What problem does it solve?
Setting up AWS Shield Advanced involves many distinct tasks—subscribing accounts, protecting resources, enabling automatic layer 7 mitigation, wiring Route 53 health checks, granting Shield Response Team access, and filing cost protection claims—each with non-obvious prerequisites and pitfalls that can silently void protection or credit eligibility.
Core Features & Use Cases
- Task Routing: Maps each Shield Advanced goal (subscribing, automatic mitigation, health-based detection, SRT setup, event review, protection groups) to a dedicated step-by-step procedure with decision tables and troubleshooting.
- Guardrails and Constraints: Enforces critical rules such as protecting resources after subscribing, keeping the ShieldMitigationRuleGroup in place, requiring Block-mode rate-based rules for cost protection, and scoping the SRT role trust policy against confused-deputy attacks.
- Use Case: After a DDoS attack spikes your CloudFront bill, use this Skill to review the Shield event detail, confirm cost protection eligibility, and file a "DDoS Concession" billing case within the 15-day deadline.
Quick Start
Ask the agent to subscribe your account to AWS Shield Advanced and protect your CloudFront distribution, then enable automatic application layer mitigation in Count mode.