  --actions '[{
    "logicAppResourceId": "/subscriptions/<sub-id>/resourceGroups/security-rg/providers/Microsoft.Logic/workflows/alert-handler",
    "actionType": "LogicApp"
  }]'

# Configure email notifications
az security contact create \
  --name default \
  --email "soc-team@company.com" \
  --alert-notifications "on" \
  --alerts-to-admins "on"
Step 6: Enable Cloud Security Graph and Attack Path Analysis

Use the cloud security graph to visualize attack paths that adversaries could exploit to reach critical assets. Prioritize remediation based on actual exploitability rather than individual finding severity.

# Query attack paths via Resource Graph
az graph query -q "
  securityresources
  | where type == 'microsoft.security/attackpaths'
  | extend riskLevel = properties.riskLevel
  | extend entryPoint = properties.attackPathDisplayName
  | where riskLevel == 'Critical'
  | project entryPoint, riskLevel, properties.description
  | limit 20
"

Key Concepts

TermDefinition
Secure ScoreA numerical measure of an organization's security posture based on the percentage of implemented security recommendations, scored per subscription and aggregated at the management group level
Cloud Security GraphA graph database mapping relationships between cloud resources, identities, network exposure, and vulnerabilities to identify exploitable attack paths
Attack Path AnalysisVisualization of multi-step attack chains an adversary could follow from an entry point to a high-value target, prioritized by real-world exploitability
Just-In-Time AccessSecurity control that blocks management ports by default and opens them temporarily upon approved request, reducing the VM attack surface
Adaptive Application ControlsMachine-learning-based allowlisting that recommends which applications should run on VMs and alerts on deviations
Defender CSPMEnhanced cloud security posture management plan providing agentless scanning, attack path analysis, and cloud security graph capabilities
Security ConnectorIntegration point connecting AWS or GCP environments to Defender for Cloud for multi-cloud posture management
Show full SKILL.md (245 more words)Show less

Tools & Systems

  • Microsoft Defender for Cloud: Core CNAPP platform providing CSPM, CWP, and threat protection across Azure, AWS, and GCP
  • Azure Resource Graph: Query engine for exploring cloud security graph data and attack paths at scale
  • Azure Logic Apps: Workflow automation platform for building remediation playbooks triggered by Defender alerts
  • Microsoft Defender Portal: Unified security operations console integrating Defender for Cloud with XDR, Sentinel, and threat intelligence
  • Azure Policy: Governance engine for enforcing Defender for Cloud recommendations as compliance requirements

Common Scenarios

Scenario: Internet-Exposed SQL Server with Known Vulnerability

Context: Defender for Cloud identifies an Azure SQL Server with a public endpoint, an unpatched critical CVE, and a service principal with database owner permissions that also has access to a Key Vault containing production encryption keys.

Approach:

  1. Review the attack path in the cloud security graph showing: Internet -> SQL Server (CVE) -> Service Principal -> Key Vault
  2. Immediately restrict the SQL Server firewall to private endpoints only
  3. Apply the SQL Server security patch through Azure Update Management
  4. Rotate the service principal credentials and scope its permissions to only the required database operations
  5. Add a Key Vault access policy requiring the service principal to authenticate via managed identity rather than secret-based credentials
  6. Verify the attack path is resolved in Defender CSPM within 24 hours

Pitfalls: Focusing on the SQL vulnerability alone misses the lateral movement path to Key Vault. Restricting the endpoint without updating application connection strings causes an outage.

Output Format

Microsoft Defender for Cloud Security Report
=============================================
Tenant: acme-corp.onmicrosoft.com
Subscriptions Monitored: 12
Report Date: 2025-02-23

SECURE SCORE: 72/100

DEFENDER PLANS STATUS:
  Servers (P2):     ENABLED - 156 VMs covered
  Containers:       ENABLED - 8 AKS clusters covered
  Storage:          ENABLED - 342 storage accounts, malware scanning active
  Databases:        ENABLED - 23 SQL servers, 5 Cosmos DB accounts
  Key Vault:        ENABLED - 18 vaults monitored
  AWS Connector:    ENABLED - 3 accounts connected
  GCP Connector:    ENABLED - 2 projects connected

CRITICAL ATTACK PATHS:
  [AP-001] Internet -> VM (RDP open) -> Managed Identity -> Storage (PII data)
    Risk: Critical | Affected Resources: 3 | Remediation: Close RDP, restrict MI scope
  [AP-002] Internet -> App Service (SQLi vuln) -> SQL DB -> Service Principal -> Key Vault
    Risk: Critical | Affected Resources: 5 | Remediation: Patch app, private endpoint

ALERT SUMMARY (Last 30 Days):
  Critical: 5 | High: 23 | Medium: 67 | Low: 134
  Top Alert Types:
    - Suspicious login activity (18)
    - Malware detected in storage (7)
    - Anomalous resource deployment (12)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/securing-azure-with-microsoft-defender of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Securing Azure With Microsoft Defender next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Securing Azure With Microsoft Defender compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Securing Azure With Microsoft Defender this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Cloud Misconfig Auditorcriptogus/agent-evolve-network288—~965Automated safety check: PassCC-BY-SA-4.0
Cloud Securityborghei/Claude-Skills891—~3.5kAutomated safety check: PassMIT
Defender For Cloud Hardeningvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Defender For Containersvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT

Similar skills

  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Cloud Security

    borghei/Claude-Skills

    Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

    891 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Defender For Cloud Hardening

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Defender For Containers

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Securing Azure With Microsoft Defender

What does Securing Azure With Microsoft Defender do?

Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring…. Securing Azure With Microsoft Defender is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring recommendations, and managing Secure Score via the unified Defender portal.

When should I use Securing Azure With Microsoft Defender?

Securing Azure With Microsoft Defender fits situations like: onboarding workloads to Defender for Cloud; setting up cloud workload protection and threat monitoring.

How do I install Securing Azure With Microsoft Defender in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-azure-with-microsoft-defender -a claude-code`. Or copy the skill folder (skills/securing-azure-with-microsoft-defender in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/securing-azure-with-microsoft-defender in your project. Claude Code loads it when a task matches its description.

How do I install Securing Azure With Microsoft Defender in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-azure-with-microsoft-defender -a codex`. Or copy the skill folder (skills/securing-azure-with-microsoft-defender in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/securing-azure-with-microsoft-defender in your project. Codex loads it when a task matches its description.

Can I use Securing Azure With Microsoft Defender in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-azure-with-microsoft-defender -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securing-azure-with-microsoft-defender, .gemini/skills/securing-azure-with-microsoft-defender, .github/skills/securing-azure-with-microsoft-defender and .opencode/skills/securing-azure-with-microsoft-defender in your project.

What does Securing Azure With Microsoft Defender need to run?

Going by SKILL.md and its folder, Securing Azure With Microsoft Defender needs Python for the scripts in its folder and the command-line tools its instructions call (az and aws). Our summary lists: Python 3.

Does Securing Azure With Microsoft Defender access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Securing Azure With Microsoft Defender safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Securing Azure With Microsoft Defender use?

Securing Azure With Microsoft Defender is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Securing Azure With Microsoft Defender use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 505 tokens, read only when the agent opens those files.

What are the alternatives to Securing Azure With Microsoft Defender?

Skills that share tags, products or a category with Securing Azure With Microsoft Defender: Cloud Misconfig Auditor (criptogus/agent-evolve-network, 288 stars), Cloud Security (borghei/Claude-Skills, 891 stars), Defender For Cloud Hardening (vinayaklatthe/microsoft-security-skills, 175 stars) and Defender For Containers (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Securing Azure With Microsoft Defender?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.