Domus Captures

A chronicle of the journey. Daily captures, meeting notes, plans, and reflections — organized by time, searchable by purpose, preserved forever.

Priorities

P0 — Critical / Blocking

Security & Compliance

  • ISE 3.2 Patch 10 upgrade — CVE-2026-20147 CVSS 9.9 / CVE-2026-20148. Propose maintenance window once patch confirmed on software.cisco.com.

  • ISE Advisory sa-ise-rce-traversal-8bYndVrZ — check Patch 10 availability

  • Mandiant Remediation — findings status tracked. Working session prep + defensive posture documented (comms-2026-04-24). Copy 4/16 updates into Excel at work. Guest ACL lockdown (WIR-M-01) pending lab validation. appendix-todos updated with MSCHAPv2 milestones.

  • Guest ACL update — guest redirect ACL work needed. Lab validate GUEST_CWA_REDIRECT_MAX_SECURITY in d000, then joint CR with NE. On today’s task list.

  • Disaster Recovery & Downtime Procedures — ISE top priority (dot1x closed mode = SPOF for network access)

    • ISE DR: Document failover sequence — PAN, MnT, PSN priority order

    • ISE DR: RADIUS dead-server detection on WLCs/switches — critical-auth VLAN fallback

    • ISE DR: Backup/restore procedures — scheduled config backups, tested restores

    • FTD/FMC DR: FMC loss = no policy management

    • Network DR: Core/distribution switch failure, STP reconvergence, HSRP failover

    • Document RTO/RPO per system

SIEM Migration (QRadar → Sentinel)

  • SIEM QRadar → Sentinel Migration — LEAD ROLE. 4 collection iterations (Apr 16, 17, 17-streamlined, 20-streamlined). Python chart pipeline built (qradar-charts.py). Migration XLSX generated. Verification pending. Comms sent Apr 23.

    • d001 artifacts: 8 JSON exports, 2 CSV inventories, migration XLSX, top5 source SVG/PNG, verification doc

    • Dependency: Monad pipeline for log source transition

    • Dependency: Sentinel KQL proficiency for query migration

  • Monad Pipeline Evaluation (origin: 2026-03-11) — lead role. Console error RESOLVED 05-12 — secrets configured in CHLA production tenant. Blocked on DCR creation (Rule ID + Stream Name). Azure private network policy unresolved. 10am call today 05-12.

  • Sentinel KQL — build proficiency, distinguish from team. Azure portal access acquired.

  • QRadar log source report — run AQL queries, fetch JSON, generate Python Excel

Active Deployments & Migrations

  • MSCHAPv2 Migration — Report due. 6-sheet Standard Report ready (Sheet 6: policy match by protocol added 05-14 for removal planning + anonymous identity validation on cert profiles). Migration window 5/4 – 5/30. 6,227 MSCHAPv2 devices, 14,249 EAP-TLS/TEAP (70% migrated). Focus: run Standard Report, turn in spreadsheet.

  • MSCHAPv2 weekly cadence — recurring Wednesday call established (first 04-22). Completed 2026-04-22.

  • MSCHAPv2 ownership matrix — sent in scoping email 4/24 with manager callouts (@Albert, @John). Completed 2026-04-24.

  • TCP Clocks deployment — new device added via ERS POST and confirmed (04-24). 7+ clocks validated. v2 query file with partials architecture. Revalidate full set — confirm no flapping.

  • SRT Research VLAN — confirm roles with Tony Sun: Tony implementor, Evan tester. CAB approved 04-21.

  • Downtime Computers enforcement — draft ISE AuthZ rule: medigate_724 + Wireless = DenyAccess. Separate CR. d001: DC queries, audit CSVs (v1-v3), wireless violations report delivered 04-21.

  • Enterprise Linux 802.1X — standardize Shahab/Ding deployment (CISO priority). Overdue since 02-24. Blocked by nmcli cert fix.

  • Abnormal Security — CR-2026-05-07-abnormal-read-write. CAB 05-12 approved, implementation 05-14. Jason Landeros implements, Evan presents. 06-01 update: Review Jihad’s policy mapping XLSX + Tyler’s Policy and Rules Migration doc before next call. Plan email migration expansion beyond security group to full environment — priority to move off ESA. Exchange rule considerations: external sender disclaimer (sender not company, outside org, not internal IP → prepend disclaimer).

    • Team: Cox/William, Landeros/Jason, Rosado/Evan, Naranjo/Mauricio, Sandoval/Carlos

Tube System Upgrade (NEW — 06-01)

  • Tube System Upgrade — iTrack 3528165. 15x 10" TS stations need MAC addresses added to ISE identity group IoT_Onboard. MACs received from vendor (C8:1A:FE:20:xx:xx series). Station list spans ICU (CTICU, PICU, BMT, NICU, NICCU), ED, Surgery, Trauma, Pharmacy. Vendor contact: John Genest. Rationale: manufacturer no longer supports current system; failure risks delayed/missed patient care.

BMS Device Inventory (NEW — 04-24)

  • BMS Device Inventory — 72 devices discovered across 37 switches (04-24). Profile-driven architecture (Claroty/Medigate). 16 queries built. Phase 0 complete. Next: cross-reference with Visio diagrams, classify by function, begin D2 diagrams. Cleanup: delete 4 orphaned test groups, migrate 4 retire-dACL devices, investigate 3 null-profile devices.

VNC Blocking (NEW — 05-11)

  • VNC Blocking — block and eliminate VNC enterprise-wide. Due mid-June 2026. Phase 0: discovery. January AQL query baseline to incorporate. Cross-reference BMS inventory for VNC-capable devices.

Investigations & Audits

  • Murus Portae (WAF) — Phase 0 discovery in progress. FMC cert expired. d001: DMZ NetScaler WAF investigation, zone map, architecture D2 diagrams (v1+v2 SVGs), FMC REST API reference guide, ops script. FMC API returning zero ACP rules — under investigation.

  • Firewall audit — FMC discovery inventory done (d001: fmc-discovery-2026-04-16). EtherChannel query, prefilter, policy assignments pending.

  • IoT Dr. Kim devices — RECURRING. All 4 MACs validated in IoT_iPSK_VLAN1620_Misc (04-24). v2 validation queries built with 7 deep analysis queries (group flapping, credential leakage, profile drift, NAS tracking, remediation timeline, deny audit, OUI scan). Revalidate — confirm no flapping since 04-24.

  • IoT device validation queries — v2 created with partials architecture, 16 queries across ERS/MnT/DataConnect/FMC. Completed 2026-04-24.

Stale Blockers (carried via carryover tracker)

  • k3s NAT verification — rule 170, 10.42.0.0/16 pod network (origin: 2026-03-09). 59 days. Blocks Wazuh indexer recovery → blocks SIEM visibility. Weekend task?

  • Strongline Gateway VLAN fix — 8 devices wrong identity group (origin: 2026-03-16). 52 days. David Rukiza assigned — follow up on status.

Administrative

  • PeopleSoft — track time for current week

  • iTrack tickets — close open tickets

  • KQL library — build initial queries in codex + d001

  • Linux Research project — finalize and review

  • Tax filing 2025 (MFJ) — see encrypted case file in data/d000/personal/ for details and action items

P1 — Important

  • MSCHAPv2 action-item tracker — owner/status/next-steps per workstream

  • ISE admin MFA enforcement — recommendation tied to advisory (interim control pending Patch 10)

  • DMZ Migration — external services audit behind NetScaler. Linked to Murus Portae investigation.

  • Vocera/Wyse iTrack RCA — complete root cause report

  • GCC ISE Support — 3/4 nodes restored, PSN-04 deferred

  • Wazuh indexer recovery — blocked by k3s NAT (origin: 2026-03-09)

  • Vocera EAP-TLS Supplicant Fix (origin: 2026-03-12)

  • iPSK Manager HA — blocked by DB replication (Ben Castillo)

  • ISE 3.4 Migration — depends on Patch 10 completion first

  • Git history scrub — murus-portae-output.md + ise-analytics CSVs

  • Encrypt prep-cmds-2026-04-15.adoc — plaintext committed to git

  • ISE MnT Messaging Service — enable UDP syslog delivery (maintenance window needed)

Infrastructure (Personal)

  • Borg backups — test and validate on ALL systems (Razer, P16g, vault-01, bind-01, kvm-01, kvm-02)

  • Borg — verify backup script paths updated from dotfiles-optimus to dots-quantum

  • Borg — create initial archive for ThinkPad P16g if none exists

  • Libvirt VLAN hook debug on both KVMs

  • Te1/0/2 cable replacement and re-test

  • Vault Raft cluster — verify vault-01 rejoined

  • Fix EAP-TLS keyring/secrets issue on Razer workstation

Completed (confirmed — do not delete, archive only)

  • CR-2026-04-15 SRT Research VLAN — submitted to iTrack. Completed 2026-04-15.

  • CAB presentation 4/21 — SRT Research VLAN 233 → CHLA-Research. APPROVED. Completed 2026-04-21.

  • Downtime Computers wireless audit — 45 computers, 16 violating, v3 report delivered. Completed 2026-04-21.

  • Git identity fix — dots-quantum/git/.gitconfig email corrected. Completed 2026-04-21.

  • MSCHAPv2 10:30 meeting — next steps + ACL coordination. Completed 2026-04-17.

Quick Access

Area Link Description

Codex

Bash · Python · Security · Git · Networking · xargs · jq · awk

CLI patterns and reference

Projects

All Projects · Portfolio (70 items) · Work Inventory

Active and archived projects

Trackers

Command Center · Q2 2026 · Subscriptions

Priorities, quarterly goals, carryover backlog

Patterns

All Patterns · API · Security · ISE · Shell · Networking

Reusable engineering patterns by domain

Case Studies

Incidents · Changes · RCA · TAC

Post-incident reviews and change records

Runbooks

All Runbooks · Arch Install · Email OAuth2

Operational procedures and templates

Operations

Operations · Weekly Review

Recurring operational tasks

Education

CISSP · RHCSA · Math

Certifications and learning tracks

Standards

STD-001 through STD-023

Governance, documentation, and operations standards

Competencies

13 Domains · Gap Analysis

Professional competency tracking

Reference

Dossier · Growth Report · Git Repos

Personal reference documents

Navigate by Time

Year Months Active Entries Status

2026

Jan - Jun

Active

Active

2025

Jan - Dec

Complete

Complete

Active Initiatives

Projects — Software & Tools

Initiative Description Status

domus-api

REST API — 44 endpoints, multi-spoke, FastAPI, filesystem-as-database

Active (Project)

domus-captures

Primary documentation spoke — 1,860 pages, repo audit in progress

Operational (Project)

netapi CLI

Multi-vendor network automation — ISE, Vault, VyOS, Monad, FMC, Infoblox

Active (Project)

Kora CLI

Universal API CLI — commercial-grade network automation

Active (Project)

domus-nvim

Neovim development configuration — Lua, LSP, DAP

Operational (Project)

dots-quantum

Dotfiles — 35+ stow packages, GNU Stow managed

Operational (Project)

tmux-quantum

tmux configuration — Catppuccin, session management

Validated (Project)

domus-antora-ui

Catppuccin theme UI bundle — 6 themes, Kroki, search

Active (Project)

Ollama Local

Local LLM inference — RTX 5090, qwen3:30b

Active (Project)

OpenCode

Open-source AI coding agent evaluation

Initial Setup (Project)

domus-asciidoc-build

Standalone AsciiDoc build toolchain — 5 HTML variants, 7 PDF themes, Antora auto-detection

Active (Project)

Projects — Infrastructure & Deployments

Initiative Description Status

ThinkPad P16g Deploy

Full Arch + AI stack — Phase 11 verification, Phase 12 security

In Progress (Project)

EVE-NG Lab

Network simulation lab — 8-phase rollout, image setup

In Progress (Project)

RHEL 9 Workstation

Dr. Shahab’s workstation — 12-phase deployment

In Progress (Project)

HA Deployment (kvm-02)

Vault HA, DNS HA, VyOS HA — multi-phase infrastructure rollout

In Progress (Phase 0 complete)

Secrets Vault

dsec CLI, gopass, age encryption, Vault PKI

Operational (Project)

Z Fold 7 Mobile

Termux + gopass + SSH — mobile engineering workflow

Operational (Project)

Worklog System

Daily capture framework — automation, templates, nav sync

Operational (Project)

Work (CHLA)

Initiative Description Status

CHLA Antora Setup

8-phase guide for deploying Antora documentation at work

Active (Project)

Mandiant Remediation

dACL enforcement, posture/ACL, ISE patch — Q2 assessment

Active (Project)

SIEM Migration

QRadar → Microsoft Sentinel — SDK integration phase

Active (Project)

ISE 3.4 Migration

ISE version upgrade planning

Planned (Project)

ISE Hardware Refresh

PSN/MnT hardware lifecycle replacement

Planned (Project)

MSCHAPv2 Migration

MSCHAPv2 → EAP-TLS migration for wired/wireless

Planned (Project)

iPSK Manager HA

High-availability iPSK manager deployment

Planned (Project)

Murus Portae (WAF)

Layer 7 WAF implementation — NetScaler AppFirewall + FTD IPS activation

Active — Discovery (Project)

Firewall Audit

FTD/FMC + ASA configuration & security audit via API

Active — Scoping (Project)

DMZ Migration

External services audit behind NetScaler reverse proxy

Active — Audit (Project)

Abnormal Security

O365 email security integration — read-only active

Active (Project)

Monad Evaluation

SIEM pipeline platform evaluation — lead role

Active (Project)

Research Segmentation

VLAN segmentation + firewall policy alignment

Active (Project)

Linux Research

Enterprise Linux deployment + 802.1X

Active (Project)

Downtime Computers

Cerner 724 wired-only enforcement — ISE DataConnect wireless audit

Active — Audit complete, enforcement pending (Project)

Disaster Recovery

DR procedures for ISE, firewalls, switches, WLCs, DNS, SIEM

Active — Scoping (Project)

Network Diagram Library

D2/Kroki enterprise network diagrams — version-controlled

Active — Scaffolding (Project)

Educational & Certifications

Initiative Description Status

CISSP

10-domain certification — Phase 0 in progress

Active (Project)

RHCSA

Red Hat system administration — 21-phase curriculum

In Progress (Project)

DELE C1/C2

Spanish certification — Don Quijote study, SIELE prep

Active (Project)

DevNet Associate

Cisco developer certification — Python, APIs, automation

Draft (Project)

CyberOps Associate

Cisco security operations certification

Draft (Project)

API CLI Mastery

jq/curl/awk/httpx — 6-level curriculum using domus-api

Complete (Codex)

Mathematics

College algebra, networking math, shell mathematics

Active (Education)

Terminal Mastery

awk, sed, jq, regex, find, grep — progressive skill tracks

Ongoing (Education)

System State Arena

Linux systems competition prep — Aug 22-24, 2026. 6 domains, air-gapped, man-pages-only

Active — Phase 0 (Project)

Documentation Ecosystem

Initiative Description Status

Standards Framework

STD-001 through STD-020 — governance, documentation, operations

Ongoing (Standards)

domus-docs Hub

Antora aggregator — playbook, multi-spoke deployment

Operational (Project)

domus-infra-ops

Infrastructure operations spoke — runbooks, deployments

Planned (Project)

domus-secrets-ops

Secrets management spoke — dsec, age, Vault docs

Planned (Project)

domus-gabriel-docs

Gabriel’s knowledge base and AsciiDoc learning

Active

reMarkable Workbooks

PDF generators for study materials — Spanish, regex, CLI, mastery

Active (Portfolio)

Recently Resolved

Initiative Description Resolution

IOT_WAN Incident

VPN passthrough blocked by firewall — IPsec ESP rules added

Resolved 2026-04-07 (INC)

HTTPie Evaluation

API testing platform — evaluated against curl+jq

Rejected (Rationale)

domus-api STD-001 Conformance

Restructured from 6 partials/4 pages to 11 partials/9 pages

Complete 2026-04-07 (Project)

Document Types

Prefix Purpose Count

WRKLOG-

Daily worklog — tasks, progress, blockers, learnings

63

CR-

Change requests — change control per STD-005

41

PRJ-

Project summaries — single-file project captures

35

TEMPLATE-

Templates — reusable document scaffolds

20

SESSION-

AI collaboration sessions — commits, agents, teaching points

17

REF-

References — command sheets, quick lookups

12

RCA-

Root cause analysis — incident postmortems per STD-010

12

INC-

Incident reports — issue tracking, resolution per STD-011

11

DEPLOY-

Deployment records — system deployments, migrations

8

PLAN-

Plans — roadmaps, strategies, learning paths

7

DOC-

Documents — research, analysis, deep dives

3

LRN-

Learning drafts — work-in-progress study notes

3

TAC-

TAC cases — vendor support documentation

2

MONTHLY-

Monthly summaries — month-end reviews

2

MONTH-

Monthly index pages — worklog month navigation

2

MTG-

Meeting notes — attendees, decisions, action items

1

SETUP-

Setup guides — configurations, installations

1

RETRO-

Retrospectives — weekly/monthly reflections

0

REPORT-

Reports — weekly progress, status summaries

1

PREP-

Preparation documents — pre-incident defense, readiness

1

INVENTORY-

Inventory captures — uncaptured priorities, asset tracking

1

YEAR-

Yearly index pages — worklog year navigation

1

Component Description Status

domus-captures

Worklogs, projects, case studies, patterns, codex, education — the primary spoke

Active (this repo)

enterprise-linux-802.1x

802.1X EAP-TLS deployment guide for Enterprise Linux

Active (local)

domus-gabriel-docs

Gabriel’s documentation and AsciiDoc learning

Active (local)

domus-docs

Antora aggregator hub — playbook, UI bundle config

Active (local)

domus-antora-ui

Catppuccin theme UI bundle — CSS, JS, Handlebars templates

Active (local)

Query all loaded spokes via domus-api: curl -s localhost:8080/components | jq

Philosophy

The unexamined day is not worth living. Every commit is a timestamp. Every capture is a memory.

— Evan Rosado

Sumergirme por entero en ello, abrazarlo y amarlo.

— Evan Rosado

Started: 2025 | Maintained by: Evan Rosado