What problem does it solve? Setting up AWS Shield Advanced correctly is error-prone: subscriptions auto-renew on a one-year commitment, subscribing alone protects nothing, automatic layer 7 mitigation needs a 24-30 day baseline, and cost protection claims are silently voided by misconfigured WAF rules. This Skill routes each Shield Advanced task to a vetted procedure so nothing critical is missed. ## Core Features & Use Cases - Task Routing: Maps seven Shield Advanced tasks (tier decision, subscribing and protecting resources, automatic application layer mitigation, health-based detection, SRT access and proactive engagement, event review and cost protection, protection groups) to dedicated reference procedures. - Guardrails and Decision Tables: Each procedure carries decision tables (Block vs Count, SUM/MEAN/MAX aggregation), eligibility rules (protection predating the attack, rate-based rule in Block mode, 15-day filing deadline), and security constraints (SRT role trust scoping, SSE-KMS log encryption, least-privilege IAM). - Use Case: After a DDoS attack spikes your AWS bill, use this Skill to review the Shield event, confirm cost protection eligibility, and file a "DDoS Concession" billing case within the deadline. ## Quick Start Ask the assistant to subscribe your account to AWS Shield Advanced and protect your CloudFront distribution, then enable automatic application layer mitigation in Count mode.