Domus Captures
A chronicle of the journey. Daily captures, meeting notes, plans, and reflections — organized by time, searchable by purpose, preserved forever.
Priorities
P0 — Critical / Blocking
Security & Compliance
-
ISE 3.2 Patch 10 upgrade — CVE-2026-20147 CVSS 9.9 / CVE-2026-20148. Propose maintenance window once patch confirmed on software.cisco.com.
-
ISE Advisory sa-ise-rce-traversal-8bYndVrZ — check Patch 10 availability
-
Mandiant Remediation — findings status tracked. Working session prep + defensive posture documented (comms-2026-04-24). Copy 4/16 updates into Excel at work. Guest ACL lockdown (WIR-M-01) pending lab validation. appendix-todos updated with MSCHAPv2 milestones.
-
Guest ACL update — guest redirect ACL work needed. Lab validate GUEST_CWA_REDIRECT_MAX_SECURITY in d000, then joint CR with NE. On today’s task list.
-
Disaster Recovery & Downtime Procedures — ISE top priority (dot1x closed mode = SPOF for network access)
-
ISE DR: Document failover sequence — PAN, MnT, PSN priority order
-
ISE DR: RADIUS dead-server detection on WLCs/switches — critical-auth VLAN fallback
-
ISE DR: Backup/restore procedures — scheduled config backups, tested restores
-
FTD/FMC DR: FMC loss = no policy management
-
Network DR: Core/distribution switch failure, STP reconvergence, HSRP failover
-
Document RTO/RPO per system
-
SIEM Migration (QRadar → Sentinel)
-
SIEM QRadar → Sentinel Migration — LEAD ROLE. 4 collection iterations (Apr 16, 17, 17-streamlined, 20-streamlined). Python chart pipeline built (
qradar-charts.py). Migration XLSX generated. Verification pending. Comms sent Apr 23.-
d001 artifacts: 8 JSON exports, 2 CSV inventories, migration XLSX, top5 source SVG/PNG, verification doc
-
Dependency: Monad pipeline for log source transition
-
Dependency: Sentinel KQL proficiency for query migration
-
-
Monad Pipeline Evaluation (origin: 2026-03-11) — lead role. Console error RESOLVED 05-12 — secrets configured in CHLA production tenant. Blocked on DCR creation (Rule ID + Stream Name). Azure private network policy unresolved. 10am call today 05-12.
-
Sentinel KQL — build proficiency, distinguish from team. Azure portal access acquired.
-
QRadar log source report — run AQL queries, fetch JSON, generate Python Excel
Active Deployments & Migrations
-
MSCHAPv2 Migration — Report due. 6-sheet Standard Report ready (Sheet 6: policy match by protocol added 05-14 for removal planning + anonymous identity validation on cert profiles). Migration window 5/4 – 5/30. 6,227 MSCHAPv2 devices, 14,249 EAP-TLS/TEAP (70% migrated). Focus: run Standard Report, turn in spreadsheet.
-
MSCHAPv2 weekly cadence — recurring Wednesday call established (first 04-22). Completed 2026-04-22.
-
MSCHAPv2 ownership matrix — sent in scoping email 4/24 with manager callouts (@Albert, @John). Completed 2026-04-24.
-
TCP Clocks deployment — new device added via ERS POST and confirmed (04-24). 7+ clocks validated. v2 query file with partials architecture. Revalidate full set — confirm no flapping.
-
SRT Research VLAN — confirm roles with Tony Sun: Tony implementor, Evan tester. CAB approved 04-21.
-
Downtime Computers enforcement — draft ISE AuthZ rule: medigate_724 + Wireless = DenyAccess. Separate CR. d001: DC queries, audit CSVs (v1-v3), wireless violations report delivered 04-21.
-
Enterprise Linux 802.1X — standardize Shahab/Ding deployment (CISO priority). Overdue since 02-24. Blocked by nmcli cert fix.
-
Abnormal Security — CR-2026-05-07-abnormal-read-write. CAB 05-12 approved, implementation 05-14. Jason Landeros implements, Evan presents. 06-01 update: Review Jihad’s policy mapping XLSX + Tyler’s Policy and Rules Migration doc before next call. Plan email migration expansion beyond security group to full environment — priority to move off ESA. Exchange rule considerations: external sender disclaimer (sender not company, outside org, not internal IP → prepend disclaimer).
-
Team: Cox/William, Landeros/Jason, Rosado/Evan, Naranjo/Mauricio, Sandoval/Carlos
-
Tube System Upgrade (NEW — 06-01)
-
Tube System Upgrade — iTrack 3528165. 15x 10" TS stations need MAC addresses added to ISE identity group IoT_Onboard. MACs received from vendor (C8:1A:FE:20:xx:xx series). Station list spans ICU (CTICU, PICU, BMT, NICU, NICCU), ED, Surgery, Trauma, Pharmacy. Vendor contact: John Genest. Rationale: manufacturer no longer supports current system; failure risks delayed/missed patient care.
BMS Device Inventory (NEW — 04-24)
-
BMS Device Inventory — 72 devices discovered across 37 switches (04-24). Profile-driven architecture (Claroty/Medigate). 16 queries built. Phase 0 complete. Next: cross-reference with Visio diagrams, classify by function, begin D2 diagrams. Cleanup: delete 4 orphaned test groups, migrate 4 retire-dACL devices, investigate 3 null-profile devices.
VNC Blocking (NEW — 05-11)
-
VNC Blocking — block and eliminate VNC enterprise-wide. Due mid-June 2026. Phase 0: discovery. January AQL query baseline to incorporate. Cross-reference BMS inventory for VNC-capable devices.
Investigations & Audits
-
Murus Portae (WAF) — Phase 0 discovery in progress. FMC cert expired. d001: DMZ NetScaler WAF investigation, zone map, architecture D2 diagrams (v1+v2 SVGs), FMC REST API reference guide, ops script. FMC API returning zero ACP rules — under investigation.
-
Firewall audit — FMC discovery inventory done (d001: fmc-discovery-2026-04-16). EtherChannel query, prefilter, policy assignments pending.
-
IoT Dr. Kim devices — RECURRING. All 4 MACs validated in IoT_iPSK_VLAN1620_Misc (04-24). v2 validation queries built with 7 deep analysis queries (group flapping, credential leakage, profile drift, NAS tracking, remediation timeline, deny audit, OUI scan). Revalidate — confirm no flapping since 04-24.
-
IoT device validation queries — v2 created with partials architecture, 16 queries across ERS/MnT/DataConnect/FMC. Completed 2026-04-24.
Stale Blockers (carried via carryover tracker)
-
k3s NAT verification — rule 170, 10.42.0.0/16 pod network (origin: 2026-03-09). 59 days. Blocks Wazuh indexer recovery → blocks SIEM visibility. Weekend task?
-
Strongline Gateway VLAN fix — 8 devices wrong identity group (origin: 2026-03-16). 52 days. David Rukiza assigned — follow up on status.
Administrative
-
PeopleSoft — track time for current week
-
iTrack tickets — close open tickets
-
KQL library — build initial queries in codex + d001
-
Linux Research project — finalize and review
-
Tax filing 2025 (MFJ) — see encrypted case file in
data/d000/personal/for details and action items
P1 — Important
-
MSCHAPv2 action-item tracker — owner/status/next-steps per workstream
-
ISE admin MFA enforcement — recommendation tied to advisory (interim control pending Patch 10)
-
DMZ Migration — external services audit behind NetScaler. Linked to Murus Portae investigation.
-
Vocera/Wyse iTrack RCA — complete root cause report
-
GCC ISE Support — 3/4 nodes restored, PSN-04 deferred
-
Wazuh indexer recovery — blocked by k3s NAT (origin: 2026-03-09)
-
Vocera EAP-TLS Supplicant Fix (origin: 2026-03-12)
-
iPSK Manager HA — blocked by DB replication (Ben Castillo)
-
ISE 3.4 Migration — depends on Patch 10 completion first
-
Git history scrub — murus-portae-output.md + ise-analytics CSVs
-
Encrypt
prep-cmds-2026-04-15.adoc— plaintext committed to git -
ISE MnT Messaging Service — enable UDP syslog delivery (maintenance window needed)
Infrastructure (Personal)
-
Borg backups — test and validate on ALL systems (Razer, P16g, vault-01, bind-01, kvm-01, kvm-02)
-
Borg — verify backup script paths updated from dotfiles-optimus to dots-quantum
-
Borg — create initial archive for ThinkPad P16g if none exists
-
Libvirt VLAN hook debug on both KVMs
-
Te1/0/2 cable replacement and re-test
-
Vault Raft cluster — verify vault-01 rejoined
-
Fix EAP-TLS keyring/secrets issue on Razer workstation
Completed (confirmed — do not delete, archive only)
-
CR-2026-04-15 SRT Research VLAN — submitted to iTrack. Completed 2026-04-15.
-
CAB presentation 4/21 — SRT Research VLAN 233 → CHLA-Research. APPROVED. Completed 2026-04-21.
-
Downtime Computers wireless audit — 45 computers, 16 violating, v3 report delivered. Completed 2026-04-21.
-
Git identity fix — dots-quantum/git/.gitconfig email corrected. Completed 2026-04-21.
-
MSCHAPv2 10:30 meeting — next steps + ACL coordination. Completed 2026-04-17.
Quick Access
| Area | Link | Description |
|---|---|---|
Codex |
Bash · Python · Security · Git · Networking · xargs · jq · awk |
CLI patterns and reference |
Projects |
Active and archived projects |
|
Trackers |
Priorities, quarterly goals, carryover backlog |
|
Patterns |
All Patterns · API · Security · ISE · Shell · Networking |
Reusable engineering patterns by domain |
Case Studies |
Post-incident reviews and change records |
|
Runbooks |
Operational procedures and templates |
|
Operations |
Recurring operational tasks |
|
Education |
Certifications and learning tracks |
|
Standards |
Governance, documentation, and operations standards |
|
Competencies |
Professional competency tracking |
|
Reference |
Personal reference documents |
Navigate by Time
| Year | Months Active | Entries | Status |
|---|---|---|---|
Jan - Jun |
Active |
Active |
|
Jan - Dec |
Complete |
Complete |
Active Initiatives
Projects — Software & Tools
| Initiative | Description | Status |
|---|---|---|
domus-api |
REST API — 44 endpoints, multi-spoke, FastAPI, filesystem-as-database |
Active (Project) |
domus-captures |
Primary documentation spoke — 1,860 pages, repo audit in progress |
Operational (Project) |
netapi CLI |
Multi-vendor network automation — ISE, Vault, VyOS, Monad, FMC, Infoblox |
Active (Project) |
Kora CLI |
Universal API CLI — commercial-grade network automation |
Active (Project) |
domus-nvim |
Neovim development configuration — Lua, LSP, DAP |
Operational (Project) |
dots-quantum |
Dotfiles — 35+ stow packages, GNU Stow managed |
Operational (Project) |
tmux-quantum |
tmux configuration — Catppuccin, session management |
Validated (Project) |
domus-antora-ui |
Catppuccin theme UI bundle — 6 themes, Kroki, search |
Active (Project) |
Ollama Local |
Local LLM inference — RTX 5090, qwen3:30b |
Active (Project) |
OpenCode |
Open-source AI coding agent evaluation |
Initial Setup (Project) |
domus-asciidoc-build |
Standalone AsciiDoc build toolchain — 5 HTML variants, 7 PDF themes, Antora auto-detection |
Active (Project) |
Projects — Infrastructure & Deployments
| Initiative | Description | Status |
|---|---|---|
ThinkPad P16g Deploy |
Full Arch + AI stack — Phase 11 verification, Phase 12 security |
In Progress (Project) |
EVE-NG Lab |
Network simulation lab — 8-phase rollout, image setup |
In Progress (Project) |
RHEL 9 Workstation |
Dr. Shahab’s workstation — 12-phase deployment |
In Progress (Project) |
HA Deployment (kvm-02) |
Vault HA, DNS HA, VyOS HA — multi-phase infrastructure rollout |
In Progress (Phase 0 complete) |
Secrets Vault |
dsec CLI, gopass, age encryption, Vault PKI |
Operational (Project) |
Z Fold 7 Mobile |
Termux + gopass + SSH — mobile engineering workflow |
Operational (Project) |
Worklog System |
Daily capture framework — automation, templates, nav sync |
Operational (Project) |
Work (CHLA)
| Initiative | Description | Status |
|---|---|---|
CHLA Antora Setup |
8-phase guide for deploying Antora documentation at work |
Active (Project) |
Mandiant Remediation |
dACL enforcement, posture/ACL, ISE patch — Q2 assessment |
Active (Project) |
SIEM Migration |
QRadar → Microsoft Sentinel — SDK integration phase |
Active (Project) |
ISE 3.4 Migration |
ISE version upgrade planning |
Planned (Project) |
ISE Hardware Refresh |
PSN/MnT hardware lifecycle replacement |
Planned (Project) |
MSCHAPv2 Migration |
MSCHAPv2 → EAP-TLS migration for wired/wireless |
Planned (Project) |
iPSK Manager HA |
High-availability iPSK manager deployment |
Planned (Project) |
Murus Portae (WAF) |
Layer 7 WAF implementation — NetScaler AppFirewall + FTD IPS activation |
Active — Discovery (Project) |
Firewall Audit |
FTD/FMC + ASA configuration & security audit via API |
Active — Scoping (Project) |
DMZ Migration |
External services audit behind NetScaler reverse proxy |
Active — Audit (Project) |
Abnormal Security |
O365 email security integration — read-only active |
Active (Project) |
Monad Evaluation |
SIEM pipeline platform evaluation — lead role |
Active (Project) |
Research Segmentation |
VLAN segmentation + firewall policy alignment |
Active (Project) |
Linux Research |
Enterprise Linux deployment + 802.1X |
Active (Project) |
Downtime Computers |
Cerner 724 wired-only enforcement — ISE DataConnect wireless audit |
Active — Audit complete, enforcement pending (Project) |
Disaster Recovery |
DR procedures for ISE, firewalls, switches, WLCs, DNS, SIEM |
Active — Scoping (Project) |
Network Diagram Library |
D2/Kroki enterprise network diagrams — version-controlled |
Active — Scaffolding (Project) |
Educational & Certifications
| Initiative | Description | Status |
|---|---|---|
CISSP |
10-domain certification — Phase 0 in progress |
Active (Project) |
RHCSA |
Red Hat system administration — 21-phase curriculum |
In Progress (Project) |
DELE C1/C2 |
Spanish certification — Don Quijote study, SIELE prep |
Active (Project) |
DevNet Associate |
Cisco developer certification — Python, APIs, automation |
Draft (Project) |
CyberOps Associate |
Cisco security operations certification |
Draft (Project) |
API CLI Mastery |
jq/curl/awk/httpx — 6-level curriculum using domus-api |
Complete (Codex) |
Mathematics |
College algebra, networking math, shell mathematics |
Active (Education) |
Terminal Mastery |
awk, sed, jq, regex, find, grep — progressive skill tracks |
Ongoing (Education) |
System State Arena |
Linux systems competition prep — Aug 22-24, 2026. 6 domains, air-gapped, man-pages-only |
Active — Phase 0 (Project) |
Documentation Ecosystem
| Initiative | Description | Status |
|---|---|---|
Standards Framework |
STD-001 through STD-020 — governance, documentation, operations |
Ongoing (Standards) |
domus-docs Hub |
Antora aggregator — playbook, multi-spoke deployment |
Operational (Project) |
domus-infra-ops |
Infrastructure operations spoke — runbooks, deployments |
Planned (Project) |
domus-secrets-ops |
Secrets management spoke — dsec, age, Vault docs |
Planned (Project) |
domus-gabriel-docs |
Gabriel’s knowledge base and AsciiDoc learning |
Active |
reMarkable Workbooks |
PDF generators for study materials — Spanish, regex, CLI, mastery |
Active (Portfolio) |
Recently Resolved
| Initiative | Description | Resolution |
|---|---|---|
IOT_WAN Incident |
VPN passthrough blocked by firewall — IPsec ESP rules added |
Resolved 2026-04-07 (INC) |
HTTPie Evaluation |
API testing platform — evaluated against curl+jq |
Rejected (Rationale) |
domus-api STD-001 Conformance |
Restructured from 6 partials/4 pages to 11 partials/9 pages |
Complete 2026-04-07 (Project) |
Document Types
| Prefix | Purpose | Count |
|---|---|---|
|
Daily worklog — tasks, progress, blockers, learnings |
63 |
|
Change requests — change control per STD-005 |
41 |
|
Project summaries — single-file project captures |
35 |
|
Templates — reusable document scaffolds |
20 |
|
AI collaboration sessions — commits, agents, teaching points |
17 |
|
References — command sheets, quick lookups |
12 |
|
Root cause analysis — incident postmortems per STD-010 |
12 |
|
Incident reports — issue tracking, resolution per STD-011 |
11 |
|
Deployment records — system deployments, migrations |
8 |
|
Plans — roadmaps, strategies, learning paths |
7 |
|
Documents — research, analysis, deep dives |
3 |
|
Learning drafts — work-in-progress study notes |
3 |
|
TAC cases — vendor support documentation |
2 |
|
Monthly summaries — month-end reviews |
2 |
|
Monthly index pages — worklog month navigation |
2 |
|
Meeting notes — attendees, decisions, action items |
1 |
|
Setup guides — configurations, installations |
1 |
|
Retrospectives — weekly/monthly reflections |
0 |
|
Reports — weekly progress, status summaries |
1 |
|
Preparation documents — pre-incident defense, readiness |
1 |
|
Inventory captures — uncaptured priorities, asset tracking |
1 |
|
Yearly index pages — worklog year navigation |
1 |
Related Components
| Component | Description | Status |
|---|---|---|
domus-captures |
Worklogs, projects, case studies, patterns, codex, education — the primary spoke |
Active (this repo) |
enterprise-linux-802.1x |
802.1X EAP-TLS deployment guide for Enterprise Linux |
Active (local) |
domus-gabriel-docs |
Gabriel’s documentation and AsciiDoc learning |
Active (local) |
domus-docs |
Antora aggregator hub — playbook, UI bundle config |
Active (local) |
domus-antora-ui |
Catppuccin theme UI bundle — CSS, JS, Handlebars templates |
Active (local) |
Query all loaded spokes via domus-api: curl -s localhost:8080/components | jq
|
Philosophy
The unexamined day is not worth living. Every commit is a timestamp. Every capture is a memory.
Sumergirme por entero en ello, abrazarlo y amarlo.
Started: 2025 | Maintained by: Evan Rosado