[{"categories":null,"contents":"My passion is to educate others, so they can audit, analyze, and secure their IT environments.\nCISOfy is the company I founded in 2013, with Lynis Enterprise as its flagship product. It performs security auditing, detects weaknesses and vulnerabilities, and provides hardening guidance. The focus is on Linux/UNIX system administrators, DevOps, IT managers, auditors and security managers, up to the CISO. The main principles of our products are simplicity, ease of use, and automation.\nWant to learn me better? ✔ Follow me on Mastodon: @mboelen ✔ Follow my blog posts: https://linux-audit.com/\nMy personal motto: There is always room to improve, and I will hunt for it!\nWork CISOfy Founder\nSince: Oct 2013 to Present\nLynis Enterprise is a software solution with the focus on security auditing, system hardening, and compliance. By targetting only Linux, macOS, and UNIX environments, we specialize and operate in a niche market.\nLynis Enterprise helps you discover and solve security weaknesses quickly, so you can put your time into interesting projects again. Regarding compliance needs, it covers popular standards like ISO27001, HIPAA, PCI DSS, CIS, SOx, SOC, and others.\nSee https://cisofy.com/lynis/ for all details.\nAs a founder, I\u0026rsquo;m responsible for a diverse set of activities, including strategic management of the company, development, marketing, and sales.\nPart-time work NLUUG Honorary member\nSince: May 2019\nAwarded the title honorary member after my work for our association and continue to help where I can.\nWebmaster\nSince: May 2023\nBuilding the most recent version of the NLUUG website together with Patrick Reijnen. My main priorities are building the skeleton of the website and its functionality. In ongoing iterations, we keep improving the website.\nMember of Program Committee\nFrom: Jan 2015 - May 2019\nSupporting the program committee to ensure the best possible quality of the conference program. Includes promotion the event and sharing details with other groups.\nBoard Member (Secretary)\nFrom: May 2016 - May 2019\nSecretary, public relations, and social media\nThe NLUUG provides twice a year a conference with focus on open standards, Linux, UNIX, and open source software. Popular subjects include DevOps, cloud computing, security, configuration automation. My focus areas for the association:\nIncreasing the quality of the talks Enhance the experience for speakers and attendees Promotion Linux Audit Editor and writer\nSince: December 2013\nWorking on creating one of the best Linux security blogs providing free and high-quality articles.\nLynis project Since: Oct 2007\nWorking on the auditing tool for Linux and Unix based systems.\nRootkit.nl Security Researcher and Developer\nSince: Jan 2003\nSecurity research and related development of open source security tools and scripts:\nRootkit Hunter - Malware scanning tool (trojans, backdoors, rootkits) Lynis - Unix/Linux security auditing tool to help with system hardening Honors and awards 2016 Best of Open Source Software Awards Issued by InfoWorld · Sep 2016\nhttp://www.infoworld.com/article/3121251/open-source-tools/bossie-awards-2016-the-best-open-source-networking-and-security-software.html#slide13\n2015 Best of Open Source Software Awards Issued by InfoWorld · Sep 2015\nInfoWorld, the technology media brand committed to keeping IT decision-makers ahead of the technology curve—has announced the winners of its 2015 Best of Open Source Software Awards, aka the Bossies. Selected by InfoWorld editors and contributors, these awards highlight the top open source software that keep the business running. From clouds, to data centers, networks and more, Bossies 2015 recipients provide a software guide for all\nhttp://www.idgenterprise.com/press/infoworld-announces-the-2015-best-of-open-source-software-awards\nEducation Koning Willem I College Technische Informatica, \u0026rsquo;s-Hertogenbosch (The Netherlands), 1999-2002.\nHAVO d\u0026rsquo;Oultremontcollege (Drunen), 1994-1999.\nCISSP By: Lancelot Institute in 2009\nTraining: CISSP (5 days)\nFollowed this CISSP training in the week of 26 October 2009, as a preparation for the CISSP exam\nLean Six Sigma - Orange Belt Tri ICT, 2012, via ASML\nCertifications Most of my certifications are old and outdated. But, it still gives an idea on how I like to keep up with knowledge, then and now.\nLPIC-1 + LPIC-2 + LPIC-3 (Core) - Issued Oct 2008 · Expired Oct 2013 = Credential ID LPI000139659 (verification code: btelrwq6x3) Linux+ - CompTIA - Issued Sep 2007 CCNA Security - Cisco - Issued Jan 2009 · Expired Jan 2012 CISA (Certified Information Systems Auditor) - ISACA - Issued Oct 2016 - Credential ID 16133964 CISSP - ISC2 - Issued May 2012 · Expired May 2021Issued May 2012 · Expired May 2021 Credential ID 362162Credential ID 362162 BHV / ERO / CPR - Issued Mar 2010 VMware VCP 3.5 - Issued Dec 2008 Security+ - CompTIA - Issued Jun 2007 SNIA Storage Networking Management and Administration (S10-201) - Issued Apr 2009 Sun Certified Network Administrator for the Solaris 10 OS (CX-310-302) - Issued Feb 2009 Sun Certified System Administrator for Solaris 10 OS (SCSA) - Sun - Issued Feb 2009 SNIA Storage Network Foundations exam; SCP (S10-101) - SNIA - Issued Dec 2008 Novell Certified Linux Administrator (CLA) - Issued Feb 2010 Novell Data Center Technical Specialist - Feb 2010 EMC Technology Foundations - CLARiiON, E20-050 - EMC - Issued Sep 2009 Solaris 10 SCNA - Sun Cisco CCNA - Cisco - Issued Jan 2009 · Expired Jan 2012 Recommendations Niels van der Pijl Received via LinkedIn on October 10, 2014 (Niels worked with me on the same team as a security consultant):\nMichael is one of a rare breed. In addition to the integrity which is part of his DNA, he is extremely skilled, driven and intelligent. As Security Coordinator I’ve worked with Michael for almost 2 years and have experienced him as an exceptionally pleasant colleague who’s technical knowledge, communication skills and personality make him a valuable asset to any team.\nWilliam Milne FinTech Consultant \u0026amp; AI Software Entrepreneur shared on May 26, 2020 via Linkedin:\nBuck stops with Michael (\u0026rsquo;nix security); he has built some awesome audit tools from ground up.\nPrevious work ASML Veldhoven (The Netherlands) From: Jan 2012 - Sep 2013\nService Manager Connectivity From: Jan 2012 - Sep 2013\nService delivery management for WAN connectivity world wide. Responsible for budgeting, forecasting, administration, projects and single point of contact for this service.\nMain services include MPLS, perimeter, network level APM (application performance management) and WAN acceleration. Since we are the center of all communication we have close relationships with general projects and security related projects. Main daily activities consist of incident handling, service improvements, capacity extensions and upgrades.\nIn a nutshell: vendor management, traffic optimization, performance, security, tuning, availability, billing, financial forecasting, service delivery management, solutions, lean IT and waste removal, proxies, firewall, WAN acceleration devices.Service delivery management for WAN connectivity world wide. Responsible for budgeting, forecasting, administration, projects and single point of contact for this service. Main services include MPLS, perimeter, network level APM (application performance management) and WAN acceleration. Since we are the center of all communication we have close relationships with general projects and security related projects. Main daily activities consist of incident handling, service improvements, capacity extensions and upgrades. In a nutshell: vendor management, traffic optimization, performance, security, tuning, availability, billing, financial forecasting, service delivery management, solutions, lean IT and waste removal, proxies, firewall, WAN acceleration devices.\nProcess Controller From: Jan 2012 - Sep 2013\nResponsible for process management of our team, with focus on ITIL related processes.\nCommon activities include: dealing with high priorities, routing exceptional cases and problem solving between teams. My direct colleagues are responsible for the technical activities and related expertise area. I manage the process related activities, to streamline their focus. Examples include communication, be a sparring partner for our manager, KPI reporting and determining improvement steps. It includes joining weekly meetings regarding process management, or when needed the CAB (Change Advisory Board).\nKeywords regarding this role are: lean IT, six sigma, waste reduction, process improvement, change, incident and problem management, crisis communication and escalations.\nPhilips Security Officer\nJul 2009 to Dec 2009 · Eindhoven, NetherlandsEindhoven, Netherlands\nResponsible for tactical and operational security within the data center team. Related activities were security incident response, vulnerability scanning, consultancy for projects and security awareness.Responsible for tactical and operational security within the data center team. Related activities were security incident response, vulnerability scanning, consultancy for projects and security awareness.\nLinux / UNIX System Engineer\nJan 2008 to Jun 2009 · Eindhoven Area (The Netherlands)Eindhoven Area (The Netherlands)\nWorking for the biggest EMEA data center to support Philips business. The primary activities of the data center is providing hardware hosting, and shared services. In my roles, I supported the UNIX team by means of security advice, UNIX and storage management, and generic process improvements (ITIL).\nT-Systems Security Officer\nFrom: Jan 2010 - Jul 2011\nEindhoven (The Netherlands)\nAs security officer responsible for security related to data center, infrastructure and to some extend hosted applications. Due to a NDA no further details can be given for this position.\nSnow Consultant\nFrom: Dec 2007 - Oct 2013\nGeldermalsen (The Netherlands)\nConsultancy for customers. Focus areas include information security, service management, and process improvements. Product group: Security IT Construction Company Network and Security Engineer\n\u0026rsquo;s-Hertogenbosch (The Netherlands)\nFrom: Oct 2002 - Nov 2007\nNetwork and internet security and related services (patching, IDS, firewalls, telecommunication taps, malware scanning) Setting up and maintaining Unix systems (Red Hat, FreeBSD) Datacenter migration Lotus Domino administration, user/identity management DO-IT-SO Automatisering Novell / Linux Administrator\n\u0026rsquo;s-Hertogenbosch (The Netherlands)\nSince: Sep 2000 - Sep 2002\nHardware replacement, PHP development, dealing with internet technologies (configuration of e-mail, DNS, web hosting) and support for Novell Netware installations.\nPrevious part-time work NLLGG Strategic advisor and promoter\nSince: Feb 2025 till March 2026\nAs of February 2025, I will be part of the communication committee. Together with others we will be focusing on making Linux more accessible for those who like to use it or want to learn about it. My primary focus will be assisting the NLLGG with a communication strategy, increasing its community, and promotion. I also will stay involved as a speaker and directly share my personal knowledge about Linux security.\nMemberships ITGilde Coöperatie Member\nFrom Sep 2015-2019\nThe \u0026ldquo;IT Guild\u0026rdquo; is a Dutch group of mostly entrepreneurs working in the field Linux and UNIX system administration, and related projects. The goals of the guild including increase knowledge sharing and promote networking opportunities. I became a member to share my knowledge in the area of Linux security, like security auditing, hardening, and compliance.\n","permalink":"https://michaelboelen.com/resume/","tags":null,"title":"Resume of Michael Boelen"},{"categories":null,"contents":" Yes, I\u0026rsquo;m moving away from LinkedIn. Why? The benefits no longer outweigh the costs for me. We are moving into different times and it became clear to me that investing time into the platform does not make sense. In this article I explain why, the plan, and the alternatives. Will you join me on this ride?\nHow it began I started using LinkedIn on 20th of October, 2007. Or at least, that\u0026rsquo;s what the platform says. Where to find this? Click on Settings, Data Privacy, Manage my activity, and go to the last page. An interesting thing with LinkedIn is that everything is buried below at least 3-4 clicks. Anyways, I guess that we can say that with 18 years my profile is an adult now. Time to let it go do its own thing ;-)\nWe had a good time LinkedIn served me for a good while, especially when working for bigger companies. The number of contacts grew quickly and now and then I saw interesting updates from my network. That feeling is gone for a while now. It\u0026rsquo;s no problem, I thought, while slowly decreasing the usage of the platform.\nHmm, not my choice This feeling changed when I noticed several times that some privacy related settings were set to \u0026lsquo;on\u0026rsquo;. On LinkedIn this typically means that you allow something to happen with your data, like sharing it with third parties. That\u0026rsquo;s clearly something that I don\u0026rsquo;t want. Over the years I gave those settings a good look, to ensure they are set in the way I want them. But now and then, I saw they were not. So these settings where clearly introduced without asking me what I prefer. That was for me the trigger to reevaluate the platform and its values.\nMore reasons to leave LinkedIn During the years the value of the platform faded away, followed by the defaults that were not in favor of my privacy.\nFocus on engagement instead of quality or a clear timeline Settings that reset each time, like choice for timeline display The increasing amount of messages that better belong on Facebook (COVID, puzzles and riddles) Overwhelming amount of messages and updates Low visibility and engagement if you post \u0026ldquo;average\u0026rdquo; things Lack of true networking, like in person Recruiter spam, even with clear message that I\u0026rsquo;m not available Unknown people connecting without introduction text Advertisements and related worries about privacy Puzzle games on a professonal platform Promoting a CEO of another Big Tech company with no clear connection to me Puzzle games or following a CEO of Google? No thanks.\nEnough for me to take some action now!\nSo delete your account and be done with it? Some people like to do things cold turkey and go all-in. With LinkedIn that is as simple as ask them to delete your account, and you are done. That might work for you, but I have some reservations.\nOne of the reasons that I don\u0026rsquo;t want to delete right away, is that specific profile URL that I once claimed. It\u0026rsquo;s part of my online presence and cultivated for a long time. More importantly, it is also scattered over the internet on some places. I still don\u0026rsquo;t know exactly where it is mentioned (including by me) over the years. I want to make sure that those links get cleaned out, so they don\u0026rsquo;t result in a 404.\nAnother reason is that I don\u0026rsquo;t want someone else to claim my profile URL. Especially with the first reason in mind, I don\u0026rsquo;t want to potentially have it link to a different person. After all, one could claim the profile URL on purpose, but it could also be happening by accident. In The Netherlands there is at least one other person by the name Michael Boelen, so he could come up with the same shortened alias that I thought of many years ago. Sorry buddy, this one stays mine for now.\nThe alternative is to put the account into hibernation. LinkedIn itself has also an option with the same name, but my goal is to keep the account active. This way people who still discover it, can see that I moved instead of getting an error.\nHow to start then? So I don\u0026rsquo;t want to throw away my account, but I also don\u0026rsquo;t want to give LinkedIn any valuable information to keep using. So I\u0026rsquo;m collecting the steps that allow me to retrieve my data, purge the profile information, and just leave enough there to communicate my message.\nThis is my journey of leaving LinkedIn, in a way that I feel comfortable with. Will you join me?\nStep by step guide To properly fade out from LinkedIn, I collected some initial steps. While clicking through the interface, more and more items are discovered. These are the steps so far that I followed and some still working on:\nStop using the LinkedIn app Start with a data export Profile Set an alternative name Background image Profile photo Adjust profile description Migrate resume to personal website Inform your network Announcements Creating a template Reaching out personally Create a few last posts Companies and Groups Limit memberships Preparing group deletion Deleting the group Preparing the exit for company pages Cleaning the data Remove links with companies and groups Leave events Erasing the history Removing activity Posts Reactions Deleting the skills Remove publications Post-LinkedIn actions Search for old links Create a new business card Stop using the LinkedIn app I never installed the LinkedIn app myself. First of all I never needed it on the go, but also because apps are harder to contain. If I had installed the app, this would be my very first step to do.\nExporting LinkedIn data The first step is to export the LinkedIn data, as it may take a while. Better get that task queued up, right?\nWhere: Me \u0026gt; Settings \u0026amp; Privacy \u0026gt; Data privacy \u0026gt; How LinkedIn uses your data \u0026gt; Get a copy of your data \u0026gt; Request archive\nAfter requesting the data export, I received one within one hour. The other one with 24 hours after the request. The challenge: the links in the email did not work. So I went back to the page to request a copy, but then there was a download button.\nThe request button changed into a download button.\nWith the zip archive extracted, it shows the following files for me:\nAds Clicked.csv Ad_Targeting.csv Articles Causes You Care About.csv Certifications.csv Comments.csv Company Follows.csv Connections.csv Courses.csv Education.csv Email Addresses.csv Endorsement_Given_Info.csv Endorsement_Received_Info.csv Events.csv guide_messages.csv Hashtag_Follows.csv Honors.csv ImportedContacts.csv Inferences_about_you.csv InstantReposts.csv Invitations.csv LAN Ads Engagement.csv Languages.csv learning_coach_messages.csv LearningCoachMessages.csv Learning.csv learning_role_play_messages.csv Logins.csv Member_Follows.csv messages.csv Organizations.csv PhoneNumbers.csv Positions.csv Profile.csv Profile Summary.csv Projects.csv Publications.csv Reactions.csv Receipts.csv Recommendations_Given.csv Recommendations_Received.csv Registration.csv Rich_Media.csv Saved_Items.csv SavedJobAlerts.csv SearchQueries.csv Security Challenges.csv Shares.csv Skills.csv Verifications Volunteering.csv Votes.csv Whatsapp Phone Numbers.csv There are definitely a few files that I want to investigate later on. Let\u0026rsquo;s move on for now.\nProfile The first steps are to start changing the profile. I want my network to see what I\u0026rsquo;m planning to do and give them time to respond and adopt. Also, I want those interested to switch to my alternative of LinkedIn, which we will cover later.\nSetting an alternative name LinkedIn allows you to use an additional name. Well, I don\u0026rsquo;t have one. So that is a nice opportunity to introduce one to the world. My official additional name is now -moving away from LI-. This clearly signals people that I\u0026rsquo;m no longer using the platform and made a decision to move away. You would expect that new invitations would stop, but I can tell that it did not.\nWhere: Me \u0026gt; Settings \u0026amp; Privacy \u0026gt; [Name, location, and industry \u0026gt; Set additional name Time: 5 minutes\nChanging the background Next step was adding my background picture to point out my new address. I downloaded my background image, opened up Gimp and added the text. Save the file and switch out the picture.\nWhere: on main profile page, click on pencil icon in corner \u0026gt; Edit cover image \u0026gt; Change photo Time: 5 minutes\nA clear hint in an otherwise boring background image\nLimit who can see the profile photo My profile photo (head) is next to be adjusted. By clicking on the photo you can tell LinkedIn who can see it. Adjusted that to 1st-degree connections only, so it is restricted. This way the profile photo remains visible for my network, while I\u0026rsquo;m informing them later that I move the platform.\nAdjust profile description This is also a good time to adjust your profile description. Make clear what the best place is for other to find you.\nMigrate the resume part LinkedIn provides a decent resume, including listing your work, certificates, societies. I prefer POSSE (Publish on your Own Site, Syndicate Elsewhere). So migrating the resume to a personal website makes the most sense. This gives me full control over the content and styling.\nI start with a simple copy-paste of the content, and while at it, remove one entry each time from the profile. This may trigger people to see my profile, and already get informed about the upcoming migration. For now, I start with a simple page. The goal is to get into action and start migrating, not fiddling around with styling. So let\u0026rsquo;s add first description text, then followed by the full-time work and part-time work activities. After that, the old employers I worked for.\nIdea for later: add some fancy styling (planned in 2038).\nInform your network Next step is informing your network that you will be leaving.\nPhase 1: announcing Phase 1 is by announcing the message with the help of creating a new post. This is especially important to do first, before we start disconnecting the network piece by piece.\nI started with the following post:\nDidn\u0026rsquo;t post in a while. One of the reasons is that I still work on writing articles and creating software, among volunteering work. The primary reason though is that I prefer Mastodon to stay in touch with others. No ads, no trackers, no silly privacy settings that the platform switches on and off.\nWant to follow my work?\nDutch: https://mastodon.nl/@mboelen English: https://mastodon.social/@mboelen This tells people that I\u0026rsquo;m still alive and what I\u0026rsquo;m up to. Also, I\u0026rsquo;m promoting Mastodon to the bigger audience.\nFun fact: after my first post, one person proposed to meet to have a drink (it was long overdue).\nPhase 2: personal touch Phase 2 is reaching out to your most important connections. Let them personally know that you will be gone and how they can still reach you. Hopefully these people already have some of your details. Better safe than sorry. Also a good opportunity for others to also quit.\nObviously we want to reduce the amount of time that we are spending on the platform. So create your custom template that you use to send out a message. Don\u0026rsquo;t start spamming it, as it may possibly trigger a mechanism of LinkedIn. Just share the message first with for you the most important people.\nThis is my template:\nHi,\nI\u0026rsquo;m reaching out to share that I will be leaving LinkedIn. The platform offers me limited value, but more importantly, it keeps being intrusive when it comes to privacy. For example, recently I saw it enabled several features again that shares data with third parties. Definitely not something I would enable, so it\u0026rsquo;s time to leave another piece of Big Tech.\nLeaving this platform does not mean to be gone instantly. I will slowly reduce my number of connections and I will remain available via Mastodon (@mboelen), my personal website (michaelboelen.com), email (redacted), and blogs.\n-Michael\np.s. did you already check your privacy settings to see if they are adjusted without your consent? Settings\u0026amp;Privacy \u0026ndash;\u0026gt; Data Privacy \u0026ndash;\u0026gt; Social, economic, and workplace research\nA few last posts By slowly moving away, you also get the time to do a few last posts. Share a bit here and there about a solution like Mastodon. Some people might not have heard about it, so why not introduce it as a possible alternative.\nDidn\u0026rsquo;t post in a while. One of the reasons is that I still work on writing articles and creating software, among volunteering work. The primary reason though is that I prefer Mastodon to stay in touch with others. No ads, no trackers, no silly privacy settings that the platform switches on and off.\nWant to follow my work?\nDutch: https://mastodon.nl/@mboelen English: https://mastodon.social/@mboelen Deleting contacts, one by one Next step is to decrease the network size. This is the part that definitely takes the most work. For some people you know it right away: connected long time ago, never spoke again, delete. I have 2000+ connections, so I\u0026rsquo;m sure many will fall in this category.\nYou probably also have many contacts that you didn\u0026rsquo;t speak in a while, which you might even regret. It shows that LinkedIn is definitely not social media, right? On the positive note, this is a good opportunity to send a personal message. Use a template or send them a personal note. Or better, maybe schedule a meeting with them right away? Don\u0026rsquo;t stick on the platform, but make the appointment via an alternative method, like email or message.\nTips:\nYou can export a profile, in case you want to store a little bit of information about a person. I suggest these two options combined for more information: Click on More (on the profile) and use Save as PDF. Right click, save as HTML. Give people some time to respond back. One option is to pick a fixed day in the week. Send those that you want to delete a message about disconnecting, then next week do the deletion itself. Companies and Groups Company account Are you an administrator of a company entity, then it\u0026rsquo;s time to decide what needs to happen with it. Will it be purged or should someone else take control over it?\nMember of a group If you are a member of a group, then you can decide if you want to inform the group that you are leaving LinkedIn. For most groups you probably don\u0026rsquo;t want to do this, but if you were active in a particular group, and people might start to miss you, then it is probably the right thing. My preference is not to share it within a group, to avoid starting unnecessary conversations or discussions.\nGroup administrator Like being the administrator of a company entity, you could be an administrator of a group. If there are multiple administrators already, just inform the other(s) that you will be leaving LinkedIn. Then leave the group.\nIf you are the only administrator, then it is time to decide if the group needs to continue or not. I have created a group a long time ago, but almost no one is posting in it. That\u0026rsquo;s a simple decision: delete the group. I will however first announce it though.\nHi all,\nThis group will be deleted as I (as the admin) will be moving away from this platform.\nOn my personal website (see header image of my profile) I have shared a blog post on the reason.\nSince you are probably still interested in Linux auditing, I suggest to check out the RSS feed of Linux-audit.com or follow me on Mastodon.\nSee you there?\nSome thoughts about this move Don\u0026rsquo;t conform to Big Tech For too long I conformed myself to the platform of \u0026ldquo;professionals\u0026rdquo;, carefully thinking about what you should or should not post on LinkedIn. After all, it are your professional peers and doing stupid things can influence other decisions. At the same time, not showing who you really are also tells a lot. That\u0026rsquo;s for a long time I became active on Twitter, where I could express my interests, including those that are related to my professional work. Well, we all know how Twitter turned out. So that\u0026rsquo;s when I made the switch to Mastodon. I already created an account early, but didn\u0026rsquo;t really use it. When Musk took over, it was time to leave Twitter and start using Mastodon. Sure, you lose some contacts, but you also gain new ones. Nothing wrong to burst out of your bubble now and then, right?\nThe alternative to LinkedIn? So I got asked many times already what the alternative is to LinkedIn. I\u0026rsquo;m pretty sure Xing is not the answer. That\u0026rsquo;s moving from one problem to another.\nI believe I have an answer now. It\u0026rsquo;s probably not a suitable replacement for all of us, but for many it could be a great one. The answer? A personal website together with Mastodon.\nPersonal website The personal website provides you with an authoritative resource where you can put your resume, your thoughts in a long form, share useful files. It will rank high in search engines and therefore you control what people can see and read about you. You decide what you want to show.\nThere is a downside though to a personal website: costs. Yes, you will have to invest some money. That goes into a domain name (renewed yearly) and hosting (monthly or yearly). Obviously you have also to create the personal website, so time is another resource that goes into it. But don\u0026rsquo;t fret it, start simple. Heck, let that be your first post and share that you are learning to create websites. Most people prefer human work above AI slop, so they appreciate the effort.\nLooking to reduce costs? Sometimes you can get free hosting for small projects. Another option is to rent a small virtual private server with some friends and share the costs.\nMastodon Then the next building block is Mastodon, where you can be yourself and share things that matter to you, all in short form. You can make it as professional, geeky, or funny as you want it to be. It allows others to learn you in a different way and interact with you.\nBe aware of the advertisements So who really benefits from LinkedIn? It may be you, advertisers, companies, but most likely share holders. LinkedIn has reached Enshittification like many other Big Tech platforms. Advertisements and weak privacy settings give already a good hint on what the platform is about. They won\u0026rsquo;t be shying away from tracking you both on LinkedIn, in the app, or even outside. In case you didn\u0026rsquo;t know, Big Tech love people who keep their session active, link services to their service, or better, install the app.\nSo my suggestions:\nRemove the app from your phone Log out of LinkedIn and remove cookies Need to log in again? Switch to a private browser session that cleans up after itself upon closing the web browser Frequently Asked Questions What is best choice, deleting the account or keeping it? That\u0026rsquo;s one you carefully have to decide for yourself. In any case, clean it up first. Can\u0026rsquo;t decide what to choose? Start with keeping it for a while, set a reminder for 6 months later to reconsider your choice. Repeat if needed.\nWhat if I still want to use the platform now and then? Using a hybrid approach is fine, like cleaning out as much as you can and change your description. Inform people your preferred way of communication. Disengage from groups as much as possible and clean out your time line.\nWhat is the best alternative for LinkedIn? The one that you fully control is the best. As a starter a personal website, for example combined with Mastodon. This way you can publish content in different formats, be accessible, easy to discover on the internet, and still network with others.\nHow do I see updates from other peers in my field of expertise? This strongly depends on your field of expertise. You will have to discover where your peers are, like on a common forum, Mastodon, or chat room.\nHow do I rebuild my network somewhere else? If you truly want to connect with peers in your field of expertise, consider running a community yourself. Create a place where people can meet, like a forum, a chatbox, or something like a Signal group.\nWhat can I do have people follow me somewhere else? Get in contact with those that you care about. Ask them what they prefer or possibly another place where they are already active. Post and promote those places on LinkedIn, so people see that there is a place where things are more active.\nI can\u0026rsquo;t create a website, what now? Start using Mastodon, connect with people, reach out to them. People tend to help others, so it is possible that someone in your network may be able to help creating that website.\nWhat can I do so others can find or follow me more easily on my new place? Make one central place where all your most important details are listed. A personal website is the perfect place for this. There you can refer to your Mastodon profile(s).\nTo make it easier for people to follow you, add/activate RSS on your website, especially if you also blog.\n","permalink":"https://michaelboelen.com/blog/moving-away-from-linkedin-step-by-step/","tags":["bigtech","mastodon","website"],"title":"Moving away from LinkedIn to a future-proof alternative (step by step)"},{"categories":null,"contents":"Latest status update (2025-09-13): Linux voor een beginner is still NOT indexed\nA crazy thought: the internet might be full! This story begins after my small new blog is poorly indexed by both Google and Bing. In February (2025) I registered a new domain vooreenbeginner.nl, which is Dutch for \u0026ldquo;for a beginner\u0026rdquo;. The idea was to create micro-websites under this domain, such as Linux voor een beginner, focused on just Linux and open source.\nAs I maintain more websites, I performed the usual steps like creating a sitemap, validating the website with Google Search Console and Bing Webmaster Tools. After the validation, the next step was adding the sitemap, so both search engines could go ahead and start crawling the website. It did not take long before both did some crawling and pages showed up in the index. So all is good, right? Well, not really.\nPages dropping out of the index After a few months, in April and May, the number of pages did start to drop. Strange, but I initially thought it might be related to the domain being fresh. Maybe Google gave me first some extra chance to shine in the first months, then started to be a little bit more picky. In the meantime, I continued creating new pages, ignoring the issue for a while.\nWhile now and then monitoring the situation, I saw more and more pages dropping out of the Google index. Bing was not much better, but with my experience that usually Bing was not indexing as many pages as Google, I didn\u0026rsquo;t think much of it. My worry started when my website was really gone from the index.\nInitial thoughts on the indexing problem My first thought was that some change negatively influenced the index state of all pages. Since it applied to the full website, including the homepage, it had to be in the template. At the same time I would not expect that, as the same template is used on some of my other websites. But then again, I did make some changes to improve readability and to improve the top menu. Did I break something?\nSome of my websites are created using the amazing Hugo. Once upon a time I used a bare bone template, but customized it such in a way that there is almost no character left from the initial template. Since the template powers my other blog Linux Audit, I knew it worked, resulted in pretty clean HTML code, and most importantly in a website that was light and easy to navigate. So in this area I could not find anything suspicious that would result in delisting from the search engine indexes.\nThe webmaster tools from Google and Bing provide good overall indicators when it comes to indexing. It covers issues like slow pages, using a \u0026rsquo;noindex\u0026rsquo;, or having server errors. I started going through both, but did not see anything that directly would result in a de-indexed website. Time to consult others seeing if they had a clue or a hint. I shared some ideas with Jos Klever (thanks Jos!) and tried some of suggestions provided by the great people responding to my Mastodon thread.\nMaking small changes Along the way I made a bunch of small changes to the templates and fixing some issues, like the top navigation menu not being fully mobile-friendly. I know search engines like websites to be mobile-friendly, but at the same time they didn\u0026rsquo;t complain about it. Also the meta properties in the head tag where cleaned up. I was pretty sure all these little things would not suddenly resolve the problem, especially considering the average website is full with minor and major defects.\nI started to document the changes. This way I had some notes that if my website was indexed again, that I had at least an idea of what could have been the change. But weeks passed, and nothing happened.\nSo if you are wondering about these changes, the include things like adding a favicon, updating the footer, adding a missing alt text on a generic icon. Small things, nothing that really hugely impacts the website or its usage.\nThe first hint? Using IndexNow On another blog I implemented IndexNow. It\u0026rsquo;s a great way to inform search engines like Bing that some of the content was updated. As I did make small changes to the website, I thought it could be beneficial to let the search engines know. It allows them to directly do a new assessment and decide if it is worthy now to put (back) in its index. The nice thing with IndexNow is that you just have to inform a single endpoint. By collaboration the search engines that use it will share the update. Looking at the log files you can see how it works. Just minutes after submitting an update, several search engines, like Bing, Yandex, and Seznam, will visit the updated page.\nBy implementing IndexNow I got an interesting hint: \u0026ldquo;Issue: Content Quality\u0026rdquo;. So is it an content issue after all?\nQuality issue on the homepage?\nResearching the content quality issue My blog posts are original work and no AI is involved. So the chance that the content is too generic or looking suspiciously similar to other websites is small. But obviously that doesn\u0026rsquo;t mean my articles are good in any way. For that we need a little bit more, like focusing on readability. When I write articles, I aim for easy words and short sentences. Paragraphs shouldn\u0026rsquo;t be too longer either.\nSo what could possibly be wrong about my articles? Also, does really the full website have a content quality issue? That doesn\u0026rsquo;t make sense. Now IndexNow shows that the homepage is impacted as well. That\u0026rsquo;s strange, as it contains an explanation about what the website is, including the author. After all, Google promotes the usage of E-A-T in its Google Search Quality Evaluator Guidelines. In case you are wondering, E-A-T is short for Expertise, Authoritativeness, and Trustworthiness. So including some background information about the author should actually help in this area.\nWhen checking out the Bing Webmaster Guidelines several times, I could not really see what could be possibly the cause that the homepage and other pages are flagged. After all, I got the sitemap, robots.txt, IndexNow, and do use normal links. The HTML is properly defined and checked with the W3C validator. The server is quick and the log files are clean, showing (almost) no errors.\nGoing for an extensive audit So with no real actionable hints from Bing\u0026rsquo;s webmaster guidelines, I checked some SEO tools that can do an audit. Someone tipped to use a free account on Ahrefs, so I did. On top of that I used a few others. Besides the usual \u0026ldquo;title too long\u0026rdquo; or \u0026ldquo;title too short\u0026rdquo;, there were close to none big actions. They were all in line with the smaller changes I already applied.\nThe good thing of using different external tools is that you can really can be sure you didn\u0026rsquo;t make an obvious mistake and simply overlook it. After all, when seeing the same code over and over, you may overlook the obvious. So although I improved the website a bit further, I can\u0026rsquo;t say that I found something that would directly make me think that I solved this puzzle.\nSome thoughts As you probably can imagine by now, I had this indexing issue on my mind. So let me share some random thoughts about the cause.\nGenerating too much new content? When I started with the blog, I tried to create a small article a day. Especially since it\u0026rsquo;s about an introduction to Linux, the articles were fairly easy to create. I just tried to write down how I would explain it to a new user. Did I create too much content in a short amount of time?\nToo much optimization? Maybe is my website too much optimized and giving bad vibes to the search engines? Hugo websites (with the right template) are insanely small and fast. Did I over-optimize it? Probably not, otherwise my other websites would have had the same issue.\nWebsite not mature? Maybe because it\u0026rsquo;s a new domain, the search engines don\u0026rsquo;t trust it (yet)? Not much that I can do, except promoting the initiative.\nWhat about using a subdomain? Google doesn\u0026rsquo;t mind about the usage of subdomains. Strictly speaking my website is not on a subdomain, it\u0026rsquo;s just a host named \u0026rsquo;linux\u0026rsquo; within the domain. But, I had no homepage on the domain (vooreenbeginner.nl) itself. Maybe that is unexpected? I created a simple page initially and put it up. To my surprise that one was actually indexed!\nMaybe I promoted the website incorrectly? I\u0026rsquo;m no longer active on Twitter/X and definitely not on Facebook. So I revealed my project on Mastodon. The good thing about this platform is that there is a nice bunch of people. They appreciated the efforts and shared it with their followers. With Mastodon being decentrally hosted, you get suddenly a spike of incoming links, as they come from multiple servers. The downside is that it may trigger the search engine in seeing duplicate messages with a link to my website. Is this considered to be spammy? Not much that I can do about that obviously. It\u0026rsquo;s simply the nature of decentral hosted social media.\nMissing incoming links? Most search engines love it when links are pointing to your website or blog. It gives them an idea on attribution and possibly a hint of good quality content to look for. Getting incoming links is hard though. It takes time and it takes some promotion. On my Linux initiative I do ask people to link to my website if they like the it. It\u0026rsquo;s a great way to donate to the initiative and at the same time promote it.\nI\u0026rsquo;m wondering if I get more incoming links, if this would resolve the indexing issue. Maybe you need just enough incoming links to get recognized? That would be great. Getting indexed would be also great, so people can discover the blog in the first place, so that they can link to it *wink*.\nChecklist for indexing issues To combat the indexing issue, I read multiple websites. Many include the generic solutions like \u0026ldquo;just wait\u0026rdquo; or \u0026ldquo;write more content\u0026rdquo;. So this checklist below is my attempt to help anyone with indexing issues.\nContent quality Content provides an insight or solution to a problem No filler text that does not add any value Grammar checked Readability Paragraphs not too long Number of words per line Indexing Sitemap file correctness Sitemap file updated on a regular basis IndexNow implemented Links Is the website getting incoming links? Are the outgoing links to healthy websites? Internal links to create an interconnected web of pages Are incoming links from bad hosts? HTML quality Test with W3C validator Meta tags defined Semantic HTML used? body header footer Schema.org markup Text surrounded with \u0026lt;article\u0026gt; tag Robots.txt Is it present? Validated that regular pages are not being blocked? No search engines blocked? Is simplification possible? Authoritativeness Is the content written by the person with the right expertise? Is the author mentioned on the page? Is there an about page? Crawling Can the search engines reach your server each time? Is the performance good Does Google state there were DNS issues Log files Are there many errors in the log file? Are the search engines within the log file? Is robots.txt and the sitemap downloaded? Anything else that should be part of this checklist?\nWhat if: there is NOT a problem with my website Is it possible that the problem is not within my website, but how the web works nowadays? I\u0026rsquo;m starting to believe that we are ruining our precious internet with AI slop. Open source developers like Daniel Stenberg from the curl project took an active stance on the crappy AI-generated issue reports. I see in my log files that the crawlers from AI companies happily traverse through my website and content. Maybe they are overwhelming Google and Microsoft as well?\nNormally if you create a new website, it takes a while to set things up and especially creating the content for it. With a little bit of automation you could now register a domain, set up its configuration, and completely fill it with auto-generated AI garbage.\nFor many years people rigged the SEO game, trying to compete for the first spot. Google took measures, including penalties for domains that showed signs of unethical behavior. At the same time, the results of Google did not become of higher quality. I liked it in the early days and I could always find an answer to my technical problems or that specific product I needed. But that time is gone for some years now. The first page is filled with advertisements, but surprisingly the second and following pages are not much better. Is it possible that Google is overwhelmed?\nIs the internet full? I\u0026rsquo;m starting to believe that the internet is full. Well, maybe I should say the web. There are so many domains, websites, and content, that companies including Google can no longer properly track it. Now with AI they get an even bigger challenge to sort through all the auto-generated crap. That leaves them less time on spending on those smaller niche blogs like mine, especially because it is in a silly non-English language!\nSo we might have reached a moment in time that it is no longer possible to get a real clear image on what the internet or web is. A tipping point in where new websites will get it really difficult to be ranked.\nWhat do you think?\nSEO challenge: find the cause Are you up for a challenge? Maybe I\u0026rsquo;m plain wrong or I simply screwed up. I encourage you to look at the website and its code. If you can find the real cause that resolves this indexing issue, you get a prominent place in this article.\n","permalink":"https://michaelboelen.com/blog/my-website-is-not-being-indexed-is-the-internet-full/","tags":["seo","website"],"title":"My website is not being indexed! Is it because the internet is full?"},{"categories":null,"contents":"Living in The Netherlands, and developing tools since an age of 10. I’m the original author of several open source tools. You might know some of them, like Rootkit Hunter (malware detection for Linux/UNIX) or Lynis (security auditing and system hardening).\nMy experience is diverse, both in the type of companies I worked for, and also the acquired skills. I’m technical, yet find it pleasing to understand business and processes. Quality makes me happy.\nBiography Michael Boelen specializes in the field of Linux and UNIX security. He worked before as a consultant for several big companies, including T-Systems, Philips, and ASML. In 2013 started the security firm CISOfy, to support companies with their auditing, hardening and compliance needs. Michael is the author of several open source security tools, like Rootkit Hunter (rkhunter) and Lynis. Both seen in the toolkit of system administrators and security professionals. Other work includes supporting the CIS benchmarks, organizing the Dutch NLUUG conference, and writing articles. He is a regular contributor to the Linux Audit blog.\nAreas of expertise Everyone has their own skillset. Mine consists of simplifying difficult things, help to structure teams, and enhance business processes.\nSharing Knowledge My interests are within IT, specifically in the field of open source and Linux, combined with security. To get a maximum effect, I’ve created several open source security tools, and written 160+ articles on my Linux security blog. I enjoy giving presentations when time allows.\n","permalink":"https://michaelboelen.com/about/","tags":null,"title":"About Michael Boelen"},{"categories":null,"contents":"Got a question or a suggestion?\nEmail: michael@computerpech.nl ","permalink":"https://michaelboelen.com/contact/","tags":null,"title":"Contact Michael Boelen"},{"categories":null,"contents":"Sharing knowledge is a great honor. In particular, I enjoy doing this in the form of an interview. Great questions might trigger unexpected answers. Here are some of my public interviews.\nWant to interview me? Sure, see the contact page.\nInterview met koploper Michael Boelen, 2023, energiecoöperatie Energiek Heusden, 🇳🇱 Dutch\nMy Linux Story: How an influential security developer got started in open source, 2021\nLearn how I got started with open-source software development.\nSecTools podcast with Michael Boelen, 2018\nA podcast about rkhunter, Lynis, the project Linux Security Expert, infosec CFPs, and more.\nInterview with Michael Boelen, author of Lynis and rkhunter, 2017\nSome background on the Lynis project, Linux security, and its development. Interview from Secure by Default (Lorenzo Martínez)\nHow to Become a Black Hat Arsenal Master, 2016\nIf you ever get the chance to demo at the Black Hat conference, go for it. Prepare with the tips given in my interview.\nBSD Magazine: Interview with Michael Boelen, 2015\nArticle about information security, trends, and my security company CISOfy. Full magazine can be downloaded for free.\nHelp Net Security: Lessons learned developing Lynis, an open source security auditing tool, 2015\nLynis is the open source tool, helping others testing security defenses on UNIX-based systems, like Linux. In this interview we discuss the project, but especially lessons learned of open source development. Interview by Mirko Zorz of Help Net Security\nInterview with Michael Boelen (2009), 2009\nInsights about information security, Lynis, and other projects. Interview by Giovanni Federico\nInterview with Rootkit Hunter author Michael Boelen\nMy first big open source project was Rootkit Hunter. This tool focused on the detection of malicious software components, with specialization in systems running Linux and UNIX. Interview by Joe Klemmer of LWN\nWant to interview me? Get in touch with me via the contact page.\n","permalink":"https://michaelboelen.com/interviews/","tags":null,"title":"Interviews"},{"categories":null,"contents":"Are you a journalist, editor, or writer? I might be able to help you with additional insights. Feel free to contact me for more details.\nExpertise: Linux and UNIX security Strengths: structure and simplification, explain technical concepts in plain English Background: business owner, security officer, system administrator, developer While being a specialist, I had the opportunity to learn a wide range of skills over the years. This results in seeing the “invisible”, things which are often overlooked by peers.\nWant to learn more? The about page is a good start.\n","permalink":"https://michaelboelen.com/media/","tags":null,"title":"Media"},{"categories":null,"contents":"During the last few years I had the opportunity to present and give demos on a regular basis. My expertise is where security, business, software development, and open source software meet.\nBelow is the list of upcoming talks or ideas. Any of these talks suitable for your conference? contact me. Do you like my presentation(s)? An endorsement of my speaking skills would be appreciated.\nDjango and security? Privacy for non-paranoia people? Securing Linux? Here is an overview of talks I’ve given in the last couple of years, or are scheduled.\n2026 Linux for beginners Date: 2026-06-24 Event: Bibliotheek Drunen Language: Dutch 🇳🇱 Presentation Van Windows naar Linux Open source Date: 2026-06-07 Event: T-DOSE Language: English Presentation We promote and talk about \u0026ldquo;open\u0026rdquo;, but are we actually -doing- it enough? Abstract As a community we love open source and open standards. Also, we are not afraid to tell others about it! With ongoing geopolitical changes, this very moment might actually be perfect for our community to grow and prosper. Except, there is one big problem we need to discuss: we talk about it, but tend to forget the challenges others encounter. Remarks as \u0026ldquo;just use Matrix\u0026rdquo; or \u0026ldquo;replace the cloud with Nextcloud\u0026rdquo; might even be counter-productive for our cause. So let\u0026rsquo;s take a step back first, then speed up.\nIn this presentation we take a good look together at some ways of promoting open source, open standards, alternatives to Big Tech, and more. From developer to end-user, we all can do a few small, but powerful things, that really help a lot. Spoiler: Less talk, do more!¹\nRandomized keywords that will be discussed: blog, first impression, social media, community building, website, presenting, ease of use, repair café, local library, documentation, simplicity;\n¹Presenter is given a one-time exception for this presentation\n2025 Linux speedrun: systemd Learn a lot about systemd in a short amount of time with this Linux speedrun.\nDate: 2025-11-20 Event: NLUUG Language: Dutch 🇳🇱 Presentation: Linux speedrun: systemd Slimmer werken met Linux? Gebruik de terminal! Translation: Working smarter with Linux? Use the terminal!\nDate: 2025-11-15 Event: NLLGG Language: Dutch 🇳🇱 Presentation: Slimmer werken met Linux? Gebruik de terminal! Linux voor een beginner (Dutch) Translation: Linux for a beginner\nDate: 2025-11-15 Event: NLLGG Language: Dutch 🇳🇱 Presentation: Linux voor een beginner: tips voor een vlotte start Sandboxing using the Linux kernel and systemd Date: 2025-05-22 Event: NLUUG Language: English Presentation: Application security: Sandboxing features of the Linux kernel and systemd Same presentation but then for the NLLGG:\nDate: 2025-03-15 Event: NLLGG Language: English Presentation: Securing applications: Using the features of the Linux kernel and systemd 2024 Faster websites with Hugo Things that I learned while migrating several websites to Hugo, including focus areas.\nDate: 2024-09-21 Event: NLLGG Language: English Presentation: Faster websites with Hugo Oo, maar dat is goed fout A talk (in Dutch) where we discuss Linux security theses.\nDate: 2024-03-16 Event: NLLGG Presentation: Oo, maar dat is goed fout 2019 Tips to create better* shell scripts Whether you call yourself a system administrator, developer, or DevOps sprint mediator, life is too short for sloppy shell scripts! In this talk, we look at how to improve them to stand the test of time. Michael will share how to create a good foundation for your scripts, so they run more reliable now and in the future. Your (future) colleagues might love you for it.\nFocus areas of this presentation include error handling, security, style, and best practices. Also, it will cover (many) mistakes made by Michael over the last 20 years. Got some of your own? They are welcome as part of the discussion.\n* Improved readability, increased fault-tolerance, and more security.\nDate: 2019-11-21 Event: NLUUG Presentation: Let’s create better* scripts 2018 Under the microscope: Linux security tools\nDate: 2018-09-15 Event: NLLGG Presentation: Under the microscope: Linux security tools (PDF) Periodic health checks for Linux systems Michael Boelen presenting at D3NH4CK 2018\nDate: 2018-06-05 Event: D3NH4CK Presentation: periodic health check for Linux systems (PDF) Original title: “de technische APK voor Linux” (Dutch) Behind the scenes of an open source project Date: 2018-03-12 and 2018-03-17 Event: Linux \u0026amp; Open Source Tilburg and NLLGG Presentation: Behind the scenes of an open source project (PDF) 2017 Why simplicity is important Date: 2017-05-16 Event: NLUUG Presentation: The beauty of simple (PDF) 2016 The state of Linux security in 2016 Stories about Linux and what happened in 2016 regarding security.\nDate: 2016-12-07 Event: DBLUG (Project 073) (Meetup) Presentation: The state of Linux security in 2016 (PDF) Getting traction for (your) open source projects Date: 2016-11-12 Event: T-DOSE / NLLGG Presentation: Getting traction for your open source projects (PDF) So you got an idea, some code, and now you only need the users and contributors? A good idea is not enough to have a successful project. Open source software projects need also marketing, promotion, and optimization. We will look at the technical and non-technical level on how to enhance OSS projects. This with the goal to get more happy users and gain more traction. I will share from personal experience what works (and what not!), including examples. Subjects include simplicity, the website, dealing with social media, optimize for users and search engines, and the tiny details that matter.\nThis talk is useful for developers, contributors, and also users of open source software. No programming skills are required.\nRelevant article: How to promote your open source project\nMichael Boelen at T-DOSE 2016 Lynis demo at Black Hat Europa (London)\nDate: 2016-11-04 Event: Arsenal at Black Hat Europa (London) A live ongoing demo about how Lynis can help with system hardening, compliance testing, and more. The Arsenal is part of the Black Hat conference and consists of passionate developers who show their open source security tools.\nMichael Boelen showing a Lynis demo at the Arsenal of Black Hat conference\nLinux Security Workshop Date: 2016-09-29 Event: Private session Linux security workshop by Michael Boelen\nLinux Malware Presentation about the types of malware and the ones affecting Linux systems. We had a look on how rootkits work and some defenses we can apply to increase detection rates.\nDate: 2016-07-06 Event: DBLUG (project 073) PDF: see earlier presentations Securing Linux Systems with Lynis Are you really sure the security of your Linux systems is done properly? Since 2002, Michael Boelen performs research in this field. The answer is short: there is too much to possible and to do. For this reason, he created several open source security tools, to help others saving time. We will look into how Lynis can help with technical security scans.\nDate: 2016-05-10 Event: Linux Usergroup Nijmegen PDF: Linux Security Scanning with Lynis Linux Security Workshop In this private workshop, 14 students learned about the wide range of possibilities when it comes to Linux security.\nPrivate session\nDate: 2016-03-29 Event: Private session Dealing with Linux Malware We often hear that viruses do not affect Linux systems. If it was only true… To understand why there is malware in the first place, we look at the reasons for evildoers to create harmful software. When that is clear, we move on by defining several types of malware, to finally focus on a very particular one, the rootkit. A quick course into the cleverness of rootkits follows, with the related challenges it offers for detection. We close the session by giving tips on detection and prevention.\nDate: 2016-03-19 Event: NLLGG Presentation: Dealing with Linux Malware (PDF) Linux Hardening So you think the systems at your employer can actually use a little bit more security? Or what about your own system to gain more privacy? In this talk, we discuss the reasons for Linux server and system hardening. First we learn why we should protect our crown jewels, and what can wrong if we ignore information security. Next is getting a better understanding of the possible resources we can use. And since system hardening can be time-consuming, we discuss some tools to help in the system hardening quest.\nDate: 2016-03-01 Event: DBLUG PDF: Linux Hardening How to Deal with a Compromised System? Presentation of Michael Boelen about handling compromised systemsMalicious software now exists for more than 40 years. Linux is just another platform having to deal with that threat. But the question remains how should we act when we find a backdoor or rootkit on our system. In this talk, the threat and defenses will be explained.\nDate: 5 February 2016 Event: FIAT! 2016 Presentation: Handling compromised Linux systems (PDF) Linux Security, from Concept to Tooling Linux is considered to be a secure operating system by default. Still there is a lot to learn about system hardening and technical auditing. This 1-hour presentation explains the need for hardening and auditing of your systems. We discussed some additional documents and tools, to further help this endeavor.\nDate: 2016-01-16 Event: NLLGG Presentation: Linux Security, from Concept to Tooling Linux Security for Developers To help developers create more secure software, we have to understand the need first. This introduction talk was 2 hours, with many individual tips to know why security is important, and the possible consequences if we ignore that. We covered specific items to enhance the security posture of our applications. Finally, we finish the presentation by sharing the need for performing regular technical audits.\nEvent: Meetup Dev070 Presentation: Linux Security for Developers 2015 BlackHat USA (Las Vegas) / BlackHat Europe (Amsterdam) – Lynis demo Haagse Hogeschool – Workshop Linux Security NLUUG – From open source to a company (Dutch) Kollab Summit – Workshop Linux Security and Hardening openSUSE Conference – Docker Security: Are your containers tightly secured to the ship? 2014 BlackHat Europe (Amsterdam) – Lynis Demo NLUUG – How Many Security Layers Are Enough? NLUUG – Security Auditing and Hardening for Linux Interested in slides? Check out some of the presentations. Some ideas for future presentations Linux IPv6 security\nAn introduction into IPv6 with the primary focus on security aspects for Linux systems. Security is hard: tool developers to blame?\nStill in 2016, security remains complicated. Why is that and how can we solve it? Showing by example how “simple” tools can still be difficult. There is room to improve. ELF 101\nA dive into ELF binaries and files, and how they work on Linux.\nMy article The 101 of ELF Binaries on Linux: Understanding and Analysis was covered on Reddit, Twitter and other websites.\n","permalink":"https://michaelboelen.com/presentations/","tags":null,"title":"Presentations"},{"categories":null,"contents":"Rootkit Hunter Rootkit Hunter (rkhunter) is the tool to find evidence of malicious software on systems running Linux, Mac OS X, and UNIX. As the original author of this tool, I released the first version in 2003. In 2006, the project was handed over to a new team, to ensure its development kept going.\nAchievements:\nBoth the tool and my name have been listed in several printed magazines rkhunter is part of the LPI 303 exam objectives Lynis After the lessons learned from Rootkit Hunter, I started a new project with a broader goal: help people improving security defenses on their systems. Also focused on Linux, macOS, and Unix-based systems. This auditing and system hardening tool is still under development since its original release in 2007.\nLinux Audit Linux Audit is the name of my **Linux security blog*8. Articles cover topics in-depth. The goal is to help both beginners and more advanced Linux users.\nThe blog was created by me in 2014 as a research project. Its goal is to provide a knowledge hub and share information about Linux security.\nMain topics include Linux system hardening, security auditing, and compliance.\nLinux Audit is an ongoing project and new articles are published after extensive research. Quality above quantity.\nLinux Security Expert The Linux Security Expert (LSE) project has the goal to create a security library, including a training focused on Linux security. One of the bigger sections is a database of open source security tools that are categorized and tagged. It also ranks the tools in a top 100. The project goal is to become a one-stop place for Linux security, whenever one is seeking to learn or doing practical tasks for better understanding.\nOther blogs Meereco.nl (Dutch only) On meereco.nl I cover topics in Dutch about DIY, making a home more sustainable, and some technical topics useful in and around the house.\nOnlyFAQs (Dutch only) The OnlyFAQs website is Question and Answer website to give quick answers to common questions. The goal is to make more information available to those new to a subject, but also a index of questions to easily refer to. This saves my time to answer the same question over and over, but also to improve discoverability in a time where people are impatient to read longer articles.\n","permalink":"https://michaelboelen.com/projects/","tags":null,"title":"Projects"},{"categories":null,"contents":"Conferences Besides being a speaker on open source and infosec conferences, I help the NLUUG, a UNIX user community in The Netherlands. Before I was board member, part of the programme committee and responsible for PR and social media. Since 2024, I decided to spread my activities a bit more towards other initiatives and laid down most of my activities for the NLUUG and focus on the website mainly.\nCommunication and promotion Another community I help is the Dutch NLLGG with focus on Linux and open source. I\u0026rsquo;m part of the communication commission, mainly in the role as strategic advisor. Part of the tasks is helping to promote our activities.\nBlogging Information sharing is something I love to do. Definitely taking a lot of time to do, but worth the effort, seeing the many positive comments. I’ve now contributed over 180 articles for the Linux Audit blog.\nAnother blog is my Dutch blog about Linux. It is focused on Linux beginners and is called Linux voor een beginner. I share entry-level articles to help people get started with Linux and open source software.\nMentoring To help younger people in the field of information security, I’m a mentor to a few people per year. I help them to make the right choices. This includes suggestions for certification and achieving actions to further progress in our field. No one was born as an expert, but we definitely need more of them.\n","permalink":"https://michaelboelen.com/volunteering/","tags":null,"title":"Volunteering efforts"}]