02 // STACK
The toolbelt
Tools change. Fundamentals do not. Many vendors, layer by layer, and no loyalty to any of them beyond what works for you.
vendor-neutral, wide field of view
Many vendors, no allegiance. I recommend what fits your setup, budget, and team.
Years across many platforms mean I am not tied to one partner program. I compare the real options and tell you what each one costs you in money, effort, and lock-in.
- Cloud and identity
- MicrosoftAWSGoogle CloudCloudflare
- Network and security
- CiscoFortinetCheck PointAruba / HPEUbiquitiNetgate pfSense
- Compute and storage
- VMwareProxmoxHyper-V / Azure LocalNetAppLinuxDocker
- Backup and protection
- VeeamKeepitVeritasESETSophos
Six layers, hardware to AI
L6Automation and AI
- PowerShell
- Bash
- Python
- REST / Graph APIs
- n8n
- Git
- AI agents
- MCP servers
- RAG / embeddings
- Local LLMs
- Claude / Codex tooling
- LLM red teaming
L5Cloud
- Microsoft Azure
- Azure Arc
- Microsoft 365
- AWS
- Google Cloud
- Intune
- Exchange Online
- SharePoint
L4Identity and security
- Entra ID
- Active Directory
- Conditional Access
- Passkeys / FIDO2
- PIM
- Zero Trust
- ZTNA
- Cisco ISE
- Security baselines
L3Network
- Firewalls
- Segmentation
- NAC / 802.1X
- IPsec / site-to-site VPN
- VLANs
- Routing
- Load balancers
- Wi-Fi
L2Virtualization and storage
- VMware
- Proxmox
- Hyper-V
- Hyper-V failover clustering
- Azure Local (formerly Azure Stack HCI)
- Storage Spaces Direct
- Docker
- SAN / NAS
- Backup and replication
L1Infrastructure
- Windows Server
- Linux
- Domain controllers
- Rack, tower, and blade
- Homelab
- Open source
> ls --all ~/toolbeltfull arsenal, current and past
- Storage
- NetApp, IBM Storwize, HP 3PAR, JBOD / MegaRAID, Storage Spaces Direct
- Servers
- Rack, Tower, Blade, Windows Server, Linux
- Switching and routing
- Cisco, Aruba, HP, Netgate
- Wi-Fi
- Aruba, Aruba Central, Cisco, UniFi
- Firewalls
- pfSense, FortiGate, Cisco, Check Point
- VPN, SDP, and ZTNA
- IPsec / L2TP, OpenVPN, Cisco Secure Client (AnyConnect), WireGuard, Harmony SASE (Perimeter 81), Cloudflare One, Global Secure Access, Pangolin
- Network access control
- Cisco ISE, 802.1X, Posture, TrustSec
- Load balancers
- KEMP, Barracuda, Zevenet
- Web and caching
- Nginx, Apache, IIS, Varnish, Memcached, Cloudflare
- Databases
- MSSQL, MySQL, PostgreSQL, MaxScale clustering
- Virtualization and HCI
- VMware, Hyper-V, Hyper-V failover clustering, Azure Local (formerly Azure Stack HCI), Proxmox, Docker, WSL
- Microsoft platform
- Active Directory, Exchange, System Center, Entra ID, Intune
- Cloud
- Azure, Azure Arc, Microsoft 365, SharePoint, Exchange Online Protection, eDiscovery, AWS, Route 53 migrations, Google Cloud
- Backup
- Veeam, Keepit, Altaro, Veritas, IBM TSM, Ahsay
- Endpoint security
- Microsoft Defender for Endpoint, ESET, Heimdal, F-Secure, Webroot
- Mail security
- DMARC, Sophos, Vipre, Exchange Online Protection
- Monitoring and SIEM
- PRTG, RMM platforms, Microsoft Sentinel, Defender XDR
- VoIP
- Asterisk, FreeSWITCH
- AI and agents
- Claude Code, OpenAI Codex, Microsoft 365 Copilot, Open-source coding agents, MCP, llama.cpp, Qwen / Devstral / Gemma, Embeddings and RAG, n8n, garak, promptfoo
- Languages
- PowerShell, Python, PHP, Perl, C#, Java, Ruby, JavaScript, SQL, Bash
- Also
- SEO, Web analytics