Azure Reliability
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Reliability development including best practices, decision making, architecture & design patterns, limits & quotas, and deployment.
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-ddos-protection --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-ddos-protection .claude/skills/azure-ddos-protection && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-ddos-protection" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protection into .claude/skills/azure-ddos-protection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-ddos-protection", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protectionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-ddos-protection --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/azure-ddos-protection .agents/skills/azure-ddos-protection && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-ddos-protection" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protection into .agents/skills/azure-ddos-protection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-ddos-protection", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-ddos-protection --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/azure-ddos-protection .cursor/skills/azure-ddos-protection && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-ddos-protection" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protection into .cursor/skills/azure-ddos-protection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-ddos-protection", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/azure-ddos-protection--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-ddos-protection --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/azure-ddos-protection .gemini/skills/azure-ddos-protection && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-ddos-protection" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protection into .gemini/skills/azure-ddos-protection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-ddos-protection", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-ddos-protectionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/azure-ddos-protection .github/skills/azure-ddos-protection && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-ddos-protection" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protection into .github/skills/azure-ddos-protection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-ddos-protection", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-ddos-protection --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/azure-ddos-protection .opencode/skills/azure-ddos-protection && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-ddos-protection" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-ddos-protection into .opencode/skills/azure-ddos-protection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-ddos-protection", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-ddos-protectionGuidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Azure Ddos Protection is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform. Covers tier selection vs free Basic infrastructure protection, scope (VNet vs single IP), traffic profiling and mitigation policy auto-tuning, attack analytics and metrics, attack alerts to Sentinel, DDoS Rapid Response engagement, integration with Azure WAF and Front Door, cost-protection guarantee, mitigation reports for compliance, and per-region capacity…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Site reliability engineering. It works with Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Ddos Protection loads about 2k tokens when it runs. Until then it costs about 231 tokens; SKILL.md has 850 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 850 words, ~2,021 tokens.
.claude/skills/azure-ddos-protection/SKILL.md (or your agent's skills folder).Azure DDoS Protection sits on the Microsoft global network and absorbs layer 3/4 volumetric and protocol attacks before they reach your workloads. The free Infrastructure Protection layer protects Azure as a platform; the paid DDoS Protection plans give you dedicated, profile-tuned mitigation, attack analytics, post-incident reports, cost protection, and Rapid Response support for your resources.
Public-facing workloads with a non-trivial cost-of-downtime: e-commerce, regulated financial APIs, multiplayer gaming, public-sector services, internet-facing AI APIs, streaming, and any campaign exposed to politically or commercially motivated DDoS.
Do not use this skill for application-layer (HTTP) attack mitigation alone
(azure-waf), Azure Firewall design (azure-firewall), or third-party DDoS appliance
patterns.
| Tier | Scope | Best for |
|---|---|---|
| Infrastructure Protection | Free, platform-level, no SLA, no analytics | Default for every workload |
| DDoS Network Protection | Per VNet, all public IPs in scope | Multi-IP workloads, large estates |
| DDoS IP Protection | Per public IP, granular | Small estates, cost-conscious, specific high-risk IP |
Pricing model differs: Network Protection is a flat fee per plan covering many resources; IP Protection is per-IP. Estate size flips the economics — model both before choosing.
Decide tier per workload.
Enable on the VNet (Network Protection) at deployment time. The platform begins traffic profiling immediately; it learns normal patterns over ~7 days and auto-tunes the per-IP mitigation policy. Mitigation accuracy improves the longer the profile runs.
Static thresholds are not a thing, by design. Mitigation is adaptive. Don't architect on the assumption of a fixed Mbps cap.
Configure alerts. DDoS metrics and alerts are first-class:
Simulate before incident. BreakingPoint Cloud and Red Button are Microsoft- approved simulation partners. Simulate quarterly on non-prod public IPs to validate mitigation engagement and runbook execution.
Attack analytics + post-incident reports. During and after an attack, the product produces a mitigation report with attack vectors, traffic volume, top sources, and mitigation actions — useful evidence for board/regulator communications.
DDoS Rapid Response (DRR). Plan on Network Protection includes engagement with Microsoft's DDoS response team during active attacks. Pre-stage:
Cost protection. A successful DDoS attack can balloon scale-out costs (autoscaled App Service, additional bandwidth, CDN egress). Network Protection includes service- credit cost protection — file the claim post-incident with the mitigation report.
Combine with WAF and Front Door. DDoS Protection covers L3/L4. L7 attacks (HTTP floods, slow loris, business-logic abuse) need WAF on Front Door / Application Gateway in front of your workload. Architect both.
Plan DDoS Protection coverage for a 6-region public-API estate with 80 public IPs.Compare Network vs IP Protection cost for a tenant with 25 public IPs in 3 VNets.Build the DDoS attack runbook including DRR engagement steps and stakeholder comms templates.Quarterly DDoS simulation with BreakingPoint Cloud — scope, success criteria, rollback.Wire DDoS metrics + alerts to Sentinel with detections for sustained mitigation events.Architect Front Door + WAF + DDoS Network Protection for a regulated e-commerce workload.File the cost protection claim after a 14-hour mitigated attack — what evidence and process.© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/azure-ddos-protection of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
Azure Ddos Protection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Ddos Protection this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~2k | Automated safety check: Pass | MIT | |
| Azure ReliabilityMicrosoftDocs/Agent-Skills | 776 | — | ~2.2k | Automated safety check: Pass | CC-BY-4.0 | |
| Azure Sre AgentMicrosoftDocs/Agent-Skills | 776 | — | ~2.7k | Automated safety check: Pass | CC-BY-4.0 | |
| Cloud Cost Optimizationwshobson/agents | 40k | 14 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Thesvgglincker/thesvg | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT |
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Reliability development including best practices, decision making, architecture & design patterns, limits & quotas, and deployment.
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Sre Agent development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns…
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
glincker/thesvg
Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.
Azure/Copilot-Studio-and-Azure
Fetches real-time Azure retail pricing using the Azure Retail Prices API (prices.azure.com) and estimates Copilot Studio agent credit consumption.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control.
Works with
Categories
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform. Azure Ddos Protection is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Azure Ddos Protection fits situations like: layer 7 / app-layer attack mitigation alone (use azure-waf); azure Firewall design (use azure-firewall); hybrid network DDoS via on-prem appliances.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a claude-code`. Or copy the skill folder (skills/azure-ddos-protection in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-ddos-protection in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a codex`. Or copy the skill folder (skills/azure-ddos-protection in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-ddos-protection in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-ddos-protection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-ddos-protection, .gemini/skills/azure-ddos-protection, .github/skills/azure-ddos-protection and .opencode/skills/azure-ddos-protection in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure Ddos Protection is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Ddos Protection is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azure Ddos Protection: Azure Reliability (MicrosoftDocs/Agent-Skills, 776 stars), Azure Sre Agent (MicrosoftDocs/Agent-Skills, 776 stars), Cloud Cost Optimization (wshobson/agents, 40k stars) and Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.