Read-only audit of flood, DDoS and scan defence on MikroTik RouterOS: the RAW table, SYN flood and syncookies, rate-based DDoS detection, udp/53 and NTP/SSDP amplification, smurf, port-scan detection, staged brute-force blacklists and their expiry, connection-tracking exhaustion, fasttrack in the wrong state, liberal/loose TCP tracking, and ICMP handled by type (echo rate limit, PMTUD, traceroute, obsolete types, final drop). This skill should be used when assessing how a RouterOS device behaves under attack, without changing configuration.