Skip to content

Tutorial Tags & Topics

Welcome to the ConfigCorner Tag Hub. Click any topic or technology below to instantly filter guides across Linux, Windows, Networking, and Cybersecurity.


Active Filter: #all (108 tutorials)

đŸˇī¸ Popular Topics & Technologies

Click any tag to filter guides

Guide

Terms of Use & Legal Disclaimer

Technical liability disclaimer, educational use policy, and execution risks for ConfigCorner tutorials.

Guide

Security & Threat Radar

Curated high-priority CVE advisories, zero-days, and enterprise threat intelligence.

🐍 Automation

Automation & Python Playbook Hub

Python system snapshots, read-only REST API polling, certificate and log alerts, network inventory reports, and Ansible patch orchestration.

đŸ›Ąī¸ Cybersecurity

Cybersecurity & Threat Defense Hub

SOC alert triage, endpoint investigations, incident response, application security testing, and identity audits.

🌐 Networking

Networking & Infrastructure Hub

Network tutorials for switching, routing, VPNs, DNS, reverse proxies, container networks, and troubleshooting.

🐧 Linux

Linux Engineering & Administration Hub

Production configurations, systemd architectures, container orchestration, and server hardening.

đŸĒŸ Windows

Windows & PowerShell Administration Hub

Enterprise administration, automation scripts, WSL2 tuning, and baseline hardening.

🐍 Automation

Roll Out Linux Patches with Ansible

Use a canary host, serial batches, package-cache refresh, reboot handling, and post-patch checks for a controlled Debian-family rollout.

🐍 Automation

Build a DNS, DHCP, and IPAM Drift Report with Python

Compare read-only DNS, DHCP, and IPAM CSV exports to report cross-source mismatches and duplicate address assignments.

🐍 Automation

Create and Verify File Integrity Manifests with Python

Build a dependency-free Python command-line tool that records SHA-256 file hashes and checks a directory for changed, missing, or unexpected files.

🐍 Automation

Real-Time Nginx Log Parser and Discord Alerting with Python

Follow a rotating Nginx access log, count HTTP 401/403 responses by client address in a rolling window, and send optional Discord alerts.

🐍 Automation

Build a Resilient REST API Poller with Python

Use Requests sessions, explicit timeouts, bounded retries, and cursor pagination for dependable read-only API automation.

🐍 Automation

Run System Commands Safely from Python

Automate trusted command-line tools with argument lists, timeouts, captured output, and clear error handling.

🐍 Automation

Automated SSL/TLS Certificate Expiry Monitor with Python

Inspect HTTPS certificate expiry, separately report TLS trust validation, and send Discord alerts with an asynchronous Python monitor.

🐍 Automation

Cross-Platform System Health Snapshots with Python

Collect CPU, memory, and disk metrics with psutil, print a JSON health snapshot, and optionally append scheduled snapshots to a JSON Lines file.

🐍 Automation

Collect Read-Only Network Device Inventory with Python and Netmiko

Use Netmiko and SSH to record device prompts and selected show-command output from authorized network equipment.

đŸ›Ąī¸ Cybersecurity

Audit Active Directory Privileged Group Membership

Use the Active Directory PowerShell module to export forest-wide direct membership of high-impact groups for a reviewable, read-only access audit.

đŸ›Ąī¸ Cybersecurity

Review AD CS Certificate Template Enrollment Exposure

Inventory enterprise CAs and published certificate templates, then review CA and template permissions, subject-name controls, and authentication-capable EKUs.

đŸ›Ąī¸ Cybersecurity

Grant Least-Privilege Linux Access with Sudoers

Create a dedicated operations group and a validated sudoers rule that lets operators inspect one service without granting broad root access.

đŸ›Ąī¸ Cybersecurity

SOC Alert Triage: Validate, Scope, and Document an Alert

Use a repeatable, tool-independent SOC workflow to validate an alert, scope related activity, assess confidence and impact, and hand off clear case notes.

đŸ›Ąī¸ Cybersecurity

Investigate an Endpoint Alert in Microsoft Defender

Work from a Defender incident to its device timeline, validate alert evidence and related activity, scope affected assets, and follow an approved containment or escalation plan.

đŸ›Ąī¸ Cybersecurity

Investigate Microsoft Entra ID Sign-In Alerts

Review identity, application, authentication method, device, IP, and Conditional Access context for a sign-in alert and document a cautious disposition.

đŸ›Ąī¸ Cybersecurity

Triage Linux SSH and Sudo Activity

Review bounded Linux journal records for SSH authentication and sudo activity, correlate users and source hosts, and document findings without changing the system.

đŸ›Ąī¸ Cybersecurity

KQL for First-Line Security Investigations in Microsoft Sentinel

Use time-bounded KQL to inspect Entra sign-ins, validate schema and ingestion, find related activity, and summarize events without treating a query result as a verdict.

đŸ›Ąī¸ Cybersecurity

SOC Phishing Email Triage

Preserve a suspected phishing message, inspect trusted header and authentication evidence, assess links and attachment metadata safely, search for related recipients, and document disposition.

đŸ›Ąī¸ Cybersecurity

Trace a Suspicious Process with Sysmon

Investigate Sysmon process-creation events by building a parent-child timeline, reviewing command lines and hashes, and correlating optional network and DNS telemetry.

đŸ›Ąī¸ Cybersecurity

Build a Small SOC Lab with Wazuh

Deploy a contained Wazuh all-in-one lab, enroll a Linux endpoint, generate benign file-integrity events, review alerts, and add a narrowly scoped local rule.

đŸ›Ąī¸ Cybersecurity

Investigate Windows Sign-In and Account Activity

Review Windows Security events for successful and failed logons, account lockouts, and privileged logons with bounded PowerShell queries and careful event correlation.

đŸ›Ąī¸ Cybersecurity

Triage DNS and Outbound Connections with Zeek Logs

Use Zeek dns.log and conn.log to review a suspicious domain or unexpected outbound connection, pivot by connection UID, and preserve the limits of network metadata.

đŸ›Ąī¸ Cybersecurity

Hunting Windows Persistence: Registry, Scheduled Tasks & WMI Subscriptions

Inventory common Windows persistence locations, correlate task, service, and WMI evidence, and preserve findings safely before approved response actions.

đŸ›Ąī¸ Cybersecurity

Linux Incident Response: Collect a First-Response Snapshot

Capture a focused Linux triage snapshot of system state, users, processes, network sockets, and recent journal entries while preserving collected files with SHA-256 hashes.

đŸ›Ąī¸ Cybersecurity

Collect a Windows Endpoint First-Response Snapshot

Capture a focused Windows host, process, network, Defender, and event-log snapshot into a restricted case folder and verify collected files with SHA-256.

đŸ›Ąī¸ Cybersecurity

Live Incident Response: Volatile Memory Acquisition and Triage

Plan and capture a live Windows or Linux memory image, record its SHA-256 hash, and begin offline triage while documenting acquisition limits.

🐧 Linux

Getting Started with Docker Engine

Understand Docker architecture and run your first containerized services on Linux.

🐧 Linux

Docker Compose Operations: Secrets, Limits, Logs, and Updates

Run and maintain a local PostgreSQL Compose stack with health checks, file-backed secrets, resource limits, log rotation, and controlled image updates.

đŸ›Ąī¸ Cybersecurity

Run an Authorized Nmap Asset Discovery

Build a small, documented Nmap inventory workflow for approved networks using conservative discovery, limited service checks, and reviewable output files.

đŸ›Ąī¸ Cybersecurity

Use CrowdSec for Linux Host Firewall Remediation

Install CrowdSec on Debian or Ubuntu, collect and parse SSH authentication logs, apply IP-level decisions with a firewall bouncer, and verify the services safely.

đŸ›Ąī¸ Cybersecurity

Deploy Sysmon for Windows Endpoint Telemetry

Install Microsoft Sysinternals Sysmon, confirm its event channel is producing data, and establish a safe starting point for centralized endpoint monitoring.

đŸ›Ąī¸ Cybersecurity

Run an OWASP ZAP Passive Baseline in an Isolated Lab

Launch a deliberately vulnerable training application and OWASP ZAP on a private Docker network, produce a passive baseline report, and remove the lab.

đŸ›Ąī¸ Cybersecurity

Write a Sigma Detection for Suspicious PowerShell

Create and validate a process-creation Sigma rule for encoded or hidden PowerShell launches, then tune it against approved administrative activity.

🐧 Linux

Build a Bash Command-Line Tool with Options and Validation

Create a reusable Bash utility with command-line options, input checks, clear errors, and meaningful exit statuses.

🐧 Linux

Process Files Safely in a Bash Loop

Use quoted paths and null-delimited find results to handle batches of Linux files, including names with spaces.

🐧 Linux

Systemd Timers vs Cron: Modern Linux Task Automation

Ditch traditional cron. Learn how to build resilient, logged, and dependency-aware background tasks using systemd services and timers.

🐧 Linux

Linux Auditd & File Integrity Monitoring with AIDE

Detect unauthorized modifications to binaries, system configurations, and sensitive directories with AIDE and the Linux Audit framework.

đŸ›Ąī¸ Cybersecurity

Use FIDO2 Security Keys for SSH Authentication

Configure OpenSSH security-key authentication with required touch and user verification, preserve a tested backup key, and harden a Linux SSH server without locking out administrators.

🐧 Linux

Build a Safe nftables Host Firewall Baseline

Inspect the active ruleset, stage a minimal host-filter policy, syntax-check it, and apply changes with an access-preserving plan.

🐧 Linux

UFW Firewall Setup & Hardening

Configure and harden the Uncomplicated Firewall on Ubuntu and Debian systems.

🐧 Linux

Create and Extract Linux Archives with tar

Create a compressed tar archive, list its contents, restore it to a fresh directory, and verify the recovered files.

🐧 Linux

SSH Hardening & Key-Based Authentication

Secure remote SSH access with ed25519 cryptographic keys and disable password logins.

🐧 Linux

Linux Filesystems and Mounts for Beginners

Understand Linux directory paths, disks, filesystems, mount points, and the safe commands used to inspect storage.

🐧 Linux

Use Linux Pipes and Redirection in the Shell

Combine Linux commands, filter their output, and save standard output and errors to files.

🐧 Linux

Linux Package Management (APT, DNF & Pacman)

Master software package installation, repositories, and maintenance across Debian/Ubuntu, RHEL, and Arch systems.

🐧 Linux

Search and Inspect Files on Linux

Use less, grep, find, file, and stat to read files and search a practice log without changing system data.

🐧 Linux

Linux Processes and Jobs: A Beginner's Guide

Learn how to list Linux processes, understand PIDs and signals, and manage safe background jobs from the shell.

🐧 Linux

Navigate the Linux Shell and Work with Files

Learn how to inspect directories, move through paths, and create, copy, rename, and read files safely.

🐧 Linux

Understand Linux Users, Groups, and File Permissions

Learn how Linux identifies users, assigns group access, and protects files with practical permission examples.

🐧 Linux

Set Up a Restricted Linux NFS Share

Create a read-only NFS export, restrict it to a client subnet, mount it for testing, and verify ownership and service state.

🐧 Linux

Expand an LVM Volume and Filesystem Online

Add a verified empty block device to an LVM volume group, extend a logical volume, and grow an ext4 or XFS filesystem.

🐧 Linux

Configure and Verify Linux Time with chrony

Install chrony, use approved time sources, inspect synchronization health, and diagnose common clock issues.

🐧 Linux

Configure Persistent systemd Journal Storage and Retention

Keep Linux systemd journal logs across reboots and set disk and age limits with a drop-in configuration.

🐧 Linux

Review Historical Linux Performance with sar

Enable sysstat collection and use sar to inspect historical CPU, memory, and disk activity after a performance issue.

🐧 Linux

Monitor Linux CPU, Memory, Disk, and Process Activity

Use sysstat tools to sample Linux resource usage, locate busy processes, and build a useful performance baseline.

🐧 Linux

Diagnose a Failed Linux systemd Service

Trace a failed systemd service from its unit definition and journal logs through safe validation and recovery.

🐧 Linux

Troubleshoot Linux Disk Space and Inode Exhaustion

Trace a full Linux filesystem safely by checking blocks, inodes, large directories, and deleted files still held open.

🐧 Linux

Managing Storage Pools and Snapshots with ZFS and Btrfs

Create mirrored storage, manage datasets and subvolumes, take snapshots, and check filesystem integrity on Linux.

🐧 Linux

Diagnose Linux Memory Pressure and OOM Kills

Use kernel logs, memory pressure metrics, process snapshots, and cgroup data to investigate Linux memory exhaustion safely.

🐧 Linux

Change a systemd Service with a Drop-In Override

Inspect a unit, add a small local override, reload systemd, verify the merged configuration, and remove only the intended drop-in.

🐧 Linux

Linux Network Interface & Connection Failure Triage

Systematic Layer 2 through Layer 7 Linux network troubleshooting methodology using iproute2, ss, resolvectl, and tcpdump.

🐧 Linux

Troubleshoot Linux DNS Resolution

Separate resolver configuration, DNS transport, authoritative answers, and local cache issues with common Linux tools.

🌐 Networking

Isolate Docker Services with Bridge and Macvlan Networks

Segment Compose services with user-defined bridge networks, an internal backend, Docker secrets, and an optional Macvlan LAN address.

🌐 Networking

Caddy Reverse Proxy with Automated TLS and Safe Headers

Install Caddy, reverse proxy a local application with automatic HTTPS, and add conservative security headers.

🌐 Networking

Troubleshoot DHCP Relay Across VLANs

Trace a DHCP request from its VLAN SVI through an IOS XE relay to the server scope and back to the client.

🌐 Networking

Pi-hole with an Encrypted DNS-over-HTTPS Upstream

Deploy Pi-hole with Docker Compose and forward queries through AdGuard DNS Proxy to an encrypted DNS-over-HTTPS resolver.

🌐 Networking

Configure Inter-VLAN Routing on Cisco IOS XE

Create routed SVIs for two VLANs on a Layer 3 switch and verify client gateways, connected routes, and forwarding.

🌐 Networking

Self-Host Jellyfin with Caddy on Windows or Linux

Install Jellyfin, configure a domain or No-IP dynamic DNS, and publish it securely through Caddy with automatic HTTPS on Windows or Linux.

🌐 Networking

Configure Access and Trunk VLAN Ports on Cisco IOS XE

Create a VLAN, assign an endpoint access port, configure an explicit trunk allow-list, and verify the switch state.

🌐 Networking

Triage DNS and TCP Problems with Wireshark

Capture an authorized test flow and use display filters to inspect DNS answers, TCP handshakes, retransmissions, and connection timing.

🌐 Networking

Diagnose Path MTU Problems on an IP Network

Use tracepath and controlled ping probes to identify suspected MTU black holes affecting VPN, TLS, or large transfers.

🌐 Networking

Tailscale Subnet Router with Explicit Access Grants

Advertise a private LAN through a Linux subnet router, approve the route, and scope access with Tailscale grants.

🌐 Networking

WireGuard VPN Quickstart

Build a point-to-point WireGuard tunnel between a Linux server and one remote client, with keys, firewall rules, and verification.

đŸĒŸ Windows

Test Windows Server Backup Recovery

Inspect Windows Server Backup versions and run a safe file-level recovery drill to an alternate path before relying on a backup.

đŸĒŸ Windows

Windows Event Viewer Basics for Administrators

Navigate Windows Event Viewer, filter System and Application events, query recent records with PowerShell, and export logs safely.

đŸĒŸ Windows

Windows File and Folder Permissions: NTFS Basics

Understand Windows NTFS permissions, inheritance, and effective access with Explorer, Get-Acl, and icacls using a safe practice folder.

đŸĒŸ Windows

PowerShell Basics for Windows Administrators

Get started with PowerShell commands, help, paths, objects, and safe file-system practice for everyday Windows administration.

đŸĒŸ Windows

Windows Server Administration Essentials (MMC, Admin Center & Roles)

Master core Windows administrative toolkits, role provisioning, MMC snap-ins, and modern Windows Admin Center operations.

đŸĒŸ Windows

Windows Services and Processes: A Beginner's Guide

Use Task Manager, Services, and PowerShell to inspect Windows processes and services, understand startup settings, and restart services cautiously.

đŸĒŸ Windows

Windows Server Performance Monitor (PerfMon) & Telemetry Baselines

Capture rolling CPU, memory, and disk counters with Performance Monitor, configure an alert, and export a closed BLG log.

đŸĒŸ Windows

Centralize Windows Events with Source-Initiated Forwarding

Set up a Windows Event Collector subscription and configure domain clients to forward selected events centrally.

đŸĒŸ Windows

Audit Active Directory User Accounts with PowerShell

Build a read-only review of enabled Active Directory accounts, recent logon metadata, and password age.

đŸĒŸ Windows

Review Microsoft Entra User Sign-In Activity with PowerShell

Export Microsoft Entra user account and sign-in activity for an access review using Microsoft Graph PowerShell.

đŸĒŸ Windows

Configure WinRM over HTTPS with a Trusted Certificate

Configure a WinRM HTTPS listener with a trusted server certificate, restrict access to management clients, and verify remoting before retiring HTTP.

đŸĒŸ Windows

SysAdmin PowerShell Diagnostic Toolkit

A step-by-step PowerShell workflow for DISM/SFC system file repair, critical event log inspection, and storage health telemetry.

đŸĒŸ Windows

Install and Scope OpenSSH Server on Windows

Enable the Windows OpenSSH Server, verify its service and firewall rule, and restrict access to a trusted management network.

đŸĒŸ Windows

Windows Security Baseline & Protocol Hardening

Audit legacy name and file-sharing protocols, apply compatible hardening, and enable PowerShell script block logging.

đŸĒŸ Windows

Create a Scoped Inbound Windows Firewall Rule

Use PowerShell to add, verify, and safely remove an inbound firewall rule limited to approved source addresses.

đŸĒŸ Windows

BitLocker Drive Encryption and Recovery Key Backup

Review BitLocker status, verify TPM and recovery protectors, and confirm a recovery key is backed up through Windows or your organization's escrow process.

đŸĒŸ Windows

Windows Defender Firewall with Advanced Security: Scoped Inbound Rules

Use the wf.msc MMC snap-in to create, scope, verify, and test a Windows Defender Firewall inbound rule for a specific TCP service and management subnet.

đŸĒŸ Windows

Deploy Windows LAPS with Active Directory Backup

Configure Windows LAPS to rotate local administrator passwords and back them up securely to Active Directory.

đŸĒŸ Windows

Windows Server DHCP Scopes and Failover Operations

Inventory IPv4 scopes, review exclusions and options, plan a safe scope change, and verify DHCP failover replication.

đŸĒŸ Windows

Windows Server DNS: Zones, Records, and Safe Scavenging

Inspect DNS zones, create and verify a host record, understand aging intervals, and plan stale-record scavenging safely.

đŸĒŸ Windows

Windows Server SMB Shares and Access Permissions

Create a restricted test SMB share, understand share and NTFS permissions together, and verify access from a client.

đŸĒŸ Windows

Storage Spaces & ReFS Resilient Volume Provisioning

Configure a dedicated-disk Storage Spaces pool, a two-way mirror, and ReFS integrity streams with explicit checks before formatting.

đŸĒŸ Windows

Back Up and Roll Out Group Policy Changes Safely

Back up GPOs, create a scoped pilot, verify resultant policy, and promote changes only after client validation.

đŸĒŸ Windows

Troubleshoot Group Policy Processing on Windows

Use gpresult, Resultant Set of Policy, and Group Policy operational events to find why a computer or user policy did not apply.

đŸĒŸ Windows

Windows Network Stack Reset as a Last Resort

Back up network settings, then reset Winsock and TCP/IP on Windows 10 or 11 when targeted troubleshooting has not resolved the issue.

đŸĒŸ Windows

Troubleshoot Windows DNS Client Resolution

Trace Windows name-resolution failures from adapter settings and DNS server reachability to record answers and cache state.

đŸĒŸ Windows

WSL2 Performance Tuning & Memory Optimization

Tame vmmem RAM consumption, optimize CPU cores, and accelerate I/O with .wslconfig.

đŸĒŸ Windows

Diagnose Windows Time Synchronization with w32tm

Inspect Windows Time configuration, source, peer reachability, and synchronization status on workgroup and domain systems.

Comments