Active Directory attack lab
A GOAD-based lab for practising attack paths against a realistic multi-domain Windows environment, on the way to OSCP. Findings are written up the way a client report would be.
Twenty years designing, migrating and running enterprise networks across firewalls, SD-WAN, wireless, NAC and cloud. I lead delivery through MaNet Secure Technologies, and I build a home lab to keep the offensive side sharp.
Platform selection, migrations and greenfield builds on Fortinet, Cisco, Palo Alto and Check Point, with inspection, VPN, ZTNA and central logging designed in.
ADVPN and DMVPN hub-and-spoke, BGP and OSPF underlays, MPLS exits, and upgrade paths for large fleets.
802.1X with Cisco ISE, posture, TACACS+ and RADIUS, single sign-on, and clean identity integration.
Hybrid links between on-premises data centres and Azure using ExpressRoute and VNet peering.
Segmentation, ACL design and commissioning for industrial systems and cyber security acceptance tests.
Standing up a NOC, monitoring, runbooks, training and the documentation that lets a team run what I build.
From Nortel and Avaya campus networks to Cisco data centres and CCIE-level routing, Fortinet security fabrics and Azure. I have configured most of what I recommend.
Customer details are withheld. Each write-up covers the problem, the design decisions and the result.
The lab is where I test ideas before they reach a client, and where I train for offensive security.
A GOAD-based lab for practising attack paths against a realistic multi-domain Windows environment, on the way to OSCP. Findings are written up the way a client report would be.
A personal set of scripts and automation for repeatable multi-vendor network work: audits, config checks and documentation generation, written in Python and Ansible.
A lab hosted in the cloud to demonstrate technologies and give teams a safe test environment. I used it to train many engineers, without touching production.
Independent network and security consulting: architecture, migrations and delivery for enterprise and government customers.
Led up to 17 engineers supporting a global enterprise network, and travelled to build its data centres in the USA, Europe and China. Also a firewall platform migration, Azure hybrid connectivity, WAN optimisation, and a NOC built from scratch. Rated "excellent", the top band, six years running.
Started on the Avaya data networking support team; the support moved to Aricent, where I carried on as TAC engineer and escalation expert for the Nortel and Avaya switch range, from ERS to the high-end VSP 9000, for premium customers. Trained new graduates, and won multiple client excellence awards.
Cisco IP telephony for retail branches and head-office sites across the UK and Hong Kong. Led the transition of the service to a new support team and trained eight analysts.
Monitored the network of a global shipping customer with around 800 sites, coordinating carriers and local IT teams to find and fix faults. Top-ranked in a team of 40 for six consecutive months.
Where it started: ran a 24-machine Windows lab network and taught programming to engineering students.
CCNP Routing & Switching, CCNP Voice, CCNA Voice, CCNA Wireless and several Cisco partner specialisations, all since retired or lapsed.
Tell me what you are trying to do and I will tell you how I would approach it.