——

All articles

90 practical guides, newest first, organised for the people who operate and defend real systems.

GuideHARDENING

· 20 min read · Intermediate

Windows Hardening for Small Business: A Practical Guide That Actually Works

A practical Windows hardening guide for small businesses. Secure local administrators, Defender, BitLocker, RDP, firewall, LAPS, ASR rules, Office macros, updates and backups without building an enterprise security department.

WindowsWindows 11hardeningcybersecuritysmall businessMicrosoft DefenderLAPSBitLockerASRsysadminransomware
Read article
CriticalVULNERABILITIES

· 17 min read · Intermediate

CVE-2026-69730: The Critical Windows DNS Vulnerability Every Admin Should Patch Now

CVE-2026-69730 is a critical Windows DNS Server remote code execution vulnerability rated CVSS 9.8. Learn what is affected, why domain controllers are at risk, how to check your servers, and why September's Windows updates also caused RDS problems.

CVE-2026-69730Windows ServerDNSActive DirectoryRCEMicrosoftcybersecuritysysadminPatch Tuesday
Read article
GuideTOOLS

· 31 min read · Intermediate

cURL — The Tool Every Administrator Needs

A practical cURL guide for system administrators. Test APIs, DNS, HTTPS, certificates, authentication, proxies, redirects, webhooks, downloads, performance and network connectivity directly from the command line.

curlsysadminLinuxWindowsmacOSnetworkingHTTPHTTPSREST APItroubleshootingDevOpscybersecurity
Read article
GuideTOOLS

· 22 min read · Intermediate

n8n: The Automation Platform Every IT Administrator Should Know

Learn what n8n is, how IT administrators and businesses can use it, practical automation examples, self-hosting basics, security risks, AI integration and real-world workflow ideas.

n8nautomationsysadminDevOpsIT automationworkflow automationself-hostedAPIcybersecurityAI automation
Read article
GuidePLAYBOOKS

· 15 min read · Intermediate

Forgotten Windows password? Why an administrator should not reset it without thinking

An administrative Windows password reset can restore sign-in while breaking access to DPAPI-protected secrets, EFS files and private keys. Learn how to identify the account type, preserve a working session, back up recovery material and prove the data still opens.

WindowsDPAPIEFSPassword RecoveryWindows 11Active DirectoryMicrosoft Entra IDWindows HelloSysadmin
Read article
HighHARDENING

· 22 min read · Intermediate

LINUX IS NOT SECURE! A practical server-hardening manual

A problem-and-solution hardening runbook for Ubuntu Server, Debian and Rocky Linux: patching, SSH keys, firewalls, Fail2ban, AppArmor or SELinux, audit logs, file-integrity checks and proof that the result actually works.

LinuxServer hardeningUbuntu ServerDebianRocky LinuxSSHFail2banFirewall
Read article
HighVULNERABILITIES

· 16 min read · Intermediate

Is Microsoft Defender suddenly full of holes? We counted before panicking

A source-checked look at the unusually dense 2026 run of Microsoft Defender vulnerabilities, what the thirteen CVEs actually affect, and how to verify Windows, macOS and Linux endpoints rather than merely hoping automatic updates worked.

Microsoft DefenderCVEPatch managementMicrosoft Defender for EndpointAdvanced HuntingVulnerability management
Read article
HighVULNERABILITIES

· 16 min read · Intermediate

LegacyHive: Windows 2000 called. It wants its registry file back

CVE-2026-62832 lets a low-privileged local attacker abuse Windows User Profile Service and the venerable UsrClass.dat registry hive to reach another user's settings and turn them into privileged code execution.

Microsoft WindowsCVE-2026-62832LegacyHivePrivilege escalationWindows RegistryIncident response
Read article
HighINCIDENTS

· 12 min read · Advanced

Your Microsoft 365 account was breached. What now?

A first-hour response that revokes access, preserves cloud evidence, checks the persistence paths attackers commonly leave behind, and explains the recovery route when you cannot sign in.

Microsoft Graph PowerShellExchange Online PowerShell
Read article
HighINCIDENTS

· 19 min read · Intermediate

You ran the mystery script. Assume it won.

What to do after running software of unknown origin: contain the computer, replace exposed sessions and secrets from a clean device, then decide whether to investigate or rebuild.

Built-in shell toolsPowerShell and Windows Event Logss or PowerShell
Read article
HighVULNERABILITIES

· 15 min read · Intermediate

15 newly exploited CVEs: how to find, fix and verify them

The 15 newest CISA Known Exploited Vulnerabilities entries, with safe version checks, exposure evidence, practical remediation, incident triage and closure tests.

Vendor administration interfacesPowerShellBuilt-in shell tools
Read article
GuidePLAYBOOKS

· 11 min read · Advanced

Playbook: Microsoft 365 account compromise

A role-based cloud identity response checklist from declaration through session revocation, evidence, persistence review, lockout recovery, and monitoring.

Microsoft Graph PowerShellExchange Online PowerShell
Read article
HighINCIDENTS

· 9 min read · Advanced

Ransomware: the first 24 hours

How to slow the damage, preserve options, and make recovery decisions without turning an outage into an evidence-destruction exercise.

findPowerShell SMB cmdletsrestic
Read article
HighINCIDENTS

· 10 min read · Beginner

Someone clicked the phishing link

A proportionate response based on what the user entered, downloaded, approved, or executed—not panic based on the click alone.

grepPython standard library
Read article
LabLABS

· 8 min read · Advanced

Build a small Wazuh SIEM lab

Deploy a single-node learning environment, add one endpoint, verify log flow, and document the first useful alert.

Wazuh agent_controllogger and Wazuh dashboardwazuh-logtest
Read article
GuidePLAYBOOKS

· 9 min read · Intermediate

Playbook: reported phishing message

Triage the message, interaction, identity, endpoint, and recipient scope without detonating the lure or deleting the only evidence.

grepPython standard library
Read article
HighINCIDENTS

· 9 min read · Advanced

A malicious OAuth app gained access

Investigate consent abuse as an identity incident: permissions, users, tokens, app activity, and the path that convinced someone to approve it.

Microsoft Graph PowerShell
Read article
GuideHARDENING

· 8 min read · Intermediate

MikroTik router security checklist

Protect the management plane, remove unnecessary services, constrain the firewall, and make configuration recovery routine.

RouterOS terminal
Read article
HighVULNERABILITIES

· 9 min read · Intermediate

Injection: data that becomes a command

Injection occurs when untrusted data changes the meaning of a query, command, template, interpreter, or downstream protocol.

node-postgresNode.js child_processcurl
Read article
GuidePLAYBOOKS

· 8 min read · Beginner

Playbook: lost or stolen managed device

Use device state, encryption, data classification, identity, remote management, and legal requirements to choose proportionate action.

BitLocker PowerShellMicrosoft Graph PowerShellPowerShell and Windows Event Log
Read article
HighINCIDENTS

· 9 min read · Advanced

A Linux server may be compromised

A careful triage path for suspicious processes, new persistence, unexpected network traffic, and altered accounts on a Linux host.

ps, ss and login toolsjournalctl and finddpkg or rpm
Read article
HighINCIDENTS

· 9 min read · Intermediate

A managed laptop was lost or stolen

Decide quickly using encryption, device state, cached credentials, data sensitivity, remote actions, and identity evidence.

BitLocker PowerShellMicrosoft Graph PowerShellPowerShell and Windows Event Log
Read article
HighINCIDENTS

· 9 min read · Intermediate

A cloud API key was exposed

Rotate the secret, but first understand where it appeared, what it could do, how it was used, and what automation depends on it.

GitShellProvider API client
Read article
HighVULNERABILITIES

· 9 min read · Intermediate

Software and data integrity failures

Integrity failures arise when applications trust updates, serialised data, cached objects, plugins, or workflow messages without verifying origin and authorised change.

TrivyYARAGit
Read article
HighINCIDENTS

· 9 min read · Advanced

Business email compromise changed the invoice

Coordinate identity response, payment interruption, bank contact, evidence preservation, and business communications when an invoice is manipulated.

Microsoft Graph PowerShellExchange Online PowerShellgrep
Read article