For the complete documentation index, see llms.txt. This page is also available as Markdown.

Yellow - NetEng/SysAdmin

Networking, protocol, operating system, Windows, Linux, macOS, Active Directory, sysadmin, and infrastructure references for security practitioners.

This page is for the fundamentals behind security work: networking, protocols, operating systems, automation, and systems administration. Keep hands-on offensive tradecraft in Red, detection and hardening in Blue, DFIR workflows in DFIR, and courses or labs in Training.

Networking

Core Learning

IP Addressing and Protocols

Distributed Systems and Infrastructure

Automation and Infrastructure as Code

  • Ansible - Configuration management and automation.

  • Terraform - Infrastructure as code.

Training

Training platforms and labs are maintained in the Training section.

Training and Resources

IP Range Reference

Operating Systems

Linux

Linux CLI and Bash references live in Code and CLI.

Bash

Windows

Active Directory attack methodology is maintained in Red Offensive.

Attacking Active Directory

Windows command-line and PowerShell references live in Code and CLI.

PowerShell

Windows Event ID references and defensive use cases are maintained in Blue/DFIR.

Windows Event Logs

macOS

macOS DFIR commands are maintained in DFIR.

MacOS DFIR Commands

Computer Science and OS Design

Adjacent Yellow Sections

Cloud

Yellow - Cloud

Containers

Yellow - Containers

Logging and Security Architecture

Yellow - Logging and Security Architecture

Infrastructure Monitoring

  • Netdata - Real-time infrastructure monitoring and troubleshooting for systems, hardware, containers, applications, cloud deployments, and edge/IoT devices.

Last updated