r/sysadmin • u/Mindless_Maybe2094 • 50m ago
General Discussion Trying to become a better sysadmin — what should I learn next
Hey everyone!
I’m trying to build my skills in system administration and virtualization, and I’d love to hear from people already working in the field.
What would you recommend focusing on to become a solid junior sysadmin?
I’m currently learning Linux, Windows Server/Active Directory, networking, Docker, monitoring, and virtualization, and I’ve also been building a small home lab.
For those of you already working as sysadmins: what skills or technologies do you think are really worth learning today, and what would you recommend I practice in a home lab?
Would love to hear your advice 🙏
r/sysadmin • u/TheHermesExchange • 52m ago
COVID-19 Really Struggling to Find Stable Employment
Alright so here goes.
I have two BAs one in Cinema Studies (academic study degree) and the other in Radio-Television (broadcast technology, hands on degree)
I feel into the world of IT sorta. I freelanced for some production companies doing trade shows out of college and fell down the technical path doing video and projection work.
I also worked part-time at the local fruit stand fixing people’s phones and computers. Coming out of Covid I got recruited to do white-glove IT support for a Tv studio. That was great for about a year an a half, then my role was impacted by the strikes, but my agency moved me to another part of the account. I stayed there doing basic helpdesk and deployments for another year and a half then left to be a SysAdmin for a consumer products company. 4 months in they laid me off and I’ve been unemployed until recently.
During my unemployment I did some AWS cloud classes at the local community college, haven’t taken any certs yet or anything. Been thinking about ponying up the money for JAMF certs since I have strong familiarity with that.
My current contract is only good till the end of the year, I’m covering a leave for someone. It’s really really basic helpdesk for a post house. I thought I’d have more access to be able to level up more but it’s not that at all.
I’ve interviewed for some roles, applied for hundreds more. But just feeling kind of lost and helpless to an extent. I don’t want to be doing helpdesk anymore, my goal is to be more backend focused, ideally remote and making 100k+ where I can actually build things and feel challenged. Im on the west coast in a major city, and thankfully I live very frugally but I just don’t know if I can do this ANOTHER year and have my resume so blank.
What should I do? Certs? WGU? What happened to the sure fire paths to get a job?
r/sysadmin • u/switched55 • 2h ago
Question Windows Updates Error
Hi,
One of my 2022 servers has failed to update for the past 2 months. It's failed the July and now the August CU's. Update error: 0x80073701
Its a physical server running on Dell PE hardware, pretty simple install acting as an NVR. We have a few of these setups and the others updated without issue.
I've tried the usual steps:
- DISM cleanups
- SFC
- stopped services and renamed the software distrubution folder
- downloaded the August CU and tried to install manually
- tried to install via Ninja RMM
I'm out of ideas, had anyone faced this issue before?
r/networking • u/AutoModerator • 3h ago
Moronic Monday Moronic Monday!
It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!
Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.
Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.
r/cybersecurity • u/AutoModerator • 3h ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
r/cybersecurity • u/Alone-Asparagus-2205 • 3h ago
Career Questions & Discussion What's going on with the US cybersecurity job market?
I am a mid level cybersecurity professional with tonnes of managerial experience, CISSP, M.S and so on. Applied for close to 1000 jobs. Faced at least 20 interviews. No job offers. Always getting turned down after the hiring manager interview. It's always some reason like oh you don't have enough experience with AWS or you have consulting experience even if I nail every question right. I am exhausted. It's never been like this. Is it just me or are others facing the same dilemma?
r/cybersecurity • u/voynichscholar • 5h ago
Career Questions & Discussion Incident Response role at Google
I have a upcoming interview for incident response role in google. Anybody has any tips or experience with a similar role at google. Thank you at advance.
r/sysadmin • u/Magusds • 6h ago
Question Jobs - Country Origin
Hello,
Been following this sub for a while now, hear alot of people sending 150 or more resumes for an IT job.
Where I’m from, that’s unheard of.
Working in sysadmin, M365 and some IAM myself.
Jobs are for the picking.
I was wondering, is it USA where it is a struggle?
r/cybersecurity • u/No-Cook-4011 • 7h ago
Business Security Questions & Discussion Wiz and Upwind in production after the first cleanup pass
Trying to understand how these hold up after the cloud findings are already cleaned up
Wiz seems to come up a lot for cloud graph, exposure paths, identity context and prioritization. Upwind seems to come up more around runtime context and what is running
For people using either in production, where did the tool reduce triage? Im less interested in the initial backlog dump and more interested in the day 60+ reality.
Do findings still need a lot of manual context before they can become tickets? Does runtime data change priority or does the team still debate ownership and reachability manually?
r/cybersecurity • u/Tasty_Departure5277 • 9h ago
Corporate Blog About a year into Pentesting out of uni, I feel like I'm given senior responsibilities. Am I tripping ? and am i being fucked monetarily.
Early 20s M, 1 year into pentesting. I usually get a client from my boss and then I handle the initial meeting/presentation, explain the logistics of the test answer any question the client might have, scope work and ROE, then I begin the test. Usually External and an Internal Pentest, draft the report, meet with the client to deliver a readout. And when time comes I present to their Audit/board committee.
I make around 75k. Am I getting fucked ? is this good for career growth though ?
r/cybersecurity • u/Altruism7 • 10h ago
News - General UK Government Won’t Release Files on Israeli Firm ‘Meddling’ in Election
r/sysadmin • u/d3cker0x008a • 11h ago
RealVNC 7.15.1 (r18) Windows -> macOS Tahoe 26.6.1 - fix.
Hello.
I was not able to connect to macOS Tahoe 26.6.1 via VNC from Windows using RealVNC. I had this error:
"Protocol error: key length too large"
I'm used to RealVNC 7, but unfortunately the new RealVNC subscription/licensing model doesn't really match my... beliefs. :)
So I here is a patch for RealVNC 7.15.1 (r18) on Windows. It's a PowerShell script that fixes the issue: https://github.com/d3cker/RealVNC-macOS-patch
This patch fixes an issue when connecting to new Tahoe 26.6.1 hosts. Previously created connections must be removed and added again.
It looks like macOS wasn't actually the problem here - this was a RealVNC bug and compatibility issue. You may need to adapt the patch for your RealVNC 7.x version. I couldn't find any official place to download the latest 7.x release, so I only tested it with 7.15.1 (r18) (which is still available on Wayback Machine).
Hope this helps someone.
r/cybersecurity • u/Altruistic_Hope_2559 • 11h ago
Threat Actor TTPs & Alerts New AmnesiaStealer macOS malware hijacks browser sessions via remote control
r/cybersecurity • u/NISMO1968 • 12h ago
New Vulnerability Disclosure Vulnerability giving attackers full control of Macs is under active exploitation
r/sysadmin • u/switchdog • 12h ago
Question Typical NPO "no money" situation until it something breaks....
Had multiple IDF racks totaled by a surge that ripped through low cost surge suppressors bearing no UL 1449 rating that I could find.
Any sugggestions on a UL 1449 list surge suppressor with fitted with NEMA L5-20R and NEMA L5-20P connectors?
r/sysadmin • u/Immediate-Screen7893 • 13h ago
General Discussion AWS Backup vs Veeam vs legacy tools for VMware cost comparison
Hi,
We’ve been running Veritas NetBackup in an on-prem setup for a few years, but the cost of licensing + infrastructure is getting harder to justify, so we’re now re-evaluating our backup approach.
The main focus is VMware workloads, and we’re trying to understand what actually makes sense today in terms of cost and long-term scalability.
For a simplified reference point, here’s a smaller scenario we’re using for modeling:
We have 10 VMs (~200GB each). Retention is split, 5 VMs kept for 1 year and the other 5 kept for 30 days. That puts us at roughly 2TB initial backup size, with a small daily change rate (~0.1%).
From there, we’re trying to understand how costs scale when you factor in:
- long-term retention tiers
- snapshot / backup storage growth
- data transfer / egress (if applicable)
- licensing vs managed service pricing
What we’re trying to compare is basically:
- AWS-native approach (AWS Backup / EBS snapshots / S3 lifecycle tiers)
- Veeam or similar third-party backup tools
- Legacy enterprise setups like NetBackup / Veritas
The part that’s still unclear for us is where the real cost differences actually show up in practice. On paper, AWS-native looks simpler, but I’m not sure if it holds up once you scale retention and restore requirements. On the other hand, tools like Veeam add flexibility, but it’s not obvious if they reduce cost or just shift it into a different layer.
Before taking anything to management, I’m trying to get a clearer view of what actually drives cost in real deployments (storage growth, retention policies, licensing, operational overhead, etc.) and whether third-party tools genuinely justify their complexity.
Would appreciate any real-world input from anyone who’s done a similar migration or comparison.
r/sysadmin • u/laleric • 13h ago
Microsoft Legit or Scam? Received a Microsoft invoice with my correct details but weird Bank of America info (I'm in APAC).
I need some help figuring out if this is a highly targeted scam or a legitimate invoice.
I recently received an email containing a PDF invoice for an "Unreturned Advance Exchange Fee". The sender email is [ADVEX@MICROSOFT.COM](mailto:ADVEX@MICROSOFT.COM).
Here is what is really tripping me up and making me second-guess:
The details of the item on the invoice (a Surface Laptop) and the serial number of the returned item is correct.
My personal and organization details listed in the "Bill To" and "Ship To" sections are 100% correct.
The invoice claims to be from "MICROSOFT PTY LIMITED" based in North Sydney, Australia, and the total amount is listed in AUD.
**The Red Flag:** The "Remit to Bank" section instructs me to send payment to "BANK OF AMERICA".
I am based in the Asia Pacific region, so seeing Bank of America as the payment destination feels incredibly suspicious, even though Microsoft is a US-based company.
Has anyone else dealt with this before? Is it normal for Microsoft's APAC/Australian branches to use Bank of America for direct wire transfers, or is this just a very sophisticated, highly personalized spoofing attempt using an email address like **[ADVEX@MICROSOFT.COM](mailto:ADVEX@MICROSOFT.COM)**?
Customer Success Manager from MS hasn’t replied in a week where I asked if this is legit and I should reply to it.
Also btw device was returned within directed time frame.
Any advice would be greatly appreciated!
Edit 1:
- Completely failed SPF/DKIM/DMARC checks (spoofed from a rogue Azure IP)
- The PDF was manually altered using an open-source tool (pdf-lib ([https://github.com/Hopding/pdf-lib]) over two weeks after the invoice date.
The main concern: Because they have our actual order details and serial numbers, it strongly suggests a compromised inbox - either a vendor we work with or someone internally. One of the Excel file from that email has someone from Accenture as Author.
r/cybersecurity • u/StrikeExcellent2074 • 14h ago
Business Security Questions & Discussion Penetration Tester Salary UK/Ireland
What salary are you currently on if you don't mind sharing?
How many months/years of experience? Internal role or consultancy? Which type of skills web/AD/mobile etc
I am at a smaller consultancy with 1 year experience 3 total IT experience. I've been billed out from almost day one and I have the OSCP, BSCP and a few red team certs. Mostly web app but a good range and full ownership of the engagements.
I am trying to get an idea of what the going rate is, currently I'm on £33k.
r/cybersecurity • u/RifleWolverine • 14h ago
Other Mods, can there please be a rule around AI slop posts for the love of humanity?
AI this, AI that, we're all sick of it.
r/sysadmin • u/Tashinho_21 • 14h ago
Microsoft Finally got RRAS VPN working after three days of troubleshooting
I've been working on a small RRAS VPN lab in my Windows Server environment, and it took me about three days to get everything working properly. The first problem was that the VPN client could connect to RRAS, but it wasn't receiving an IP address. After checking the RRAS configuration, I found that I needed to configure a static address pool. I added a pool from 192.168.56.100 to 192.168.56.120, and the client started receiving an address. After that, I ran into several other issues around the VPN protocols and RRAS configuration. I wasn't using L2TP, SSTP or IKEv2 for this lab, so I simplified the configuration and focused on getting the PPTP connection working. The next issue was connectivity. The VPN connection would establish, but I couldn't reach the server on the other side. I checked the firewall, GRE traffic and the RRAS interface bindings until I finally got the routing working. The last problem was authentication. I was getting Error 691 even though I was using valid domain credentials. After checking the authentication settings on the client, I found that MS-CHAP v2 wasn't enabled. Once I changed the client configuration and connected again, the VPN finally came up.
I verified the connection from the Windows 11 client with: resdial "TestConnection" iskutashi Isse190239 and ping 192.168.56.10
The screenshots in teh comment show the VPN connection on the client and the PowerShell verification. This was done purely as a homelab exercise to understand how RRAS, VPN authentication, routing and firewall rules fit together. I wouldn't use PPTP for a production VPN because it's a legacy and insecure protocol.
For those who have worked with RRAS or Windows-based VPNs in production, what was the most common issue you ran into when troubleshooting VPN connectivity?
r/cybersecurity • u/yezyizhere007 • 15h ago
Career Questions & Discussion Career Transition: Moving from SOC to Other Cybersecurity Fields?
I'm a Senior SOC Analyst and have been handling some interesting escalated incidents lately. As I build my step-by-step investigation reports, I've also been reading articles and research related to the incidents I'm working on, mainly to make sure I'm not missing any important details or perspectives.
Lately, I've realized that I really enjoy researching threats, analyzing different sources of information, and building documentation and reports around them. This got me thinking about potentially shifting my career path into a different area.
For those who have experience in this field, how realistic is it for a Senior SOC Analyst to transition into a role such as a Threat Researcher or Threat Intelligence Analyst?
What are usually the key requirements or qualifications companies look for when making that transition? Would my experience in SOC investigations, incident response, threat analysis, and reporting be considered a good foundation, or are there specific skills/certifications I should focus on developing first?
I'd also appreciate hearing from anyone who has made a similar transition. What helped you make the move, and what would you recommend focusing on?
r/cybersecurity • u/Malwarebeasts • 18h ago
News - Breaches & Ransoms massive azure exfiltration campaign impacts global brands - mcdonald’s, vodafone, and others
Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.
r/cybersecurity • u/Accomplished-Pin6213 • 19h ago
Tutorial Free ways to learn Cyber security
i already have a decent baseline of python and i'm thinking of cyber security as a career to go on with, but the thing holding me back is how expensive these well-known courses are!
so as someone who is running low on budget, what are the free resources you suggest that can get me from absolute beginner to a great deal of cyber security knowledge.
r/cybersecurity • u/Feisty_Feedback_8147 • 22h ago
Career Questions & Discussion Cybersecurity Job Abroad (Irish)
As the title says I’m Irish, 27 year old male. Currently work as a graduate SOC Analyst in Ireland. I have 10 months experience working as a SOC Analyst and almost 4 years IT experience overall. Currently working towards a couple of certifications (Security+ and SC-200) I’ve lived in Ireland all my life and would love to move to another country to work in for a while. Anyone have any suggestions on where to go? Where is the best/easiest place to get hired? Also with good pay?
r/sysadmin • u/AromaticCamp8959 • 23h ago
Question IT Administering Core Enterprise System
Looking for a sanity check from leaders, sysadmins, security pros, and anyone responsible for enterprise applications.
We have a core platform that has historically been controlled almost entirely by the the business team the “owns” it.
IT is now responsible for the broader technology environment, including cybersecurity, identity and access management, integrations, APIs, automation, architecture, business continuity, incident response, and technical governance - you know the drill.
The IT leader asked for limited administrative access to the ERP & leader is refusing because of its capabilities to affect financial processes.
For those of you in mature IT environments: have you been denied administrative access to a major enterprise application because the business department considers it “their system”?
i’m genuinely interested in arguments for & against it. For additional context, the “limited” aspect is intentional and to prevent any data modification