Process Explorer: Private Bytes vs Working Set Explained
The ticket said the Citrix session host was sluggish around 4 PM every weekday. Twenty minutes with Process Explorer running and a baseline export from the day before…
Creating Enforced Authentication Policies in Active Directory
It was 03:14 when the SOC at one of our financial services clients flagged a Tier 0 admin credential authenticating from a workstation in the call center VLAN. The acc…
Tracing Windows Boot and Service Init with Sysinternals
After the third “slow login” ticket in a week from one of our managed customers, I went back to Sysinternals boot logging because nothing else was going to give me wha…
AD Server Parameter: FQDN vs NetBIOS Name Explained
While scripting a bulk user migration for a client last quarter, I hit one of those issues that wastes an hour before you realize what happened. Half the Get-ADUser ca…
Using Autoruns to Audit Every Windows Autostart Location
During a quarterly security review for a client running a 200-seat Windows environment, we found a DLL registered under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersi…
AdExplorer: Browsing and Snapshotting Active Directory Offline
Three service accounts disabled in production. No change ticket. No record of who did it or when. The helpdesk was fielding calls for forty minutes before we traced th…
Windows Admin Center: Browser-Based Server Management Done Right
Last year, a logistics client with fourteen Windows Server instances across two sites called us in a panic — their lone sysadmin had left, and nobody else knew how to…
Windows Server Hardening: Stop Guessing, Start Baselining
We inherited an environment last year where the client had been running Windows Server 2019 domain controllers with NTLMv1 still enabled, SMBv1 wide open, and zero Gro…
Windows Group Policy Incident: A Real Post-Mortem
It was a Tuesday. 4:47 PM. My phone started ringing before I even got up from my desk. Help desk on line one, my manager on line two, and a Slack flood that would take…
Active Directory Security: Harden Your AD Environment
In March 2023, Cl0p operators compromised a regional financial services company and reached their domain controllers in 87 minutes. The initial vector was a spearphish…
Managing Active Directory Objects: A Complete Guide
Managing Active Directory objects is the core administrative task for any Windows domain environment. AD objects – including users, computers, groups, and contacts – f…
How to Raise the Active Directory Forest Functional Level
Raising the Active Directory forest functional level is one of those tasks that many administrators either delay indefinitely or rush through without adequate preparat…