Active Directory & Domain Architecture
Enterprise Infrastructure
Forest Architecture, Cross-Forest Trusts & Read-Only Domain Controllers
Automated virtual machine deployments via WDS & PXE network boot. Installed Active Directory Forest Root, raised functional levels, established cross-forest trust relationships (`SERVER1 ↔ CORP1`), and deployed Read-Only Domain Controllers (RODCs) with password replication policies. Configured Sites & Subnets for optimized inter-site replication and enabled the Active Directory Recycle Bin for object recovery.
AD Forest Trusts
RODC Deployment
AD Sites & Subnets
WDS / PXE Boot
AD Recycle Bin
Storage Spaces & File Services
Storage Networking
Distributed File System (DFS), Storage Spaces & iSCSI Target
Configured enterprise storage pools using Storage Spaces with RAID parity arrays and attached remote block storage using iSCSI Target & Initiator services. Deployed Distributed File System (DFS) Namespaces and Replication, file auditing, disk quotas, file screening rules, and managed complex NTFS vs. SMB sharing permissions.
DFS Replication
Storage Spaces / RAID
iSCSI Target
File Screen Quotas
NTFS Permissions
Identity, High Availability & Services
High Availability & PKI
DHCP Failover, Domain GPOs, AD Certificate Services (PKI) & Containers
Deployed enterprise DNS zones with zone transfers and established DHCP failover for high availability. Enforced domain-wide Group Policy Objects (GPOs), provisioned internal Active Directory Certificate Services (AD CS / PKI), deployed WSUS patch updates, and hosted containerized web apps using Docker on Windows Server and Nano Server.
DHCP Failover
GPO Security
AD CS (PKI)
WSUS Updates
Windows Containers
PKI & Cryptographic Systems
Security & Cryptography
Public Key Infrastructure, Certificate Signing & Attack Surface Reconnaissance
Generated Certificate Signing Requests (CSRs), inspected Root CAs and system trust stores, and tested SSL/TLS cipher suites and handshakes. Executed attack surface reconnaissance, scanned open service ports with Nmap, evaluated default credential vulnerabilities, and compared symmetric (AES) vs. asymmetric (RSA) encryption.
CSR Generation
Root CA Trust Stores
SSL/TLS Ciphers
Port Recon (Nmap)
AES / RSA Crypto
Network Attacks & Threat Analysis
Threat Defense
Layer 2 Attacks, ARP Poisoning, Ransomware Telemetry & Hash Cracking
Analyzed Layer 2 attacks including ARP Poisoning and DNS Spoofing to intercept traffic in Man-in-the-Middle (MitM) scenarios. Evaluated ransomware payloads and malicious URLs using VirusTotal telemetry, tested software keylogger delivery mechanisms, performed password hash cracking, and analyzed wireless Wi-Fi reconnaissance.
ARP Poisoning / MitM
DNS Spoofing
Ransomware Telemetry
Password Cracking
Wireless Recon
vSphere ESXi Hypervisor Infrastructure
Enterprise Virtualization
Bare-Metal ESXi Hosts, vCenter Server & Storage Provisioning
Configured bare-metal ESXi 7 hosts and deployed the vCenter Server Appliance. Joined ESXi hosts and vCenter to Microsoft Active Directory domain, managed SSH / TSM shell services, provisioned VMDK datastores comparing Thin vs. Thick-provisioned disks, organized VM templates, and deployed Windows 10 virtual machines with VMware Tools integration.
vCenter Server
ESXi 7 Hosts
AD Domain Joining
VMDK Provisioning
VM Templates
Server Deployment & Kernel Architecture
Linux Administration
Dual-Distribution Provisioning, Live Boot & Dynamic Kernel Modules
Deployed and configured Fedora Workstation and Ubuntu Server environments. Managed Linux kernel modules using `lsmod`, `modprobe`, and persistent `/etc/modprobe.d/` configurations. Managed software packages across `apt` and `dnf`, navigated system hierarchy, and configured remote access.
Ubuntu Server
Fedora Workstation
Kernel Modules (modprobe)
CLI Navigation
Package Management
Filesystem Storage & Volume Management
Filesystems & LVM
Filesystem Hierarchy, LVM Dynamic Storage & Granular POSIX ACLs
Partitioned storage devices with `fdisk` and `parted`, initialized LVM Volume Groups with dynamically expandable Logical Volumes, enforced granular permissions using POSIX ACLs (`setfacl`/`getfacl`), implemented user disk quotas, maintained filesystem integrity with `fsck`, and configured persistent `/etc/fstab` mounts.
LVM Volumes
POSIX ACLs
fdisk / parted
vi / Regex
fsck & Quotas
Shell Automation & System Administration
Scripting & Admin
BASH Shell Scripting, I/O Redirection, User Lifecycles & Backups
Constructed automation BASH scripts utilizing standard I/O streams (`>`, `<`, `2>&1`) and pipelines (`|`). Administered enterprise user and group accounts with delegated `sudoers` privileges. Automated archive compression (`tar`, `gzip`, `xz`) and synchronized incremental network backups utilizing `rsync`.
BASH Scripting
I/O Redirection & Pipes
User/Group (sudoers)
tar / gzip / xz
rsync Backups
System Initialization & Process Management
systemd & Init
GRUB2 Bootloader, Custom systemd Units & Process Scheduling
Configured GRUB2 bootloader parameters and systemd runlevel targets. Authored custom systemd service units, managed running processes with signals (`SIGTERM`, `SIGKILL`), adjusted CPU scheduling priorities using `nice`/`renice`, and scheduled automated background jobs with `cron` and `at`.
systemd Unit Files
GRUB2 Bootloader
Process Signals
nice / renice
Cron & at Automation
Network Routing & Interfaces
Networking & Routing
Persistent Static IPs, Netplan YAML & Bottom-Up Diagnostics
Configured network interfaces and persistent static IP addressing across Fedora using NetworkManager (`nmcli`) and Ubuntu Server using Netplan YAML. Configured DNS nameservers and local `/etc/hosts` name resolution. Executed bottom-up network diagnostic procedures utilizing `ip addr`, `ip route`, `ping`, `ss`, `netstat`, and `dig`.
NetworkManager (nmcli)
Netplan YAML
Static Routing
DNS / hosts
Diagnostic Suite
Secure Remote Services & Distributed Shares
Network Services
Hardened OpenSSH Key Authentication, SFTP Jails & NFS Storage
Configured OpenSSH server daemon policies with public/private key-pair authentication. Deployed restricted SFTP chroot directory jails for secure file transfers, exported multi-client Network File System (NFS) shared storage mounts, and configured Apache web service hosting.
SSH Key Auth
NFS Exports
SFTP Security
Apache Web Server
Network Services
Perimeter Hardening & Performance Profiling
Security & Profiling
Host Firewalls, journalctl Log Auditing & Performance Profiling
Audited attack surfaces and open ports, configured stateful host firewall rules (UFW/iptables), aggregated and analyzed unified system logs with `journalctl` and `/var/log`, and diagnosed hardware resource bottlenecks using `top`, `vmstat`, and `iostat`.
Host Firewalls
journalctl Auditing
Security Hardening
Performance Tuning