IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Secure Credential Management: Removing Cleartext Passwords from Scripts

Password Safety
Image generated with Gemini AI


The Problem: Cleartext Passwords in Source Code

Automation via scripting is the beating heart of system administration. However, hardcoding credentials (passwords, API tokens, cryptographic keys) in cleartext inside .sh or .ps1 files is a critical security violation. Anyone with read access to the file system or the Git repository compromises the entire corporate ecosystem.

The Solution: Encrypted Secrets Management

We must decouple the script's logic from the sensitive data by leveraging the operating system's native protection mechanisms.

1. In PowerShell Environments (Windows)

In Microsoft infrastructures, we can use Export-Clixml to encrypt a credential object. The encryption is tightly bound to the user account that generated it and the physical machine (thanks to the Windows Data Protection API).

# Run once to save the encrypted password
Get-Credential | Export-Clixml -Path "C:\secure\admin_creds.xml"

# In the production script, call the file:
$cred = Import-Clixml -Path "C:\secure\admin_creds.xml"

2. In Bash Environments (Linux)

On Unix systems, the most immediate, zero-cost method to protect daemons and cron scripts is to isolate variables into a separate configuration file, restricting permissions exclusively to the root user.

# Create the protected configuration file
echo "DB_PASS='SuperSecret!'" > /etc/script_secrets.conf
sudo chmod 400 /etc/script_secrets.conf

In the main script (executed with elevated privileges), simply import the variables using the source /etc/script_secrets.conf command. The code remains clean, and credentials remain invisible to unauthorized users.

Linux Server Hardening: The 5 Mandatory Post-Install Steps

Linux Hardening


The Problem: Default Exposure

A freshly installed Linux server exposed to the public cloud is a blank canvas, but also an easy target. Default SSH daemon configurations and open ports immediately attract automated scanners, botnets, and brute-force attacks.



The Solution: 5 Steps to Hardening

Before installing any enterprise application, the infrastructure must be locked down by enforcing the principle of least privilege.

  • 1. Public Key Authentication: Ditch passwords entirely. Generate a certificate using ssh-keygen, copy it to the server, and edit /etc/ssh/sshd_config by setting PasswordAuthentication no.
  • 2. Disable Root Login: In the same SSH configuration file, ensure you set PermitRootLogin no to force access only via standard users and subsequent privilege elevation via sudo.
  • 3. Firewall Segmentation (UFW): Drop all incoming traffic except what is strictly necessary.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Brute-Force Mitigation (Fail2Ban): Automatically ban malicious IPs at the network level that repeatedly fail login attempts.
    sudo apt install fail2ban -y
  • 5. Silent Updates: Keep the system protected from zero-day vulnerabilities by installing unattended-upgrades for the automatic application of critical security patches without service interruptions.

WSL 2 for IT: From Windows to Linux in 5 Mins

The Problem: The Burden of Virtual Machine Management



For years, sysadmins and developers forced to operate in hybrid environments have faced an exhausting compromise: maintaining a cumbersome dual-boot setup or relying on heavy, resource-hungry virtual machines (VMs). The need to execute Bash scripts, network tools, or Docker containers directly from a Windows Server or client infrastructure has historically led to performance bottlenecks and workflow fragmentation.

The Solution: Windows Subsystem for Linux 2 (WSL 2)

With WSL 2, the rules of the game have changed. Microsoft introduced a real, native Linux kernel integrated directly into Windows. This is no longer a simple translation layer, but a highly optimized architecture based on a lightweight Hyper-V utility. The result is native file system access and I/O performance that almost rivals a bare-metal installation.

WSL2

1. Quick Installation via PowerShell

Deployment has been drastically simplified. Simply open PowerShell with administrator privileges and run a single command to install the subsystem along with the default distribution (Ubuntu):

wsl --install

For production environments, the rock-solid stability of Debian is often preferred. You can view the list of available distributions and perform a targeted installation:

wsl --list --online
wsl --install -d Debian

2. Hardening and Resource Optimization

One of the most insidious field issues is the tendency of WSL 2 to progressively consume all available RAM on the host system. To prevent this architectural "memory leak", enforcing a strict resource limit is mandatory.

Create or edit the .wslconfig file located in the root of your user profile (the path is C:\Users\YourUsername\.wslconfig) and apply the following parameters:

[wsl2]
memory=4GB
processors=2
swap=0

To forcefully apply the new configuration, restart the WSL service from your terminal:

wsl --shutdown

Conclusion

Implementing WSL 2 transforms a Windows workstation or server into the ultimate Swiss Army knife for IT Management. You instantly gain the power of the Linux terminal for troubleshooting and networking, without giving up Microsoft's native domain administration and security tools.

Send Large Files via PEC using Google Cloud Storage

Data encryption

In daily ICT consulting, especially when interfacing corporate infrastructures with law firms or Public Administrations, a known and frustrating technical limitation often arises: the attachment size limit of Certified Electronic Mail (PEC). Most Italian PEC providers impose a hard cap of 50 to 100 MB. But how do you proceed when you need to legally transmit log archives, digital forensic images, or entire CAD projects that exceed several gigabytes?

The optimal solution is to decouple the physical transport of the file from its legal certification. In this article, we will explore how to use Python to automate the upload of a large file to Google Cloud Storage, calculate its SHA-256 hash to guarantee integrity, and automatically send a PEC containing the download link and the cryptographic fingerprint.

Solution Architecture

Including the file's cryptographic hash within the body of a PEC message legally binds that specific file (hosted externally) to the certified communication. If even a single bit of the file on Google Cloud Storage were to change, the hash would no longer match the one "notarized" by the PEC delivery receipt.

  • Hash Calculation: We use SHA-256 to generate a unique fingerprint of the local file.
  • Cloud Storage: We upload the file to a GCS bucket and generate a Signed URL or public link for downloading.
  • SMTP Automation: We send the PEC using Python's standard libraries, authenticating on the PEC provider's SMTP server.

The Python Script: Step-by-Step Implementation

To run this script, ensure you have the official Google Cloud library installed:
pip install google-cloud-storage. You will also need a Service Account JSON with write permissions to your bucket.

import hashlib
import smtplib
from email.message import EmailMessage
from google.cloud import storage
import os

# Variable Configuration
FILE_PATH = "C:\\Projects\\huge_file_to_send.zip"
BUCKET_NAME = "your-corporate-bucket"
PEC_SENDER = "your.email@pec.it"
PEC_PASSWORD = "YourSecurePassword"
PEC_RECIPIENT = "recipient@pec.it"
SMTP_SERVER = "smtps.pec.aruba.it" # Example for Aruba PEC
SMTP_PORT = 465

def calculate_sha256(file_path):
    """Calculates the SHA-256 hash of a local file."""
    sha256_hash = hashlib.sha256()
    with open(file_path, "rb") as f:
        # Read the file in chunks to handle large files efficiently
        for byte_block in iter(lambda: f.read(4096), b""):
            sha256_hash.update(byte_block)
    return sha256_hash.hexdigest()

def upload_to_gcs(file_path, bucket_name):
    """Uploads the file to Google Cloud Storage and returns the URL."""
    # Set the environment variable for GCP authentication
    os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = "service_account.json"
    
    storage_client = storage.Client()
    bucket = storage_client.bucket(bucket_name)
    blob_name = os.path.basename(file_path)
    blob = bucket.blob(blob_name)
    
    print(f"[*] Uploading to GCS: {blob_name}...")
    blob.upload_from_filename(file_path)
    
    # Makes the file temporarily accessible
    # Note: For production use Signed URLs for enhanced security
    blob.make_public()
    return blob.public_url

def send_pec(file_url, file_hash):
    """Sends the link and hash via PEC (Certified Email)."""
    msg = EmailMessage()
    msg['Subject'] = "Project Transmission and Cryptographic Hash"
    msg['From'] = PEC_SENDER
    msg['To'] = PEC_RECIPIENT
    
    message_body = f"""
    Dear User,
    
    The requested project is transmitted via virtual attachment. 
    Due to PEC size limitations, the file is available for download at the following secure link:
    
    DOWNLOAD LINK: {file_url}
    
    To ensure the integrity and legal validity of this transmission, the file's cryptographic footprint is provided:
    ALGORITHM: SHA-256
    HASH: {file_hash}
    
    Best regards,
    The System Administrator
    """
    msg.set_content(message_body)
    
    print("[*] Connecting to PEC SMTP server...")
    with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT) as server:
        server.login(PEC_SENDER, PEC_PASSWORD)
        server.send_message(msg)
    print("[+] PEC sent successfully!")

if __name__ == "__main__":
    print("[*] Starting Hash calculation...")
    file_hash = calculate_sha256(FILE_PATH)
    print(f"[+] SHA-256 Hash: {file_hash}")
    
    file_url = upload_to_gcs(FILE_PATH, BUCKET_NAME)
    print(f"[+] File URL: {file_url}")
    
    send_pec(file_url, file_hash)

Conclusions for IT Risk Management

This hybrid infrastructure not only solves a burdensome operational roadblock, but it does so while complying with strict Information Security standards. By utilizing cloud buckets, we can enforce automated Data Retention policies (e.g., auto-deleting the blob after 30 days), while embedding the hash into the PEC transaction legally seals the perimeter of our corporate communication.

Practical Guide: KVM Hypervisor with Cockpit Web UI on Debian 12

Cockpit Dashboard

In our previous article, we analyzed the post-Broadcom VMware crisis. It is now time to take action by providing a robust and cost-effective technical solution.

In this guide, we will configure a clean Debian 12 (Bookworm) server as a Type 1 hypervisor using KVM (Kernel-based Virtual Machine). For management, we will use Cockpit, a native Linux web interface that makes administering Virtual Machines simple and intuitive.

1. System Verification and Update

First, verify that the CPU supports virtualization extensions (Intel VT-x or AMD-V):

egrep -c '(vmx|svm)' /proc/cpuinfo

Ensure the system is up to date:

sudo apt update && sudo apt full-upgrade -y

2. Installing the KVM and Libvirt Stack

Proceed with installing the hypervisor and management libraries.

sudo apt install qemu-kvm libvirt-clients libvirt-daemon-system bridge-utils virtinst libosinfo-bin -y

3. Network Configuration (Bridge)

To allow VMs to be visible on the LAN network, we must configure a Network Bridge (e.g., br0).

ATTENTION: An incorrect configuration of `/etc/network/interfaces` can cause loss of remote connectivity. Proceed with caution, preferably having physical or IPMI access.
# /etc/network/interfaces

auto lo
iface lo inet loopback

allow-hotplug enp3s0
iface enp3s0 inet manual

auto br0
iface br0 inet static
    address 192.168.1.100
    netmask 255.255.255.0
    gateway 192.168.1.1
    dns-nameservers 8.8.8.8
    bridge_ports enp3s0
    bridge_stp off
    bridge_fd 0
    bridge_maxwait 0

4. Cockpit Setup for Web Management

Install the base package and the specific module for VM management:

sudo apt install cockpit cockpit-machines -y

5. Complete Installation Video Tutorial

Integrating the textual guide, here is an Asciinema recording showing the entire process. You can copy text directly from the player.

Conclusions

By navigating to https://server_ip_address:9090, you now have full access to manage your virtual machines. We have transformed a standard Debian server into a powerful enterprise-grade KVM hypervisor, without licensing costs and vendor lock-in.




The VMware Earthquake: Broadcom’s Licensing Impact and the Open Source Exodus

VMWAREEscape


Broadcom’s acquisition of VMware was not merely a financial transaction; it was a seismic event that redefined the boundaries of the enterprise virtualization market. For years the de facto standard in data centers of all sizes, VMware is now experiencing a profound crisis of trust from its user base.

At IT Chronicle, we analyze infrastructural evolutions daily, and what we are observing in the field is unprecedented: a massive acceleration towards "de-VMware-ization" strategies. In this article, we will analyze the technical and economic causes of this exodus and why Open Source is no longer just a cheaper alternative, but a strategic necessity.

A Technical Analysis of the "Licensing Problem"

The shift in direction imposed by Broadcom is based on two pillars that have made remaining on the platform unsustainable for many organizations:

1. The Forced Transition to Subscriptions

Broadcom has eliminated the option to purchase perpetual licenses (SnS). Now, the software is only available via subscription. For companies that had planned long-term CAPEX investments, this translates into a drastic increase in OPEX, with renewal costs often tripling compared to the past.

2. Aggressive Portfolio Simplification

Dozens of standalone products have been consolidated into just two main suites: VMware Cloud Foundation (VCF) and VMware vSphere Foundation (VVF).

The technical-economic problem is evident: a customer requiring only the basic hypervisor (ESXi) and centralized management (vCenter) is now forced to purchase vSAN, NSX, and the Aria suite, even if they have no intention of using them. This "commercial over-provisioning" has made the TCO unjustifiable.

Consequences in the Field: The Tesco Case

The impact does not only concern SMBs. Giants of the caliber of Tesco, the British supermarket chain, have initiated plans to migrate thousands of hosts away from VMware. When players of this magnitude face the technical risks of an infrastructural migration, the signal to the market is unmistakable: the risk of vendor lock-in with Broadcom is considered higher than the migration risk.

Beyond VMware: Open Source Alternatives

The question our clients ask us is no longer "if" to migrate, but "where". The Linux-based ecosystem offers mature and standardized solutions.

  • Proxmox VE: Debian-based, gaining enormous popularity due to its "all-in-one" interface similar to vCenter.
  • XCP-ng: Solid and enterprise-grade for those coming from the Xen world.
  • KVM + Cockpit: The native Linux technology that powers the largest public clouds. Raw and incredibly high-performing.

For organizations seeking bare-metal stability without the complexity of hyper-converged clusters, the combination of Debian, KVM, and Cockpit represents the ideal solution. In our next article, we will provide a complete deployment guide for this stack.

IT First Aid - Ep. 30: "This app has been blocked for your protection"


You are trying to install an old (perhaps management) software that is perfectly legitimate, but a large red Windows screen yells at you: "This app has been blocked for your protection". There is no "Run anyway" button.

1. The Certificate Block

The UAC (User Account Control) intercepts software whose digital signature certificate has expired or been revoked. Right-click the downloaded .exe file, go to Properties. If you see a security warning at the bottom, check the "Unblock" box and hit Apply.

2. Forced Launch via Terminal

App Lock


If Windows continues to block it, use Admin authority. Open the Command Prompt by running it as Administrator. Navigate using the cd command to the folder where the file is located (e.g., cd C:\Downloads) and type the name of the executable (e.g., setup.exe). Being launched from an already verified environment with maximum privileges, the installation will bypass the graphical block.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 29: Forgot Windows Local Password


Warning: this maneuver is exactly why we sysadmins always insist on encrypting drives with BitLocker. If the account is local (not linked to a Microsoft email) and unencrypted, here is the classic "skeleton key" trick.

Forgot Password


1. The Utilman Trick

Boot the PC with a Windows installation USB drive. Use Shift+F10 to open the command prompt. The game involves navigating to the System32 folder and renaming the Accessibility executable (utilman.exe), replacing it with the command prompt (cmd.exe).

2. The Brutal Reset

Rebooting the PC normally, when you reach the lock screen, clicking on the Accessibility icon in the bottom right will open a command prompt with maximum privileges (SYSTEM). Just type net user username newpassword to force the change and get back into the system. No formatting required.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 28: Bluetooth paired but won't connect


Your headphones or mouse show up in the "Paired" devices list, but clicking Connect does absolutely nothing. Endlessly removing and re-adding the device sometimes doesn't help if the radio stack is frozen.

Bluetooth Service


1. Restarting Radio Services

Press Win + R, type services.msc, and hit Enter. Look for the Bluetooth Support Service (or bthserv). If it's stopped, Start it; if it's already running, give it a nice Right-click > Restart. Do the same for related services you find nearby (like Bluetooth Audio Gateway Service).

2. The Troubleshooter

If restarting the daemon isn't enough, go to Settings > System > Troubleshoot > Other troubleshooters and run the one dedicated to Bluetooth. Windows will force a reset of the internal antenna's radio driver.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 27: Can't access Network Folders or NAS


You just set up a corporate NAS or a printer with a shared folder, but your PC categorically refuses to see it on the Network, giving you a generic error.

SMB 1.0


1. Network Discovery

First common oversight: ensure your connection profile is set to "Private" and not "Public", otherwise the Windows firewall will close sharing ports by default.

2. The SMBv1 Protocol Demon

If the NAS or network device is a bit old, it uses the SMBv1 protocol to communicate. For security reasons (ransomware prevention), Windows 10/11 disables it out of the box. Press Start, type "Turn Windows features on or off", scroll down to "SMB 1.0/CIFS File Sharing Support", expand it, and check the "SMB 1.0/CIFS Client" box. Reboot your PC.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 26: High CPU from Antimalware Service Executable


Your computer is struggling; you open Task Manager and see a process at the top of the list called Antimalware Service Executable devouring RAM and CPU. It's the Windows Defender background engine.

1. The Scanning Paradox

The reason it gets stuck is often surreal: the antivirus is incessantly checking its own folder and files in an infinite loop.

High CPU from Antimalware Service


2. The Exclusions Trick

Open Windows Security > Virus & threat protection. Under settings, click on "Manage settings" and scroll down to Exclusions. Click "Add or remove exclusions". Choose "Process" and type exactly MsMpEng.exe. Also add a Folder exclusion pointing to C:\ProgramData\Microsoft\Windows Defender. Now the antivirus will breathe.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 25: "Connection is not private"


You open Chrome, try to go to Google or social media, and a giant red warning appears: "Your connection is not private". You switch browsers and the problem persists on every HTTPS site. You are not being hacked.

1. The Time Problem

SSL security certificates (the green padlock on websites) rely on strict issuance and expiration dates. If your PC's clock is out of sync (perhaps due to a dead motherboard CMOS battery), the browser will think the website's certificates are from the future or the past, invalidating them.

The Time Problem


2. Forced Synchronization

Go to Settings (Win + I) > Time & language. Ensure that "Set time automatically" is enabled, but more importantly, click on the "Sync now" button. By updating the clock with global NTP servers, websites will magically become accessible again.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 24: PC waking up from sleep by itself


You put the PC to Sleep at night, and at 3 AM it lights up the room, turning itself back on like a horror movie. The culprit is always an "overly sensitive" peripheral or a hidden scheduled task.

Auto Wake Up


1. Catch the Culprit

Open the Command Prompt (cmd) and type this magic sysadmin command: powercfg -lastwake. This command will tell you exactly what triggered the last wake event (often it's the network adapter or the mouse).

2. Revoke Permissions

If it's the mouse picking up vibrations, open Device Manager, right-click on your Mouse > Properties. Go to the Power Management tab and uncheck "Allow this device to wake the computer". Peaceful sleep guaranteed.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 23: PDFs keep opening in Edge


You installed Adobe Reader or your favorite PDF viewer, double-click a file, and... Microsoft Edge opens. You change it, and after the next reboot, it opens with Edge again. Extension hijacking policies are ruthless.

PDFs keep opening


1. The Definitive Method

Don't use the "Open with" command. Go to Windows Settings (Win + I) > Apps > Default apps.

2. Force the Extension

Scroll down to the bottom and select "Choose default apps by file type" (on Win 10) or use the search bar by typing .pdf directly (on Win 11). Click on the Edge icon that appears next to it and brutally force the change by selecting your preferred program. Windows will now stop trying to use its browser as a Swiss Army knife.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 22: Folder Access Denied


You transferred a hard drive from an old PC or tried to modify a specific folder, but Windows denies you access even if you are an Administrator. The blame lies with the ACLs (Access Control Lists).

Folder Access Denied


1. Taking Ownership

Right-click the inaccessible folder > Properties > Security tab > click on Advanced. At the top, you will see "Owner: TrustedInstaller" or an unknown alphanumeric code. Click on Change.

2. Apply Permissions

Type your username or simply "Administrators", press "Check Names", and hit OK. Pay close attention: check the box "Replace owner on subcontainers and objects" before hitting Apply. Now that you are the legal owner of the files, you can delete or modify them at will.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 21: Windows Search broken


You press the Start button, begin typing the name of a file or program and... nothing. The menu closes or loads indefinitely. The indexing database is corrupted.

Windows Search broken


1. Restart the Process

Open Task Manager (Ctrl+Shift+Esc), go to the "Details" tab, and look for the SearchUI.exe (or SearchHost.exe on Windows 11) process. Right-click and select End task. Windows will restart it automatically, clearing temporary glitches.

2. Rebuild the Index

If that isn't enough, the index needs to be reset. Press Win + R, type control to open the classic Control Panel. Go to Indexing Options > Advanced. Under the Troubleshooting section, click the Rebuild button. It might take a while, but your search engine will be flawless again.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 20: Keyboard typing wrong characters


You are typing a document quickly, you press the letter "W", and a "Z" appears on the screen. Punctuation symbols no longer match the keys. It's not a virus; it's a phantom Windows shortcut.

1. The Cursed Shortcut

Keyboard typing wrong characters


Without meaning to, you pressed Alt + Shift or Win + Spacebar. This move instantly swaps your keyboard layout from QWERTY to QWERTZ or AZERTY. Press the combination again to revert it.

2. Fixing it at the Root

To prevent this from happening again, go to Settings (Win + I) > Time & language > Language & region. If you see installed languages you don't use, click the three dots next to them and select Remove. No alternate language, no accidental swapping.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 19: C Drive Full? How to Safely Free Up Hidden Gigabytes

The Problem: The C Drive Bar Turns Red

Your local C drive bar has suddenly turned red. You have emptied the recycle bin and cleared out your old download folders, but dozens of Gigabytes are still missing. Here is where these ghost files are hiding and how to safely recover your storage space without compromising OS stability.

Ghost Files


The Solution: Deep Cleanup and Automation

1. The Hidden Windows Update Folder

Every time Windows installs a major update, the system keeps a massive backup of the previous files just in case you need to perform a rollback. To remove this data surgically:

  • Press Start and type Disk Cleanup.
  • Run the utility with elevated privileges by clicking Run as administrator (or by clicking the Clean up system files button inside the app).
  • Scroll through the list, check the box for Windows Update Cleanup (on systems that haven't been maintained in a while, this can easily exceed 20 GB!), and click OK.

2. Automate with Storage Sense

In IT Management, automation is everything. To avoid having to repeat this process manually in the future, let's delegate the routine workload to Windows:

  • Press the Win + I keyboard shortcut to open Settings.
  • Navigate to System > Storage.
  • Toggle the Storage Sense switch to On.

From now on, this tool will work completely silently in the background, deleting orphaned temporary files and flushing browser caches as soon as the system detects a drop in available storage space.

IT First Aid - Ep. 18: Webcam and Mic not working


You join an important video call and your screen is black, or no one can hear you. You check the USB cables, and everything is fine. The real culprit is often Windows' paranoid privacy management.

Camera not working


1. The Windows Privacy Block

Windows 10 and 11 feature a master switch that disconnects peripherals at the software level. Press Win + I to open Settings. Go to Privacy & security.

2. Unlock Desktop Apps

Scroll down to "App permissions" and click on Camera (or Microphone). Ensure the master switch "Let apps access your camera" is turned On. The most crucial part: scroll to the very bottom and make sure the option "Let desktop apps access your camera" is enabled. Otherwise, legacy programs like Zoom, Teams, or OBS will be completely cut off.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

IT First Aid - Ep. 17: 100% Disk Usage

Disk Usage 100%



You open Task Manager and see the Disk column painted an ominous red at 100%, while your PC stutters and lags. It's often not a hardware failure, but a loop caused by Windows optimization services.

1. Disable the SysMain Service (formerly Superfetch)

This service tries to preload your most frequently used apps into RAM, but on mechanical drives or stressed SSDs, it causes massive bottlenecks. Press Start, type services.msc, and hit Enter. Look for the SysMain service. Right-click it > Properties. Set "Startup type" to Disabled and click "Stop".

2. Tame Windows Search

Continuous file indexing can saturate your disk. Still in services.msc, look for Windows Search. If your disk starts breathing again after stopping this service, consider disabling it temporarily during heavy workloads.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services