[{"content":" About Me # Hi, I\u0026rsquo;m Pralaya — a Technical Consultant, working across Microsoft 365, Azure, Entra ID, security automation, and PowerShell.\nI run this homelab to test and document the kind of infrastructure I work with professionally — networking, virtualization, identity, and security — in a space where I can break things safely and write up what I learn.\nAnd yes this summary was written by AI.\nBackground # Microsoft Certified Trainer (MCT) since 2021, currently working toward Microsoft MVP Certifications: GCIH, GSEC, AZ-104, with AZ-800/801, Linux+, SC-300, MS-700, AZ-500, MD-102, and MS-102 in progress or upcoming Enrolled in the SANS MSISE master\u0026rsquo;s program This homelab # Built and documented here to track:\nNetworking — VLANs, DNS, firewall rules Infrastructure — Proxmox, Docker hosts Windows Lab — Active Directory, Entra ID, Intune Security — hardening notes, audit findings Runbooks — step-by-step recovery procedures Elsewhere # Blog: journalctl.io — PowerShell Basics and Graph API for Sysadmins series ","externalUrl":null,"permalink":"/hello-world/","section":"Hello World","summary":"About Me # Hi, I’m Pralaya — a Technical Consultant, working across Microsoft 365, Azure, Entra ID, security automation, and PowerShell.\nI run this homelab to test and document the kind of infrastructure I work with professionally — networking, virtualization, identity, and security — in a space where I can break things safely and write up what I learn.\n","title":"Hello World","type":"hello-world"},{"content":" 📚 Explore all posts 💻 GitHub Profile 🎓 MSISE Journey 🖥️ Homelab Site ","date":"27 July 2026","externalUrl":null,"permalink":"/","section":"","summary":" 📚 Explore all posts 💻 GitHub Profile 🎓 MSISE Journey 🖥️ Homelab Site ","title":"","type":"page"},{"content":"Technical Consultant, based in Brisbane, Australia.\nMCT (Microsoft Certified Trainer) since 2021. Currently completing an MSISE at SANS Technology Institute with a 4.0 GPA.\nFocus areas: Microsoft 365, Azure, Entra ID, Security Automation, and PowerShell.\nBlogging at JournalCTL — technical, direct, no-fluff content for the sysadmin and security community.\n","date":"27 July 2026","externalUrl":null,"permalink":"/about/","section":"","summary":"Technical Consultant, based in Brisbane, Australia.\nMCT (Microsoft Certified Trainer) since 2021. Currently completing an MSISE at SANS Technology Institute with a 4.0 GPA.\nFocus areas: Microsoft 365, Azure, Entra ID, Security Automation, and PowerShell.\nBlogging at JournalCTL — technical, direct, no-fluff content for the sysadmin and security community.\n","title":"About","type":"page"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/posts/","section":"Blog","summary":"","title":"Blog","type":"posts"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/tags/giac/","section":"Tags","summary":"","title":"GIAC","type":"tags"},{"content":"TL;DR\nGIAC exams are open-book, but time pressure requires a fast, searchable index to pass cleanly. A proven 4-phase indexing workflow (Read, Capture, Refine, Test) used to score 90%+ on GSEC and GCIH. Focus on high-value keywords, exact command syntaxes, and book page numbers over long summaries. Open-book sounds like a gift. In practice, it isn\u0026rsquo;t; not if you haven\u0026rsquo;t built a proper GIAC index before walking in.\nGIAC exams are timed, scenario-heavy, and cover material spread across five or more books. If you\u0026rsquo;re stopping to flip through a book every few questions, you\u0026rsquo;ll run out of time long before you run out of questions. As a result, the open-book format rewards people who built an index, not people who skimmed the material and assumed they could just look things up.\nI\u0026rsquo;ve sat two GIAC exams - GSEC and GCIH - scored 90%+ on both, and used the same indexing system for both. This is that system. I\u0026rsquo;m currently building the index for GSTRT, and the workflow is unchanged.\nWhy a Good GIAC Index Changes Everything # The goal of an index is not to replace studying. Instead, it\u0026rsquo;s to eliminate the need to open a book during the exam. When you\u0026rsquo;ve already internalized the concepts and just need to confirm a command syntax, a page reference, or a specific step - that\u0026rsquo;s a three-second index lookup, not a two-minute book hunt.\nThe index also forces you to study. Building it means reading every page, every lab, every cheat sheet, and deciding what matters enough to capture. Consequently, that process is where most of the learning actually happens.\nI first came across a structured approach to GIAC indexing through Tisiphone\u0026rsquo;s guide on GIAC testing. I adapted the format over two exams and refined it based on what I actually needed during practice tests. What\u0026rsquo;s below is the version that works for me.\nThe GIAC Index Format # I use Google Sheets. Single file, one tab per exam, sorted alphabetically A-Z. The columns:\nColumn What goes here Keyword The term, tool name, command, concept, or topic you\u0026rsquo;d search for Book Book number (e.g. Book 1, Book 4) Page Page number(s) Description One-line summary with enough context to confirm you\u0026rsquo;re in the right place Command / Syntax Exact command-line syntax where applicable Notes Lab references, mind map links, cross-references to related entries The 4-Phase Indexing Workflow # Phase 1: First Pass (Reading \u0026amp; Initial Capture) # As you complete your first pass of course books or OnDemand videos, log entries directly into Google Sheets. Focus on key tools, syntax, protocols, and architectural concepts.\nPhase 2: Lab Audit \u0026amp; Command Capture # Go through lab workbooks. Ensure every command parameter, tool flag, and syntax variation is explicitly captured in the Command / Syntax column.\nPhase 3: Practice Test 1 \u0026amp; Gap Analysis # Take Practice Test 1 using your digital index on a secondary monitor. Note down every search term that failed or took longer than 10 seconds to locate.\nPhase 4: Final Refinement \u0026amp; Printing # Alphabetize A-Z, format for clean printing with column header rows on every page, print double-sided, and bind into a spiral notebook or tabbed binder.\nWrapping Up # The index doesn’t replace knowing the material — it extends what you can reliably recall under time pressure. Build it seriously, test it twice, and walk into exam day knowing exactly where to find anything you might need. I’ve used this system for GSEC and GCIH. I’m using it again for GSTRT, and the format is unchanged — only the content is different.\n","date":"22 March 2026","externalUrl":null,"permalink":"/posts/giac-indexing-system/","section":"Blog","summary":"TL;DR\nGIAC exams are open-book, but time pressure requires a fast, searchable index to pass cleanly. A proven 4-phase indexing workflow (Read, Capture, Refine, Test) used to score 90%+ on GSEC and GCIH. Focus on high-value keywords, exact command syntaxes, and book page numbers over long summaries. Open-book sounds like a gift. In practice, it isn’t; not if you haven’t built a proper GIAC index before walking in.\nGIAC exams are timed, scenario-heavy, and cover material spread across five or more books. If you’re stopping to flip through a book every few questions, you’ll run out of time long before you run out of questions. As a result, the open-book format rewards people who built an index, not people who skimmed the material and assumed they could just look things up.\n","title":"How to Build a GIAC Index That Actually Works","type":"posts"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/tags/sans/","section":"Tags","summary":"","title":"SANS","type":"tags"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/series/sans-msise-journey/","section":"Series","summary":"","title":"SANS MSISE Journey","type":"series"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/tags/sans-msise-journey/","section":"Tags","summary":"","title":"SANS MSISE Journey","type":"tags"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","date":"22 March 2026","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":"","date":"15 March 2026","externalUrl":null,"permalink":"/tags/powershell/","section":"Tags","summary":"","title":"PowerShell","type":"tags"},{"content":"","date":"15 March 2026","externalUrl":null,"permalink":"/series/powershell-basics/","section":"Series","summary":"","title":"PowerShell Basics","type":"series"},{"content":"TL;DR\nExperts don\u0026rsquo;t memorize thousands of cmdlets â€” they use the built-in help system. Always run Update-Help -Force as administrator to download local help documentation. Master the 4-step terminal discovery pattern: Get-Command, help, help -Parameter, help -Examples. Experts don\u0026rsquo;t memorise thousands of PowerShell commands. Don Jones and Jeff Hicks cite a study in Learn PowerShell in a Month of Lunches â€” two groups of IT pros, beginners and experts, sat a written test on PowerShell. Scores were similar across both groups. Then they ran the test again with access to a running PowerShell session. The gap between the two groups became significant. The difference? Experts knew how to use the help system to find answers on the fly.\nThe PowerShell help system is not documentation you read once and forget â€” it\u0026rsquo;s a tool you use every single session.\nPrerequisites # PowerShell 7+ installed (see Post #1) Administrator rights on your machine (required for Update-Help) Internet access for initial help download Update Your Help Files First # Before running any Get-Help examples in this post, download the latest help files. Without this step, many commands return incomplete output or no content at all. Run this as administrator:\nUpdate-Help -Force Some modules throw errors during the update â€” that\u0026rsquo;s expected. It means the module author didn\u0026rsquo;t configure updatable help. Ignore those and move on. Run this periodically as PowerShell modules update.\nOffline Machines (Save-Help) # If working in an air-gapped environment, use Save-Help on a connected machine, then copy the files across:\n# On the internet-connected machine Save-Help -DestinationPath C:\\PSHelp # On the offline machine (as administrator) Update-Help -SourcePath C:\\PSHelp Exploring Cmdlet Documentation with Get-Help # Get-Help is your first stop when you don\u0026rsquo;t know how a command works, what parameters it accepts, or what it returns.\nGet-Help -Name Get-Service The output is structured into key sections:\nNAME The command name SYNOPSIS One-line summary SYNTAX Available parameter sets DESCRIPTION Detailed explanation RELATED LINKS Online documentation \u0026amp; related cmdlets 1. Viewing Full Documentation # help Get-Service -Full 2. Viewing Command Examples # help Get-Service -Examples 3. Inspecting Parameter Details # help Get-Service -Parameter ComputerName Finding Commands with Get-Command # When you don\u0026rsquo;t know the exact cmdlet name, search by Verb, Noun, or wildcard pattern using Get-Command:\n# Find all cmdlets with Noun \u0026#39;Service\u0026#39; Get-Command -Noun Service # Find all cmdlets with Verb \u0026#39;Get\u0026#39; Get-Command -Verb Get -Module Microsoft.Graph.Users # Search by wildcard name pattern Get-Command -Name *User* -CommandType Cmdlet The Terminal Discovery Pattern # # Step 1: Discover candidate commands Get-Command -Noun Service # Step 2: Learn how to use a candidate cmdlet help Get-Service -Full # Step 3: Check specific parameter details help Get-Service -Parameter ComputerName # Step 4: Inspect real-world examples help Get-Service -Examples Wrapping Up # Command Purpose Key Parameter / Syntax Update-Help Download or refresh local help files -Force, -SourcePath help View interactive paged help documentation -Full, -Examples, -Parameter Get-Command Search for cmdlets by name pattern or noun/verb -Noun, -Verb, -Module Get-Help about_* Read conceptual PowerShell topics \u0007bout_Execution_Policies, \u0007bout_Pipelines ","date":"15 March 2026","externalUrl":null,"permalink":"/posts/powershell-help-system/","section":"Blog","summary":"TL;DR\nExperts don’t memorize thousands of cmdlets â€” they use the built-in help system. Always run Update-Help -Force as administrator to download local help documentation. Master the 4-step terminal discovery pattern: Get-Command, help, help -Parameter, help -Examples. Experts don’t memorise thousands of PowerShell commands. Don Jones and Jeff Hicks cite a study in Learn PowerShell in a Month of Lunches â€” two groups of IT pros, beginners and experts, sat a written test on PowerShell. Scores were similar across both groups. Then they ran the test again with access to a running PowerShell session. The gap between the two groups became significant. The difference? Experts knew how to use the help system to find answers on the fly.\n","title":"PowerShell Basics #2: The Help System","type":"posts"},{"content":"TL;DR\nPowerShell is a cross-platform, object-oriented shell \u0026amp; scripting language for Windows, Linux, and macOS. Install PowerShell 7+ Core via Winget alongside Windows Terminal for the optimal command-line experience. Understand the difference between legacy Windows PowerShell 5.1 and modern cross-platform PowerShell 7+. PowerShell is a command-line shell and scripting language from Microsoft for Windows, Linux, and macOS. It helps automate administrative tasks and manage infrastructure cleanly.\nCommand-line shell: Interactive prompt with tab completion \u0026amp; predictive IntelliSense Scripting language: Write complete, reusable scripts (.ps1) to automate complex workflows Object-oriented: Commands (cmdlets) pass rich .NET objects through the pipeline, not raw text strings Cross-platform: Runs on Windows, Linux, and macOS (PowerShell 7+) Windows PowerShell 5.1 vs. PowerShell 7+ # Feature Windows PowerShell 5.1 PowerShell 7+ (Core) Underlying Engine .NET Framework (Windows only) .NET 8+ (Cross-platform) Supported OS Windows 7 / 10 / 11 / Server Windows, Linux, macOS Performance Standard High performance \u0026amp; parallel pipeline (ForEach-Object -Parallel) Executable Name powershell.exe pwsh.exe Note: Windows PowerShell 5.1 comes built into Windows and will remain for backward compatibility. Modern automation should target PowerShell 7+ (pwsh.exe).\nInstalling PowerShell 7+ \u0026amp; Windows Terminal # Step 1: Install PowerShell 7 via Winget # Open Command Prompt or Windows PowerShell and run:\nwinget install --id Microsoft.PowerShell --source winget Step 2: Install Windows Terminal # Windows Terminal provides tabbed sessions, custom HSL color schemes, and GPU-accelerated text rendering:\nwinget install --id Microsoft.WindowsTerminal --source winget Step 3: Verify Version # Launch Windows Terminal, open a new PowerShell tab, and check $PSVersionTable:\nSystem.Collections.Hashtable Expected output:\nName Value ---- ----- PSVersion 7.4.x PSEdition Core OS Microsoft Windows 10.0.22631 Wrapping Up # Concept / Tool Purpose Command / Path PowerShell 7+ Modern cross-platform shell engine pwsh.exe Winget Windows Package Manager for automated setup winget install Microsoft.PowerShell Windows Terminal Modern host application for command-line tools winget install Microsoft.WindowsTerminal System.Collections.Hashtable Automatic variable checking PowerShell edition \u0026amp; version $PSVersionTable.PSVersion ","date":"5 February 2026","externalUrl":null,"permalink":"/posts/get-started-with-powershell/","section":"Blog","summary":"TL;DR\nPowerShell is a cross-platform, object-oriented shell \u0026 scripting language for Windows, Linux, and macOS. Install PowerShell 7+ Core via Winget alongside Windows Terminal for the optimal command-line experience. Understand the difference between legacy Windows PowerShell 5.1 and modern cross-platform PowerShell 7+. PowerShell is a command-line shell and scripting language from Microsoft for Windows, Linux, and macOS. It helps automate administrative tasks and manage infrastructure cleanly.\nCommand-line shell: Interactive prompt with tab completion \u0026 predictive IntelliSense Scripting language: Write complete, reusable scripts (.ps1) to automate complex workflows Object-oriented: Commands (cmdlets) pass rich .NET objects through the pipeline, not raw text strings Cross-platform: Runs on Windows, Linux, and macOS (PowerShell 7+) Windows PowerShell 5.1 vs. PowerShell 7+ # Feature Windows PowerShell 5.1 PowerShell 7+ (Core) Underlying Engine .NET Framework (Windows only) .NET 8+ (Cross-platform) Supported OS Windows 7 / 10 / 11 / Server Windows, Linux, macOS Performance Standard High performance \u0026 parallel pipeline (ForEach-Object -Parallel) Executable Name powershell.exe pwsh.exe Note: Windows PowerShell 5.1 comes built into Windows and will remain for backward compatibility. Modern automation should target PowerShell 7+ (pwsh.exe).\n","title":"PowerShell Basics #1: Setting Up Your Environment","type":"posts"},{"content":"","date":"1 February 2026","externalUrl":null,"permalink":"/tags/gcih/","section":"Tags","summary":"","title":"GCIH","type":"tags"},{"content":"TL;DR\nThe SANS GCIH (SEC504) covers incident response, hacker techniques, exploits, and live forensics. Preparation requires an in-depth index, hands-on workbook auditing, and strategic practice test timing. Passed at 90%+ score as part of the SANS Technology Institute Master\u0026rsquo;s Degree program. Passing the SANS GCIH (SEC504) exam was one of the most challenging yet rewarding experiences in my cybersecurity journey. As part of my master\u0026rsquo;s degree program at SANS, I tackled this comprehensive incident handling certification.\nHere is my complete preparation strategy, indexing workflow, and exam day retrospective.\nWhy GCIH (SEC504)? # The GCIH (GIAC Certified Incident Handler) certification is a core milestone in SANS\u0026rsquo; Master\u0026rsquo;s Degree Program. The SEC504 course (Hacker Techniques, Exploits \u0026amp; Incident Handling) provides hands-on proficiency in detecting, responding to, and mitigating security incidents across enterprise environments.\nKey Domains Covered: # Incident Handling \u0026amp; Response Procedures: PICERL framework (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) Computer \u0026amp; Network Vulnerabilities: Password attacks, web application exploits, session hijacking Live System Forensics: Memory analysis, persistence detection, log analysis with PowerShell \u0026amp; Linux CLI Course Materials \u0026amp; Preparation Strategy # I opted for the OnDemand course format, allowing flexible video playback and lab repetitions. The course package included:\n5 Main Course Textbooks: Comprehensive technical theory and command references. Lab Workbooks \u0026amp; Virtual Machines: Hands-on exercises covering Wireshark, Volatility, Metasploit, and PowerShell forensic scripts. 2 Practice Exams: Official GIAC practice tests simulating actual exam timing and questions. The Indexing Strategy # Building a custom Google Sheets index was the single most important preparation activity.\nMy Index Schema: # Column Purpose Keyword Tool name, attack technique, or protocol Book / Page Book number and exact page reference (e.g. B2 P145) Description Concise summary of the concept Command / Syntax Exact command line syntax and flags Full Strategy here: How to Build a GIAC Index That Actually Works\nExam Day Retrospective \u0026amp; Key Takeaways # Time Management: Keep moving. Don\u0026rsquo;t spend more than 2 minutes on a multiple-choice question before flagging or looking up in your index. Lab Questions First Pass: Perform lab questions carefully; they carry significant score weight. Index Trust: Trust your index lookup over browsing books randomly during the exam session. Wrapping Up # Milestone / Strategy Description Key Action SEC504 OnDemand 6-section course video \u0026amp; lab training Complete all labs twice Google Sheets Index Alphabetized term \u0026amp; syntax reference Print double-sided \u0026amp; tab Practice Test 1 Initial test run with index Identify missing keywords Practice Test 2 Final timed dry-run Finalize physical index binding ","date":"1 February 2026","externalUrl":null,"permalink":"/posts/my-journey-to-gcih-certification/","section":"Blog","summary":"TL;DR\nThe SANS GCIH (SEC504) covers incident response, hacker techniques, exploits, and live forensics. Preparation requires an in-depth index, hands-on workbook auditing, and strategic practice test timing. Passed at 90%+ score as part of the SANS Technology Institute Master’s Degree program. Passing the SANS GCIH (SEC504) exam was one of the most challenging yet rewarding experiences in my cybersecurity journey. As part of my master’s degree program at SANS, I tackled this comprehensive incident handling certification.\n","title":"My Journey to GCIH Certification","type":"posts"},{"content":"","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"}]