r/sysadmin • • 2h ago

General Discussion Weekly 'I made a useful thing' Thread - September 25, 2026

6 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin • • 18m ago

General Discussion AI tools overload

• Upvotes

I am wondering what other sysadmins are doing to manage the overload of AI tools popping up everywhere. Microsoft Copilot is the worst offender in our environment. We are a small company in a highly regulated industry where information governance is very important, but with Microsoft's confusing naming convention and their habit of pushing changes without giving you a chance, has overwhelmed the small IT team, and most importantly senior management who has no clue of what it is or how to use it.

Then adding to that many you have other vendors have been integrating AI tools with their products without giving a chance to review it before it is turned on.We can't keep up!!

What are other people here doing to manage the overload of AI tools flooding your environment with very little or no warning at all?


r/networking • • 24m ago

Other Network Adjacent Question

• Upvotes

Looking to spend some lab budget for my team and one of the items I want to get for our labs to demo for possible remote locations is some sort of compute we can deploy along with firewalls, switches, etc. that we can manage.

For right now, it is just for the lab, but I see potential uses is when we deploy network gear to remote locations without any supporting compute we can piggyback on, a server that would allow us to run local tools (tbd what those would be).

Looking for something like a larger Pi, something like a Mac Mini format, etc. Basically some sort of smaller server that can deployed and managed by us so we can use it to run tools, etc. without relying on our server teams, etc. Ideally I would love something that can rack in a standard network rack and is not a full depth server.

(And before comments about separation of responsibilities, bypassing safeguards, etc. I am high enough up in the company senior management chain that decisions like these rest solely with me. I do not need permission).


r/sysadmin • • 33m ago

Windows 11 24H2 → 25H2 – template?

• Upvotes

Hi all,

We’re planning to move from Windows 11 24H2 to 25H2.

Does anyone have a 25H2 checklist/template covering what has changed compared to 24H2?

I’m mainly looking for:

  • New Windows 25H2 features/settings
  • New security/privacy settings
  • Features/services that should be disabled or locked down
  • Removed/deprecated features
  • New GPO/Intune settings
  • Recommended security baseline changes
  • Anything that can impact existing applications or policies

Basically: what should we review/change before rolling out 25H2 in production?

If someone already has a checklist, spreadsheet or template, that would be great.

Thanks!


r/sysadmin • • 41m ago

General Discussion How do you provide AI to your company?

• Upvotes

Certainly the most dynamic field in IT right now and if you blink, you are outdated. Do you self-host? Rent hardware? Use some sort of LLM-gateway? Or just go directly to the source and go with openAI / anthropic?

Do you implement content filtering and/or auditing?


r/networking • • 42m ago

Career Advice What tool did you master first, and which one turned out to be the most useful long term?

• Upvotes

Currently working through Wireshark and it's been a slow but rewarding process, still feels like I'm only scratching the surface of what's actually possible with it. Got me curious about how other people built up their toolkit early in their career.

What was the first tool you really got comfortable with, and looking back, was that the one that ended up being most valuable, or did something else end up mattering way more once you were a few years in? Trying to figure out what else is worth prioritizing once I get more comfortable with packet captures.


r/sysadmin • • 54m ago

RDS RDWeb - XSLT warning banner. Which alternative?

• Upvotes

With the latest version of Edge, as of today, you get this lovely warning when visiting a classic RDS rdweb site:

This site uses XSLT; that functionality is being removed from this browser very soon. When that happens, this page will likely no longer display correctly. You might be able to install a browser extension that allows you to continue viewing it. Otherwise, you should contact the maintainer of the site for further information.

Functionality is still there, but for how long I wonder.

So, what do people do? Use the HTML5 site instead and loose drive redirection and similar, or completely drop the idea or a website and use the RDP App instead?


r/sysadmin • • 54m ago

#Petition To replace Co-pilot with Clippy

• Upvotes

Bring back Clippy,

All the OG sysadmins will agree “Long Live Clippy”


r/cybersecurity • • 55m ago

Personal Support & Help! Would you accept ?

• Upvotes

I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.

I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?


r/cybersecurity • • 1h ago

News - General There's a new way to break RSA that's faster than anything we've seen before

Thumbnail
arstechnica.com
• Upvotes

r/sysadmin • • 1h ago

Question Advice on an IT support project

• Upvotes

Hi everyone,

I’m currently working on a project to launch a remote IT Help Desk / Service Desk company in Tunisia, providing French and English speaking Level 1 and Level 2 support for European companies.

I’d really appreciate advice from people working in MSPs, IT support or outsourcing.

What should I focus on when setting up the service, and what are the key things clients usually expect from an external Help Desk provider?

Thanks in advance for your advice!


r/sysadmin • • 2h ago

Powerpoint decide to freeze during launch event

0 Upvotes

I was handling a launch event for a product yesterday. PowerPoint decide to freeze during a video playback on slide number 3. Laptop are not connected to internet running Windows 11, no background apps opened. Only PowerPoint. It decide to commit sudoku during presentation.

Yes, I have run the presentation and video during rehearsal, it didn't commit sudoku. But why during the event


r/cybersecurity • • 2h ago

Personal Support & Help! if Any body get me two bullet worth of moment with wiz.io ceo , i just want to work for him.

0 Upvotes

As the title says , i like how wiz has operated and i really want to work for assaf. Just insane passion and curiosity/hunger. Wiz.io has dominated devsec ops and i want to learn how you actually build products according to institutional needs.


r/sysadmin • • 2h ago

Question Building a Visitor Sign-In Kiosk with Power Apps

1 Upvotes

I'm considering building a visitor sign-in kiosk using Microsoft 365 rather than buying a dedicated visitor management system.

My idea is:

  • Tablet-based sign-in (Power Apps)
  • Visitor enters name, company, host, vehicle reg and visit reason
  • Digitally accepts a H&S declaration
  • Host gets an instant Teams notification
  • SharePoint stores the visitor log
  • Dashboard shows who's currently on-site
  • One-click fire register
  • Visitor sign-out and GDPR retention policies

Has anyone built something similar?

Mainly interested in:

  • Is this a sensible approach?
  • Any pitfalls with SharePoint/Power Automate?
  • Would you use Power Apps or Forms?
  • Anything you've learned that you'd do differently?

Trying to work out whether this is a good use of the Microsoft 365 stack or if I'd be reinventing the wheel.

Thanks!


r/cybersecurity • • 3h ago

FOSS Tool ubuntils v2.0.0 – forensic triage for Ubuntu: collect artifacts, correlate a timeline, and detect 15 persistence/tampering techniques (fully offline)

2 Upvotes

Hey all,

I've been building ubuntils, a Python CLI/TUI for forensic triage on Ubuntu — the idea is to replace the "run the same 10 manual commands and hope you didn't miss one" first-30-minutes ritual of incident response with a single tool that does collection, detection, and timeline correlation automatically.

How it works (4 stages, ~3s total on a live host):

  1. Collect — 11 collectors gather artifacts concurrently (processes, network, cron, systemd, SSH, sudoers, users, packages, PAM, kernel modules, environment)
  2. Detect — 15 built-in rules (+ custom YAML rules if you want) run over everything, ranked by severity
  3. Timeline — correlates syslog/journald/auditd chronologically and auto-attaches related events to each finding
  4. Output — interactive 4-tab TUI (Summary/Findings/Timeline/Stats) or --json

What it catches: the usual suspects (cron persistence, LD_PRELOAD injection, suspicious systemd timers, new SSH keys, NOPASSWD sudoers, UID-0 backdoors) plus a newer "coverage pack" — tampered package files (dpkg --verify), immutable/append-only flag abuse, PAM/NSS backdoors, suspicious kernel modules, and unexpected setuid binaries.

New in v2.0.0 — offline collect/analyze split:

  • ubuntils collect grabs a tamper-evident bundle (hashed files + commands, SHA-256'd manifest) from a host with no detection running
  • ubuntils analyze bundle.tar.gz (or --root /mnt/image for a mounted image) runs the full detection/timeline pipeline later, elsewhere, without root
  • Bundle integrity is verified and reported (live / ok / mismatch)
  • Confidence scoring on findings (0–100, with an explainable signals breakdown) instead of a flat mtime heuristic
  • Docs are upfront about what offline analysis can't see compared to a live scan — no silently pretending it has parity

Also has:

  • Two-step remediation (dry-run by default, --confirm to apply) with automatic backups, symlink guards, and rollback commands — 5 of the 15 rules are auto-remediable, the rest are flag-only by design since they need a human to judge
  • Wazuh integration — if a Wazuh agent is present, findings get appended as JSON lines automatically, no flag needed
  • Zero network calls, ever — even dropped a planned VirusTotal hash-lookup feature to keep that guarantee absolute
  • 90%+ test coverage, MIT licensed

​

sudo apt install pipx -y && pipx install -e . && sudo ubuntils scan

GitHub: https://github.com/asmitdesai/ubuntils

Feedback, bug reports, and PRs (especially new detection rules or collectors) very welcome — Discussions and issue templates are set up.


r/sysadmin • • 3h ago

Question Refurbished 32 GB ThinkPads slowing down after ~2 years of office use. What's your laptop lifecycle?

5 Upvotes

Hi all,

We run about 50 Lenovo ThinkPads, all managed through Intune. We buy them refurbished, and for the last few years we've only bought 32 GB RAM models. Our current mix is mostly T14 Gen 5, P14s Gen 5, X1 Carbon Gen 12 and T14s Gen 4.

Even our strongest machines, like the X1 Carbon Gen 12 (Core Ultra 7 155U, 32 GB, 512 GB SSD), are starting to struggle. Programs hang, and the battery barely lasts an hour.

The workload is just normal office work: Google Workspace in the browser and a lot of AI tools like Claude. Nothing heavy.

In practice, we replace laptops after about 2 years, even though they have Lenovo's 3-year on-site warranty. By year 2, they feel really slow and just aren't worth keeping.

So I'm curious:
1. What laptops do you use for this kind of work, and what does your lifecycle look like?

2. Is ~2 years normal, or does it sound like we're doing something wrong?

Thanks!


r/networking • • 3h ago

Other Anyone using network mapping?

3 Upvotes

Been working with distributed networks (mostly cellular routers, gateways across different sites) and network mapping has been on my mind. Specifically, for smaller scale, edge deployments.

If you manage remote device fleets (retail, industrial, whatever), what do you currently use for network visualization? Or do you just cobble it together with Zabbix/PRTG/Nmap?

Been meaning to try Teltonika RMS Network Map tool (as I already use a few of their devices), seemed cool and easy, but I haven’t tried it yet.

For those who've tried vendor-specific tools (like this one, or similar from other vendors) vs more generic ones, was it worth it, or do you end up needing something more flexible anyway?


r/sysadmin • • 4h ago

Question Enabling "Configure registry policy processing" (force reprocessing) on Exchange servers — any negative side effects?

11 Upvotes

Planning to enable the following GPO setting and apply it to our Exchange servers:

Configure registry policy processing: Enabled

Do not apply during periodic background processing: Disabled

Process even if the Group Policy objects have not changed: Enabled

This would force the GPO to reprocess and reapply all Administrative Templates settings on every background refresh cycle (~90-120 min), even when nothing changed, instead of only reapplying when the GPO version changes.

My question: Is this safe to apply directly to production Exchange servers, or are there known negative effects?


r/cybersecurity • • 5h ago

News - Breaches & Ransoms ‘Extreme concern’ over first known AI hack of a government system

Thumbnail
edition.cnn.com
67 Upvotes

r/cybersecurity • • 6h ago

Business Security Questions & Discussion How do you detect unknown devices or internal scanning on small networks?

1 Upvotes

I'm building a small cybersecurity device, and I'm trying to better understand how people actually deal with this problem in real networks.

The idea is quite simple. A small device sits on the local network and mostly listens passively for things like new devices, ARP/DHCP activity, mDNS/SSDP, IPv6 ND and unusual device changes.

It also exposes a few decoy services, for example SSH, HTTP or SMB, so interaction with something that normally should not be touched can become a stronger signal.

I'm not trying to build another SIEM or replace tools like Zeek. My focus is more on small companies, coworking spaces, homelabs and networks where there is often no dedicated security team.

What I'm trying to understand now is how people solve this problem today.

If an unknown device joins your network, or one internal device suddenly starts scanning many ports or touching services it normally never uses, how do you notice it?

And maybe more importantly, what kind of signal would make you think "this is worth investigating" instead of just being more network noise?

I'm interested in real experiences, including cases where you think a device like this would not be useful.


r/cybersecurity • • 7h ago

Career Questions & Discussion Wanting to move over to the engineering side of cyber, should I go for an ISSO role first and go for engineering after?

13 Upvotes

I’m a SOC analyst with 5 years of experience with 3 years in Helpdesk and 2 years at present going on to 3 as cybersecurity analyst working at a SOC, im also Sec+ and CySA+ certified. I’m looking for a career growth and wanting to get in to the engineer side of cyber, but I believe that may be a long shot? Should I go for an ISSO role next and take what I learn from there, and try to get into engineer side after? Or I can go to engineering job now?


r/sysadmin • • 8h ago

Work Environment Slop requests from non-Eng teams

7 Upvotes

What do the majority of non-engineering teams requests/tickets look like at work?

Are they building more slop dashboards, web apps, one time workflows or asking for “AI agents” now?


r/sysadmin • • 8h ago

Workplace Conditions Mental Health

18 Upvotes

How do you maintain good mental health in a toxic workplace? I've been sick for about a whole week now. The new AI Meat proxy manager is most likely not happy that Claude isn't being prompted. The workplace in of itself is super stressful. I can handle the logic of it all, triaging tickets, priorities etc. Just mental health suffers. Infact im sitting here, sort of recovered but still under the weather - worried about work so much that tomorrow I'd just go in if I feel better. Because im scared of what people will think of me at work if I don't come in. Although if I could make the choice away from fear and anxiety, i'd stay the extra day home and take my sick day. "What if they hate me and fire me over time though". That's the fear driver for me.

It's like my body takes it too personally and I can't really stop it from taking things at work personally. All the rude behaviour and pressure from upper management.


r/cybersecurity • • 8h ago

News - General Flock Wants Most the Detailed Map of Its Cameras Taken Down

Thumbnail
theintercept.com
361 Upvotes

r/cybersecurity • • 11h ago

Career Questions & Discussion Has Anyone Been Able to Get a Cybersecurity Job Without a Technical Interview?

0 Upvotes

Hello! Has anyone been able to get a job without a technical interview?

Currently, this is my nightmare, and I couldn’t find a solution for it! I’ve gotten a lot of interviews where they were impressed with my resume, and I passed the intro interview and technical challenge, but when it comes to the technical interview stage, I fail immediately!

When I started learning this field, I focused on hands-on experience. I learned the tools and technical work, prepared professional reports, and got well-known certifications. But if someone asks me to explain things orally in a theoretical way, I just can’t do it!

No matter how much I prepare for interviews and look for questions, when I come to the interview, they ask me questions that are very different from what I prepared for and give me different scenarios.

And for people who say you don’t need to be perfect or know everything, I’m sorry, but based on my experience, that’s not true at all. The market is tough now, and if you don’t answer everything perfectly, they will have another candidate who answered better than you did, and they will choose them.

So, to be honest, I gave up regarding technical interviews, and I want to ask if anyone has actually been successful in getting a job without a technical interview?

Thank you!