# TechnoLitero — full public text > Practical field notes for admins, builders, and curious tinkerers Public content only. Generated from live published notes, pages, downloads, resources, and tools. Index: https://www.technolitero.com/llms.txt --- ## Pages # About TechnoLitero - URL: https://www.technolitero.com/about - Markdown: https://www.technolitero.com/raw/about The public notebook for Unifi, Meshtastic, local AI, and PowerShell that solves a real admin problem.

This site focuses on small projects that were designed for learning at home. I have a thirst for knowledge and in my professional life can't learn these things in production. I want to understand how things work so I lab it out, break it, fix it and then write how I do it. You get some insight into my processes, the way I think and plan out small projects. I am an Infrastructure Architect by trade and have been in the field for a long time. I support Open Source software, sharing my knowledge on topics that I find interesting.

Software I build lives on GitHub and on the [downloads](https://www.technolitero.com/downloads) page. External references — Unifi, Meshtastic, packet tools, AI products — stay on the [resources](https://www.technolitero.com/resources) list so they can be updated without hunting through old posts. - [GitHub](https://github.com/Technolitero) for source and releases - [Contact](https://www.technolitero.com/contact) for site owner details - [Privacy policy](https://www.technolitero.com/privacy) for advertising and cookies --- # Contact - URL: https://www.technolitero.com/contact - Markdown: https://www.technolitero.com/raw/contact Reach the author about an article, a download, or the privacy policy. **Buddy** — Infrastructure Architect TechnoLitero is a personal technical blog. Use this page if you need to reach the author about an article, a download, or the privacy policy. GitHub is the public channel for software and issues — [github.com/Technolitero](https://github.com/Technolitero). - [About](https://www.technolitero.com/about) - [Privacy Policy](https://www.technolitero.com/privacy) - [Downloads](https://www.technolitero.com/downloads) --- # Home - URL: https://www.technolitero.com - Markdown: https://www.technolitero.com/raw/home Field notes for Unifi, Meshtastic, local AI, and PowerShell — written to be useful the same day you read them. ## Tech Decoded. IT can feel complicated, but it clicks the moment you understand how things are actually supposed to work. This is a collection of hands-on personal projects exploring how systems connect under the hood. We don't just look at the how, we tear into the why, when you anchor your work in real use cases and find meaning in what you build, the complexity turns into fun. If you have ten minutes, pick a lane below or jump straight into the featured note.

Get the architectural mindset alongside the messy reality: real hardware, actual commands, and the design missteps I had to debug along the way. If you want to learn how to think strategically and build from the ground up, pick a lane below or dive straight into the featured note.

## Different Paths. Open the one you are already on. - [Networking](https://www.technolitero.com/topics/networking): Unifi, firewalls, and the field notes that keep networks stable without overthinking them. - [Meshtastic](https://www.technolitero.com/topics/meshtastic): Off-grid messaging, private meshes, MQTT, and the practical setups that actually work on real property. - [AI](https://www.technolitero.com/topics/ai): Local models, context engineering, and using AI as a thought partner instead of a search bar. - [PowerShell](https://www.technolitero.com/topics/powershell): Scripts, automation, and admin tooling published for others to reuse and extend. - [Learning](https://www.technolitero.com/topics/learning): Get started with IT thinking, dive into thought processes that allow you to grow as an engineer. - [Hardware](https://www.technolitero.com/topics/hardware): Hardware doesn't need to be hard. Projects and notes to simplify deployment. ## Recent field notes - [Repurposing a Surface HUB 1](https://www.technolitero.com/blog/repurposing-a-surface-hub-1): I enjoy figuring out how to make locked down hardware useful after its use case is no longer a thing. A few months ago I was gifted a Surface Hub 1..... - [Building a WebSite with AI](https://www.technolitero.com/blog/building-a-website-with-ai): I am a fan of WordPress but I am also a fan of using the newest tools, my lab for example does run Beta versions just so I can get access to the latest features. So what's a guy to do when I hear that AI can build a website in 10 minutes... - [Learning in IT - Find a use case](https://www.technolitero.com/blog/learning-in-it-find-a-use-case): I'm going to go through my thought process for a project I recently completed and that is repurposing a Unifi Cloud Key Plus as a standalone docker host..... - [Learning in IT - Think like an Architect](https://www.technolitero.com/blog/learning-in-it-think-like-an-architect): There are many qualities in a great Engineer and an Architect. I would say that in my experience I have worked with many Engineers that could become Architects if they wanted to. The expectations.... - [Local AI on a Budget](https://www.technolitero.com/blog/local-ai-on-a-budget): One of my many side projects is using Local AI but like most, I’m on a budget. Smaller models act like smaller models — until you stop treating them as one giant brain. - [The Modern Engineering Stack: Moving Beyond the Search Bar](https://www.technolitero.com/blog/the-modern-engineering-stack-moving-beyond-the-search-bar): AI is quickly becoming an accelerator for more things than just Google searches. Copilot, Claude, OpenAI, and Gemini each earn a different seat in the stack. - [Learning AI – The Basics](https://www.technolitero.com/blog/learning-ai-the-basics): Let’s be honest with ourselves, AI is one of the greatest things since the internet. The question is what you offload, and how you stay in control of the result. - [Getting the most out of AI, starts with you!](https://www.technolitero.com/blog/getting-the-most-out-of-ai): Prompt engineering is one of the most misunderstood issues with AI for the masses. I asked for a screwdriver, not a therapist. ## Tools I built because the article was not enough - [Unifi Analyzer](https://www.technolitero.com/downloads/unifi-analyzer): A Windows tool that pulls Unifi UDM configuration over the API and SSH so you can analyze, export, capture packets, and keep config history. - [PowerShell Public Scripts](https://www.technolitero.com/downloads/powershell-public): Public PowerShell scripts from the TechnoLitero toolkit. Clone the repo, take what you need, and keep the rest out of your production path until you have tested it. - [Meshtastic Notes](https://www.technolitero.com/downloads/meshtastic-notes): Companion notes and configs for Meshtastic work: private meshes, MQTT, and the hardware paths that actually get used. ## Around the notes, not instead of them. The blog is the reason this site exists. These doors are here because a note needed a tool, a link, a file, or a locked drawer. - [Resources](https://www.technolitero.com/resources): The Unifi, Meshtastic, GitHub, and vendor links I actually keep around instead of burying them in old posts. - [Media](https://www.technolitero.com/media): Music and video from the library. Public folders play without an account; the rest waits for a sign-in. - [Members](https://www.technolitero.com/subscribe): Prompts, code notes, the vault, and the mind map. Subscribe or ask for a grant if that door should be open. - [About](https://www.technolitero.com/about): An infrastructure architect’s public notebook. Contact and privacy live next to it when you need the boring pages. New notes land on the [blog](https://www.technolitero.com/blog) and in [RSS](https://www.technolitero.com/feed). If you want the locked drawers — prompts, code notes, the vault — start at [subscribe](https://www.technolitero.com/subscribe) or [sign in](https://www.technolitero.com/login). I am [Buddy](https://www.technolitero.com/about), infrastructure architect. The source lives on [GitHub](https://github.com/Technolitero). --- # Privacy Policy - URL: https://www.technolitero.com/privacy - Markdown: https://www.technolitero.com/raw/privacy What this site collects, including advertising cookies if AdSense is enabled. Last updated August 15, 2026. This page exists so you know what is collected here, including advertising cookies if AdSense is enabled. ## Who runs this site TechnoLitero is operated by Buddy, infrastructure architect. The site publishes technical articles, software downloads, and links to public resources, including GitHub. Questions about this policy can be sent through the [GitHub organization](https://github.com/Technolitero) or the [contact page](https://www.technolitero.com/contact). ## What this site collects The public pages are a blog. They do not require an account. The admin area is private and used only to publish content. Server logs may include IP address, browser type, and the pages requested, which is normal for hosting. ## Google AdSense This site may show third-party advertising through Google AdSense. Google uses cookies and similar technologies to serve and measure ads. Google's use of advertising cookies is described in [How Google uses information from sites or apps that use our services](https://policies.google.com/technologies/ads). - [Google Ad Settings](https://adssettings.google.com/) - [Opt out of personalized advertising](https://www.google.com/settings/ads/anonymous) ## Cookies Advertising cookies may be set by Google when AdSense is enabled. A separate session cookie is used only if you log into the site. The public blog does not use that cookie. ## Third-party links Articles and the resources page link to GitHub, Unifi, Meshtastic, vendors, and other sites. Those sites have their own privacy practices. This policy only covers TechnoLitero. ## Children This site is written for working admins and builders. It is not directed at children under 13, and we do not knowingly collect personal information from children. ## Changes If the advertising setup or the way this site handles data changes, this page will be updated and the date at the top will change. --- ## Blog # Repurposing a Surface HUB 1 - URL: https://www.technolitero.com/blog/repurposing-a-surface-hub-1 - Markdown: https://www.technolitero.com/raw/repurposing-a-surface-hub-1 - Date: 2026-08-19 - Author: Buddy - Topic: Hardware I enjoy figuring out how to make locked down hardware useful after its use case is no longer a thing. A few months ago I was gifted a Surface Hub 1.....

I enjoy figuring out how to make locked down hardware useful after its use case is no longer a thing. A few months ago I was gifted a Surface Hub 1. It's a 55-inch touch screen with pen input made specifically for Microsoft Teams. I went through Microsoft's recommendation, which was to use Replacement PC Mode. It worked and I could've stopped there. I had a large touchscreen the input worked, it ran Windows, but I also had a computer that was eating power that was doing nothing. That didn't set well with me, so what's a tech guy supposed to do? I opted for working around the issue, removing the standard OS and choosing Linux since it was free and to be honest once I saw it boot from the USB drive and installed it once.... even though it wouldn't boot I figured it was just the screwy way they locked it down.

I ran into a few issues along the way. The BIOS is locked down and all I would've had to do was unlock the BIOS and turn off secure boot and install Linux. Unfortunately, you can only do that with help from Microsoft Support and while they were gracious once the equipment was End of Support last year, they deleted the tool that would allow you to unlock the device. So that was a bust, next I thought well maybe I can move GRUB to a USB and boot from it and then have it run from the hard drive. Ugly I know, I didn't feel good about it and fortunately that didn't work either even though at the time I was disappointed I had to persist. This came down to a restricted secure boot issue, with an extra handful of custom UEFI weirdness and a problem that I was determined to fix, I mean how hard could it be right? Queue the tutorials, somebody must've done it before... and nope. I was on my own.... or was I. I had a piece of hardware that new was over 10K, locked down like the BIOS was in prison. So, I did what most IT Pro's do today, asked my favorite AI and it lied to me and caused more problems than it was worth. So, I asked another AI, OpenAI to be specific and was up and running in a couple of hours. I followed the instructions and when things didn't work, I refined my prompt, tested and worked through the issue like I have done for a very long time. My pain is now your guide, I only have the one Surface Hub but these directions should get you closer if not work out of the gate. The beauty of it is that you can get a Surface Hub 1 for next to nothing and have a portable touchscreen running Ubuntu Linux in a couple of hours. [Surface_Hub_1_Ubuntu_24.04_Standalone_Build](https://www.technolitero.com/storage/Resources/a5ccedf7-Surface_Hub_1_Ubuntu_24.04_Standalone_Build.docx) --- # Building a WebSite with AI - URL: https://www.technolitero.com/blog/building-a-website-with-ai - Markdown: https://www.technolitero.com/raw/building-a-website-with-ai - Date: 2026-08-17 - Author: Buddy - Topic: AI I am a fan of WordPress but I am also a fan of using the newest tools, my lab for example does run Beta versions just so I can get access to the latest features. So what's a guy to do when I hear that AI can build a website in 10 minutes... I am a fan of WordPress but I am also a fan of using the newest tools, my lab for example does run Beta versions just so I can get access to the latest features. So what's a guy to do when I hear that AI can build a website in 10 minutes that rivals what a Web Developer can do in months. Well if you're like me you have to test that hypothesis. ## Design I already had a live site and to be honest didn't want to recreate everything and also liked the layout. I decided to use Cursor for this one, the main reason is that I had a ton of tokens I hadn't used and was running low on Codex. So I simply asked Cursor to build a site based off of my current one, I used this prompt and it started working its magic. I would like you to interview me for rebuilding a website building for a site, it is going to be a blog site mainly, I want visitors to use code blocks that I have defined, and download software I have created. Allow for linking to external sources such as GitHub and I want to be able to update it similar to how WordPress works. I want a modern feel and content based on my own website www.technolitero.com I know this wasn't the cleanest of prompts but it kicked out a halfway decent site. It was fully functional in 10 minutes but lacking in many areas. I told it what I wanted when I didn't really know how to explain what that meant. Some pages were hard coded, the editor wasn't great but I liked the layout and how it functioned otherwise. I asked for a pretty site, it put lipstick on a pig. I could of just left it and dealt with it, it worked mostly but I like production systems so I had to refine it. ## Testing and Refining You have to think of yourself as a junior Engineer, your job is not necessarily to create but to run through what is delivered and see what works well and what doesn't, you are in effect QA but less experienced with code. I did several iterations until it was pretty good. I can edit the pages, they save in a standard format. The features and code blocks I needed were placed in the correct locations and was almost as good as WordPress without the need for WordPress. I still have some refining to do but all in all I think it came out pretty good. My best advice is to be happy when you feel its complete and keep refining until you're happy with the results. ## Security There are two things I have seen as an Architect, deployment scalability and security are rarely thought about by developers. It doesn't matter how many times you tell them they wait until the end.... in my case so did I. Luckily we have AI now and its doing all the work. When you get past the functionality piece ther are two things I like to do. The first is to tell AI that you want it scan the code for any security vulnerabilities and the second is to refactor the code. This helps clean it up and remove things that'll bite you in the future. AI is also good for suggesting things that you don't see, I'm not an experienced developer and while I know more on the security side that is not my daily job. AI can help with this. The last thing you want is someone putting NSFW content on your site. In my case I run it behind Cloudflare so I can run it any where not just in the cloud. Cloudflare is great for this and allows caching and some access rule options as well. ## Deployment The site is done, local testing is complete and now you have to decide how you want to deploy it. I decided on Docker Compose, this allows me to spin it up anywhere but does add a little complexity. AI to the rescue, I had it create my YAML and package the container. How you plan on it working is vital to a few things, first how easy is it to update and maintain, secondly what is your comfort level with the technology running the site. AI is good at a lot of things but right now, this is your responsibility. Troubleshooting is harder in a container, deployment is easier you just have to know the differences and align around it. ## Testing Now that it was deployed I ran through live testing, Docker had permissions that needed aligned but all in all it was pretty seamless. Everything worked as it did locally and based on feedback I gave AI the site workflow improved. ## Final Thoughts The site you are on was created by AI, refined by AI, and the deployment was configured by AI. So where does that leave people like me. You have to be the person building the product as more of a Product Manager. AI doesn't have context unless you give it that context. You have to be able to tell it where the gaps are, that is your job. AI can do much of the heavy lifting but it is not all knowing. Testing is also critical, AI will do what you tell it to but it doesn't understand basic human workflows completely so if you don't want a bad product don't just take its first iteration. All in all my 10 minutes gave me a site, 8 hours gave me a production site that would've taking me much longer doing it myself if even possible. I know have a site that I can change any way I want, that works as a CMS and allows me to add options that WordPress would have a hard time with such as layout. AI is a tool, use it as such, be the master craftsman that knows what you want and do your best to explain what that is. --- # Learning in IT - Find a use case - URL: https://www.technolitero.com/blog/learning-in-it-find-a-use-case - Markdown: https://www.technolitero.com/raw/learning-in-it-find-a-use-case - Date: 2026-08-16 - Author: Buddy - Topic: Learning I'm going to go through my thought process for a project I recently completed and that is repurposing a Unifi Cloud Key Plus as a standalone docker host..... I'm going to go through my thought process for a project I recently completed and that is repurposing a Unifi Cloud Key Plus as a standalone docker host.  I won't go into the details but how I worked through it.  I didn't need a docker host, I have plenty of them but I liked that it was POE and figured I could make something cool out of it.  So where do you start, I followed my standard process that I have outlined below.  When I received the Cloud Key, I knew I didn't have a need for one.  My network has it built in to the UDM Pro Max I own but I hate having hardware go unused if I could find a way to reuse it, especially POE capable computers that have a built in hard drive. Thought Process: - Identify the use case: in my case it was to use it as a standalone docker host that I could use for network tools.  I wanted something that was portable, performant and customizable as I built new tools or found Docker containers that just simply worked. - Identify what you are working with: In this case it was an ARM processor with 3GB of RAM, not powerful but would work for my needs.  - Identify what information is already out there:  I know how to install Docker, I know Linux but in this case it was a locked down device with a custom firmware which makes getting this done a little more complicated.  Searching using Google or Reddit typically will take you down the path to get something done.  AI helps with that but like many of you have already figured out, AI is trained on old Data so the searches might get you what you need it could be the old way of doing things. - Try following the path that others have carved: In my case there was a little information out there on how to get it working. Working is just part of the issue, the Cloud Key is a great piece of tech but due to the custom firmware the boot files and the software installs went to a standard EMMC drive and I was concerned that too many writes would eventually wear down the drive. I decided that writing to the SSD I installed was a much better option long term. - Use your life experiences as a guide:  I have been working with Linux for decades, I like the OS but its not for beginners even though either its gotten a lot better or I have.  In any case I knew I could move things around to not only save space but also get Docker off of the EMMC and onto the SSD.  Queue the research... I found others who had felt the same way and had created scripts to pull all of the Unifi software off. I found software on Github that had drivers for the screen and updated refreshes it at a set interval based on what I have installed as well a web page that can monitor ports your Docker containers are running on and allow you to click on to launch to their web interfaces.(HTTP only unfortunately) - Have fun:  I find playing around with a new project once its complete opens a whole new can of use cases.  Once you have it running the gaps are glaring.  Sure it functions but wouldn't it be cool if it did this.... always comes to mind. - Make it better:  So now I have a Cloudkey that I can plug into a POE port and run Docker containers on that save everything to a 1TB SSD.  The next question is what can I do with it.  I decided on the following containers.  Containers: - Guacamole: This allows for remote access through a webpage for SSH and RDP. - WireShark: Why not? I can look at packets, the Cloud Key has a USBC port and you can plug another adapter into it or just use the built in Ethernet. - SMB Files:  I wanted a Web Interface to copy files to and from that was portable and easy to use wherever I needed it. - NetAlertX: Network scanning tool for longer runs, this shows whats actively using your network. I could do this with Wireshark but this lays it out better for longer runs. - UnifiAnalyzer: This is a tool I created to pull Unifi information off a UDM, allow /var/message streaming etc... - SpeedTest: Allow for testing up to 1GB speeds using the Cloud Key from another machine. - Chromium: Allows me to get to management web sites internally using the Cloud Key.

The most important thing that I can tell you is to stay curious, rely on your past experiences and question what can you do to make things better. A project is almost never complete, learning is never done and things you weren't aware of 6 months ago now are possible.

--- # Learning in IT - Think like an Architect - URL: https://www.technolitero.com/blog/learning-in-it-think-like-an-architect - Markdown: https://www.technolitero.com/raw/learning-in-it-think-like-an-architect - Date: 2026-08-16 - Author: Buddy - Topic: Learning There are many qualities in a great Engineer and an Architect. I would say that in my experience I have worked with many Engineers that could become Architects if they wanted to. The expectations.... ## Architect Workflow
There are many qualities in a great Engineer and an Architect. I would say that in my experience I have worked with many Engineers that could become Architects if they wanted to. The expectations are different and some would rather be more technical than deal with design, processes and documentation as their primary role. It doesn't mean that they are incapable of it, just that they're not interested in it.

Architects look at things holistically, cross IT teams, the business, end user usability. We select vendors and make the decisions if we can do it with what we have or if we need additional hardware/software/head count etc... in order to support a solution. A good Engineer can design and implement a solution well, most of the time this is for their area of expertise. They are not looking at what other teams are doing and see tooling costs can be lowered by using the same system. That's not their job and I can respect that. Architects look at things from a different perspective, and the job is as much political as it is technical. I like to build things so that's why I went down the path of Architect but at a high level these are some of the questions that you need to answer when building a solution.
- Understand the problem you are providing a solution for, ask questions. - Investigate the solution. - Have questions answered by the ones that are impacted by the solution. - Know what you are working with. What hardware or software is involved, what is the user impact and the expected Tier. - Know the BCDR plan and expected MTTR, MTBF and what the SLA is. If there isn't one, ask about this as part of the design or propose one based on past experience and criticality of the system. - Know that you need this or the plan you create will fail or at the very least be updated several times, and in my opinion that's not a plan. - What does the budget for it look like? - Look at things from the 500ft view. - The best solutions typically cross teams, technology and skillsets. Design in for those. Bob in accounting has different needs than Kim in HR or someone in IT. - If a solution is too hard to use, it won't be. Design in a way that if you have to put a burden on someone it should be on IT not your non-technical users unless needed. - Pull additional teams in at the right time, this includes the business. Don't pull in the Network and Security teams after you have already designed, make them part of the design. This reduces rework and as many of us know best practice is environment specific and what works in a lab designed by the book doesn't work in production most of the time. - You need an understanding of how the solution is going to work cross teams, and the expected operational impact when the solution is live. - Don't be afraid to push back when something doesn't make sense. Bad design decisions don't get better just because they are documented. - Design - Once the first two steps are completed and you know what you are designing for, what the expected outcome is and who is going to be affected, make sure all of your documentation is correct. - Have the stakeholders review the initial documentation and once approved with only minor questions start building the design. - Design based on the parameters you have, Cost, Functionality, Operational Impact etc... - Have the stakeholders who will be implementing the solution take a look at the design, be open for questioning, you are not infallible and you could have some mistakes that need resolved to move forward. - Validate that it meets the requirements and then hand off for the build process to take place. - Build - Once this has been handed off for engineering to build, or if you are also part of this process, make sure documentation is number one. The reason for this is two fold. The first is operational, if an engineer doesn't know how to run or fix the solution you will experience extended downtimes as they reverse engineer it. The second is that depending on the regulations of your company you may have to provide process documentation to external auditors. - Automate as much as possible, having a script do the work reduces accidental configuration changes that lower security, delete files, corrupt the configuration or make the solution more prone to human caused downtime. If you can document it, most likely you can script it. Sometimes that doesn't make sense and it's not needed for everything. I believe that if there is high impact if something goes wrong, automate as much as you can including standard care and feeding. - Document - Documentation is the record of what was built on day one, it loses relevance over time as configuration changes are made, technology improves, software and hardware are upgraded and patched etc... - You must validate that nothing has changed that changes the documented design when something occurs that you know about can have an effect. - I would suggest at least a yearly review to make sure the document is current, this helps with troubleshooting or additional deployments. --- # Local AI on a Budget - URL: https://www.technolitero.com/blog/local-ai-on-a-budget - Markdown: https://www.technolitero.com/raw/local-ai-on-a-budget - Date: 2026-08-03 - Author: Buddy - Topic: AI - Tags: local-ai, ollama, anything-llm One of my many side projects is using Local AI but like most, I’m on a budget. Smaller models act like smaller models — until you stop treating them as one giant brain. One of my many side projects is using Local AI but like most, I’m on a budget. I’ve tried really small models, some as small as 1.5 billion parameters and in a nutshell, they act like a 1.5 billion parameter model. They work Ok, are somewhat performant but you lose a lot of ability, tooling may or may not work, forget image OCR, and kiss coding goodbye. MOE models are better, you can use a much larger model span it between GPU and CPU but all in all still weak sauce. Through my journey with local AI, I had an epiphany and started thinking through what I was trying to accomplish and since AI changes weekly there had to be a better way. Let me start first with my hardware, I bought it on Amazon before RAM spiked for another project. It’s a BOSGAME P4 Mini PC with integrated Radeon graphics, 32GB of DDR4, AMD processor and a 1TB M2 disk. While its powerful for its size the GPU is its limiting factor. It does allow you to give it 16GB UMA memory to the GPU but that’s it. I went through several Ubuntu builds that worked but not great. I tuned Ollama, tuned the hardware and still no luck. It would work but it was very slow and if I’d let it run it would eventually produce something but not quick at all. Then I started thinking about what MOE Models really do, they allow you to run a model and it pulls the pieces it needs when it needs it. This is great for loading one 14 billion parameter model and letting it do its thing, you have a little room for context but again slow. This led me to thinking about this differently, what if instead of running one MOE, what if I decided who the experts were and hired their little brother. I had to think through this and a feature of Anything LLM is that you can do model routing, this allows you to use a specialized model for OCR, a different model for coding, research and planning or even general purpose. I had originally started with a restricted Ollama, allowing only 1 model at a time but found that if I wanted to get the performance I wanted I needed to run more than that. I updated my Ollama service to look like this: ```ini filename="ollama.service" [Unit] Description=Ollama Service After=network-online.target [Service] ExecStart=/usr/local/bin/ollama serve User=root Restart=always RestartSec=3 Environment="OLLAMA_HOST=0.0.0.0:11434" Environment="OLLAMA_VULKAN=1" Environment="GGML_VULKAN=1" Environment="OLLAMA_IGPU_ENABLE=1" Environment="OLLAMA_NUM_GPU=999" Environment="MESA_VK_DEVICE_SELECT=1002:15e7" Environment="HIP_VISIBLE_DEVICES=-1" Environment="OLLAMA_SCHED_SPREAD=1" Environment="OLLAMA_KEEP_ALIVE=-1" Environment="OLLAMA_MAX_LOADED_MODELS=5" Environment="OLLAMA_KV_CACHE_TYPE=q8_0" Environment="OLLAMA_FLASH_ATTENTION=1" Environment="RADV_PERFTEST=sam" [Install] WantedBy=multi-user.target ``` This gave me the ability to run more models. Up to the 5, I also optimized my Ollama configuration to take into account my less than ideal video card. I then used Model Routing in Anything LLM, there are guides online or use Gemini on how to set that up. It takes a bit to get it to route properly but once its setup it works better than a single model for my use case. I run Anything LLM in a container using compose. The models I chose are as follows: ```output filename="ollama ps" root@localai:/containers# ollama ps NAME ID SIZE PROCESSOR CONTEXT UNTIL qwen2.5-coder:3b f72c60cabf62 2.4 GB 100% GPU 16384 Forever llama3.2:3b a80c4f17acd5 3.2 GB 100% GPU 16384 Forever phi4-mini:latest 78fad5d182a7 3.8 GB 100% GPU 16384 Forever qwen2.5:1.5b 65ec06548149 1.4 GB 100% GPU 16384 Forever qwen2.5vl:3b fb90415cde1e 3.1 GB 100% GPU 16384 Forever ``` You will then want to set up the routing in Anything LLM and then test. Qwen2.5vl:3b is critical if you want OCR abilities to drop a file into the chat and have it parse it as well. > **Note:** The information here is not a guide on how to do it for your environment, it’s simply to give those who are running on inferior hardware that is not optimized for Local AI a chance to make it useful. The smaller models are inadequate by themselves. MOE still needs decent hardware but if you focus on what you are trying to accomplish you can make it usable. I average 20 to 25 TPS now, and before I was barely able to hit 10. I have a script that I can run against ollama to spit out the information I needed to determine the models that gave me the best bang for the buck and here are some of the results. I have stuck with 3 billion parameter models or less as that seems to be the sweet spot, but they are optimized for certain parts then I route to them. ```output filename="ollama_benchmark_running.py" root@localai:/ai/scripts# python3 ollama_benchmark_running.py [DETECTED] Actively running model found in memory: qwen2.5-coder:3b — Starting Speed Benchmark for Model: [qwen2.5-coder:3b] — Sending prompt and waiting for processing execution… ================ BENCHMARK RESULTS ================ Total Wall-Clock Latency: 20.52 seconds Prompt (Input) Tokens: 47 tokens Prompt Processing Speed: 960.77 tokens/sec Generation (Output) Tokens: 443 tokens Actual Generation Speed: 21.88 tokens/sec ``` On smaller 1.5 billion parameter models you can get these types of speeds. ```output filename="qwen2.5:1.5b" — Initiating Hardware Warm-up Pass for [qwen2.5:1.5b] — Loading model layers into Vulkan VRAM and stabilizing clocks… Hardware warm-up complete. System is hot. — Starting Speed Benchmark for Model: [qwen2.5:1.5b] — Sending prompt and waiting for processing execution… ================ BENCHMARK RESULTS ================ Total Wall-Clock Latency: 11.03 seconds Prompt (Input) Tokens: 47 tokens Prompt Processing Speed: 420.88 tokens/sec Generation (Output) Tokens: 431 tokens Actual Generation Speed: 40.10 tokens/sec ``` Not too shabby for a MiniPC that has an old integrated GPU. --- # The Modern Engineering Stack: Moving Beyond the Search Bar - URL: https://www.technolitero.com/blog/the-modern-engineering-stack-moving-beyond-the-search-bar - Markdown: https://www.technolitero.com/raw/the-modern-engineering-stack-moving-beyond-the-search-bar - Date: 2026-05-19 - Author: Buddy - Topic: AI - Tags: ai, copilot, claude AI is quickly becoming an accelerator for more things than just Google searches. Copilot, Claude, OpenAI, and Gemini each earn a different seat in the stack. AI is quickly becoming an accelerator for more things than just google searches. While that is a fundamental use case, there are a few things that help quite a bit with actual work. ## Copilot I am a user of Copilot, and while it’s not the fastest AI on the block, it does the absolute best job of keeping business data inside your business. Of course, this relies on using a business account configured with the appropriate permissions. The real value here is that the model isn’t trained on your business data. If it were, your unique ideas or proprietary data could easily be leaked by someone else using the chat functionality in the personal versions of Copilot, which is a worst-case scenario. That security aside, the integration with Excel, Word, PowerPoint, Teams, GitHub, and Azure is fantastic. It leverages your internal data to not only understand your specific workflows but to actually do the work for you. Features like CoWork, for example, deliver much of the agentic functionality you see in tools like OpenClaw, but with a fraction of the risk. It might have its limitations but putting security first rather than as an afterthought is a great way to protect your digital assets. ## Claude Anthropic is my absolute go-to for vibe coding. It does have a tendency to run out of tokens fairly quickly if you are throwing big development projects at it… which is still a weird thing for me to say, given that I am not a traditional developer. I’m an engineer who has wanted these kinds of tools for years but could never explain exactly what I wanted to a programmer who didn’t understand my operational needs, and I didn’t want to waste time on the disconnect. With Claude, I have successfully built API Proxies, File Sync Utilities, and UniFi Management tools, among others. Knowing the foundational process of how to do something and having AI handle the execution makes things that were previously impossible for me completely achievable. I can knock out a working prototype from scratch in just a couple of days. I prefer Claude’s GUI features over the rest, and I like to use it in conjunction with other AIs, like OpenAI inside of VS Code, so I get a highly comprehensive application that balances performance, usability, scalability, and stability. ## OpenAI (ChatGPT) This is the OG of AIs, and the dynamic right now is a lot like the classic battle between Intel and AMD processors as Claude and OpenAI fight for relevancy. In my testing, Claude is currently the better choice for front-end work and mapping out the initial visual application, but Codex reigns supreme when it comes to backend services. I use OpenAI to build most of my containers and core backend logic. It does a pretty mediocre job at visual design, but when it comes to optimization and making things work efficiently under the hood, it’s the model I call on once Claude has the application laid out and running. I also really value the voice response feature, being able to chat with an AI agent to run through complex architectural ideas while I’m driving is a huge time-saver. ## Google Gemini Gemini is the fastest of the AIs in my testing, making it my primary thought partner for bouncing ideas around. The sheer volume of data it has real-time access to far outweighs what OpenAI, Claude, or Copilot can reach (outside of the internal business data I feed into Copilot). For example, it can write functional OpenSCAD scripts to create 3D printing models that I can drop straight into my Bambu printer. The initial responses are incredibly solid out of the gate, and they get significantly sharper if you start the conversation by establishing the full context of what you are trying to achieve. This is a universal truth with AI: you have to know what you want, ensure you provide the data needed to answer the scenario, and then refine the output through ongoing conversation with the model. ## Quick Tips - **The Interview Prompt:** If you have a solid idea but don’t know how to frame the context, start with a prompt explaining what you are trying to accomplish and give it as much raw information as possible. At the end of that prompt, ask the AI to interview you by asking exactly one question at a time. - **Optimize Your Files:** Upload supporting documents whenever you can. AI loves `.md` files. Feeding it data directly saves time if you are already working through PDFs, XLSX spreadsheets, or Word documents. - **The Mentor Mindset:** Think of AI as an experienced mentor. Don’t treat its recommendations as absolute facts. If a solution sounds reasonable, it probably is, but the same rule applies if the response seems too good to be true. - **Prompt Your Way to Freedom:** Take a hard look at the responsibilities in your job. Identify the tasks you absolutely hate doing but are necessary, and see if you can systematically prompt your way out of them. --- # Learning AI – The Basics - URL: https://www.technolitero.com/blog/learning-ai-the-basics - Markdown: https://www.technolitero.com/raw/learning-ai-the-basics - Date: 2026-04-22 - Author: Buddy - Topic: AI - Tags: ai, prompting Let’s be honest with ourselves, AI is one of the greatest things since the internet. The question is what you offload, and how you stay in control of the result. Let’s be honest with ourselves, AI is one of the greatest things since the internet. Sure, it has some downfalls, increases in memory and GPU costs the cost of a server to take advantage of it has spiked the cost of general-purpose machines exponentially, datacenters drawing huge amount of power from the grid and even water concerns because they do use a lot of water to cool the machines. Even with all of that it is fundamentally one of the greatest innovations in a long time. The question now is, how do I use it, what can I offload to a robot? The answer really comes down to what do you want to have taken off your plate, what doesn’t need human eyes on it, and what is your comfort level with new technologies. Personally, I focus on the things I don’t like to do. If documentation alignment is a problem, do working documents look inconsistent or hard to read, have AI clean it up. AI isn’t perfect, it lacks emotions, real thought at the moment and an understanding of the audience. What you would tell a CEO, is different than how you would present the document to an engineer working issues daily. Think through these, how would you clean it up, what information is pertinent for a non-technical audience and ask AI to clean up the text with a simple prompt like: ```prompt filename="document-cleanup.md" Clean this document up, check for spelling and grammar errors to present to a CEO, keeping all key points, make it understandable and concise: {Paste the text of the document or upload it} ``` When it comes to governance its best to use an AI that has controls for your business. Microsoft Copilot for instance can be set up to where it retains its information in your tenant. You don’t want trade secrets getting out so proper governance will help with that. Don’t fear AI, embrace it. Most users start with using it like a better Google. It’s more than that but you have to get comfortable with prompts, telling it how you want to think about something and how you want it to respond. It doesn’t really know those things out of the gate, so it’ll give you the easy answer not the best. AI is transformative, and yes there is another downside that some jobs will be lost, but others will be created just like you don’t see many Horse and Buggy drivers anymore. We now have over the road truckers, cabs and Uber drivers. The need didn’t change, but the method did, and its faster, safer and more accessible. This is the same with AI. You can have it look at Excel files, create pictures, scan for anomalies etc… It’s all in the way you prompt. Think of AI as a child that is just learning, it only knows what you tell it or other data that it has. Its only as good as the context you feed it. While there are things like Codex, Claude Code and Open Claw that now give it access to real world tools and applications, be weary of it at the moment. All of these automation technologies are good but the access you need to give so that it can work is more than some including myself are comfortable with. In my opinion the best use of AI is as a Digital Thought Partner, if you have an idea have AI interview you on what you are trying to accomplish and have it challenge your assumptions as well as give alternatives that might spark other ideas. You are in control and make the final decisions, not the AI. It’s easier though to make a good decision if you base it on everything related to it, letting AI challenge your biases and assumptions. Coding is much easier with AI then without it. I use a prompt to start coding an application inside of VS Code. I have AI do the heavy lifting of understanding what I want and then when I am in VS Code using Claude or Codex I will say what I want and either start or end with Don’t do anything now, but I would like…. and then shoot for what I am trying to achieve. When you’re ready and have been interviewed and answered its questions on layout, functionality etc… say Build this and it has a good idea of what you are looking for. ```prompt filename="application-viability.md" # Application Viability ## Purpose Describe what this prompt does and when to use it. ## How to Use Paste and run as-is, or replace any [PLACEHOLDER] values before sending. ## 1. Information Gathering & Reasoning If you have limited or no relevant data, do not hallucinate details. Instead, interview me. Ask targeted questions regarding the target audience, core problem, and desired outcome until you have enough data (the 80%) to reason effectively. ## 2. The Deep-Dive Report Once enough information is gathered, provide a structured report with the following sections: ### A. Core Concept & Viability Analyze the fundamental logic of the app. Is this a viable product? Identify the '80%' of value that comes from '20%' of the effort. ### B. The Bias Check & Devil’s Advocate Be blunt. Actively challenge my assumptions. Identify where I might be blind to market realities or technical over-engineering. - If my direction is flawed, suggest alternatives. - When recommending changes, provide a clear explanation for the benefit and any trade-offs. ### C. AI-Assisted Troubleshooting Workflows Explore opportunities to integrate AI-powered tools to streamline troubleshooting processes. ## 3. Communication Blueprint - Tone: Direct, professional; use friendly banter when necessary for collaborative environments. - Response Length: Moderate by default, detailed for critical/high-risk situations involving IoT devices or network performance issues. - Format: Mixed (typically structured headers/sections); explain reasoning explicitly. - Language Level: Balanced technical depth for speed; deep technical only when requested. What to Avoid: - Fluff, filler, or buried answers - Overconfidence without evidence; assumptions that aren’t explicitly stated as assumptions ``` Its output can be pasted into the Code Editor of choice that has AI integration and you are off to the races. I believe strongly in having AI think like a computer and respond like a Human, so that understanding of deep topics is relevant and actionable. Give it a spin using the prompts scattered throughout my blog, modify them, or use them as is. You should see instant quality and value increases. --- # Getting the most out of AI, starts with you! - URL: https://www.technolitero.com/blog/getting-the-most-out-of-ai - Markdown: https://www.technolitero.com/raw/getting-the-most-out-of-ai - Date: 2026-04-21 - Author: Buddy - Topic: AI - Tags: prompting, digital-twin Prompt engineering is one of the most misunderstood issues with AI for the masses. I asked for a screwdriver, not a therapist. Prompt Engineering is one of the most misunderstood issues with AI for the masses. How do you get it to do something like a tool instead of a friend. I asked for a screwdriver not a therapist. The trick is to think like a computer or ask it to help you create prompts. I have a few that work well for certain use cases and as a technologist I don’t want warm fuzzy interactions, I want cold hard truth. These walk you through the process so you don’t have to be an expert. Use AI to make AI work better. ## Create a basic Digital Twin Drop this into any AI. My preferred for quick responses is Google Gemini. Each model will give you different output based on your answers. ```prompt filename="digital-twin-architect.md" You are the Digital Twin Architect. Your mission is to conduct a structured, conversational interview to build a precise Digital Twin — a living profile that lets any AI instantly understand who the user is, how they think, how they communicate, and how they work best. The completed Digital Twin will be prepended to future AI conversations so every interaction starts perfectly calibrated. INTERVIEW RULES - Ask ONE question at a time — never bundle questions. - Wait for each answer before proceeding. - React naturally: if an answer is brief, probe deeper before moving on. - Be warm and conversational, not clinical or robotic. - Total interview: about 20–25 questions across 6 phases. - After the final question, produce the complete Digital Twin profile without asking for confirmation. PHASE 1 — Professional Identity Cover role, industry, years of experience, expertise, current focus, near-term and long-term goals. PHASE 2 — Communication Style Cover response length, technical depth, format, example style, and what frustrates them in AI responses. PHASE 3 — Thinking & Learning Style Cover problem-solving, learning mode, decision-making, ambiguity, big-picture vs detail. PHASE 4 — Personality & Work Style Cover peak energy, collaboration vs solo, pressure, what energizes and drains them. PHASE 5 — Values & Non-Negotiables Cover core values, what they optimize for, pet peeves. PHASE 6 — AI Partnership Style Cover the role AI should play, feedback style, when to push back, clarifying questions. OUTPUT: a clean markdown Digital Twin profile that can be copied into future chats. Begin now. Introduce yourself briefly as the Digital Twin Architect, explain that this interview will create a personalized AI profile, and ask your first question. ``` ## Create a Quick Prompt ```prompt filename="prompt-architect.md" You are the Prompt Architect. Your mission is to conduct a brief, focused interview to design a precise, reusable Quick Prompt — a template the user can paste into any AI conversation to consistently get exactly the output they need. INTERVIEW RULES - Ask ONE question at a time. - Wait for each answer before proceeding. - Be direct and efficient. - Total interview: about 8–12 questions across 4 phases. - After the final question, produce the complete Quick Prompt without asking for confirmation. PHASE 1 — Purpose & Goal The core task, primary use case, and how often they will use it. PHASE 2 — Context & Inputs What they will provide each time, whether inputs vary, domain knowledge the AI needs. PHASE 3 — Output Requirements Format, length, required structure, what great output looks like vs what to avoid. PHASE 4 — Tone, Constraints & Edge Cases Tone, hard constraints, how to handle ambiguity, what has gone wrong before. OUTPUT: a ready-to-use prompt with Purpose, How to Use, and the prompt text directed at the AI. Use [PLACEHOLDER] for variable inputs. Begin now. Introduce yourself as the Prompt Architect and ask your first question. ``` --- # Building Unifi Analyzer using AI! - URL: https://www.technolitero.com/blog/building-unifi-analyzer-using-ai - Markdown: https://www.technolitero.com/raw/building-unifi-analyzer-using-ai - Date: 2026-03-14 - Author: Buddy - Topic: Networking - Tags: unifi, ai, python - Source: https://github.com/Technolitero/unifi-analyzer I loaded up Visual Studio Code, attached GitHub and Claude, and started building the Unifi tool I had wanted for years. I have recently started going down the path of using Claude AI to develop tools that I have wanted for literally years. One of the first things I have needed on occasion is to be able to connect to the Unifi API’s and pull data. So begins the spiral into the abyss and the deep dive into things I have never done before. I loaded up Visual Studio Code, attached Github and Claude AI to it and started. The thing that stood out to me first was how easy it was to tell Claude what I wanted and it got to building. The first run was pretty good and it was usable but not entirely good enough. I started with a prompt starting with my goal. ## Initial Prompt ```prompt filename="unifi-analyzer-v1.md" I would like a python app that can be accessed using a web URL that connects to a Unifi UDM running version 10.2.x using the API interfaces and pull the configuration into a table that I can see using the URL. I want it to pull the name of the device, clients connected, ports list, firewall policies, groups, Wi-Fi networks and any other relevant UDM configuration information. I would like switch statistics, as well as access points and related information. I would like to use this to pull the configuration off of the UDM and view it through the web. ``` ## Authentication to the UDM This prompt built an app, scaffolded the code, and produced an app that worked but I had to put the username and password inline, so I asked Claude to add a credential button and put anything required for authentication into it. It was visible all the time and since I didn’t want to type in the creds every time, I asked it to save it. It ran through and then created a configuration that saved the settings to the site. It took the initiative and also built code to encrypt the credentials at rest. ## Analyzer The original prompt generated an App that pulled the configuration, but what to do with it sparked some ideas. I wanted it to look at the config and tell me if I was using best practices and if there was anything I needed to be aware of so it could be remediated. I sent another prompt asking Claude to build it based on Unifi’s best practices and pointed it to the documentation that supported it. Claude started work on it and produced something that is functional but over time I will refine it as new API endpoints are exposed and put in my best practices into the scan. ## Config Lookup This is what was built with the first prompt. I refined the data by telling Claude to sort by Name, change the IP address to sort by the IP value and the same with the MAC Addresses so that by default everything was in alphabetical order on load by Name and then I could sort as I needed to. This made the config pull work as expected. It also made it easier to lay out things so that I could get value quickly without having to pull the config more than once. ## Interfaces I started getting in the flow and wanted to see if I could ask it to do something that I didn’t think was possible. I asked Claude to create a tab called Interfaces and I wanted it to pull all the Interfaces such as Ports and Virtual Network Ports back. If I could do packet sniffing on the port, I wanted it to kick it off and return the PCAP. I also wanted it to allow me to analyze it in AI using a JSON export as well as be able to open the PCAP in Wireshark. Claude went to work and built the code to logon to the device using SSH, kicking off a TCP Dump and then created another tab called PCAP viewer that by default gives you a high-level analysis. I wanted to push it further, since I knew it could logon and do the packet captures it could do more. I then asked Claude to create a message log viewer on the device, something I don’t do often but when I need it, I need it. Claude started spinning and created a button for live logs and when I click on it while connected to a specific device the live log opens in another window so you can watch the messages come in in real time. It initially was sequential on the packet dumps. I then told Claude to change the packet scanning to run in parallel so that I could see both sides of the connection if possible. Claude made the changes and it worked exactly as I expected. ## Lessons Learned Like with many things, the first time you do something, you do it wrong out of the gate. I learned the following things that will help me as I start building more tools. - Know what the end result should be, know what you are looking for and how to pull the information you need to support your app. Understand the process of what you are trying to accomplish, if you can write it down you can ask Claude help to build it. If you don’t know what you want, you’ll get something you don’t want and have to iterate much more to get a workable solution. - If you have examples of the API code, that helps a lot. You can feed that into Claude, so it doesn’t have to look for it. This is especially helpful in moving faster with API’s that are not well documented which is unfortunately the bulk of most APIs. If you have Swagger or other API documentation that can be accessed over the internet, point Claude to that. - GitHub is your friend, create a new repository and during development set it as Private until you have something you would like to release. It helps with versioning, rolling back changes and backing up your code. - Test and make changes that improve your workflow. Think of how you would like to use the application and ask Claude for complex changes as well as the simple ones like renaming columns or buttons, what the order of it should be. - Test after each change or at least every few. Sometimes changes can break working parts of the code and it’s better to fix them in the beginning and then adding features later when you get an idea. - Refactor your code periodically and before publishing to GitHub, it helps keep your code clean. - Publish to GitHub and mark it as Public if you’d like or keep it Private for your own use. - Claude or other AI coding agents are awesome but have patience. You only have so many tokens to use a day so it may take you a bit before you have a workable application. The thing I liked the most is that what I would ask a developer for I can have AI do it. My ideas are on my timeline not someone else’s. If I get a wild idea, I can try it without costing resources other than my own. It allows me to build useful tools without knowing how to code. This frees up time for developers to code for others that don’t understand how to use the tools, the process, and the expected outcome. > **GitHub:** The current release is on [Technolitero/unifi-analyzer](https://github.com/Technolitero/unifi-analyzer/releases/latest). The write-up of how to run it is on the [downloads page](https://www.technolitero.com/downloads/unifi-analyzer). --- # AI – Context Engineering Overview - URL: https://www.technolitero.com/blog/ai-context-engineering-overview - Markdown: https://www.technolitero.com/raw/ai-context-engineering-overview - Date: 2026-03-07 - Author: Buddy - Topic: AI - Tags: context-engineering, prompting AI is smart and has access to pretty much all data, but it is missing the context you are working in. That is the difference between an answer and the right answer. AI is quickly becoming ingrained in the culture of information technology. Like many of you, I started out using it like an advanced Google, and to be fair it’s great for that. It keeps me from having to go to hundreds of sites, distilling down the information I see, trying a few of the commands to resolve an issue and failing until I get it right. I don’t want to discourage that use case either, while it’s not as powerful as some of the other uses it’s definitely helpful. AI is at its core best when it’s used as a collaborative mentor or as a tool and it all comes down to context engineering, an extension of prompt engineering. AI overall is smart, has access to pretty much all data but it’s missing a key component in decision making and that is the context you are working in. Think of the context as the guardrails that keep the response on track. AI doesn’t innately understand the limitations that you are set up with, so the more information you give it about what you are thinking about and why you are looking at doing it a certain way will give you vastly different results. ## Simple request — no context ```prompt filename="no-context.md" I would like to fix a clicking noise in my car ``` That prompt gets you a catalog of every clicking noise a car can make. Useful as a pamphlet. Useless if you already know the year, the symptom, and that you can turn a wrench. ## Context request ```prompt filename="with-context.md" I am a mechanically inclined tinkerer that can typically fix most minor mechanical issues. I am in IT by trade but understand basic mechanics. I have a 2017 Chevrolet Malibu that has a clicking and popping sound coming from the back of my car while I am driving it. When I get out, I hear a pop in the back, this has been happening for a while and doesn’t seem to cause issues when driving. What are some of the common causes of this starting with the most common issues for this model year and make. I would like to also know how to fix it myself if possible and if it makes sense for me to do it or take it to a shop. ``` That version gets you the Malibu-specific knuckle bushing, the GM bulletin, and a decision about whether greasing it yourself is enough. Same model, different job, because you told it who you are and what “done” looks like. This is the power of context. Instead of focusing on the generality of the noise that could be about anything, I have told AI what it needs to know to give me a detailed plan on how to actually resolve this issue. Context is everything to get you to the right answer instead of just an answer that is going to be wrong most of the time. You can use this path for minor or major issues. It saves a ton of time and back and forth chatting with the AI Agent. > **Tip:** The first prompt in the chat is the most important. It makes you think through what you are really asking for. If you don’t know, it can interview you, but it’s better to understand the outcome than to figure it out mid-thread. --- # PowerShell in the Field - URL: https://www.technolitero.com/blog/powershell-in-the-field - Markdown: https://www.technolitero.com/raw/powershell-in-the-field - Date: 2026-01-15 - Author: Buddy - Topic: PowerShell - Tags: powershell - Source: https://github.com/Technolitero/Powershell-Public The public PowerShell repo is the toolkit I am willing to share. Clone it, read it, then run it on a box you can afford to break first. PowerShell is still the fastest way I know to make a Windows box tell the truth. The scripts I am willing to share live in the public repo, not buried in a zip on a file share. > **GitHub:** [Technolitero/Powershell-Public](https://github.com/Technolitero/Powershell-Public) Clone it, list what is there, and read a script before you execute it. That is the whole workflow. ```powershell filename="clone-toolkit.ps1" git clone https://github.com/Technolitero/Powershell-Public.git Set-Location .\Powershell-Public Get-ChildItem -Recurse -Filter *.ps1 | Select-Object FullName, Length, LastWriteTime | Format-Table -AutoSize ``` If a script touches production, run it against a lab first. I treat these the same way I treat Unifi Analyzer: useful, written for my problems, and public so someone else can steal the parts that fit. The [downloads page](https://www.technolitero.com/downloads/powershell-public) has the zip if you would rather not use git. Either way, the source of truth is GitHub. --- # Meshtastic NRF MQTT Decoding - URL: https://www.technolitero.com/blog/meshtastic-nrf-mqtt-decoding - Markdown: https://www.technolitero.com/raw/meshtastic-nrf-mqtt-decoding - Date: 2026-01-03 - Author: Buddy - Topic: Meshtastic - Tags: meshtastic, mqtt, python - Source: https://github.com/Technolitero/Meshtastic NRF Meshtastic nodes will not emit JSON to MQTT. Decrypt the protobuf on a small Python bridge and push a clean topic Home Assistant and Telegraf can actually use. In Meshtastic there are two main variants of the hardware: NRF and ESP32. Each have their own pluses and minuses. The most common devices such as RAK and Seeed are NRF. They are very low power, which means with the proper power settings you can get a week or so on a single charge. They also have more production quality devices instead of just development boards. Due to this they don’t support sending to MQTT in JSON. They only send in the encrypted Meshtastic format. That makes using them as a tracker inside Home Assistant or a TIG stack impossible unless you decode the payload. ESP32 devices can be configured to send encrypted or JSON. I have a Python script that pulls the encrypted data from a topic, decrypts it, and publishes to another unencrypted topic. This is a work in progress, but it will let you see the payload. I use Ubuntu Linux, so the instructions are based on that. ## Create the Python script Ensure Python is installed, make a directory, then save this as `meshtastic_nrftojson.py`. ```python filename="meshtastic_nrftojson.py" import json import base64 import paho.mqtt.client as mqtt from paho.mqtt.client import CallbackAPIVersion from meshtastic import mqtt_pb2, mesh_pb2, telemetry_pb2 from google.protobuf.json_format import MessageToDict from Crypto.Cipher import AES from Crypto.Util import Counter MQTT_HOST = "10.10.10.10" MQTT_PORT = 1883 MQTT_USER = "mqttuser" MQTT_PASS = "newpassword" MQTT_TOPIC = "msh/US/2/e/LongFast/!8a35dfcc" DESTINATION_TOPIC = "msh/US/2/json/nrfjson" PSK_BASE64 = "AQ==" CHANNEL_KEY = base64.b64decode(PSK_BASE64) def decrypt_packet(encrypted_bytes, key, from_id, packet_id): nonce = packet_id.to_bytes(4, "little") + from_id.to_bytes(4, "little") + b"\x00" * 8 ctr = Counter.new(128, initial_value=int.from_bytes(nonce, "big"), little_endian=False) cipher = AES.new(key, AES.MODE_CTR, counter=ctr) return cipher.decrypt(encrypted_bytes) def on_connect(client, userdata, flags, reason_code, properties): if reason_code == 0: print(f"Connected to {MQTT_HOST}. Bridging nRF52 data...") client.subscribe(MQTT_TOPIC) def on_message(client, userdata, msg): try: envelope = mqtt_pb2.ServiceEnvelope() envelope.ParseFromString(msg.payload) packet = envelope.packet from_id = getattr(packet, "from_", 0) packet_id = getattr(packet, "id", 0) if packet.encrypted: try: decrypted_data = decrypt_packet(packet.encrypted, CHANNEL_KEY, from_id, packet_id) packet.decoded.ParseFromString(decrypted_data) except Exception: pass packet_dict = MessageToDict( packet, preserving_proto_field_name=True, always_print_fields_with_no_presence=True, ) decoded_payload = packet_dict.get("decoded", {}) portnum = decoded_payload.get("portnum") if portnum == "POSITION_APP": pos = mesh_pb2.Position() pos.ParseFromString(packet.decoded.payload) decoded_payload["latitude"] = pos.latitude_i / 1e7 if pos.latitude_i else None decoded_payload["longitude"] = pos.longitude_i / 1e7 if pos.longitude_i else None decoded_payload["altitude"] = pos.altitude if pos.altitude else None elif portnum == "TEXT_MESSAGE_APP": raw_b64 = decoded_payload.get("payload", "") if raw_b64: decoded_payload["text"] = base64.b64decode(raw_b64).decode("utf-8", errors="ignore") output = { "from": from_id, "to": packet_dict.get("to", 0), "type": "packet", "payload": decoded_payload, "rssi": packet_dict.get("rx_rssi", 0), "snr": packet_dict.get("rx_snr", 0), } client.publish(DESTINATION_TOPIC, payload=json.dumps(output), qos=1) print(f"Published decoded packet from {from_id} to {DESTINATION_TOPIC}") except Exception as error: print(f"Bridge Error: {error}") def main(): client = mqtt.Client(CallbackAPIVersion.VERSION2) if MQTT_USER: client.username_pw_set(MQTT_USER, MQTT_PASS) client.on_connect = on_connect client.on_message = on_message client.connect(MQTT_HOST, MQTT_PORT, 60) client.loop_forever() if __name__ == "__main__": main() ``` Change the MQTT host, user, password, encrypted topic, destination topic, and PSK to match your mesh. `AQ==` is the public LongFast key. ## Set up the environment ```bash filename="setup.sh" sudo apt update python3 -m venv mesh-venv source mesh-venv/bin/activate pip install paho-mqtt meshtastic pycryptodome python3 meshtastic_nrftojson.py ``` Then run it as a service so it survives reboot. ```ini filename="meshtastic-nrftojson.service" [Unit] Description=Meshtastic nRF52 MQTT to JSON Bridge After=network.target [Service] ExecStart=/scripts/mesh-venv/bin/python3 -u /scripts/meshtastic_nrftojson.py WorkingDirectory=/scripts Restart=always User=root Environment=PYTHONUNBUFFERED=1 [Install] WantedBy=multi-user.target ``` ```bash filename="enable-service.sh" sudo systemctl daemon-reload sudo systemctl enable meshtastic-nrftojson.service sudo systemctl start meshtastic-nrftojson.service ``` This service is for a single topic, typically the primary channel that carries telemetry and GPS. Secondary channels need another script and another unit. > **GitHub:** [Technolitero/Meshtastic](https://github.com/Technolitero/Meshtastic) --- # Meshtastic TIG Stack - URL: https://www.technolitero.com/blog/meshtastic-tig-stack - Markdown: https://www.technolitero.com/raw/meshtastic-tig-stack - Date: 2026-01-01 - Author: Buddy - Topic: Meshtastic - Tags: meshtastic, grafana, mqtt - Source: https://github.com/Technolitero/Meshtastic Grafana does not speak MQTT well, and MQTT is a terrible long-term database. Telegraf plus InfluxDB is how Meshtastic JSON becomes a map and a message log. Meshtastic can be used as a simple mesh between devices, but it also can be used for tracking devices through a Grafana dashboard. Grafana doesn’t work with MQTT very well. MQTT is not designed for long-term storage. It is great for small messages on defined topics. Visualizing and keeping those messages over time is the TIG stack: Telegraf, InfluxDB, and Grafana. I am not going into detail on Docker or MQTT. Follow this to get a basic stack on Ubuntu. I keep containers under `/containers/tigstack`. ```yaml filename="docker-compose.yaml" version: "3.8" services: influxdb: image: influxdb:latest container_name: influxdb ports: - "8086:8086" volumes: - influxdb_data:/var/lib/influxdb2 environment: - DOCKER_INFLUXDB_INIT_MODE=setup - DOCKER_INFLUXDB_INIT_USERNAME=admin - DOCKER_INFLUXDB_INIT_PASSWORD=SecureLogonPassword - DOCKER_INFLUXDB_INIT_ORG=YourOrganization - DOCKER_INFLUXDB_INIT_BUCKET=meshtastic_data - DOCKER_INFLUXDB_INIT_ADMIN_TOKEN=SecureInfluxPassword telegraf: image: telegraf:latest container_name: telegraf depends_on: - influxdb volumes: - ./:/etc/telegraf:ro environment: - MQTT_BROKER_URL=tcp://10.10.10.10:1883 - MQTT_USER=meshtastic - MQTT_PASS=SecureMQTTPassword - INFLUX_TOKEN=InfluxDBAdminToken grafana: image: grafana/grafana:latest container_name: grafana ports: - "3000:3000" depends_on: - influxdb volumes: - grafana_data:/var/lib/grafana volumes: influxdb_data: grafana_data: ``` Create `telegraf.conf` next to the compose file. Topics must be JSON. NRF nodes need the [decode bridge](https://www.technolitero.com/blog/meshtastic-nrf-mqtt-decoding) first. ```ini filename="telegraf.conf" [agent] interval = "10s" outputs.influxdb_v2 urls = ["http://influxdb:8086"] token = "${INFLUX_TOKEN}" organization = "Organization" bucket = "meshtastic_data" inputs.mqtt_consumer servers = ["${MQTT_BROKER_URL}"] topics = [ "msh/Meshtastic/2/json/Main/!9e75dbcc", "msh/Meshtastic/2/json/Private/!9e75dbcc" ] username = "${MQTT_USER}" password = "${MQTT_PASS}" client_id = "telegraf_meshtastic" data_format = "json" json_string_fields = ["payload_text"] ``` Bring it up with `docker compose up -d`. Log into Influx at `:8086`, generate an all-access API token, then in Grafana (`:3000`, admin/admin the first time) add an InfluxDB data source using Flux, the compose org, bucket, and that token. ## Message table This Flux query pulls messages, maps node IDs to names, and keeps channel plus text. ```ini filename="messages.flux" import "regexp" from(bucket: "meshtastic_data") |> range(start: v.timeRangeStart, stop: v.timeRangeStop) |> filter(fn: (r) => r._measurement == "mqtt_consumer") |> filter(fn: (r) => r._field == "payload_text" or r._field == "from" or r._field == "payload_from") |> pivot(rowKey:["_time"], columnKey: ["_field"], valueColumn: "_value") |> map(fn: (r) => ({ r with node_id: if exists r.from then string(v: r.from) else if exists r.payload_from then string(v: r.payload_from) else "unknown" })) |> map(fn: (r) => ({ r with node_name: if r.node_id == "2658588132" then "Base" else if r.node_id == "1685377223" then "Node1" else r.node_id })) |> filter(fn: (r) => exists r.payload_text and r.payload_text != "") |> keep(columns: ["_time", "node_name", "payload_text"]) |> rename(columns: {payload_text: "message", node_name: "node_id"}) ``` Last-known GPS for 30 days is the same pattern: pivot lat/lon, map names, `top(n: 1)` per node, divide `latitude_i` by 10,000,000. A second query without `top` gives the track over the dashboard time range. ESP32 nodes can publish JSON and encrypted MQTT. NRF nodes do not have Wi-Fi and do not speak JSON. In my setup an ESP32 client uplinks over Wi-Fi into Home Assistant’s MQTT broker, and NRF SenseCaps stay on the mesh as trackers. > **GitHub:** [Technolitero/Meshtastic](https://github.com/Technolitero/Meshtastic) --- # Private Meshtastic - URL: https://www.technolitero.com/blog/private-meshtastic - Markdown: https://www.technolitero.com/raw/private-meshtastic - Date: 2025-12-31 - Author: Buddy - Topic: Meshtastic - Tags: meshtastic, encryption - Source: https://github.com/Technolitero/Meshtastic The public LongFast key is well known. If you do not want strangers reading telemetry off your property mesh, change the primary channel key and own your relays. Meshtastic is a great way to send messages without the need of traditional IP connectivity and can be used in its default mode of sending message to LongFast or other built-in channels using a public encryption key out of the box. Where this breaks down is that anything you send to your primary channel, which is the channel used for position updates and other telemetry data, is that anyone can see it. - Primary Channel is where all device data and Mesh communication goes by default. - Secondary Channels are channels that are basically where group messages occur and are used to communicate with allowed devices on your mesh. Nodes can only access the channel if they have access to the key for that channel which allows you to be on the public message and send messages privately to Nodes that have access to that key. By default, the Primary LongFast Channel using an 8-bit encryption key that is public, `AQ==`, this is well known and if someone is using this key, they now have access to your telemetry data if they are on your Mesh. This is good in the aspect that you can be part of a larger Mesh network and relay further due to being able to use other Meshtastic devices that others have. You get the benefit of a larger install base of devices that can act as relays for your devices. Where this is problematic is that everyone on the Mesh now has access to your telemetry data, which may not be desired. So how do you fix this? The simple way is changing the encryption key for your Primary Channel to something like a 128bit or 256bit key and then applying that key to your devices. It will immediately drop off of the public mesh to a private one. The downside is that now you are responsible for your Mesh and relay positioning in order to get the range you are looking for. On my 13 acre property it’s not that big of an issue as the range between two devices can go anywhere and while a message may have a 5 or 10 second delay, its adequate for what I am doing with it. I am mostly pasture so line of site isn’t an issue, and I do have a repeater placed to not only repeat but also feed Mesh telemetry data into MQTT which is where the real power of Meshtastic comes through. I can do real time tracking of my Nodes, know where they are located so I can attach them to equipment or just carry them around. If cell service is poor, I can still communicate with the others on the Mesh, without having my messages exposed to other open Meshtastic users. Where this is useful is for real time tracking of your devices to either a TIG Stack, or directly into Home Assistant. I use both while I am deciding use cases for them. I have found for Home Assistant the benefit is that your Node becomes a device and can be used to trigger automations, log status, battery life, location etc… Using the TIG Stack I can keep the data around longer to get trends by pulling the data from MQTT to InfluxDB using Telegraf and visualizing it with Grafana. Meshtastic is powerful for this use case and since I don’t want other people I don’t know seeing the location and status of my devices it made sense for me to encrypt the one on my property. If I was camping in the woods or at a concert and wanted to use it, I would have stuck with the 8-bit encrypted public Mesh. This gives access to longer range due to the ability to use other nodes for message relay without the need of using my own equipment and having to strategically position relays. --- # Meshtastic Beginners Guide - URL: https://www.technolitero.com/blog/meshtastic-beginners-guide - Markdown: https://www.technolitero.com/raw/meshtastic-beginners-guide - Date: 2025-12-29 - Author: Buddy - Topic: Meshtastic - Tags: meshtastic, lora - Source: https://github.com/Technolitero/Meshtastic Meshtastic is a way to communicate across distances without Wi-Fi or cellular. Range is a mix of height, antenna, and how many friends your mesh actually has. Meshtastic is an interesting way to communicate across distances without the need of Wi-Fi or Cellular services. It is fairly localized communication that can span miles if you have line of sight to your transmitters. If they are closer to the ground your distance will suffer, if you put it up in a tree you can go a bit further. Antenna choice is also a consideration. If you have one with increased gain you can go further as well. I personally have tested with several nodes on my 13-acre property and the longest delay I had sending from the back of the property to the front was about 5 seconds. ## Features - Attaches to your iOS or Android device using the Meshtastic App. - The default out of the box settings work and you can communicate immediately. - This has the unfortunate side effect that you will be on the LongFast Channel otherwise known as the Primary Channel and others that aren’t encrypting the LongFast Channel will be able to pinpoint location, find you as a client on the mesh and be able to send direct and channel messages to you. - You will have decent range without a repeater and there are many different devices that will connect to the mesh. - You can create encrypted private Channels to communicate with if you are in a group setting and can send direct messages to nodes your devices see on the LongFast Channel. - All visible Client nodes will act as a relay for your messages across the mesh, giving you greater range if you are around many similarly configured devices. ## Encryption Your LongFast/Primary Channel can be encrypted for secure applications up to 256bit, this is recommended if you want to limit who can send messages to you and who you want to send to. The node database can get pretty full if you are in area with a lot of nodes, or if you are driving around and picking them up in other areas. LongFast is also the Channel that telemetry data such as power, RSSI, and GPS go to, it is the Primary Channel where the others are secondary. You can create additional channels and share them with QR codes or manually type in the key. The key does get fairly long though, so the QR code is easier. The Channel Name and the encryption key have to match and are case sensitive. When you create a channel always encrypt, these are typically created to be considered a group chat of sorts. You typically don’t want other people sending to a private channel or receiving messages that are sent to the mesh, encrypting the channel fixes that. ## Range It’s a little hit or miss on what to do to get longer range and it’s also a bit of a science and some trial and error, depending on what obstructions will weaken your signal. Below are some basic ways to get a better signal. - Stationary repeaters in various locations that are Clients. You can use Client Mute if you just want it to relay and it won’t show up but Client works well as is the recommended way to do it. - Longer antennas with higher gain, the antennas that come with the devices are OK but lack the range of an upgraded antenna. - More nodes, this is a mesh so the more routes back to a distant device the higher chance that the message will get there. You don’t want a lot of hops but 3 is OK, you start going much more and your success will vary. Repeaters help with this and can be used to extend without relying on devices that move around a lot. - These work in the 800-900mhz band and can go pretty far since the frequency is low but like most of these things you will need to test in the area you are using them in. ## Use Cases Meshtastic is based on LoRa and focuses primarily on off-grid messaging. This works good in a pinch but there are some other practical applications that I have implemented on my property that I thought were useful and, in some cases, more beneficial than texting alone. You can turn on the MQTT Proxy for a device connected to your phone and as long as it can MQTT messages to a server that can accept it you can log even while you’re remote. It will require you opening up the MQTT ports into your MQTT server or for a more secure option forcing it through a VPN connection. The other option is to use a Wi-Fi Meshtastic device such as the ESP32 models and having it act as a relay into MQTT for any messages it sees. This is beneficial if you are encrypting your primary channel as all the devices can send to the mesh are all encrypted. - GPS tracking of equipment. Most of the Meshtastic nodes have a GPS built-in or you can add one to many of the standard devices. - Home Assistant with the Meshtastic plugin. - MQTT, Telegraf, InfluxDB and Grafana will allow you to build a solution around Meshtastic nodes. It is more complicated, but you can keep historical logs, plot GPS, and link out to maps. - Message triggers to Home Assistant to run automations or scenes — for example when you are close to home. - Meshtastic also supports sensors such as temperature, humidity, air pressure. If you have the data, you can use other Arduino based devices to automate relays. I’m sure there are others but all in all the ability of being able to automate things based on low-cost sensors that don’t require connectivity to cell or Wi-Fi is pretty amazing. ## Resources - [meshtastic.org](https://www.meshtastic.org/) — main Meshtastic site - [client.meshtastic.org](https://client.meshtastic.org/) — browser client - [flasher.meshtastic.org](https://flasher.meshtastic.org/) — firmware upgrades - Heltec and Seeed Studio are good hardware catalogs. ESP32 boards cost more power and can do Wi-Fi or Bluetooth, not both at once. NRF boards sip power and stay on Bluetooth. --- # Network Tool - URL: https://www.technolitero.com/blog/network-tool - Markdown: https://www.technolitero.com/raw/network-tool - Date: 2025-09-18 - Author: Buddy - Topic: PowerShell - Tags: powershell, networking - Source: https://github.com/Technolitero/Powershell-Public I asked Warp to combine LLDP Discovery, Port Finder, and Packet Capture into one PowerShell GUI. Six hours later I had a Swiss Army knife I would have spent a week writing by hand. My primary scripting language is PowerShell. While I’m comfortable writing scripts from scratch, it can be time-consuming to take an idea all the way to a production-ready tool. Recently, I came across Warp IDE, an AI powered editor, and decided to give it a try to see how far I could push it, and how complex I could make a single tool that automates many of the tasks I typically perform manually at the command line. I started with a simple prompt: “Build a PowerShell script with a GUI interface and combine each of these scripts into one.” The scripts I referenced already had GUI components, and I began with tools like LLDP Discovery, Port Finder, and Packet Capture. Warp did a solid job combining them, and when I launched the script, some parts worked as expected while others needed debugging. Using Warp, I was able to troubleshoot and refine the script until it was functioning well. Encouraged by the results, I kept going. I added a local ARP table lookup and enhanced the Port Finder to run `netstat -ano`, displaying active ports along with the associated executables. I asked Warp to add a Passwords tab, a HOSTS file editor using a DataGrid, ARP table management, and CSV export. The final script prompts to restart with administrative privileges, since many of the tasks require elevated access. Altogether, this took me about six hours to build. If I had done it manually, it would have easily taken a week or more. ## What it does - **Passwords** — store a password in the tool and copy it to the clipboard when you need it. - **Host File** — editor so you don’t have to elevate Notepad and edit the file by hand. - **ARP Table** — view, clear, or delete individual entries. - **Packet Capture** — create PCAP and TXT files. If Wireshark or Notepad is installed, launch them from the tool. - **LLDP Discovery** — see which Ethernet port the machine is plugged into when the switch speaks LLDP. - **Port Finder** — open ports on the machine and which services started them. - **Port Scan** — scan an IP or hostname for open ports. - **Ping Scan** — a single IP or a range. When launched it will ask if you want to reopen in an Administrative PowerShell Console. Choose yes. It will create export folders at launch under `C:\NetworkTools` if they don’t exist. ## Requirements - PowerShell 5.1 or better - Wireshark installed if you want the Wireshark button. pktmon still writes ETL, PCAP, and TXT without it. - Windows with pktmon. Built on Windows 11. - Local admin privileges - Ability to create folders on `C:\` Extract the zip, move the NetworkTools directory to `C:\`, and read the script before you run it. > **GitHub:** Related scripts are in [Technolitero/Powershell-Public](https://github.com/Technolitero/Powershell-Public). --- # LLDP Discovery in Windows - URL: https://www.technolitero.com/blog/lldp-discovery-in-windows - Markdown: https://www.technolitero.com/raw/lldp-discovery-in-windows - Date: 2025-09-15 - Author: Buddy - Topic: Networking - Tags: powershell, lldp - Source: https://github.com/Technolitero/Powershell-Public LLDP tells you which switch port a Windows box is sitting on. pktmon already lives on the machine. Wrap it in a GUI and stop tracing cables by guesswork. LLDP does one thing very well: it will tell you about the port on a switch that a device is connected to and some information around the switch configuration. Where this comes in handy is if you need to move a port to another VLAN or trace a cable during switch upgrades. I searched everywhere for a Windows application that could do that and came up empty. At a basic level it uses pktmon, which is a built-in Microsoft utility that allows you to create `.etl` files and then convert those to `.txt` so you can parse. That’s where the magic happens. I wrapped it in a GUI. The zip has the code and two executables. These need to be run from an elevated administrative session. - `LLDPDiscovery.ps1` has the GUI code. - `LLDPDiscoveryNoGUI.ps1` is the raw script. - `LLDPDiscovery.exe` launches a PowerShell console for debugging. - `LLDPDiscoveryNC.exe` launches without a console. ```powershell filename="LLDPDiscoveryNoGUI.ps1" $sessionName = "LLDPListener" $etlPath = "$env:TEMP\LLDPListener.etl" $txtPath = "$env:TEMP\LLDPListener.txt" function Reset-Capture { Get-NetEventSession | ForEach-Object { Stop-NetEventSession -Name $_.Name Remove-NetEventSession -Name $_.Name } Remove-Item $etlPath, $txtPath -ErrorAction SilentlyContinue pktmon stop > $null pktmon filter remove > $null } function Start-Capture { Write-Host "Starting LLDP capture session..." New-NetEventSession -Name $sessionName -CaptureMode RealtimeLocal | Out-Null Add-NetEventPacketCaptureProvider -SessionName $sessionName -Level 0x0 -CaptureType Physical -TruncationLength 128 | Out-Null Start-NetEventSession -Name $sessionName | Out-Null pktmon filter add "LLDP" -d LLDP > $null pktmon start --capture --type flow --pkt-size 0 --file-name $etlPath --comp nics > $null } Reset-Capture Start-Capture Write-Host "Listening for LLDP packets on Ethernet interfaces... (Press Ctrl+C to stop)" do { Start-Sleep -Seconds 2 $counters = pktmon counters } while ($counters -match "All counters are zero.") Write-Host "LLDP packet received!" pktmon stop > $null pktmon etl2txt $etlPath --out $txtPath --verbose 3 > $null ``` These are for my own use, and no warranty is implied, but you are welcome to use the code. > **GitHub:** [Technolitero/Powershell-Public](https://github.com/Technolitero/Powershell-Public) --- # Packet Capture No Wireshark Needed - URL: https://www.technolitero.com/blog/packet-capture-no-wireshark-needed - Markdown: https://www.technolitero.com/raw/packet-capture-no-wireshark-needed - Date: 2025-09-15 - Author: Buddy - Topic: Networking - Tags: powershell, pktmon - Source: https://github.com/Technolitero/Powershell-Public Microsoft pktmon is a stripped-down NPCAP you already have. Wrap it in a small GUI and you get PCAP plus a TXT file AI can actually read. Microsoft has a tool called pktmon that gives you a stripped-down version of NPCAP that can be used to get Packet Captures from Windows machines without having to install a third-party piece of software. It’s not horrible to configure from the command line and you can go that route if you wish, but for most use cases and end users just getting into packet log investigation it can be a pain. I have converted the script to an executable to make it easier to run for those that don’t have much PowerShell experience. Double-click the `.exe`, it loads PowerShell in the background and launches a GUI. It will automatically create `C:\PacketCaptures`. The warning you see is telling you it needs to run with administrative permissions so pktmon can interrogate your network interfaces. Right-click and Run as administrator. By default the capture duration is 30 seconds. Adjust it up or down. Start the capture if possible, then work in the application you are having issues with for a set amount of time. Once the timer completes it generates two files by converting the ETL into a PCAP and a TXT file. The TXT is for dropping into a private AI workflow. The PCAP is for Wireshark. Files get a date stamp so you can run it over and over. ```powershell filename="Start-PacketCapture.ps1" # Run elevated. pktmon is built into Windows. pktmon start --capture --pkt-size 0 --file-name C:\PacketCaptures\capture.etl Start-Sleep -Seconds 30 pktmon stop pktmon etl2pcap C:\PacketCaptures\capture.etl --out C:\PacketCaptures\capture.pcap pktmon etl2txt C:\PacketCaptures\capture.etl --out C:\PacketCaptures\capture.txt --verbose 3 ``` > **Warning:** Like all scripts you are responsible for its use. It works well for me. Your mileage may vary. > **GitHub:** [Technolitero/Powershell-Public](https://github.com/Technolitero/Powershell-Public) --- # Repurpose Starlink Cable as Ethernet - URL: https://www.technolitero.com/blog/repurpose-starlink-cable-as-ethernet - Markdown: https://www.technolitero.com/raw/repurpose-starlink-cable-as-ethernet - Date: 2025-09-14 - Author: Buddy - Topic: Hardware - Tags: starlink, ethernet The new Dishy cable is Ethernet with weird ends and a weirder color code. Here is the pinout that actually passed a 1 Gig wire map. ## This has been tested on the new Dishy Cable in 2025 I was doing some testing on the new Dishy Cable at my house. Once testing was done, I was left with a Starlink cable that I didn’t feel like fishing back through conduit, so I decided to rewire it. I knew that it was actually an Ethernet cable with special ends. What I was not aware of is that it also uses a different color code. After I cut the cable, I realized the pairs on the RJ45 on the Dishy side were laid out different. My first attempt failed a wire map. I wrote down the color code I had initially used, then asked ChatGPT for the pin color pinout. That got me closer. A couple of reversed pins later I had a pinout I could land on an RJ45 wall jack. I kept the RJ45 on the Dishy side and plugged it into an outdoor AP. The cable is built well. It looks like CAT5 since it’s missing the plastic insert that CAT6 has, but it’s outdoor rated and for my use case it worked. The cable tested at 1 Gig. ## Dishy-side pinout if you keep the existing RJ45 1. Blue 2. White 3. Dark Green 4. Purple 5. Light Brown 6. Light Green 7. Brown 8. Gray On shorter runs the color doesn’t matter a whole lot at the ends. Another option for Gen2 Dishy is a conversion adapter so you can run it over existing CAT6. I make no claim that it will work for you, but it has saved me quite a bit of time. --- # PowerShell Introduction - URL: https://www.technolitero.com/blog/powershell-introduction - Markdown: https://www.technolitero.com/raw/powershell-introduction - Date: 2025-07-09 - Author: Buddy - Topic: PowerShell - Tags: powershell - Source: https://github.com/Technolitero/Powershell-Public PowerShell is one of my favorite scripting languages. These are the practices that keep scripts readable when you are not the person running them. ## PowerShell (My) Best Practices PowerShell is one of my favorite scripting languages, there are many reasons for this. The first is that it’s the language I know the best, it gets points for that. I like the modules that you can import, how it works with Task Scheduler for automated runs, and the fact that I can do most of a module’s function natively by writing my own code. I’ve written literally thousands of scripts over the years to basically take humans out of a tedious process. This allows standard operations to be automated, reducing the likelihood of human errors. The only downside is multithreading and some specific security and network-based operations that require or at least are easier to do in Python that are better documented. PowerShell is also made for linear execution not multithreading. I have only seen a need to multithread a few times for Infrastructure Management, and you can do it in PowerShell, but it gets complicated fast. - Import Modules at the top of the script. This lets you know what modules are available so you can choose the cmdlets you want to run later. - Variables should be placed under the modules so that you can call them as needed. Having them at the top makes them easier to change without hunting through the body. - I rarely define variables in the body that will regularly change. Those stay at the top. Dynamic values from a `.csv` or `.json` live in the body. - Create Functions under the Variables where appropriate so you can reuse code without duplicating it. - When you need to connect to services such as M365 or Remote PowerShell, put the connection code next. Get the logons done before the work starts. - Script as you will not be the person running it or who understands what it does. - Less is more. Most of the time you just need it to do a function well. - Error checking for production scripts. I don’t waste time on scripts only I run. If another user or process runs it, I log failures to a database or a `.csv`. The layout below is a guide. The code doesn’t do anything useful on purpose. ```powershell filename="script-layout.ps1" ## Modules Import-Module WhateverModuleYouWant ## Variables $TestVar1 = "Testing1" $TestVar2 = "Testing2" $outputFile = "C:\Errors.csv" $errorList = @() ## Functions function TestFunction { param ( $Test, $Test123 = "Testing 123" ) } ## Connect to Services $CredM365 = Connect-ExchangeOnline ## Start Script Body try { $Testing = TestFunction -Test 123456 } catch { $errorDetails = [PSCustomObject]@{ TimeStamp = Get-Date Message = $_.Exception.Message } $errorList += $errorDetails } if ($errorList.Count -gt 0) { $errorList | Export-Csv -Path $outputFile -NoTypeInformation -Force Write-Output "Errors have been logged to $outputFile" } else { Write-Output "No errors occurred." } ``` > **GitHub:** Public scripts live in [Technolitero/Powershell-Public](https://github.com/Technolitero/Powershell-Public). --- # Unifi Security Settings - URL: https://www.technolitero.com/blog/unifi-security-settings - Markdown: https://www.technolitero.com/raw/unifi-security-settings - Date: 2025-06-29 - Author: Buddy - Topic: Networking - Tags: unifi, firewall - Source: https://github.com/Technolitero/Unifi Zone-based firewall on Unifi was confusing at first. Zones, policies, network objects, region blocking, and honeypots are what I actually turn on. ## Quickstart Unifi released the Zone Based Firewall a while back and at first it was a little confusing. I have gotten much better with it since its release and wanted to give some tips and tricks as well as some information how to use it. ## What is a Zone? A Zone is basically a collection of networks that allows you to apply a firewall policy to the collection or individual addresses to block or allow certain network traffic. ## How do I add a Firewall Rule to a Zone? - Open the Unifi Console - Click the Gear Icon on the Left near the bottom - Click Policy Engine - Scroll down and click Create Policy You will need a name. I normally start with what it does, then a descriptive target: `Allow Internal to Guest for` as an example. **Source Zone:** the zone the device lives in. Then Any, Device, Network, or IP. Source port is usually Any because clients pick random ports. **Action:** Block (default, looks closed), Allow, or Reject (tells the source it was blocked). **Destination Zone:** where the traffic is going. External for the internet. Then Any, App, IP, Domain, Region, and a destination port. IP Version is Both in most cases. Protocol is All, TCP/UDP, TCP, UDP, or Custom (ICMP). Connection State defaults to All. Firewall policies go down the list. First match wins. Less restrictive allow rules sit above a broad block. If you want one client on the internet while a zone is blocked, allow DNS/HTTP/HTTPS for that IP above the block. Validate in Flows. Kick off traffic and watch whether it is allowed or blocked. You may need to move the policy so it matches first. ## Network Objects Profiles These streamline rules you reuse. - Gear → Profiles → Network Objects → Create New - Port, port range, IPv4, or IPv6. SMB, internet access, and standard deny lists belong here. ## Region Blocking Gear → Cybersecure → Region Blocking. Block selected regions, or allow only selected regions. Both directions, outgoing, or incoming. This is the “stop random scanners from half the planet” switch. ## Honeypot Gear → Cybersecure → Honeypot → Create New. Pick a network and an unused IP. It opens commonly used ports with no services behind them so you can see if a compromised machine is scanning you. ## Detections and Intrusions Detection Mode can Notify or Notify and Block. Categories include botnets, malware, exploits, P2P/dark web, recon, and protocol vulns. You can exclude IPs or networks if blocking is too hot. Intrusion Prevention on enables DPI for calls that look like they will compromise the network. I have found these less intrusive while still being effective. Content filtering, encrypted DoH, and app blocking exist if you want a house with no Spotify. Bandwidth is less of a concern now, so I usually skip those unless there is a reason. --- # Unifi Advanced Networking - URL: https://www.technolitero.com/blog/unifi-networking - Markdown: https://www.technolitero.com/raw/unifi-networking - Date: 2025-06-28 - Author: Buddy - Topic: Networking - Tags: unifi - Source: https://github.com/Technolitero/Unifi Port profiles, DHCP guardian, and a Default network that is not 192.168.1.0/24. The advanced Unifi settings I actually leave on. ## Enhancing your Network Starting with Unifi can be overwhelming and while I won’t cover all the advanced settings, I will cover the ones that I have found helpful for maintaining a robust stable network. ## Networks - If you are changing the IP range of the Default network there is no need to change the name. New networks need a name. - The default Router should be sufficient. This gives you zone-based firewall policies instead of switch ACLs. - Uncheck Auto-Scale Network. I don’t like things automatically doing anything unless I defined the guardrails. - Default is really VLAN 1. Change it off `192.168.1.0/24`. I use `10.0.0.0/8` and pick a `/24` that will never collide with a VPN or the ISP router. - Click Manual. Auto does some best practices, but I want VLAN, spanning tree, and multicast under my control. Typical routed network: - VLAN ID 2–4096 - Isolate Network unchecked - Allow Internet Access checked unless it is storage - IGMP Snooping checked - Multicast DNS checked, unless it is a noisy IoT VLAN - DHCP Server, range `.100`–`.199` unless it is wireless-only - DHCP Guardian set to the router address on that VLAN so a guest’s old Netgear cannot hand out leases - DNS: UDM primary, then Google or OpenDNS - Lease Time 86400 - Ping Conflict Detection checked - Option 43 checked with the Default network UDM IP so Unifi devices find the controller faster ## Creating Port Profiles I love Port Profiles. They keep switches consistent. Naming I use: - Uplink Port – DeviceType (`Uplink Port – AP`) - Access Port – VLANID (Purpose) (`Access Port – VLAN2 (IOT)`) - Disabled **Uplink:** Native VLAN of the network, Tagged VLAN Management Allow All, POE if the AP needs it, STP on, LLDP-MED on, loop protection off. Uplinks carry multiple VLANs. APs with several SSIDs belong here. **Access:** Native VLAN, Tagged VLAN Management Block All, loop protection on, STP on. One VLAN, tagged as a single network. **Disabled:** Port Disabled. Use it on empty jacks so someone plugging in does not get a surprise VLAN, and on backup uplinks you do not want forming a loop. ## Assigning Port Profiles Devices → switch → Port Manager. Select ports, pick the Ethernet Port Profile, Apply Changes. Edit the profile later and every assigned port follows. ## Global Network Settings - mDNS checked, proxy All if you want Chromecast and AirPlay across VLANs - IGMP Snooping checked, Fast Leave checked - Spanning Tree Protocol: RSTP - Rogue DHCP Server Detection checked - L3 Network Isolation and Device Isolation ACLs unchecked unless you have a real reason. A firewall policy is usually the better tool. ## Changing the Internet Port If the ISP is faster than 1 Gig, move WAN to a 10GB SFP. Gear → Internet → WAN port → Port. Apply Changes only after it is cabled or you will take yourself offline. The UDM can fail over or load balance two WANs. You only get two 10GB ports, so pick what matters. --- # Unifi UDM Quick Start - URL: https://www.technolitero.com/blog/unifi-udm-quick-start - Markdown: https://www.technolitero.com/raw/unifi-udm-quick-start - Date: 2025-06-28 - Author: Buddy - Topic: Networking - Tags: unifi, udm - Source: https://github.com/Technolitero/Unifi Unifi is not Cisco with a prettier UI. Get the UDM online, adopt devices, and stand up Wi-Fi without dragging enterprise habits into a 15-minute install. ## Basic Settings The Unifi line of products is amazing, the relatively low cost, the features, the stability…. the list goes on. I have spent over a decade using Ubiquiti products and have deployed many of them for small businesses, home users and even some more complicated installs using fiber optics to cover a million square foot underground warehouse to cover the main locations inside of it. I was able to do all of this using Unifi. The issue I run into with a lot of Network Engineers that are familiar with Cisco is that they overthink the configuration and try too hard to fit Unifi into the same bucket, granted most vendors such as Palo Alto, Fortinet, HPE etc… use many of the same commands. Unifi is different and should be configured as such. ## Router Install - When you first get your Unifi equipment, create a Unifi Account. - Download the Unifi App for your phone or tablet, open it and log in. - Install your router. Mount it if necessary. - Cable all of your Unifi devices. This can be done after the fact as well but streamlines the process. - Plug your ISP into port 9 which is marked on the UDM Pro/SE/Max. - Power up your UDM and wait a couple of minutes. - Open the Unifi App and tap Set Up. - Name your UDM based on your standards and tap Next. - It will do a speed test, let that finish and tap Next. - The router will then begin its setup with the default configuration. - Tap Go to Dashboard. The basic setup is done. > **Warning:** The default IP range of the internal network is `192.168.1.0/24`. This can be a problem if your ISP uses the same IP range. You will want to change it on the ISP equipment or routing will fail. The same route cannot be on two interfaces of the UDM. ## Device Adoption - You can do this through the App which is how I typically do it, or you can login to the router itself by going to its IP or [https://unifi.ui.com](https://unifi.ui.com) in a web browser and logging in with your Unifi Account. - When you go under devices, tap the device and then click Adopt Device. - Unifi will then grab the device and apply its settings to it. It may also do software upgrades if needed but this usually doesn’t take more than a few minutes. - If this is a used device, reset it to factory default before adopting it. - I always suggest that you assign static IP addresses to any network devices. If you lose power and the device starts faster than the router it will default to the default IP address. While it may still work you won’t be able to manage it until you reboot it. ## Wi-Fi Setup Unifi can handle up to 4 SSIDs per radio. That means you can have 4 2.4GHz and 4 5GHz SSIDs for a total of 8. In my example you will create an SSID that will have both, but it eats up 2 SSIDs to do that. It cuts down on sprawl because the SSID is the same for both and who really wants to remember 8 passwords. Decide on your SSID name. What I typically do on existing installations is to create an SSID that is identical to the existing one on the other hardware. Devices will automatically connect and you don’t have to change it on them. You can create that and be done, but let’s say its called Netgear123 you probably don’t want to use that SSID forever. The more SSIDs you use can also impact performance so less is better. I find the configuration is easier through the web interface vs the App so login to unifi.ui.com and open your console. 1. Click on Settings, the gear icon on the left near the bottom. 2. Click Wi-Fi and then click Create New. 3. Enter the SSID name and the password. 4. Broadcasting APs should be All. 5. Advanced should be Auto. 6. Click Add Wifi Network at the bottom of the page. 7. Test after it deploys. This should be done in about 15 minutes and get the basics up and running. There are things you might consider before statically assigning IPs to network devices, creating VLANs, creating Port Profiles etc… but you should be able to get on the internet and Wi-Fi if you have APs. --- # Entry Level AI - URL: https://www.technolitero.com/blog/entry-level-ai - Markdown: https://www.technolitero.com/raw/entry-level-ai - Date: 2025-06-25 - Author: Buddy - Topic: AI - Tags: ai When people think about using AI it gets daunting. What if you thought about AI as a mentor instead of a technology? ## AI for the rest of us! When people think about using AI it gets daunting, what can I use it for, how can it help me? What if you thought about AI as being a mentor instead of a technology? I think most people start the journey on the path to AI with a use case, the how do I do something, write a script, make an angry email sound a little softer but still get your point across. Sure, it’s good for that, maybe not perfect but better than doing it all by yourself. I have found that AI is more powerful when you use it as digital mentor. **Guard Rails:** AI will train itself based on the data provided. What this means is that it will take your data and use it to learn. While this is powerful and overall helps the quality of the data it is basing its answers on, it will use that data for others. A good practice is to clean your data of any identifiable marker. Remove names, addresses, social security numbers etc… Pretty much anything that you wouldn’t sit on a park bench. You can also use AI’s, such as Microsoft Copilot, which can be trained on company data but in a bubble protecting you from data leakage that could be detrimental to your business. **Your AI journey:** When you start using AI, most people start with a simple ask, a sentence, maybe a paragraph. When you give AI the full context and are specific on your ask, your results are much better. - **Sentence:** Write a script that creates a conference room in M365. - **Paragraph:** Write a script that creates a conference room in M365. I want to set the location, how many users the room can handle, and a room manager that can move or delete meetings. This should be a cloud only conference room with no AD sync. I would like to use a .csv file to create the room based on fields in the .csv. - **Contextual:** I am an IT professional and I need a script that allows users to create a conference room with the following format based on input from a .csv. It should base it off a field called confrmname and take a generic name such as NewConfRoom and have the displayname and name fields changed to follow this format: NewConfRoom-Video. The other fields I would like are for the room manager labeled as rmmgr that can add or remove meetings, a field called capacity that is numeric, and a field called location for the physical location of the conference room. I want this to be easy to update so let me know if there is a way that I can either use a .csv or if one is not provided that it ask me the questions to create the room using a similar format. In any case it will create a script to do what you asked for. You may have some cleanup to do but the more details you can provide, the less you have to fix. You can also use AI as a life coach, a business mentor, a financial advisor etc… the key is that you are in control and if it sounds off, well it probably is. AI is in my opinion a technology that is as awesome as the internet. When I started in IT, we did everything using WIKIs if they existed, otherwise we banged our head on the keyboard until we figured it out. Then came the internet, then YouTube. AI is the culmination of this shared knowledge. Learn to speak AI, learn to leverage AI responsibly, and get a competitive edge on the folks that are fighting against the technology and its potential. --- ## Downloads # Unifi Analyzer - URL: https://www.technolitero.com/downloads/unifi-analyzer - Version: 1.1.1 - Released: 2026-03-14 - Platforms: Windows, Python 3.8+ - Source: https://github.com/Technolitero/unifi-analyzer - Releases: https://github.com/Technolitero/unifi-analyzer/releases/tag/Unifi A Windows tool that pulls Unifi UDM configuration over the API and SSH so you can analyze, export, capture packets, and keep config history. Unifi Analyzer was created as a personal tool for configuration work on Unifi equipment. It uses the API and SSH to pull the information you need without bouncing between the controller UI and a terminal. ## Features - **Analyze:** Looks for common misconfiguration items, validates they are corrected, and lets you ignore findings that are intentional. - **Config Lookup:** Networks, Wi-Fi SSIDs, firewall, zones, firewall policies, policy groups, DNS records, routing, port forwards, port profiles, port lists, devices, and clients. Export to Excel and save into History. - **Interfaces:** Pull ports that are online by default, show all ports if needed, packet sniff where the device allows it, and SSH in to view device message logs. - **PCAP Viewer:** Export JSON for dropping into a private AI workflow, or download the PCAP for Wireshark. - **History:** Save configuration workbooks and download them later. > **Warning:** Do not send PCAPs or JSON exports into a public AI service. This data should stay in a business or local environment. ## Install Extract the release zip and run `install.bat`. Default settings install it as a Windows service on port **8080**. - Local: `http://127.0.0.1:8080` - Remote: `http://{IPofConfigServer}:8080` if Windows Firewall allows the port You need Python 3.8 or higher. Support is limited; the README and install scripts are the intended path. ## Credentials Use the credentials button after install: - **UDM Host:** IP of the UDM - **API Port:** 443 by default - **Site:** default - **API Username / Password:** admin credentials - **SSH Port:** 22 by default - **UDM User:** root by default - **Device User:** admin by default for SSH to devices If the passwords match, use Copy API Pass and then save. > **GitHub:** Source, issues, and releases live at [Technolitero/unifi-analyzer](https://github.com/Technolitero/unifi-analyzer). --- # PowerShell Public Scripts - URL: https://www.technolitero.com/downloads/powershell-public - Version: main - Released: 2026-01-01 - Platforms: Windows, PowerShell - Source: https://github.com/Technolitero/Powershell-Public - Releases: https://github.com/Technolitero/Powershell-Public Public PowerShell scripts from the TechnoLitero toolkit. Clone the repo, take what you need, and keep the rest out of your production path until you have tested it. This is the public PowerShell collection: scripts written for admin work, then cleaned up enough to share. Clone it, read the script before you run it, and treat it like any other field tool. ```powershell filename="clone-toolkit.ps1" git clone https://github.com/Technolitero/Powershell-Public.git Set-Location .\Powershell-Public Get-ChildItem -Recurse -Filter *.ps1 | Select-Object FullName ``` > **GitHub:** [Technolitero/Powershell-Public](https://github.com/Technolitero/Powershell-Public) --- # Meshtastic Notes - URL: https://www.technolitero.com/downloads/meshtastic-notes - Version: main - Released: 2026-01-01 - Platforms: Meshtastic, MQTT - Source: https://github.com/Technolitero/Meshtastic - Releases: https://github.com/Technolitero/Meshtastic Companion notes and configs for Meshtastic work: private meshes, MQTT, and the hardware paths that actually get used. The Meshtastic repository is the code-and-config companion to the Meshtastic articles on this site. If you are starting from zero, read the beginners guide first, then clone the repo for anything that belongs in Git instead of a blog post. > **GitHub:** [Technolitero/Meshtastic](https://github.com/Technolitero/Meshtastic) --- # Resources - URL: https://www.technolitero.com/resources ## GitHub - [Technolitero on GitHub](https://github.com/Technolitero): Public repos for Unifi Analyzer, PowerShell, Meshtastic, and Unifi notes. - [Unifi Analyzer repository](https://github.com/Technolitero/unifi-analyzer): Source and releases for the Unifi Analyzer Windows tool. - [PowerShell Public](https://github.com/Technolitero/Powershell-Public): Shared PowerShell scripts from the field toolkit. ## Unifi - [Unifi Network Community](https://community.ui.com/): Great for digging into Unifi Network issues. - [Unifi Network Management](https://unifi.ui.com/): Remote management of Unifi equipment. ## Home Automation - [Home Assistant](https://www.home-assistant.io/): Leading open source home automation. Nabu Casa is the paid remote-access option. ## Support - [Speedtest.net](https://www.speedtest.net/): Validate network speeds before you chase a ghost. - [MXToolbox](https://mxtoolbox.com/): DNS, blacklist, and mail record checks. - [Gibson Research Shields Up](https://www.grc.com/shieldsup): Remote firewall port scan to see what the internet can actually see. - [DownDetector](https://downdetector.com/): Near-real-time view of whether an outage is just you or everyone. ## AI Tools - [Microsoft 365 Copilot](https://copilot.microsoft.com/): Licensed business AI that can stay inside a tenant with proper governance. - [Google Gemini](https://gemini.google.com/): Free enough to get your feet wet. - [ChatGPT](https://chatgpt.com/): The original public chat bot, still a useful baseline. - [Claude](https://claude.ai/): Strong for developers and scripters, including editor integrations. - [xAI Grok](https://x.ai/): Another public chat option if you want a different model personality. ## Installable Tools - [Wireshark](https://www.wireshark.org/): Packet capture and analysis. Worth the learning curve. - [PuTTY](https://www.putty.org/): SSH client for devices that still live on a command line. - [WinSCP](https://winscp.net/): SFTP and SCP file access that pairs well with PuTTY. ## Meshtastic - [Meshtastic](https://meshtastic.org/): Official Meshtastic site, flasher, and client. - [Meshtastic Web Client](https://client.meshtastic.org/): Connect to a Meshtastic device from a browser. - [Meshtastic Flasher](https://flasher.meshtastic.org/): Firmware upgrades for Meshtastic devices. --- # Tools - URL: https://www.technolitero.com/tools Wrappers around third-party scanners and looking glasses. TechnoLitero does not run the lookup; the browser talks to the provider. - [Open Ports](https://www.technolitero.com/tools/open-ports) (YouGetSignal): Check whether a host answers on a TCP port. Runs at YouGetSignal, not here. - Provider: https://www.yougetsignal.com/tools/open-ports/ - [Port Scanner](https://www.technolitero.com/tools/port-scanner) (SubnetOnline): Another browser-side port check when you want a second opinion. - Provider: https://www.subnetonline.com/pages/network-tools/online-port-scanner.php - [Visual Traceroute](https://www.technolitero.com/tools/visual-traceroute) (YouGetSignal): Map the hops from the provider’s network to a host. - Provider: https://www.yougetsignal.com/tools/visual-tracert/ - [Looking Glass](https://www.technolitero.com/tools/ping-pe) (ping.pe): Ping, traceroute, and MTR from many vantage points. - Provider: https://ping.pe/ - [Ping / Traceroute / DNS](https://www.technolitero.com/tools/ping-eu) (ping.eu): Classic network tests from ping.eu. - Provider: https://ping.eu/ - [Redirect Checker](https://www.technolitero.com/tools/redirect-checker) (redirect-checker.org): Follow HTTP redirects and see the hop chain. - Provider: https://www.redirect-checker.org/ - [MX Toolbox](https://www.technolitero.com/tools/mxtoolbox) (MXToolbox): MX, blacklist, SMTP, and related mail/DNS checks in SuperTool. - Provider: https://mxtoolbox.com/SuperTool.aspx - [intoDNS](https://www.technolitero.com/tools/intodns) (intoDNS): DNS health report for a domain (NS, MX, SOA, and common misconfigs). - Provider: https://intodns.com/ - [DNS Dumpster](https://www.technolitero.com/tools/dnsdumpster) (HackerTarget): Passive DNS recon and related host mapping. - Provider: https://dnsdumpster.com/ - [DNS Watch](https://www.technolitero.com/tools/dnswatch) (dnswatch.info): Look up records from a public DNS UI. - Provider: https://www.dnswatch.info/ - [DNS Lookup](https://www.technolitero.com/tools/dns-lookup) (dnslookup.online): Query common record types from dnslookup.online. - Provider: https://dnslookup.online/ - [Global DNS Propagation](https://www.technolitero.com/tools/whatsmydns) (whatsmydns.net): See how a record looks around the world. Opens at the provider because they block embeds. - Provider: https://www.whatsmydns.net/ - [Mail Tester](https://www.technolitero.com/tools/mail-tester) (mail-tester.com): Score an outbound message for spam and authentication issues. - Provider: https://www.mail-tester.com/ - [WHOIS](https://www.technolitero.com/tools/whois) (whois.com): Domain registration lookup. - Provider: https://www.whois.com/whois/ - [IP WHOIS](https://www.technolitero.com/tools/ip-whois) (ipwho.is): IP geolocation and network details from ipwho.is. - Provider: https://ipwho.is/ - [BGP Toolkit](https://www.technolitero.com/tools/bgp) (Hurricane Electric): Prefixes, ASNs, and routing views from Hurricane Electric. - Provider: https://bgp.he.net/ - [SSL Server Test](https://www.technolitero.com/tools/ssl-labs) (Qualys SSL Labs): Qualys SSL Labs. Opens in a new tab because they block embeds. - Provider: https://www.ssllabs.com/ssltest/ - [Security Headers](https://www.technolitero.com/tools/security-headers) (securityheaders.com): Grade a site’s HTTP security headers. Opens at the provider. - Provider: https://securityheaders.com/ - [Mozilla Observatory](https://www.technolitero.com/tools/observatory) (Mozilla): Mozilla’s site security scanner. Opens in a new tab. - Provider: https://observatory.mozilla.org/