What G8KEPR Is, in Plain English
The security startup I build on nights and weekends, explained without the jargon: what it guards, how it does it, and where it runs.
Thread: Building G8KEPR ↗Tagged · 45 notes
Everything tagged Security, wherever it's filed, newest first.
The security startup I build on nights and weekends, explained without the jargon: what it guards, how it does it, and where it runs.
Thread: Building G8KEPR ↗API security, MCP security, an AI gateway and a verification engine, one at a time: what each one looks at and what it's there to catch.
Thread: Building G8KEPR ↗What MCP is, how a tool's own description can be turned against the model reading it, and why a hash that's re-checked on every call is such a useful tripwire.
Thread: Building G8KEPR ↗A lot of AI security tools ask another AI model to grade the first one. G8KEPR doesn't. Here's why, what it costs, and what the published numbers do and don't mean.
Thread: Building G8KEPR ↗G8KEPR is self-hosted by design: deployed with Helm or Terraform, sitting in your request path, sending zero bytes out and charging nothing per token. Here's the reasoning.
Thread: Building G8KEPR ↗One founder, a Delaware C-Corp, evenings and weekends, and a codebase with more lines of tests than lines of code. Here's what that ratio says about how I build.
Thread: Building G8KEPR ↗G8KEPR started as an AI security platform that tried to do everything. In September 2026 I narrowed it to the one thing that's actually different, and kept most of what I'd built.
Thread: Building G8KEPR ↗My brand-new blog got an F on a security header scan. Here's why, what actually matters for a static site, and the fixes that work on DigitalOcean App Platform.
Thread: Building this notebook ↗One script that locks a departing user out, cleans up their groups and licenses, and keeps their mail, with a CSV record of every step.
Thread: The Microsoft Graph toolbox ↗Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
Thread: Local admin, done right ↗Find the updates the most machines are actually missing, bundle them into a group, and deploy them to a pilot collection, with a WhatIf preview first.
Thread: Windows Update, untangled ↗Before you rename, rescope or delete a group, find out what it's wired to. Members, owners, licenses, apps and Intune policies, in one report.
Thread: The Microsoft Graph toolbox ↗A computer inventory straight out of AD, with OS build, last logon, password age and OU in one tidy CSV, ready for audits or a stale-machine cleanup.
Thread: Keeping Active Directory tidy ↗Repack .7z files as plain Deflate ZIPs with UTF-8 file names, including password-protected ones, and test every result before the original goes anywhere.
Thread: Archive conversion workshop ↗A quick, safe software inventory from the registry, local or remote, that returns objects you can filter and export instead of a wall of colored text.
Thread: PowerShell craft ↗Clean old user profiles off shared PCs and servers through Win32_UserProfile, so the folder and the registry entry go together and nobody gets a TEMP profile.
Thread: Spring cleaning for Windows PCs ↗When Windows Update is greyed out or just won't run, check all the policy values and services that can block it, and put them back the way Windows shipped.
Thread: Windows Update, untangled ↗Pull shutdown, startup and crash events from the System log so you can tell a planned restart from a power cut, and see who or what asked for it.
Thread: Windows Update, untangled ↗A one-off local admin account done properly, with a hidden password prompt, a language-proof group lookup, and an expiry date for the temporary ones.
Thread: Local admin, done right ↗Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
Thread: Local admin, done right ↗Empty the Recycle Bin with no prompt, for one user or everyone on the machine, and optionally keep anything deleted recently.
Thread: Spring cleaning for Windows PCs ↗Clear the Windows DNS client cache locally or across a list of machines, and know when a flush will actually fix anything.
Thread: Spring cleaning for Windows PCs ↗A decade-plus of Windows migrations, endpoint security, and infrastructure work, boiled down to what I did and how big it was.
For the Entra-joined PC that never showed up in Intune. Check it's ready, kick off enrollment, and see why it failed if it does.
Thread: Getting devices into Intune ↗Load mobile numbers into Entra ID as an authentication method before users ever sign in, without stomping on numbers they've already registered.
Thread: The Microsoft Graph toolbox ↗How RADIUS VSAs work, how to add one in Windows NPS or FreeRADIUS to hand out DNS servers, and how to prove your VPN or NAS is actually using it.
A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗A practical checklist for taking a device that gets its security policy through Defender for Endpoint and enrolling it in Intune without leaving a gap.
Thread: Getting devices into Intune ↗Point each domain controller at a partner DC first and itself (127.0.0.1) last, the way Microsoft recommends, across all your DCs in one pass.
Thread: Keeping Active Directory tidy ↗Audit who still talks SMBv1 to your machines, then switch it off for good, with one script and three modes.
Thread: PowerShell craft ↗Turn on Dell's Password Bypass so patch reboots don't sit at a power-on password prompt all night, then turn it back off when you're done.
Thread: Dell BIOS passwords, without the pain ↗How I think about patch risk now. Sort updates by blast radius, roll them out in rings, decide what "bad" looks like up front, and know your way back before you need it.
Thread: Windows Update, untangled ↗Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.
Thread: Keeping Active Directory tidy ↗Compare files, whole folder trees, or a download against its published checksum with Get-FileHash, and get back a clear Match or Different for every file.
Thread: File wrangling ↗How to build a configuration profile in Intune, roll it out to machines that are already in people's hands, and confirm it actually landed.
Thread: Getting devices into Intune ↗One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.
Thread: Keeping Active Directory tidy ↗Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.
Thread: Keeping Active Directory tidy ↗Put a BIOS admin password on new Dells, or change the old one across the fleet, with both passwords handed over at runtime.
Thread: Dell BIOS passwords, without the pain ↗Clear the BIOS setup password on Dell PCs and see exactly what changed, with the password supplied at runtime instead of sitting in a package.
Thread: Dell BIOS passwords, without the pain ↗Find out which Chrome version a machine is really running, whether an update is stuck waiting on a restart, and kick Google's updater into checking now.
Thread: Spring cleaning for Windows PCs ↗Remove the internal drive password from Dell PCs with Dell's PowerShell provider, without ever writing the password into a script or package.
Thread: Dell BIOS passwords, without the pain ↗Onboarding to Defender for Endpoint and enrolling in Intune are two different things, and you almost never have to offboard one to get the other.
Thread: Getting devices into Intune ↗Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
Thread: Local admin, done right ↗Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.
Thread: Keeping Active Directory tidy ↗Feed it a list of computers and a service name, get back one row per machine saying whether it's installed, running, and how it starts.
Thread: PowerShell craft ↗