SpinfoSecurity

IT services · PowerShell · network triage

SpinfoSecurity

I unblock people with PowerShell triage, network checks, and tickets seniors can trust.

Public Windows-focused tools: ranked diagnosis, DNS honesty, clock skew, reachability matrices, and one-page escalations. Built for IT services teams that expect initiative and clean handoffs.

What I ship in public

Same pattern every time: measure, rank the cause, fix safely, prove it, escalate only when needed.

Primary · PowerShell · Windows · MIT

IT Triage Toolkit

Six scripts for second-line style endpoint work: Why-Broken ranks clock/DNS/disk/path failures; Dns-Truth catches resolver lies; Auth-Clock finds SSO-breaking skew; Reach-Matrix separates path vs app; Stack-Reset heals DNS/DHCP with before/after proof; Escalate-Smart writes a one-page brief for senior IT.

  • Rank, don’t dump

    Hypothesis #1 with evidence and a suggested fix—not a wall of ipconfig output.

  • Prove the fix

    Stack-Reset shows before/after metrics so reboot theater isn’t the default.

  • Escalate clean

    Impact, what you tried, evidence, one ask—so senior time isn’t wasted.

The IT Triage Toolkit turns everyday L2 judgment into runnable PowerShell: find the real blocker, fix what is safe, and hand senior IT a brief they can act on. ICS OT Protector applies the same discipline to authorized network reachability checks.


Additional · PowerShell + Bash · authorized TCP checks · MIT

ICS OT Protector

Defensive reachability scanners for industrial networks. Same craft as the triage toolkit: scripting, networking, structured findings, and clear authorized-use limits.

Knowledge base, not slide decks

IT services scales when answers live in searchable docs—not in someone’s head.


Self-service feed · CISA CSAF · RSS + JSON

ICS/OT Advisories

Search current industrial advisories by vendor or product, filter by severity, open the official write-up. Model for internal KB tooling: refreshable, filterable, linked to source of truth.


Runbook · install → safe defaults → report

Nmap for ICS/OT Security

Install steps, conservative timing, protocol command tables, and how to report findings. Written like an internal guide: clear steps, explicit “do not” list, no exploit payloads.

What you can verify in the repos

Skills you can verify by reading and running the public repos.

PowerShell
Windows endpoint triage scripts with clear output and safe opt-in fixes
Networking
DNS honesty checks, DHCP renew with proof, TCP reachability to critical services
Tickets & handoffs
Ranked hypotheses, already-tried checklists, one-page escalation briefs
Documentation
Runbooks and KB-style public docs that reduce repeat questions
Security hygiene
Authorized-use limits, no AD writes from laptop scripts, clear non-goals
Delivery
GitHub-hosted tools someone else can clone and run

Also in the work: Windows · TCP/IP · DNS · DHCP · SSO/clock skew awareness · GitHub

How I work

Signals that show up in the public repos—and in how the docs are written.

  • Hands-on

    Ship working CLIs and demos, not decks. Prefer a runnable path over a slide.

  • Concise and accurate

    Findings, limits, and next steps written so teammates can trust the handoff.

  • Prioritize the unblock

    Severity labels and remediation notes first—so the urgent path is obvious.

Find the work

Start with the PowerShell triage toolkit, then the ICS/OT scanners if you want more networking examples.

What this is—and is not

Is

Public PowerShell IT triage tooling, network reachability checks, and operator documentation you can review in code.

Is not

An exploit toolkit. Not Active Directory or IdP account automation. No unauthorized scanning.

Authorized use only. Do not run network scanners against systems without explicit asset-owner permission.