Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR.

MITAuto-check passedSecurity

Install Defender For Iot

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-iot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills defender-for-iot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defender-for-iot .claude/skills/defender-for-iot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender-for-iot
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
822 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR.

  • Works in 7 steps: Network mapping by Purdue level first.… → Pick sensor placement. One sensor per OT… → Deploy passively. OT sensors are fully… → …
  • IoT Hub data-plane security (Azure platform)
  • SKILL.md covers When to use, OT vs Enterprise IoT — pick…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender For Iot is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. Covers OT sensor deployment (physical/virtual, SPAN/TAP), Purdue model alignment, on-premises management console, cloud-managed sensors, EIoT (printers, cameras, VoIP) discovered through MDE, asset inventory, vulnerability data, threat intelligence, and integration with Sentinel and Defender XDR. WHEN: Defender for IoT, OT…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Network security, OSINT and Deployment. It works with Microsoft Defender and Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • IoT Hub data-plane security (Azure platform)
  • Azure Sphere device hardening
  • Generic endpoint EDR (use defender-for-endpoint)

Example prompts

  • “/defender-for-iot”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Network mapping by Purdue level first. Identify Level 0/1 (controllers, sensors),
  2. Pick sensor placement. One sensor per OT site, attached to a SPAN port that mirrors
  3. Deploy passively. OT sensors are fully passive — no probing, no active scans.
  4. Build the asset inventory. Within 14 days the sensor builds a baseline of devices,
  5. Enable alerts. Categories: malware, network anomalies, protocol violations,
  6. Stream to Sentinel. Use the Defender for IoT data connector. Build OT-specific
  7. Vulnerability program. Sensor identifies device firmware → matched to known CVEs.

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender For Iot loads about 1.9k tokens when it runs. Until then it costs about 231 tokens; SKILL.md has 822 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~231
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 822 words, ~1,852 tokens.

Download SKILL.mdSave it as .claude/skills/defender-for-iot/SKILL.md (or your agent's skills folder).
name
defender-for-iot
description
Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. Covers OT sensor deployment (physical/virtual, SPAN/TAP), Purdue model alignment, on-premises management console, cloud-managed sensors, EIoT (printers, cameras, VoIP) discovered through MDE, asset inventory, vulnerability data, threat intelligence, and integration with Sentinel and Defender XDR. WHEN: Defender for IoT, OT security, ICS security, SCADA monitoring, Purdue model network security, OT sensor deployment, SPAN port monitoring, enterprise IoT discovery, unmanaged device protection, factory floor security, NDR for OT, ICS threat detection, IoT asset inventory. DO NOT USE for IoT Hub data-plane security (Azure platform), Azure Sphere device hardening, or generic endpoint EDR (use defender-for-endpoint).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Defender for IoT

Defender for IoT delivers agentless network detection and response for two distinct estates that legacy endpoint tools miss:

  • OT / ICS (operational technology, SCADA, PLCs, industrial networks).
  • Enterprise IoT (EIoT) — printers, cameras, VoIP phones, smart-building devices on the corporate network — discovered and protected via the Microsoft Defender for Endpoint sensor and surfaced in Defender XDR.

When to use

Securing factory, utility, healthcare, or building-automation networks; or extending visibility to unmanaged "things" on the enterprise LAN that cannot run an endpoint agent.

Do not use this skill for IoT Hub / IoT Central data-plane security, Azure Sphere firmware design, or workstation/server EDR (defender-for-endpoint).

OT vs Enterprise IoT — pick the right path

EstatePathSensor
Plant networks, ICS, SCADA, PLCs (Levels 0–3 Purdue)Defender for IoT — OTDedicated OT network sensor (physical or virtual VM) attached to SPAN/TAP
Corporate LAN unmanaged devices (printers, cameras, VoIP)Defender for IoT — EIoTExisting MDE sensors on Windows endpoints; no separate appliance

Rule of thumb: if it speaks Modbus / DNP3 / S7 / EtherNet/IP, you need an OT sensor. If it's an IP camera on the office VLAN, EIoT via MDE is enough.

Approach

OT estate
  1. Network mapping by Purdue level first. Identify Level 0/1 (controllers, sensors), Level 2 (SCADA HMI), Level 3 (operations management). Sensors monitor traffic between levels and east-west within Level 2/3.

  2. Pick sensor placement. One sensor per OT site, attached to a SPAN port that mirrors the core OT switch. Aggregate multi-site sensors into a cloud-connected model (preferred for new deployments) or the legacy on-prem management console (for air-gapped sites).

  3. Deploy passively. OT sensors are fully passive — no probing, no active scans. This is non-negotiable in safety-critical environments. Confirm with plant ops before any port turn-up.

  4. Build the asset inventory. Within 14 days the sensor builds a baseline of devices, firmware versions, and protocol relationships. Validate the baseline with the OT team before enabling alerting.

  5. Enable alerts. Categories: malware, network anomalies, protocol violations, operational (e.g. unauthorized PLC programming change). Tune to plant context — many "anomalies" are legitimate maintenance windows.

  6. Stream to Sentinel. Use the Defender for IoT data connector. Build OT-specific workbooks and playbooks (e.g., auto-ticket on unauthorized PLC reprogram).

  7. Vulnerability program. Sensor identifies device firmware → matched to known CVEs. Do not push patches via the same channel as IT — coordinate with OT change windows.

Enterprise IoT estate
  1. Already have MDE deployed? EIoT is a license toggle on top of MDE — enable in Defender XDR settings. Devices on the LAN segment seen by an MDE-enrolled endpoint get discovered.
  2. Review the device inventory in security.microsoft.com → Assets → Devices, filtered to Device type = IoT.
  3. Group and tag by function (printers, cameras, VoIP, building automation). Apply network access policies (NAC / NSG / firewall) per group.
  4. Vulnerability findings + threat alerts flow into Defender XDR alongside endpoint detections.
Show full SKILL.md (352 more words)Show less

Guardrails

  • OT sensors must be passive. Never enable active probing in production OT — risk of PLC reset / safety-system trip.
  • Coordinate with OT operations before any deployment change. Changes to switches, VLANs, or SPAN configuration require an OT change window.
  • Don't ship OT alerts straight to the IT SOC without context. OT analysts and IT analysts triage differently. Either build OT-aware playbooks or route to an OT SOC.
  • EIoT requires MDE on at least one endpoint per network segment to see the unmanaged devices. Coverage gaps = blind spots.
  • Don't push patches to OT devices on IT cadence. OT change windows are quarterly or annual. Use the vuln data to plan, not to auto-remediate.
  • Air-gapped sites cannot use cloud-connected mode. Stay on the on-prem management console; plan for the migration once connectivity is allowed.
  • Defender for IoT ≠ Azure IoT Hub security. Different product, different scope.

Common anti-patterns

  • "Active scan to inventory PLCs faster" — caused a safety-system trip in a real refinery. Always passive in OT.
  • "One sensor for the whole multi-site estate over the WAN" — SPAN traffic isn't WAN-friendly. One sensor per site.
  • "Routed OT alerts to the standard IT incident queue" — IT analysts close them as "expected legacy protocol" and miss real attacks.
  • "Skipped EIoT because we already have MDE" — discovery of unmanaged devices is the whole point; turn it on.
  • "Patched OT firmware in the IT monthly window" — production outage. Plan with OT.
  • "Used Defender for IoT to monitor IoT Hub device telemetry" — wrong product.

Example prompts

  • Plan Defender for IoT OT sensor placement for a 5-site manufacturing estate (1 plant network per site).
  • Enable EIoT discovery via MDE in a tenant with 80,000 endpoints.
  • Stream OT alerts into Sentinel with a workbook for unauthorized PLC programming.
  • Build a runbook for "Suspicious S7 protocol activity" alert — who triages, what changes, when do we escalate.
  • Compare cloud-connected sensors vs on-prem management console for an air-gapped utility.
  • Tag and group EIoT devices by function and apply NAC quarantine policy.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/defender-for-iot of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Defender For Iot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender For Iot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender For Iot this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Azure Content SafetyMicrosoftDocs/Agent-Skills776—~1.8kAutomated safety check: PassCC-BY-4.0
Azure Information ProtectionMicrosoftDocs/Agent-Skills776—~1.3kAutomated safety check: PassCC-BY-4.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Deploying Cloud Deception With Decoy Resourcesmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Implementing Cloud Vulnerability Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Azure Content Safety

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security…

    776 GitHub stars~1.8k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Azure Information Protection

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Information Protection development including best practices, decision making, configuration, and deployment.

    776 GitHub stars~1.3k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Deploying Cloud Deception With Decoy Resources

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Cloud Vulnerability Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implement multi-cloud CSPM to detect cloud-native misconfigurations and vulnerabilities (IAM over-permissions, exposed storage, unencrypted data, missing network controls) using AWS Security Hub…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Compromised Cloud Credentials

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft…

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Defender For Iot

What does Defender For Iot do?

Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. Defender For Iot is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR.

When should I use Defender For Iot?

Defender For Iot fits situations like: ioT Hub data-plane security (Azure platform); azure Sphere device hardening; generic endpoint EDR (use defender-for-endpoint).

How do I install Defender For Iot in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-iot -a claude-code`. Or copy the skill folder (skills/defender-for-iot in vinayaklatthe/microsoft-security-skills) into .claude/skills/defender-for-iot in your project. Claude Code loads it when a task matches its description.

How do I install Defender For Iot in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-iot -a codex`. Or copy the skill folder (skills/defender-for-iot in vinayaklatthe/microsoft-security-skills) into .agents/skills/defender-for-iot in your project. Codex loads it when a task matches its description.

Can I use Defender For Iot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-iot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender-for-iot, .gemini/skills/defender-for-iot, .github/skills/defender-for-iot and .opencode/skills/defender-for-iot in your project.

What does Defender For Iot need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender For Iot is instructions for the agent only.

Does Defender For Iot access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Defender For Iot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defender For Iot use?

Defender For Iot is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender For Iot use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defender For Iot?

Skills that share tags, products or a category with Defender For Iot: Azure Content Safety (MicrosoftDocs/Agent-Skills, 776 stars), Azure Information Protection (MicrosoftDocs/Agent-Skills, 776 stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Deploying Cloud Deception With Decoy Resources (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender For Iot?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.