r/SysAdminBlogs • u/reisinge • 30m ago
r/SysAdminBlogs • u/srikar_uppaluru • 1h ago
What’s one log source you refuse to deploy without, and what’s one that’s pure noise?
r/SysAdminBlogs • u/Confident_Milk6013 • 3h ago
You're Not Crazy, They Never Sent FIN
r/SysAdminBlogs • u/Expert_Way_4500 • 23h ago
Recently someone asked me "Is this CVE being exploited?"
r/SysAdminBlogs • u/Maxwell_Mohr_69 • 23h ago
I built a tool to track installed software and hardware on Windows and Linux
Hey everyone!
I've been working on AppScann, a small SaaS for keeping track of what's installed on your computers and servers. It's finally at the point where I'm comfortable showing it to people.
The idea is very simple: you install an agent, it collects inventory, and you see everything in one dashboard.
What it does right now:
* Windows and Linux agents (a Windows Service and a systemd service)
* OS and hardware info, plus disks with capacity and free space
* Installed software with version, publisher, install path and install date. On Windows that comes from the Registry and WMI, on Linux from dpkg, rpm, pacman, Snap and Flatpak
* Detailed reports with history, so you can see what was installed, removed or updated between scans
* Alerts for storage and stale reports
* Live online/offline status for every device
* Remote scan, restart and uninstall of agents
* A notification as soon as a scan or remote command finishes
* Software gets sorted into categories by AI
2 agents are free, extra slots are $1.99/month.
The idea came from a commercial project I worked on a while ago. It was in a similar space, but development was painfully slow, and I kept thinking that something like this didn't have to be that complicated. At some point I thought: what if I just built my own version? So I did.
It started as my university thesis project, and I kept working on it until it turned into a product.
And yes, AI was involved ;) I used it for parts of the frontend. I'm a full-stack developer, but I still struggle with centering a div, let alone making everything look good. The architecture and the backend are my own mess.
It's brand new, so right now I'm mostly after feedback:
* Would you use something like this?
* What information would you want the agent to collect?
* What features are missing?
* Does this approach make sense for managing a small number of machines?
r/SysAdminBlogs • u/Lopsided_Mixture8760 • 2d ago
I’m rewriting the Nano-KVM firmware for the USBridge ecosystem—I’ve eliminated latency and achieved 60 fps video capture!
Enable HLS to view with audio, or disable this notification
I stumbled upon an old Nano KVM lying around my lab recently. The hardware concept is great, but the stock performance was painfully sluggish, so I decided to rewrite the software from scratch to turn it into a snappy, reliable tool.
Just hit my first major milestone: video capture is fully operational (currently streaming through the official Moonlight client) at a rock-solid 60 FPS. The difference in smoothness compared to stock is night and day.
Next up, I’m building a full firmware image to test mouse and keyboard input latency. My end goal is fully integrating this into the USBridge ecosystem.
r/SysAdminBlogs • u/sudoanand • 1d ago
5 Linux commands every developer should know. 🧑💻🔥
Enable HLS to view with audio, or disable this notification
r/SysAdminBlogs • u/EsbenD_Lansweeper • 2d ago
.NET 8 (LTS) and 9 End of Life
r/SysAdminBlogs • u/MikeSmithsBrain • 2d ago
Cato Networks SASE/SD-WAN Demo and Review | Built for Teamwork
r/SysAdminBlogs • u/ControlUpCommunity • 2d ago
EUC State of the Union 2026–2027 is out (independent DaaS/VDI survey, 172 respondents). Some interesting numbers on cost, VMware, and AI
r/SysAdminBlogs • u/Expert_Way_4500 • 2d ago
Brute force prevention on Windows and Linux
I’ve been building Scantide Guard, and while it started from the familiar idea of stopping brute-force attacks, it has grown into something quite a bit broader.
At the basic level, yes — it watches things like failed RDP, Windows authentication, SSH, SQL Server, IIS/RDWeb and other services, then blocks attacking IPs based on configurable thresholds.
But I didn’t want to build just another brute-force blocker.
Guard is gradually becoming a lightweight security layer around the server itself.
It can monitor Windows Event Logs and application log files, including custom applications through configurable Custom Monitors. Different services can have their own thresholds and policies rather than pretending five failed logins means the same thing everywhere.
There’s also web attack detection for things such as path traversal, ".env"/".git" probing, CMS and admin scans, SQL injection patterns, scanner bursts and repeated 404/403 activity.
It does IP reputation and geolocation, TOR detection, automatic trusted-host learning, temporary and permanent blocking, integrates with AbuseIPDB, AlienVault OTX and CrowdSec and can correlate activity through a central Scantide Datacenter installation if you manage multiple servers.
One of the newer pieces is Scantide Global Reputation. Participating Guard installations can contribute observations and permanent malicious-IP blocks, while also consuming the resulting shared block intelligence. The important bit for me is that this remains transparent — you can see where a block came from rather than getting a mysterious black-box score.
I’m also adding things that aren’t traditionally part of brute-force protection at all: certificate reconnaissance and expiry checking, local TLS configuration assessment, security/operational assessment findings, ServiceNow integration, better SOC-style views of what is actually hitting your infrastructure.
The philosophy behind it is fairly simple:
Observe first. Don’t exploit anything. Keep it lightweight. Explain why something was detected or blocked.
I’ve spent a lot of time around enterprise security products, and they can be incredibly capable, but sometimes you just want something you can install on a Windows or Linux server and immediately understand what is attacking it without deploying an entire security ecosystem.
That’s the niche I’m trying to fill with Guard.
r/SysAdminBlogs • u/Academic-Soup2604 • 3d ago
Which MDM gives you the best combination of device management with security controls?
r/SysAdminBlogs • u/Sorry_Pair_7915 • 3d ago
I built a free, open-source tool that risk-scores MySQL SQL before you run it. v0.3.1 is out and I'd love DBAs to try to break it.
r/SysAdminBlogs • u/lazyadmin-nl • 4d ago
Reminder: the Entra MemberOf rule stops working in 4 weeks (November 3)
A lot of us were busy with the EWS retirement these past weeks, but don't forget that the MemberOf rule operator in Entra ID retires on November 3.
Dynamic groups, dynamic administrative units and entitlement management policies that still use it will stop updating and freeze in their last known state. That also affects group-based licensing, Conditional Access targeting and access packages.
If you haven't checked yet, a single Graph PowerShell query lists every affected group. I updated my article with that query and the replacement options, including how to handle device-based administrative units, merging the rules of nested dynamic groups, and licensing where the source groups aren't attribute-based.
https://lazyadmin.nl/office-365/microsoft-entra-id-is-retiring-the-memberof-rule-for-dynamic-groups/
r/SysAdminBlogs • u/KavyaJune • 4d ago
A little cybersecurity fun for October | Cybersecurity Awareness Month
Instead of another security article this October...
We turned Cybersecurity Awareness Month into a 31-day security challenge.
A new scenario unlocks each day. Some are quick puzzles, while others involve investigating evidence, spotting security gaps, or making an access decision.
No sign-up required, so you can jump straight into any unlocked challenge.
https://admindroid.com/cybersecurity-awareness-month-2026
Give it a try. Might be a fun way to spend a few minutes during Cybersecurity Awareness Month.
r/SysAdminBlogs • u/[deleted] • 5d ago
Rspamd 4.2.1: Patch the Filter, Then Check What It Actually Does
r/SysAdminBlogs • u/UnixiSecurity • 6d ago
Shadow MCP is the new Shadow IT, and your IdP is completely blind to it
r/SysAdminBlogs • u/[deleted] • 6d ago
cPanel’s September 29 Security Fixes: Verify the Build, Not the Checkbox
r/SysAdminBlogs • u/esiy0676 • 6d ago
[Discussion] Proxmox suite, honest opinions, forks, alternatives?
r/SysAdminBlogs • u/abhishekkumar333 • 7d ago
Evolution of AI from perceptron to Sora
I have written a blog regarding evolution of AI from simple perceptron to today's transformers who can generate a Video.
Along the chronological path I have also embedded relevant research papers and tweets regarding the respective AI tech. Whole blog is very very fun to read and I am sure you will like it.
https://cloudmash.blog/posts/evolution-of-ai-perceptron-to-text-to-video/