Windows Server
Handle a nearly full Windows Server system disk without deleting WinSxS or logs at random by measuring usage, identifying supported cleanup targets, checking VSS, moving durable data, and restoring safe free-space headroom.
View →
Networking / VPN
Collect useful evidence during a site-to-site VPN incident, isolate whether the failure is connectivity, negotiation, routing, policy, or the peer, and restore service without destroying diagnostic evidence.
View →
Linux
Recover space on a saturated Linux filesystem without deleting files blindly by checking blocks and inodes, du results, deleted-but-open files, journald and application logs, Docker usage, quotas, and the long-term cause.
View →
Backup
Run a real backup restore test without touching production by defining a scenario, choosing a restore point, using an isolated target, setting success criteria, measuring RTO and RPO, and producing an actionable report.
View →
VMware
Stabilize a nearly full VMware datastore without deleting VM files at random by inventorying space usage, snapshots, ISO files and logs, creating safe headroom, migrating or extending capacity, and consolidating cleanly.
View →
Linux & Docker
Recover a Docker container stuck in a restart loop without hiding the root cause by inspecting configuration, logs, exit codes and OOM events, validating dependencies, controlling the restart policy, and relaunching deliberately.
View →
Microsoft 365
Contain a suspected compromised Microsoft 365 account by collecting sign-in evidence, blocking access, revoking sessions, resetting credentials, reviewing MFA, mailbox rules, forwarding, consented applications, and validating the account before reactivation.
View →
Windows Server
Rotate the password of a Windows service account without causing an outage by inventorying services, scheduled tasks, IIS pools, and applications, coordinating the change, validating dependent services, and checking for failed logons afterward.
View →
Active Directory
Diagnose degraded Active Directory replication by separating topology, DNS, network and RPC reachability, time and Kerberos, replication errors, and directory health before attempting intrusive repair.
View →
FortiGate
Modify a production FortiGate IPsec tunnel with a documented baseline, coordinated peer changes, a maintenance window, explicit success criteria, and a timed rollback plan.
View →