armourinfosec GitHub avatar

Enterprise-Windows-Infrastructure-Security

armourinfosec

A four-month, hands-on curriculum teaching enterprise Windows infrastructure administration and security hardening through 20 modules, 7 labs, and 10 capstone projects, progressing from first logon to purple-team practices.

Stars

83

7-day growth

No data

Forks

35

Open issues

0

License

CC-BY-4.0

Last updated

2026-07-22

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It uniquely integrates security hardening into every service module rather than treating it as an afterthought, and provides a complete, self-paced, lab-driven path from beginner to advanced Windows Server administration and defense.

Who it is for

  • IT professionals seeking practical Windows Server administration skills
  • System administrators transitioning to enterprise roles
  • Security analysts wanting hands-on Windows hardening and purple-team experience
  • Students preparing for Microsoft AZ-800/AZ-801 or CompTIA Server+ certifications

Use cases

  • Building and defending a fully functional enterprise Windows domain in an isolated lab
  • Preparing for Windows Server administration certifications with exam-aligned content
  • Practicing purple-team attack and defense techniques in a controlled environment
  • Developing reproducible hardening baselines for production Windows estates

Strengths

  • Lab-driven pedagogy with real `corp.local` domain examples and step-by-step reproducibility
  • Modular structure with prerequisite chaining and cross-linking for both sequential learning and reference
  • Security is embedded in every service module (least privilege, auditing, firewalling) plus a dedicated purple-team capstone
  • Strong alignment with multiple certifications (AZ-800, AZ-801, CompTIA Server+, Network+)

Considerations

  • Requires a host with hardware virtualization (VT-x/AMD-V) and at least 16 GB RAM to run the multi-VM lab
  • Focuses exclusively on on-premises Windows Server; does not cover Azure hybrid or cloud-native services
  • Attacker exercises are strictly limited to isolated lab environments and may not fit all learners' security policies

README quick start

Enterprise Windows Infrastructure & Security

A four-month, lab-driven curriculum that takes a learner from first logon to designing, running, and hardening a full stack of enterprise Windows services — the operating system and command line, Active Directory, Group Policy, DNS, DHCP, file and web services, remote access, backup, monitoring, and the security and purple-team practice that keep a production Windows estate defensible.

Curriculum home: Repository README


Course Information

PropertyValue
Course TitleEnterprise Windows Infrastructure & Security
FolderEnterprise-Windows-Infrastructure-Security/
TagWindows Server Administration & Security
Slugwindows-infra
LevelBeginner to Advanced
Duration4 Months (16 Weeks · 1 Hour/Day · ~120 Hours)
FocusWindows Server Administration & Enterprise Hardening
Reference SystemsWindows Server 2019 / 2022 / 2025 · Windows 10 / 11
Modules20
DeliverySelf-paced notes + hands-on labs
LanguageEnglish

[!NOTE] What this course is A study-and-practice track built as an Obsidian knowledge base and published as GitHub-flavored Markdown. Each module is a folder with its own Readme hub and a set of deep-dive notes containing tagged, copy-ready commands and configuration. It is designed to be read in order but is fully cross-linked for reference use.


Course Description

Master Windows Server administration and defensive hardening end to end: the operating system, the command line, and PowerShell; virtualization and lab setup; networking fundamentals; then the core enterprise identity and infrastructure services — Active Directory Domain Services, Group Policy, DNS, and DHCP — followed by file services and DFS, IIS web hosting, FTP, proxy, and remote-access/VPN. The program closes with server management, backup and disaster recovery, monitoring and logging, and a dedicated enterprise-security and purple-team practice.

The course is delivered through extensive, reproducible hands-on labs modelled on a real corp.local domain, so every concept is paired with a working configuration you can build, break, attack, and harden.


Overview

The Enterprise Windows Infrastructure & Security program provides practical, enterprise-ready skills

Description

An Obsidian-based knowledge base for Windows Server administration and defensive hardening.

Related repositories

Similar projects matched by category, topics, and programming language.

m-novotny
Featured
m-novotny GitHub avatar

memguard-rs

A Rust library that provides secure memory handling primitives including zeroization on drop, memory locking, constant-time comparison, and compile-time guarded regions, with zero dependencies and no_std support.

Embedded & IoTSecurity
131
AgriciDaniel
Featured
AgriciDaniel GitHub avatar

anti-slop

Anti-slop is a tool for detecting and repairing substance defects in AI-assisted prose, code, documentation, and agent output using deterministic scanners and structural procedures that produce verifiable artifacts rather than authorship judgments.

AI & Machine LearningLarge Language Models
9
Kritt-ai
Kritt-ai GitHub avatar

open-kritt

open·kritt is an open-source, self-hosted platform that orchestrates AI agents to perform focused, parallel code analysis for finding real vulnerabilities, with de-duplication and validation.

JavaScript
436