Tutorial Tags & Topics
Welcome to the ConfigCorner Tag Hub. Click any topic or technology below to instantly filter guides across Linux, Windows, Networking, and Cybersecurity.
đˇī¸ Popular Topics & Technologies
Click any tag to filter guidesTerms of Use & Legal Disclaimer
Technical liability disclaimer, educational use policy, and execution risks for ConfigCorner tutorials.
Security & Threat Radar
Curated high-priority CVE advisories, zero-days, and enterprise threat intelligence.
Automation & Python Playbook Hub
Python system snapshots, read-only REST API polling, certificate and log alerts, network inventory reports, and Ansible patch orchestration.
Cybersecurity & Threat Defense Hub
SOC alert triage, endpoint investigations, incident response, application security testing, and identity audits.
Linux Engineering & Administration Hub
Production configurations, systemd architectures, container orchestration, and server hardening.
Networking & Infrastructure Hub
Network tutorials for switching, routing, VPNs, DNS, reverse proxies, container networks, and troubleshooting.
Roll Out Linux Patches with Ansible
Use a canary host, serial batches, package-cache refresh, reboot handling, and post-patch checks for a controlled Debian-family rollout.
Create and Verify File Integrity Manifests with Python
Build a dependency-free Python command-line tool that records SHA-256 file hashes and checks a directory for changed, missing, or unexpected files.
Windows & PowerShell Administration Hub
Enterprise administration, automation scripts, WSL2 tuning, and baseline hardening.
Collect Read-Only Network Device Inventory with Python and Netmiko
Use Netmiko and SSH to record device prompts and selected show-command output from authorized network equipment.
Real-Time Nginx Log Parser and Discord Alerting with Python
Follow a rotating Nginx access log, count HTTP 401/403 responses by client address in a rolling window, and send optional Discord alerts.
Build a Resilient REST API Poller with Python
Use Requests sessions, explicit timeouts, bounded retries, and cursor pagination for dependable read-only API automation.
Run System Commands Safely from Python
Automate trusted command-line tools with argument lists, timeouts, captured output, and clear error handling.
Build a DNS, DHCP, and IPAM Drift Report with Python
Compare read-only DNS, DHCP, and IPAM CSV exports to report cross-source mismatches and duplicate address assignments.
Automated SSL/TLS Certificate Expiry Monitor with Python
Inspect HTTPS certificate expiry, separately report TLS trust validation, and send Discord alerts with an asynchronous Python monitor.
Cross-Platform System Health Snapshots with Python
Collect CPU, memory, and disk metrics with psutil, print a JSON health snapshot, and optionally append scheduled snapshots to a JSON Lines file.
Audit Active Directory Privileged Group Membership
Use the Active Directory PowerShell module to export forest-wide direct membership of high-impact groups for a reviewable, read-only access audit.
Review AD CS Certificate Template Enrollment Exposure
Inventory enterprise CAs and published certificate templates, then review CA and template permissions, subject-name controls, and authentication-capable EKUs.
Grant Least-Privilege Linux Access with Sudoers
Create a dedicated operations group and a validated sudoers rule that lets operators inspect one service without granting broad root access.
Hunting Windows Persistence: Registry, Scheduled Tasks & WMI Subscriptions
Inventory common Windows persistence locations, correlate task, service, and WMI evidence, and preserve findings safely before approved response actions.
Linux Incident Response: Collect a First-Response Snapshot
Capture a focused Linux triage snapshot of system state, users, processes, network sockets, and recent journal entries while preserving collected files with SHA-256 hashes.
Live Incident Response: Volatile Memory Acquisition and Triage
Plan and capture a live Windows or Linux memory image, record its SHA-256 hash, and begin offline triage while documenting acquisition limits.
Collect a Windows Endpoint First-Response Snapshot
Capture a focused Windows host, process, network, Defender, and event-log snapshot into a restricted case folder and verify collected files with SHA-256.
SOC Alert Triage: Validate, Scope, and Document an Alert
Use a repeatable, tool-independent SOC workflow to validate an alert, scope related activity, assess confidence and impact, and hand off clear case notes.
Investigate an Endpoint Alert in Microsoft Defender
Work from a Defender incident to its device timeline, validate alert evidence and related activity, scope affected assets, and follow an approved containment or escalation plan.
Investigate Microsoft Entra ID Sign-In Alerts
Review identity, application, authentication method, device, IP, and Conditional Access context for a sign-in alert and document a cautious disposition.
Triage Linux SSH and Sudo Activity
Review bounded Linux journal records for SSH authentication and sudo activity, correlate users and source hosts, and document findings without changing the system.
KQL for First-Line Security Investigations in Microsoft Sentinel
Use time-bounded KQL to inspect Entra sign-ins, validate schema and ingestion, find related activity, and summarize events without treating a query result as a verdict.
SOC Phishing Email Triage
Preserve a suspected phishing message, inspect trusted header and authentication evidence, assess links and attachment metadata safely, search for related recipients, and document disposition.
Trace a Suspicious Process with Sysmon
Investigate Sysmon process-creation events by building a parent-child timeline, reviewing command lines and hashes, and correlating optional network and DNS telemetry.
Build a Small SOC Lab with Wazuh
Deploy a contained Wazuh all-in-one lab, enroll a Linux endpoint, generate benign file-integrity events, review alerts, and add a narrowly scoped local rule.
Investigate Windows Sign-In and Account Activity
Review Windows Security events for successful and failed logons, account lockouts, and privileged logons with bounded PowerShell queries and careful event correlation.
Triage DNS and Outbound Connections with Zeek Logs
Use Zeek dns.log and conn.log to review a suspicious domain or unexpected outbound connection, pivot by connection UID, and preserve the limits of network metadata.
Run an Authorized Nmap Asset Discovery
Build a small, documented Nmap inventory workflow for approved networks using conservative discovery, limited service checks, and reviewable output files.
Use CrowdSec for Linux Host Firewall Remediation
Install CrowdSec on Debian or Ubuntu, collect and parse SSH authentication logs, apply IP-level decisions with a firewall bouncer, and verify the services safely.
Deploy Sysmon for Windows Endpoint Telemetry
Install Microsoft Sysinternals Sysmon, confirm its event channel is producing data, and establish a safe starting point for centralized endpoint monitoring.
Run an OWASP ZAP Passive Baseline in an Isolated Lab
Launch a deliberately vulnerable training application and OWASP ZAP on a private Docker network, produce a passive baseline report, and remove the lab.
Write a Sigma Detection for Suspicious PowerShell
Create and validate a process-creation Sigma rule for encoded or hidden PowerShell launches, then tune it against approved administrative activity.
Use FIDO2 Security Keys for SSH Authentication
Configure OpenSSH security-key authentication with required touch and user verification, preserve a tested backup key, and harden a Linux SSH server without locking out administrators.
Create and Extract Linux Archives with tar
Create a compressed tar archive, list its contents, restore it to a fresh directory, and verify the recovered files.
Linux Filesystems and Mounts for Beginners
Understand Linux directory paths, disks, filesystems, mount points, and the safe commands used to inspect storage.
Linux Package Management (APT, DNF & Pacman)
Master software package installation, repositories, and maintenance across Debian/Ubuntu, RHEL, and Arch systems.
Use Linux Pipes and Redirection in the Shell
Combine Linux commands, filter their output, and save standard output and errors to files.
Linux Processes and Jobs: A Beginner's Guide
Learn how to list Linux processes, understand PIDs and signals, and manage safe background jobs from the shell.
Search and Inspect Files on Linux
Use less, grep, find, file, and stat to read files and search a practice log without changing system data.
Navigate the Linux Shell and Work with Files
Learn how to inspect directories, move through paths, and create, copy, rename, and read files safely.
Understand Linux Users, Groups, and File Permissions
Learn how Linux identifies users, assigns group access, and protects files with practical permission examples.
Getting Started with Docker Engine
Understand Docker architecture and run your first containerized services on Linux.
Docker Compose Operations: Secrets, Limits, Logs, and Updates
Run and maintain a local PostgreSQL Compose stack with health checks, file-backed secrets, resource limits, log rotation, and controlled image updates.
Configure and Verify Linux Time with chrony
Install chrony, use approved time sources, inspect synchronization health, and diagnose common clock issues.
Configure Persistent systemd Journal Storage and Retention
Keep Linux systemd journal logs across reboots and set disk and age limits with a drop-in configuration.
Monitor Linux CPU, Memory, Disk, and Process Activity
Use sysstat tools to sample Linux resource usage, locate busy processes, and build a useful performance baseline.
Review Historical Linux Performance with sar
Enable sysstat collection and use sar to inspect historical CPU, memory, and disk activity after a performance issue.
Build a Bash Command-Line Tool with Options and Validation
Create a reusable Bash utility with command-line options, input checks, clear errors, and meaningful exit statuses.
Process Files Safely in a Bash Loop
Use quoted paths and null-delimited find results to handle batches of Linux files, including names with spaces.
Systemd Timers vs Cron: Modern Linux Task Automation
Ditch traditional cron. Learn how to build resilient, logged, and dependency-aware background tasks using systemd services and timers.
Linux Auditd & File Integrity Monitoring with AIDE
Detect unauthorized modifications to binaries, system configurations, and sensitive directories with AIDE and the Linux Audit framework.
Build a Safe nftables Host Firewall Baseline
Inspect the active ruleset, stage a minimal host-filter policy, syntax-check it, and apply changes with an access-preserving plan.
SSH Hardening & Key-Based Authentication
Secure remote SSH access with ed25519 cryptographic keys and disable password logins.
UFW Firewall Setup & Hardening
Configure and harden the Uncomplicated Firewall on Ubuntu and Debian systems.
Expand an LVM Volume and Filesystem Online
Add a verified empty block device to an LVM volume group, extend a logical volume, and grow an ext4 or XFS filesystem.
Set Up a Restricted Linux NFS Share
Create a read-only NFS export, restrict it to a client subnet, mount it for testing, and verify ownership and service state.
Managing Storage Pools and Snapshots with ZFS and Btrfs
Create mirrored storage, manage datasets and subvolumes, take snapshots, and check filesystem integrity on Linux.
Diagnose a Failed Linux systemd Service
Trace a failed systemd service from its unit definition and journal logs through safe validation and recovery.
Troubleshoot Linux Disk Space and Inode Exhaustion
Trace a full Linux filesystem safely by checking blocks, inodes, large directories, and deleted files still held open.
Diagnose Linux Memory Pressure and OOM Kills
Use kernel logs, memory pressure metrics, process snapshots, and cgroup data to investigate Linux memory exhaustion safely.
Linux Network Interface & Connection Failure Triage
Systematic Layer 2 through Layer 7 Linux network troubleshooting methodology using iproute2, ss, resolvectl, and tcpdump.
Change a systemd Service with a Drop-In Override
Inspect a unit, add a small local override, reload systemd, verify the merged configuration, and remove only the intended drop-in.
Troubleshoot Linux DNS Resolution
Separate resolver configuration, DNS transport, authoritative answers, and local cache issues with common Linux tools.
Pi-hole with an Encrypted DNS-over-HTTPS Upstream
Deploy Pi-hole with Docker Compose and forward queries through AdGuard DNS Proxy to an encrypted DNS-over-HTTPS resolver.
Triage DNS and TCP Problems with Wireshark
Capture an authorized test flow and use display filters to inspect DNS answers, TCP handshakes, retransmissions, and connection timing.
Self-Host Jellyfin with Caddy on Windows or Linux
Install Jellyfin, configure a domain or No-IP dynamic DNS, and publish it securely through Caddy with automatic HTTPS on Windows or Linux.
Caddy Reverse Proxy with Automated TLS and Safe Headers
Install Caddy, reverse proxy a local application with automatic HTTPS, and add conservative security headers.
Configure Inter-VLAN Routing on Cisco IOS XE
Create routed SVIs for two VLANs on a Layer 3 switch and verify client gateways, connected routes, and forwarding.
Troubleshoot DHCP Relay Across VLANs
Trace a DHCP request from its VLAN SVI through an IOS XE relay to the server scope and back to the client.
Isolate Docker Services with Bridge and Macvlan Networks
Segment Compose services with user-defined bridge networks, an internal backend, Docker secrets, and an optional Macvlan LAN address.
Configure Access and Trunk VLAN Ports on Cisco IOS XE
Create a VLAN, assign an endpoint access port, configure an explicit trunk allow-list, and verify the switch state.
Diagnose Path MTU Problems on an IP Network
Use tracepath and controlled ping probes to identify suspected MTU black holes affecting VPN, TLS, or large transfers.
Tailscale Subnet Router with Explicit Access Grants
Advertise a private LAN through a Linux subnet router, approve the route, and scope access with Tailscale grants.
WireGuard VPN Quickstart
Build a point-to-point WireGuard tunnel between a Linux server and one remote client, with keys, firewall rules, and verification.
Test Windows Server Backup Recovery
Inspect Windows Server Backup versions and run a safe file-level recovery drill to an alternate path before relying on a backup.
Windows Event Viewer Basics for Administrators
Navigate Windows Event Viewer, filter System and Application events, query recent records with PowerShell, and export logs safely.
Windows File and Folder Permissions: NTFS Basics
Understand Windows NTFS permissions, inheritance, and effective access with Explorer, Get-Acl, and icacls using a safe practice folder.
PowerShell Basics for Windows Administrators
Get started with PowerShell commands, help, paths, objects, and safe file-system practice for everyday Windows administration.
Windows Server Administration Essentials (MMC, Admin Center & Roles)
Master core Windows administrative toolkits, role provisioning, MMC snap-ins, and modern Windows Admin Center operations.
Windows Services and Processes: A Beginner's Guide
Use Task Manager, Services, and PowerShell to inspect Windows processes and services, understand startup settings, and restart services cautiously.
Windows Server Performance Monitor (PerfMon) & Telemetry Baselines
Capture rolling CPU, memory, and disk counters with Performance Monitor, configure an alert, and export a closed BLG log.
Centralize Windows Events with Source-Initiated Forwarding
Set up a Windows Event Collector subscription and configure domain clients to forward selected events centrally.
Windows Server DHCP Scopes and Failover Operations
Inventory IPv4 scopes, review exclusions and options, plan a safe scope change, and verify DHCP failover replication.
Windows Server DNS: Zones, Records, and Safe Scavenging
Inspect DNS zones, create and verify a host record, understand aging intervals, and plan stale-record scavenging safely.
Audit Active Directory User Accounts with PowerShell
Build a read-only review of enabled Active Directory accounts, recent logon metadata, and password age.
Review Microsoft Entra User Sign-In Activity with PowerShell
Export Microsoft Entra user account and sign-in activity for an access review using Microsoft Graph PowerShell.
Configure WinRM over HTTPS with a Trusted Certificate
Configure a WinRM HTTPS listener with a trusted server certificate, restrict access to management clients, and verify remoting before retiring HTTP.
SysAdmin PowerShell Diagnostic Toolkit
A step-by-step PowerShell workflow for DISM/SFC system file repair, critical event log inspection, and storage health telemetry.
Install and Scope OpenSSH Server on Windows
Enable the Windows OpenSSH Server, verify its service and firewall rule, and restrict access to a trusted management network.
Windows Security Baseline & Protocol Hardening
Audit legacy name and file-sharing protocols, apply compatible hardening, and enable PowerShell script block logging.
BitLocker Drive Encryption and Recovery Key Backup
Review BitLocker status, verify TPM and recovery protectors, and confirm a recovery key is backed up through Windows or your organization's escrow process.
Create a Scoped Inbound Windows Firewall Rule
Use PowerShell to add, verify, and safely remove an inbound firewall rule limited to approved source addresses.
Windows Defender Firewall with Advanced Security: Scoped Inbound Rules
Use the wf.msc MMC snap-in to create, scope, verify, and test a Windows Defender Firewall inbound rule for a specific TCP service and management subnet.
Deploy Windows LAPS with Active Directory Backup
Configure Windows LAPS to rotate local administrator passwords and back them up securely to Active Directory.
Storage Spaces & ReFS Resilient Volume Provisioning
Configure a dedicated-disk Storage Spaces pool, a two-way mirror, and ReFS integrity streams with explicit checks before formatting.
Windows Server SMB Shares and Access Permissions
Create a restricted test SMB share, understand share and NTFS permissions together, and verify access from a client.
Back Up and Roll Out Group Policy Changes Safely
Back up GPOs, create a scoped pilot, verify resultant policy, and promote changes only after client validation.
Troubleshoot Group Policy Processing on Windows
Use gpresult, Resultant Set of Policy, and Group Policy operational events to find why a computer or user policy did not apply.
Windows Network Stack Reset as a Last Resort
Back up network settings, then reset Winsock and TCP/IP on Windows 10 or 11 when targeted troubleshooting has not resolved the issue.
Troubleshoot Windows DNS Client Resolution
Trace Windows name-resolution failures from adapter settings and DNS server reachability to record answers and cache state.
Diagnose Windows Time Synchronization with w32tm
Inspect Windows Time configuration, source, peer reachability, and synchronization status on workgroup and domain systems.
WSL2 Performance Tuning & Memory Optimization
Tame vmmem RAM consumption, optimize CPU cores, and accelerate I/O with .wslconfig.