IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Linux Server Hardening: The 5 Mandatory Post-Install Steps

Linux Hardening


The Problem: Default Exposure

A freshly installed Linux server exposed to the public cloud is a blank canvas, but also an easy target. Default SSH daemon configurations and open ports immediately attract automated scanners, botnets, and brute-force attacks.



The Solution: 5 Steps to Hardening

Before installing any enterprise application, the infrastructure must be locked down by enforcing the principle of least privilege.

  • 1. Public Key Authentication: Ditch passwords entirely. Generate a certificate using ssh-keygen, copy it to the server, and edit /etc/ssh/sshd_config by setting PasswordAuthentication no.
  • 2. Disable Root Login: In the same SSH configuration file, ensure you set PermitRootLogin no to force access only via standard users and subsequent privilege elevation via sudo.
  • 3. Firewall Segmentation (UFW): Drop all incoming traffic except what is strictly necessary.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Brute-Force Mitigation (Fail2Ban): Automatically ban malicious IPs at the network level that repeatedly fail login attempts.
    sudo apt install fail2ban -y
  • 5. Silent Updates: Keep the system protected from zero-day vulnerabilities by installing unattended-upgrades for the automatic application of critical security patches without service interruptions.

Hardening Server Linux: I 5 Passi Obbligatori Post-Installazione

Immagine generata con Gemini AI


Il Problema: L'Esposizione Predefinita

Un server Linux appena installato ed esposto su cloud pubblico è una tela bianca, ma anche un bersaglio facile. Le configurazioni predefinite del demone SSH e le porte aperte attirano immediatamente scansioni automatizzate, botnet e attacchi brute-force.

La Soluzione: 5 Passaggi di Hardening

Prima di installare qualsiasi applicativo aziendale, l'infrastruttura deve essere blindata applicando il principio del minimo privilegio.

  • 1. Autenticazione a Chiave Pubblica: Abbandona le password. Genera un certificato con ssh-keygen, copialo sul server e modifica /etc/ssh/sshd_config impostando PasswordAuthentication no.
  • 2. Disabilitare l'accesso Root: Nello stesso file di configurazione SSH, assicurati di inserire PermitRootLogin no per forzare l'accesso solo tramite utenza standard e successiva elevazione tramite sudo.
  • 3. Segmentazione con Firewall (UFW): Chiudi tutto il traffico in ingresso tranne lo stretto necessario.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Mitigazione Brute-Force (Fail2Ban): Banna automaticamente a livello di rete gli IP malevoli che falliscono ripetutamente i login.
    sudo apt install fail2ban -y
  • 5. Aggiornamenti Silenti: Mantieni il sistema protetto dalle vulnerabilità zero-day installando unattended-upgrades per l'applicazione automatica delle sole patch di sicurezza critiche, senza interruzioni di servizio.

WSL 2 for IT: From Windows to Linux in 5 Mins

The Problem: The Burden of Virtual Machine Management



For years, sysadmins and developers forced to operate in hybrid environments have faced an exhausting compromise: maintaining a cumbersome dual-boot setup or relying on heavy, resource-hungry virtual machines (VMs). The need to execute Bash scripts, network tools, or Docker containers directly from a Windows Server or client infrastructure has historically led to performance bottlenecks and workflow fragmentation.

The Solution: Windows Subsystem for Linux 2 (WSL 2)

With WSL 2, the rules of the game have changed. Microsoft introduced a real, native Linux kernel integrated directly into Windows. This is no longer a simple translation layer, but a highly optimized architecture based on a lightweight Hyper-V utility. The result is native file system access and I/O performance that almost rivals a bare-metal installation.

WSL2

1. Quick Installation via PowerShell

Deployment has been drastically simplified. Simply open PowerShell with administrator privileges and run a single command to install the subsystem along with the default distribution (Ubuntu):

wsl --install

For production environments, the rock-solid stability of Debian is often preferred. You can view the list of available distributions and perform a targeted installation:

wsl --list --online
wsl --install -d Debian

2. Hardening and Resource Optimization

One of the most insidious field issues is the tendency of WSL 2 to progressively consume all available RAM on the host system. To prevent this architectural "memory leak", enforcing a strict resource limit is mandatory.

Create or edit the .wslconfig file located in the root of your user profile (the path is C:\Users\YourUsername\.wslconfig) and apply the following parameters:

[wsl2]
memory=4GB
processors=2
swap=0

To forcefully apply the new configuration, restart the WSL service from your terminal:

wsl --shutdown

Conclusion

Implementing WSL 2 transforms a Windows workstation or server into the ultimate Swiss Army knife for IT Management. You instantly gain the power of the Linux terminal for troubleshooting and networking, without giving up Microsoft's native domain administration and security tools.

WSL 2 per IT: Da Windows a Linux in 5 Minuti

Il Problema: L'Onerosa Gestione delle Macchine Virtuali



Per anni, i sistemisti e gli sviluppatori costretti a operare in ambienti ibridi hanno dovuto affrontare un compromesso logorante: mantenere un dual-boot macchinoso o affidarsi a macchine virtuali (VM) pesanti e avide di risorse. L'esigenza di eseguire script Bash, tool di rete o container Docker direttamente da un'infrastruttura Windows Server o client ha sempre comportato colli di bottiglia nelle prestazioni e una netta frammentazione del flusso di lavoro.

La Soluzione: Windows Subsystem for Linux 2 (WSL 2)

Con WSL 2, le regole del gioco cambiano. Microsoft ha introdotto un vero kernel Linux integrato in Windows. Non si tratta più di un semplice layer di traduzione, ma di un'architettura basata su Hyper-V estremamente leggera. Il risultato garantisce un accesso nativo al file system e prestazioni I/O quasi equiparabili a quelle di un'installazione bare-metal.

WSL2

1. Installazione Rapida tramite PowerShell

L'implementazione è stata drasticamente semplificata. È sufficiente aprire PowerShell con privilegi di amministratore ed eseguire un singolo comando per installare il sottosistema e la distribuzione predefinita (Ubuntu):

wsl --install

Per ambienti di produzione, spesso si preferisce la stabilità di Debian. Puoi visualizzare l'elenco delle distribuzioni disponibili online e procedere con un'installazione mirata:

wsl --list --online
wsl --install -d Debian

2. Hardening e Ottimizzazione delle Risorse

Uno dei problemi più insidiosi riscontrati sul campo è la tendenza di WSL 2 a consumare progressivamente tutta la RAM disponibile nel sistema host. Per prevenire questo "memory leak" architetturale, è obbligatorio applicare un limite rigido alle risorse.

Crea o modifica il file .wslconfig nella root del tuo profilo utente (il percorso è C:\Users\NomeUtente\.wslconfig) e inserisci i seguenti parametri:

[wsl2]
memory=4GB
processors=2
swap=0

Per applicare e forzare le modifiche, riavvia immediatamente il servizio WSL dal terminale:

wsl --shutdown

Conclusione

Implementare WSL 2 trasforma una workstation o un server Windows nel coltellino svizzero definitivo per l'IT Management. Si ottiene la potenza del terminale Linux per il troubleshooting e il networking, senza rinunciare agli strumenti nativi di amministrazione di dominio e sicurezza del mondo Microsoft.

Guida Pratica: Hypervisor KVM con Web Cockpit su Debian 12

Cockpit Dashboard

Nel precedente articolo abbiamo analizzato la crisi di VMware post-acquisizione Broadcom. È tempo di passare all'azione fornendo una soluzione tecnica robusta ed economica.

In questa guida vi mostrerò come configurare un server Debian 12 (Bookworm) come hypervisor di livello 1 utilizzando KVM (Kernel-based Virtual Machine). Per la gestione, utilizzeremo Cockpit, un'interfaccia web nativa Linux che rende l'amministrazione delle Macchine Virtuali (VM) semplice e intuitiva.

1. Verifica e Aggiornamento del Sistema

Verifichiamo che la CPU supporti le estensioni di virtualizzazione (Intel VT-x o AMD-V):

egrep -c '(vmx|svm)' /proc/cpuinfo

Aggiorniamo il sistema:

sudo apt update && sudo apt full-upgrade -y

2. Installazione dello Stack KVM e Libvirt

Procediamo all'installazione dell'hypervisor e delle librerie di gestione.

sudo apt install qemu-kvm libvirt-clients libvirt-daemon-system bridge-utils virtinst libosinfo-bin -y

3. Configurazione del Networking (Bridge)

Per permettere alle VM di essere visibili nella rete LAN, configuriamo un Network Bridge (es. br0).

ATTENZIONE: Una configurazione errata di `/etc/network/interfaces` può causare la perdita di connettività remota del server. Procedi avendo un accesso fisico o IPMI/iLO.
# /etc/network/interfaces

auto lo
iface lo inet loopback

allow-hotplug enp3s0
iface enp3s0 inet manual

auto br0
iface br0 inet static
    address 192.168.1.100
    netmask 255.255.255.0
    gateway 192.168.1.1
    dns-nameservers 8.8.8.8
    bridge_ports enp3s0
    bridge_stp off
    bridge_fd 0
    bridge_maxwait 0

4. Setup di Cockpit per la Gestione Web

Installiamo l'interfaccia e il plugin per le VM:

sudo apt install cockpit cockpit-machines -y
Colleghiamoci al nostro server andando all'indirizzo https://localhost:9090/system
Buon divertimento a creare le vostre macchine virtuali
Cockpit Dashboard

5. Video Tutorial Completo dell'Installazione

A integrazione della guida, ecco la registrazione tramite Asciinema dell'intero processo. Puoi copiare il testo direttamente dal player.

Conclusioni

Navigando su https://indirizzo_ip_server:9090 avrai ora pieno accesso alla gestione delle tue macchine virtuali. Abbiamo trasformato un server Debian in un potente hypervisor KVM enterprise-grade, senza costi di licenza e senza vendor lock-in.

Practical Guide: KVM Hypervisor with Cockpit Web UI on Debian 12

Cockpit Dashboard

In our previous article, we analyzed the post-Broadcom VMware crisis. It is now time to take action by providing a robust and cost-effective technical solution.

In this guide, we will configure a clean Debian 12 (Bookworm) server as a Type 1 hypervisor using KVM (Kernel-based Virtual Machine). For management, we will use Cockpit, a native Linux web interface that makes administering Virtual Machines simple and intuitive.

1. System Verification and Update

First, verify that the CPU supports virtualization extensions (Intel VT-x or AMD-V):

egrep -c '(vmx|svm)' /proc/cpuinfo

Ensure the system is up to date:

sudo apt update && sudo apt full-upgrade -y

2. Installing the KVM and Libvirt Stack

Proceed with installing the hypervisor and management libraries.

sudo apt install qemu-kvm libvirt-clients libvirt-daemon-system bridge-utils virtinst libosinfo-bin -y

3. Network Configuration (Bridge)

To allow VMs to be visible on the LAN network, we must configure a Network Bridge (e.g., br0).

ATTENTION: An incorrect configuration of `/etc/network/interfaces` can cause loss of remote connectivity. Proceed with caution, preferably having physical or IPMI access.
# /etc/network/interfaces

auto lo
iface lo inet loopback

allow-hotplug enp3s0
iface enp3s0 inet manual

auto br0
iface br0 inet static
    address 192.168.1.100
    netmask 255.255.255.0
    gateway 192.168.1.1
    dns-nameservers 8.8.8.8
    bridge_ports enp3s0
    bridge_stp off
    bridge_fd 0
    bridge_maxwait 0

4. Cockpit Setup for Web Management

Install the base package and the specific module for VM management:

sudo apt install cockpit cockpit-machines -y

5. Complete Installation Video Tutorial

Integrating the textual guide, here is an Asciinema recording showing the entire process. You can copy text directly from the player.

Conclusions

By navigating to https://server_ip_address:9090, you now have full access to manage your virtual machines. We have transformed a standard Debian server into a powerful enterprise-grade KVM hypervisor, without licensing costs and vendor lock-in.




IT First Aid - Ep. 29: Forgot Windows Local Password


Warning: this maneuver is exactly why we sysadmins always insist on encrypting drives with BitLocker. If the account is local (not linked to a Microsoft email) and unencrypted, here is the classic "skeleton key" trick.

Forgot Password


1. The Utilman Trick

Boot the PC with a Windows installation USB drive. Use Shift+F10 to open the command prompt. The game involves navigating to the System32 folder and renaming the Accessibility executable (utilman.exe), replacing it with the command prompt (cmd.exe).

2. The Brutal Reset

Rebooting the PC normally, when you reach the lock screen, clicking on the Accessibility icon in the bottom right will open a command prompt with maximum privileges (SYSTEM). Just type net user username newpassword to force the change and get back into the system. No formatting required.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 29: Password di Windows locale dimenticata


Attenzione: questa manovra è il motivo per cui noi sistemisti insistiamo sempre per cifrare i dischi con BitLocker. Se l'account è locale (non collegato a una mail Microsoft) e non è cifrato, ecco il classico trucco del "passpartout".

Forgot Password


1. Il trucco di Utilman

Avvia il PC con una chiavetta di installazione di Windows. Usa Shift+F10 per aprire il prompt dei comandi. Il gioco consiste nel navigare nella cartella System32 e rinominare l'eseguibile dell'Accessibilità (utilman.exe) sostituendolo con il prompt dei comandi (cmd.exe).

2. Il reset brutale

Riavviando il PC normalmente, arrivato alla schermata di blocco, cliccando sull'icona in basso a destra dell'Accessibilità, si aprirà un prompt dei comandi con privilegi massimi (SYSTEM). Basterà digitare net user nomeutente nuovapassword per forzare il cambio e rimettere piede nel sistema. Niente formattazione.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

IT First Aid - Ep. 22: Folder Access Denied


You transferred a hard drive from an old PC or tried to modify a specific folder, but Windows denies you access even if you are an Administrator. The blame lies with the ACLs (Access Control Lists).

Folder Access Denied


1. Taking Ownership

Right-click the inaccessible folder > Properties > Security tab > click on Advanced. At the top, you will see "Owner: TrustedInstaller" or an unknown alphanumeric code. Click on Change.

2. Apply Permissions

Type your username or simply "Administrators", press "Check Names", and hit OK. Pay close attention: check the box "Replace owner on subcontainers and objects" before hitting Apply. Now that you are the legal owner of the files, you can delete or modify them at will.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 22: "Per eseguire l'operazione è necessaria l'autorizzazione"


Hai trasferito un hard disk da un vecchio PC o provi a modificare una cartella specifica, ma Windows ti nega l'accesso anche se sei un Amministratore. La colpa è delle ACL (Access Control List).

Folder Access Denied


1. Diventare il Proprietario (Owner)

Fai clic destro sulla cartella inaccessibile > Proprietà > scheda Sicurezza > clicca su Avanzate. In alto, vedrai la voce "Proprietario: TrustedInstaller" o un codice alfanumerico sconosciuto. Clicca su Cambia.

2. Applicare le autorizzazioni

Digita il nome del tuo utente o semplicemente "Administrators", premi "Controlla nomi" e dai OK. Fai molta attenzione: spunta la casella "Sostituisci proprietario in sottocontenitori ed oggetti" prima di premere Applica. Ora che sei il proprietario legale dei file, puoi eliminarli o modificarli a piacimento.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

IT First Aid - Ep. 19: C Drive Full? How to Safely Free Up Hidden Gigabytes

The Problem: The C Drive Bar Turns Red

Your local C drive bar has suddenly turned red. You have emptied the recycle bin and cleared out your old download folders, but dozens of Gigabytes are still missing. Here is where these ghost files are hiding and how to safely recover your storage space without compromising OS stability.

Ghost Files


The Solution: Deep Cleanup and Automation

1. The Hidden Windows Update Folder

Every time Windows installs a major update, the system keeps a massive backup of the previous files just in case you need to perform a rollback. To remove this data surgically:

  • Press Start and type Disk Cleanup.
  • Run the utility with elevated privileges by clicking Run as administrator (or by clicking the Clean up system files button inside the app).
  • Scroll through the list, check the box for Windows Update Cleanup (on systems that haven't been maintained in a while, this can easily exceed 20 GB!), and click OK.

2. Automate with Storage Sense

In IT Management, automation is everything. To avoid having to repeat this process manually in the future, let's delegate the routine workload to Windows:

  • Press the Win + I keyboard shortcut to open Settings.
  • Navigate to System > Storage.
  • Toggle the Storage Sense switch to On.

From now on, this tool will work completely silently in the background, deleting orphaned temporary files and flushing browser caches as soon as the system detects a drop in available storage space.

IT First Aid - Ep. 17: 100% Disk Usage

Disk Usage 100%



You open Task Manager and see the Disk column painted an ominous red at 100%, while your PC stutters and lags. It's often not a hardware failure, but a loop caused by Windows optimization services.

1. Disable the SysMain Service (formerly Superfetch)

This service tries to preload your most frequently used apps into RAM, but on mechanical drives or stressed SSDs, it causes massive bottlenecks. Press Start, type services.msc, and hit Enter. Look for the SysMain service. Right-click it > Properties. Set "Startup type" to Disabled and click "Stop".

2. Tame Windows Search

Continuous file indexing can saturate your disk. Still in services.msc, look for Windows Search. If your disk starts breathing again after stopping this service, consider disabling it temporarily during heavy workloads.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 17: Disco fisso perennemente al 100% nel Task Manager

Disk Full 100%


Apri il Task Manager e vedi la colonna del Disco colorata di un rosso minaccioso al 100%, mentre il PC si muove a scatti. Spesso non è un problema hardware, ma un loop dei servizi di ottimizzazione di Windows.

1. Disattivare il servizio SysMain (ex Superfetch)

Questo servizio cerca di precaricare in RAM le app che usi più spesso, ma sui dischi meccanici o su SSD sotto sforzo causa colli di bottiglia mostruosi. Premi Start, digita services.msc e premi Invio. Cerca il servizio SysMain. Fai clic destro > Proprietà. Imposta "Tipo di avvio" su Disabilitato e clicca su "Interrompi".

2. Tenere a bada Windows Search

L'indicizzazione continua dei file può saturare il disco. Sempre in services.msc, cerca Windows Search. Se il disco torna a respirare fermando questo servizio, valuta di disabilitarlo temporaneamente durante i carichi di lavoro intensi.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

IT First Aid - Ep. 11 Windows 11 upgrade, with some troubles

Good morning everyone!

Here we are again, with a new problem, and obviously a new solution: the upgrade from Windows 10 to Windows 11.

About time, you might say! But a tiny clarification is needed here: as an IT technician, one of the things that has always bored me is spending my free time fixing my own devices. Because of this, my devices are always the last ones to be put on the waiting list.

Better late than never. At this point, however, you might wonder what's so special about this how-to compared to the hundreds available on the internet, especially for a procedure that requires no dark magic. Well, in my case, as Murphy's Law dictates, things got a bit more complicated. I had originally set up an MBR partition instead of GPT, a problem compounded by the fact that I hadn't enabled the BIOS in UEFI mode nor enabled Secure Boot.

In short, I unconsciously complicated things just to make the solution more interesting. Let's proceed and see how we managed to get out of this IT mess.

Phase 1: The illusions of the Microsoft tool (MBR2GPT)

On paper, Microsoft provides us with a command-line tool that should do the magic: MBR2GPT. The idea is that, by running it with administrator privileges, it converts the disk from MBR to GPT without touching the data, creating a ready-to-use EFI partition.

Let's verify that the partitions are ready using the Microsoft tool:

mbr2gpt /validate /disk:0 /allowFullOS

If the validation is successful, we execute the command. Unfortunately for me, the validation failed, and I had to rebuild the bootloader manually. Once the bootloader was rebuilt, I moved on to the actual conversion:

mbr2gpt /convert /disk:0 /allowFullOS
WARNING: TO CONVERT PARTITIONS WITH BITLOCKER, IT IS NECESSARY TO SUSPEND OR DISABLE BITLOCKER FIRST, OTHERWISE YOU WON'T BE ABLE TO REBOOT THE PC.

The tool creates the EFI and MSR partitions and updates the BCD without formatting. Do not unplug the PC during the operation.

At this point, we need to restart the PC in UEFI mode. Let's proceed from Windows:
Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → UEFI Firmware Settings → Restart.

UEFI boot


Upon reboot, we will have to enter the BIOS by pressing a key between F11 or F12 (depending on your PC manufacturer) before Windows boots. Once inside the BIOS, we will disable Legacy/CSM and set the boot mode strictly to UEFI. Save the settings and exit.

(Editor's note: If you have to use Diskpart to force a partition deletion like I did because of corrupt EFI volumes left behind, you might run into this beautiful Windows safety block: Virtual Disk Service error: Delete is not allowed on the current boot, system, pagefile, crashdump or hibernation volume. Just use the override parameter to bypass it. And when fixing the bootloader with bcdboot, wait for the majestic Boot files successfully created.)

At this point, Windows will boot up, and we can proceed with the upgrade to Windows 11 by going to the Windows Update tab and clicking to check for updates. If this doesn't show the option to switch to Windows 11, the reason you are not seeing the update yet is simply a matter of server timing. Microsoft handles the transition to Windows 11 with a staged rollout. Even if your PC is ready today, the Windows Update algorithm might put you in a "queue" and show you the banner weeks or even months from now. Obviously, there is no reason to wait for Microsoft's server timelines. There is an official and direct method to trigger the update immediately, keeping all your programs, files, and settings intact.

Here is how to force a clean upgrade:

The Windows 11 Installation Assistant

This is the official Microsoft tool designed specifically for those who have a compatible PC but don't want to wait for the Windows Update notification.

  1. Go to the official Microsoft download page by googling "Download Windows 11" (make sure the site is microsoft.com).
  2. The first option at the top will be the Windows 11 Installation Assistant.
  3. Click on Download Now.
  4. Run the downloaded file (Windows11InstallationAssistant.exe). Note: it might ask you to download and install the "PC Health Check" app for a final double-check; do it if prompted.
  5. Accept the license terms and click on Accept and install.

Note: If you run into TPM issues right after switching from Legacy to UEFI, you might see errors in Windows Security like Device health attestation isn't supported on this device and TPM storage is not available. Please clear your TPM. Simply click on Clear TPM in the UI and confirm upon reboot to reset the cryptographic keys.

At this point, the Assistant will do everything on its own. It will start the background download of Windows 11 (you can continue using the PC in the meantime), prepare the files, and, when ready, will ask you to restart. The reboot will take some time, similar to a large cumulative update, and upon completion, you will find yourself directly on the new Windows 11 desktop.

Pronto Soccorso IT - Ep. 11 Passaggio a Windows 11, con qualche problema

Buongiorno a tutti!

Eccoci di nuovo qui, per un nuovo problema, ed ovviamente una nuova soluzione: il passaggio da Windows 10 a Windows 11.

Alla buon'ora, direte voi! Però qui è necessaria una piccola, piccolissima precisazione: da tecnico informatico, una delle cose che mi ha sempre annoiato è impiegare il mio tempo libero per mettere a posto i miei dispositivi, motivo per cui nella lista d'attesa i miei dispositivi sono sempre gli ultimi ad essere serviti.

Meglio tardi che mai. Però a questo punto vi domanderete cosa ci sia di particolare in questo howto, rispetto alle centinaia disponibili su internet, e per di più per un procedimento che non ha nulla di alchemico: beh nel mio caso, come legge di Murphy impone, le cose si sono un po' più complicate, avendo creato in origine una partizione MBR e non GPT, problema al quale si è aggiunto il non avere abilitato il BIOS in modalità UEFI e l'avvio protetto.

Insomma, ho voluto un po' complicare le cose per rendere la soluzione più interessante. 

Procediamo quindi a descrivere come siamo riusciti a venire fuori da questo ginepraio informatico.

Fase 1: Le illusioni dello strumento Microsoft (MBR2GPT)

Sulla carta, Microsoft ci fornisce uno strumento a riga di comando che dovrebbe fare la magia: MBR2GPT. L'idea è che, avviandolo con i permessi di amministratore, converta il disco da MBR a GPT senza toccare i dati, creando una partizione EFI pronta all'uso.

Verifichiamo che le partizioni siano pronte utilizzando lo strumento di Microsoft:

mbr2gpt /validate /disk:0 /allowFullOS

Se la validazione ha successo eseguiamo il comando. Purtroppo per me la validazione non è andata a buon fine, ed ho dovuto ricostruire il bootloader. Una volta ricostruito il bootloader sono passato alla conversione vera e propria:

mbr2gpt /convert /disk:0 /allowFullOS
ATTENZIONE: PER CONVERTIRE PARTIZIONI CON BITLOCKER, È NECESSARIO PRIMA SOSPENDERE O DISATTIVARE BITLOCKER, ALTRIMENTI NON SAREMO IN GRADO DI RIAVVIARE IL PC.

Il tool crea le partizioni EFI e MSR e aggiorna il BCD senza formattare. Non scollegare il PC durante l’operazione.

A questo punto è necessario riavviare il pc in modalità UEFI, procediamo da Windows:
Impostazioni → Sistema → Ripristino → Avvio avanzato → Riavvia ora → Risoluzione problemi → Opzioni avanzate → Impostazioni firmware UEFI → Riavvia

Riavvio UEFI


Al riavvio dovremo entrare nel BIOS premendo un tasto fra F11 o F12 (a seconda del produttore del vostro pc) prima dell’avvio di Windows. Una volta entrati nel BIOS, disabiliteremo Legacy/CSM e imposteremo avvio solo UEFI, salviamo le impostazioni e usciamo.

A questo punto si avvierà Windows e potremo procedere all’aggiornamento a Windows 11 andando nella scheda aggiornamenti e cliccando per verificare la presenza di aggiornamenti. Se questo non dovesse mostrarci la possibilità di passare a Windows 11, il motivo per cui non vedi ancora l'aggiornamento su Windows Update è semplicemente una questione di tempistiche dei server. Microsoft gestisce il passaggio a Windows 11 con un rilascio scaglionato (staged rollout). Anche se il tuo PC è pronto oggi, l'algoritmo di Windows Update potrebbe mettersi in "coda" e proporti il banner tra settimane o addirittura mesi. Ovviamente, non c'è alcun motivo di aspettare i tempi tecnici dei server Microsoft. Esiste un metodo ufficiale e diretto per far partire l'aggiornamento immediatamente, mantenendo intatti tutti i tuoi programmi, i file e le impostazioni.

Ecco come forzare l'aggiornamento in modo pulito:


L'Assistente per l'installazione di Windows 11

Questo è il tool ufficiale di Microsoft pensato proprio per chi ha un PC compatibile ma non vuole aspettare la notifica di Windows Update.

  1. Vai sulla pagina ufficiale di download di Microsoft cercando su Google "Download Windows 11" (assicurati che il sito sia microsoft.com).
  2. La prima opzione in alto sarà Assistente per l'installazione di Windows 11.
  3. Clicca su Scarica ora.
  4. Avvia il file scaricato (Windows11InstallationAssistant.exe). Nota: potrebbe chiederti di scaricare e installare l'app "Controllo integrità PC" per un'ultima doppia verifica, fallo se te lo chiede.
  5. Accetta i termini di licenza e clicca su Accetta e installa.

A questo punto, l'Assistente farà tutto da solo. Inizierà il download in background di Windows 11 (puoi continuare a usare il PC nel frattempo), preparerà i file e, quando sarà pronto, ti chiederà di riavviare. Il riavvio richiederà un po' di tempo, simile a un grosso aggiornamento cumulativo, e al termine ti ritroverai direttamente sul nuovo desktop di Windows 11.

IT First Aid - Ep. 9 Windows Update stuck at 0% (or 100%)


Updates are vital for Cybersecurity and compliance. But what should you do when Windows Update freezes indefinitely?

1. Unblock the Service

The update engine is stuck. Open the Command Prompt as Administrator and type these two commands, pressing Enter after each:

net stop wuauserv
net start wuauserv

2. Clear Corrupted Cache

If restarting the service isn't enough, navigate to C:\Windows\SoftwareDistribution\Download. Delete everything inside this folder (not the folder itself!). Next time, Windows Update will start fresh.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 9 Windows Update bloccato


Gli aggiornamenti sono vitali per la Cybersecurity e la compliance normativa. Ma cosa fare quando Windows Update rimane "congelato" scaricando all'infinito?

1. Sbloccare il Servizio

Il motore degli aggiornamenti si è incantato. Apri il Prompt dei comandi (CMD) come Amministratore e digita questi due comandi in sequenza, premendo Invio dopo ciascuno:

net stop wuauserv
net start wuauserv

2. Svuotare la cache corrotta

Se il riavvio del servizio non basta, i file scaricati potrebbero essere corrotti. Naviga in C:\Windows\SoftwareDistribution\Download. Cancella tutto il contenuto di questa cartella (non la cartella stessa!). Al prossimo avvio, Windows Update ripartirà da zero con file puliti.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

Happy Easter! The Sysadmin's Easter Egg: Unlocking "God Mode" in Windows 11

I have decided to give my readers a typical gift, a kind of present typical of the IT and video game world: Easter Eggs.

In software development jargon, an Easter Egg is a hidden feature, message, or inside joke intentionally inserted by programmers into an operating system or application, or very often a hidden level or room in a video game. To find them, you need to know exactly where to look or what specific "ritual" of keys to execute.

Today, in keeping with the holiday theme, we are going to "unwrap" the ultimate Easter egg of Microsoft systems: Windows 11 God Mode.


What is "God Mode"?

The term "God Mode" originates from video games, indicating a cheat that makes the player invincible. On Windows, its actual technical name is the Windows Master Control Panel shortcut.

It is a special hidden folder that, once unlocked, acts as a centralized hub providing direct access to over 200 advanced system administration and configuration tools, bypassing the modern (and sometimes fragmented) Windows 11 Settings interface.

For a Systems Programmer or an IT Security Manager, it's an incredibly useful tool to have everything under control in a single window, from disk partitioning to advanced network management and local security policies.


How to unlock the secret menu (Tutorial)

The activation process is straightforward and does not require any dangerous Registry edits. You simply need to create a folder and assign it a specific Windows Globally Unique Identifier (GUID).

Here are the steps:

  1. Right-click on an empty spot on your Desktop (or any other directory where you want to place the menu).
  2. Select New > Folder.
  3. Now, select the newly created folder and press F2 to rename it.
  4. Copy and paste exactly the following string as the folder name:
GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}

Sysadmin note: the word "GodMode" before the dot can be replaced with any name you prefer (e.g., AdminTools.{ED7BA...}), but the alphanumeric string inside the curly brackets must remain intact.


The Result

As soon as you press Enter, you will see the folder icon change instantly: it will become identical to the legacy Control Panel icon, losing the text name you assigned to it.

Double-clicking on this new icon will open a window containing a massive list of shortcuts divided by category: Windows Tools, Credential Manager, Network and Sharing Center, BitLocker, Troubleshooting, and much more.

In an era where Microsoft is progressively hiding advanced settings in favor of a more "user-friendly" interface (which can be frustrating for power users), this Easter Egg remains an essential escape route for IT professionals.

Happy Easter and happy system hacking!

Buona Pasqua! L'Uovo di Pasqua dei Sistemisti: Sbloccare il "God Mode" su Windows 11

Ho deciso di fare ai miei lettori, un regalo tipico, un tipo di dono tipico dell'informatica e del mondo dei videogame: gli Easter Egg.

Nel gergo dello sviluppo software, un Easter Egg è una funzione nascosta, un messaggio o uno scherzo inserito intenzionalmente dai programmatori all'interno di un sistema operativo o di un'applicazione, o molto spesso un quadro o una stanza nascosta in un videogame. Per trovarli, bisogna sapere esattamente dove cercare o quale "rituale" di tasti eseguire.

Oggi, in tema con le festività, andiamo a "scartare" l'uovo di Pasqua per eccellenza dei sistemi Microsoft: il God Mode di Windows 11.


Cos'è il "God Mode"?

Il termine "God Mode" (Modalità Dio) deriva dal mondo dei videogiochi, dove indica un trucco che rende il giocatore invincibile. Su Windows, il suo vero nome tecnico è Windows Master Control Panel shortcut.

Si tratta di una speciale cartella nascosta che, una volta sbloccata, funge da hub centralizzato fornendo l'accesso diretto a oltre 200 strumenti di amministrazione e configurazione avanzata del sistema, bypassando le moderne (e a volte dispersive) interfacce delle Impostazioni di Windows 11.

Per un Programmatore Sistemista o un IT Security Manager, è uno strumento utilissimo per avere tutto sotto controllo in una singola finestra, dal partizionamento dei dischi alla gestione avanzata delle reti, fino alle policy di sicurezza locale.


Come sbloccare il menu segreto (Tutorial)

Il processo per attivarlo è semplicissimo e non richiede modifiche pericolose al Registro di Sistema. È sufficiente creare una cartella e assegnarle un codice identificativo univoco (GUID) specifico di Windows.

Ecco i passaggi:

  1. Fai clic col tasto destro in un punto vuoto del tuo Desktop (o in qualsiasi altra directory in cui desideri posizionare il menu).
  2. Seleziona Nuovo > Cartella.
  3. Ora, seleziona la cartella appena creata e premi F2 per rinominarla.
  4. Copia e incolla esattamente la seguente stringa come nome della cartella:
GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}

Nota sistemistica: la parola "GodMode" prima del punto può essere sostituita con qualsiasi nome tu preferisca (es. AdminTools.{ED7BA...}), ma la stringa alfanumerica tra parentesi graffe deve rimanere intatta.


Il Risultato

Appena premerai Invio, vedrai l'icona della cartella cambiare istantaneamente: diventerà identica a quella dello storico Pannello di Controllo, perdendo il nome testuale che le avevi assegnato.

Facendo doppio clic su questa nuova icona, ti si aprirà una finestra contenente un lunghissimo elenco di scorciatoie suddivise per categoria: Strumenti di Windows, Gestione credenziali, Centro connessioni di rete, BitLocker, Risoluzione dei problemi e molto altro.

In un'epoca in cui Microsoft sta progressivamente nascondendo le impostazioni avanzate a favore di un'interfaccia più "user-friendly" (spesso frustrante per i power user), questo Easter Egg rimane una via di fuga essenziale per noi professionisti IT.

Buona Pasqua e buon "hacking" dei sistemi!

Removing Duplicate SPNs in Active Directory


While monitoring system logs, a critical error was identified related to the Key Distribution Center (KDC). The logs flagged the presence of duplicate Service Principal Names (SPNs), an issue that can trigger non-secure authentication downgrades from Kerberos to NTLM or cause total connection failures to database instances.

Error Log:
"The KDC encountered duplicate names while processing a Kerberos authentication request. The duplicate name is MSSQLSvc/ZXCSY.local:1433"

Root Cause Analysis

In an Active Directory environment, an SPN must be unique and mapped to a single account (either user or computer). If the same SPN is registered across multiple objects, the Kerberos protocol cannot determine which cryptographic key to use for the service ticket, thus compromising the security of the transaction.

Technical Resolution Procedure

Step 1: Identifying Duplicates

Using the setspn command-line tool with the -F (forest-wide search) and -Q (query) flags, I located the conflicting accounts: setspn -F -Q MSSQLSvc/ZXCSY.local:1433


The output confirmed that the SPN was registered to both the ZXCSY computer account and a dedicated domain service account.

Step 2: Selecting the Correct Account

By checking the SQL Server service configuration via services.msc on the target server, I verified that the instance was running under a Domain User Account. Therefore, the SPN registered to the computer account was redundant and the primary cause of the conflict.

Step 3: Removing the Duplicate SPN

I proceeded to delete the incorrect entry from the computer account using the -D (Delete) parameter: setspn -D MSSQLSvc/ZXCSY.local:1433 ZXCSY

Conclusion and Verification

A follow-up query confirmed that the SPN is now exclusively associated with the service account. This resolution restored proper Kerberos authentication, eliminating insecure NTLM fallbacks and stabilizing infrastructure access for the SQL instance.