<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TristanPoulsen.com</title>
	<atom:link href="https://tristanpoulsen.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://tristanpoulsen.com</link>
	<description>Welcome to TristanPoulsen.com</description>
	<lastBuildDate>Tue, 11 Aug 2026 16:07:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://tristanpoulsen.com/wp-content/uploads/2024/07/cropped-Tristan-Forryst-Poulsen-initials-logo-32x32.png</url>
	<title>TristanPoulsen.com</title>
	<link>https://tristanpoulsen.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire</title>
		<link>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/</link>
					<comments>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/#respond</comments>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 15:46:19 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<category><![CDATA[Private Equity]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=919</guid>

					<description><![CDATA[Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition. The short version: Two firms, one border between them These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in ... <a title="Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire" class="read-more" href="https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/" aria-label="Read more about Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition.</em></p>



<p class="wp-block-paragraph"><strong>The short version:</strong></p>



<ul class="wp-block-list">
<li><strong>Client:</strong> Two sister engineering firms, one in the US and one in Canada (anonymized), serving industrial clients</li>



<li><strong>Engagement:</strong> Seven years and counting of outsourced IT support and security</li>



<li><strong>Scope:</strong> Email security, cloud storage, remote and in-person helpdesk, phone systems, hardware</li>



<li><strong>Status:</strong> Both firms are now being acquired, primarily for their engineering talent. I still run their security today.</li>
</ul>



<h2 class="wp-block-heading">Two firms, one border between them</h2>



<p class="wp-block-paragraph">These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in the US and one in Canada, both doing engineering work for industrial clients. Neither one had internal IT, and neither one needed a big MSP contract with a 40-page SLA. They needed someone who picked up the phone.</p>



<p class="wp-block-paragraph">That&#8217;s been the shape of the whole relationship. I handle their email security, their cloud storage, and their day-to-day support, remote when that works and in person when it doesn&#8217;t. Over the years the scope grew the way it does with small firms: I&#8217;ve run their phone system migrations, built their workstations by hand when off-the-shelf machines didn&#8217;t fit the budget, and made a hundred small calls about where to spend money and where to hold off. IT support for small business lives in those decisions. The stack matters less than the judgment behind it.</p>



<h2 class="wp-block-heading">The customer security test</h2>



<p class="wp-block-paragraph">A few years in, one of their major industrial customers raised the stakes. Before awarding project work, the customer required compliance with its corporate IT security policy and information security program. Buried in the requirements was a hard one: all project data had to stay in Canada.</p>



<p class="wp-block-paragraph">That&#8217;s a data residency requirement, and it&#8217;s the kind of thing that quietly kills deals for small vendors. The engineering team just wanted to work. The customer wanted proof their data wouldn&#8217;t drift onto US servers. My job was to close that gap without blowing up the budget or the workflow.</p>



<p class="wp-block-paragraph">I laid out three options with real time and cost estimates: client-side encryption with Canadian-held keys on their existing cloud storage, a locally encrypted vault, or a move to a Canadian-hosted cloud platform. They picked the Canadian platform. I ran the migration, kept the working copies flowing for the engineer who needed them daily, and mapped the setup against the customer&#8217;s security policy documents so the answers were ready before anyone asked.</p>



<p class="wp-block-paragraph">Small firms lose big customers over vendor security assessments they can&#8217;t answer. This one kept theirs.</p>



<h2 class="wp-block-heading">Then the acquisition came</h2>



<p class="wp-block-paragraph">Both firms are now being acquired by a larger company, and the deal is mostly about people. The acquirer wants the engineers. That&#8217;s the whole thesis.</p>



<p class="wp-block-paragraph">Talent deals move slowly, and this one has. Which makes the IT story simple to state and hard to fake: through the entire drawn-out process, the engineers have kept working, the systems have stayed up, and the security stack has kept running. Seven years in, the incident count is still zero. Nobody on the buyer&#8217;s side has had to ask why the target&#8217;s email got breached or where the customer data lives, because those answers were settled years ago.</p>



<p class="wp-block-paragraph">I&#8217;m not running this deal, and this case study isn&#8217;t about deal work. It&#8217;s about the thing that makes deal work easy: an acquirer doing diligence on these firms finds documented systems, a customer-vetted security posture, and a support relationship that didn&#8217;t wobble when ownership went into limbo.</p>



<h2 class="wp-block-heading">What seven years buys</h2>



<p class="wp-block-paragraph">Here&#8217;s the honest math on long-term outsourced IT support. Any provider can look good for six months. The value shows up in year three when a customer&#8217;s security team comes knocking, and in year seven when a buyer does, and both times the answers are already written down.</p>



<p class="wp-block-paragraph">These two firms got acquired for their talent. The reason talent was the <em>only</em> thing under negotiation, rather than talent minus a pile of IT risk, is seven years of unglamorous maintenance: patched systems, secured email, data where the contracts say it should be.</p>



<h2 class="wp-block-heading">If your customers are bigger than you</h2>



<p class="wp-block-paragraph">Industrial customers push their security requirements downstream, and acquirers read your environment like a balance sheet. Both happen on their schedule, not yours. The firms that come through clean are the ones that treated security as routine long before anyone was checking.</p>



<p class="wp-block-paragraph">If you&#8217;re staring down a customer&#8217;s vendor security assessment, a data residency requirement, or a sale where your IT needs to hold up to inspection, that&#8217;s the work I do.</p>



<p class="wp-block-paragraph"><em>Facing a security review you&#8217;re not sure you&#8217;d pass? <a href="https://tristanpoulsen.com/contact/">Get in touch.</a></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybersecurity Due Diligence Case Study: A Real PE Acquisition</title>
		<link>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/</link>
					<comments>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/#respond</comments>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 15:00:28 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<category><![CDATA[Private Equity]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=912</guid>

					<description><![CDATA[From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities. The short version: It started with a breach They found me the way ... <a title="Cybersecurity Due Diligence Case Study: A Real PE Acquisition" class="read-more" href="https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/" aria-label="Read more about Cybersecurity Due Diligence Case Study: A Real PE Acquisition">Read more</a>]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition</h2>



<p class="wp-block-paragraph"><em>How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities.</em></p>



<p class="wp-block-paragraph"><strong>The short version:</strong></p>



<ul class="wp-block-list">
<li><strong>Client:</strong> Single-location self-storage operator in Colorado (anonymized)</li>



<li><strong>Buyer:</strong> Private equity-backed storage operator with 50+ facilities</li>



<li><strong>My role:</strong> IT and security provider for 4.5 years, then transition lead on the seller side</li>



<li><strong>Handoff:</strong> Three weeks, kickoff to done</li>
</ul>



<h2 class="wp-block-heading">It started with a breach</h2>



<p class="wp-block-paragraph">They found me the way a lot of my clients do: mid-incident. Their previous IT provider had gone defunct, and the provider&#8217;s abandoned website was serving malware. Someone at the storage company opened that site looking for support and infected their machine instead.</p>



<p class="wp-block-paragraph">I took the call, cleaned the infection, recovered their systems, and combed through everything for leftover malicious code. Then I rebuilt their stack so it wouldn&#8217;t happen twice: antivirus, EDR through Huntress, cloud backup, and same-day helpdesk, remote and onsite. All of it sized and priced for a single-location business.</p>



<h2 class="wp-block-heading">Four and a half years of quiet</h2>



<p class="wp-block-paragraph">For the next 4.5 years I ran their IT and security. Webroot and Huntress covered the endpoints. Backups ran to the cloud and got checked. When something broke, I fixed it the same day. No repeat incidents, no drama.</p>



<p class="wp-block-paragraph">That stretch of quiet matters more than it sounds. When a buyer showed up years later, the company had a documented, monitored environment with a real security history behind it. Most small businesses walk into a sale with none of that.</p>



<h2 class="wp-block-heading">Then a buyer showed up</h2>



<p class="wp-block-paragraph">A private equity-backed storage operator with 50+ facilities acquired the company. Deals like this live or die in diligence, and the buyer&#8217;s team had two questions about IT: is this environment secure, and is it cost-effective?</p>



<p class="wp-block-paragraph">That&#8217;s technology due diligence in one sentence. Buyers want proof, and on small acquisitions they rarely get it, because the seller&#8217;s IT knowledge lives in one person&#8217;s head or a defunct vendor&#8217;s filing cabinet. Here, I had run the environment for years and could answer with documentation instead of guesses. That alone shortened the timeline.</p>



<h2 class="wp-block-heading">The three-week handoff</h2>



<p class="wp-block-paragraph">Post merger IT integration for this deal came down to four workstreams.</p>



<p class="wp-block-paragraph"><strong>RMM migration.</strong> The buyer standardized every acquisition onto their own remote management platform. Instead of touching each machine by hand, I wrote a script that deployed their agent and removed mine (ConnectWise Automate, at the time) across all systems in one pass.</p>



<p class="wp-block-paragraph"><strong>Backup migration.</strong> I moved their cloud backups off my platform and onto the buyer&#8217;s, and verified restore points on both ends before cutting over. A migration without verified restores is a gamble, and nobody gambles during a closing.</p>



<p class="wp-block-paragraph"><strong>Access control.</strong> The buyer&#8217;s team ran the access control migration themselves. I supported from the client side, kept credentials flowing, and made sure nothing on our end held them up.</p>



<p class="wp-block-paragraph"><strong>Data cleanup and destruction.</strong> The buyer&#8217;s compliance requirements meant old data had to go, and go for real. I purged stale records the business no longer needed, then dealt with the retired hard drives that held customer data: a seven-pass wipe on each drive, and then I opened them up and pulled the platters out. Nobody is recovering that data. The platters make decent coasters, if you&#8217;re wondering.</p>



<p class="wp-block-paragraph">Secure data destruction is the step small-business acquisitions skip most, and it&#8217;s the one that turns into a lawsuit years later when a drive full of customer records surfaces at a pawn shop.</p>



<p class="wp-block-paragraph">Total time, including the buyer&#8217;s inspection and the back-and-forth between their team and my client: three weeks.</p>



<h2 class="wp-block-heading">The result</h2>



<p class="wp-block-paragraph">The buyer got what diligence teams almost never get from a small acquisition: a documented environment, a working security stack, verified backups, and proof that legacy customer data was destroyed instead of forgotten in a closet. My client walked into closing without IT sitting on the deal as an open issue.</p>



<p class="wp-block-paragraph">And the whole thing traced back to a malware infection five years earlier. The same work that saved them from a breach made them a cleaner company to buy.</p>



<h2 class="wp-block-heading">Why this matters if you&#8217;re buying or selling</h2>



<p class="wp-block-paragraph">Most small businesses run on undocumented IT held together by whoever set it up. In an acquisition, undocumented becomes risk, and risk becomes a price reduction or a delayed close. Buyers now run cybersecurity due diligence on deals of every size, and sellers who can&#8217;t answer basic questions about their environment pay for it at the negotiating table.</p>



<p class="wp-block-paragraph">If you&#8217;re a buyer, a searcher, or an owner planning an exit, the cheapest time to fix your technology story is before diligence starts. That&#8217;s the work I do: assess the stack, close the gaps, and run the handoff so the deal keeps moving.</p>



<p class="wp-block-paragraph"><em>Working a deal and want a second set of eyes on the technology? <a href="https://tristanpoulsen.com/contact/">Get in touch.</a></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Consolidating Business Apps in 2026</title>
		<link>https://tristanpoulsen.com/consolidating-business-apps-in-2026/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 01 Apr 2026 18:27:48 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=898</guid>

					<description><![CDATA[April 1st 2026I&#8217;m working on trying to make my life easier and consolidate my apps to as few as possible. That has led me to start using ClickUp for as many features that I need for my daily needs. I&#8217;m currently using ClickUp for the following + what it&#8217;s replaced: It&#8217;s starting to replace a ... <a title="Consolidating Business Apps in 2026" class="read-more" href="https://tristanpoulsen.com/consolidating-business-apps-in-2026/" aria-label="Read more about Consolidating Business Apps in 2026">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">April 1st 2026<br>I&#8217;m working on trying to make my life easier and consolidate my apps to as few as possible. That has led me to start using ClickUp for as many features that I need for my daily needs.</p>



<p class="wp-block-paragraph">I&#8217;m currently using ClickUp for the following + what it&#8217;s replaced:</p>



<ul class="wp-block-list">
<li>Time tracking (starting today) &#8211; I used to use Toggl</li>



<li>To-do lists (primary) &#8211; Used to use To-doist
<ul class="wp-block-list">
<li>Both for work and for personal stuff like Shopping lists</li>
</ul>
</li>



<li>Project Tracking (primary) &#8211; Used to use Asana/Trello/Monday + others in the past</li>



<li>Company Chat &#8211; I used to use Slack</li>
</ul>



<p class="wp-block-paragraph">It&#8217;s starting to replace a lot of apps / functionality so I&#8217;m not bouncing from app to app throughout the day. It&#8217;s nice only using one app for a lot of different use cases. We&#8217;ll see if it can help me organize and bring synergy to my businesses.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Best Daily Brake Pads for VW GTI MK7 &#8211; my pick</title>
		<link>https://tristanpoulsen.com/the-best-daily-brake-pads-for-vw-gti-mk7-my-pick/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Mon, 26 May 2025 22:05:22 +0000</pubDate>
				<category><![CDATA[Random Other Posts]]></category>
		<category><![CDATA[VW GTI MK7]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=869</guid>

					<description><![CDATA[I put the Hawk HP Street 5.0 pads from Hawk Performance on my 2017 VW GTI SE manual a couple of years ago and have been absolutely loving them.Quiet, great stopping power, and they are decently priced (compared to other performance pads I&#8217;ve tried on other vehicles). I got mine for $122.40 after tax on ... <a title="The Best Daily Brake Pads for VW GTI MK7 &#8211; my pick" class="read-more" href="https://tristanpoulsen.com/the-best-daily-brake-pads-for-vw-gti-mk7-my-pick/" aria-label="Read more about The Best Daily Brake Pads for VW GTI MK7 &#8211; my pick">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I put the Hawk HP Street 5.0 pads from Hawk Performance on my 2017 VW GTI SE manual a couple of years ago and have been <strong>absolutely</strong> loving them.<br>Quiet, great stopping power, and they are decently priced (compared to other performance pads I&#8217;ve tried on other vehicles). I got mine for $122.40 after tax on Tire Rack, but you can find them in a few online retailers &#8211; I&#8217;m not sure about in-store availability.</p>



<p class="wp-block-paragraph"><br>They are everything I look for in upgraded street pads in comparison to the OEM pads. As their website says <em>&#8220;HPS 5.0 is a Ferro-Carbon compound that provides advanced braking characteristics to enhance the driving experience. This compound combines the safety and quality of aerospace design with the braking technology of motorsports. The results are shorter stopping distances, improved performance under heavy braking conditions, and street car friendly characteristics.&#8221;</em> &#8211; <a href="https://www.hawkperformance.com/hps-5-0">hawkperformance.com</a><br><br>Now they are going for around 180 for front pads (I still need to do my rear pads here shortly)<br></p>



<figure class="wp-block-image size-full is-resized"><img fetchpriority="high" decoding="async" width="732" height="504" src="https://tristanpoulsen.com/wp-content/uploads/2025/05/image-1.png" class="wp-image-873" alt="Hawk High Performance Street 5.0 brake pads for VW GTI MK7." style="width:473px;height:auto" srcset="https://tristanpoulsen.com/wp-content/uploads/2025/05/image-1.png 732w, https://tristanpoulsen.com/wp-content/uploads/2025/05/image-1-300x207.png 300w" sizes="(max-width: 732px) 100vw, 732px" /> </figure>



<p class="wp-block-paragraph">I tend to use my brakes more than engine braking, so I have a pretty good idea how they feel. A bit soft on the initial response (which I like personally). They grab nicely when you put adequate pressure. Used them in the snow for a season, and they do well with the ABS when sliding on ice. </p>



<p class="wp-block-paragraph">My only gripe with them is they seem to produce more dust than the OEM &#8211; so cleaning the wheels takes a bit longer and I can live with that. I&#8217;ll certainly buy them again when I need to replace my pads on my MK7.</p>



<p class="wp-block-paragraph"><br><br><em>Note to self: When I do replace them, I&#8217;ll try to come back with the pictures and the mileage achieved with the Hawk hp street 5.0 pads</em></p>



<p class="wp-block-paragraph"><br></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How I Stopped Bots from Crashing My cPanel Server</title>
		<link>https://tristanpoulsen.com/how-i-stopped-bots-from-crashing-my-cpanel-server/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 07 May 2025 17:36:09 +0000</pubDate>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Random Tech Posts]]></category>
		<category><![CDATA[Strategy And Tips]]></category>
		<category><![CDATA[Tech]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=856</guid>

					<description><![CDATA[If you&#8217;re managing a cPanel + WHM server (mine runs on AlmaLinux) and notice CPU usage spiking to 100%, there&#8217;s a good chance that aggressive bots or inefficient PHP processes are hammering your server. That’s exactly what happened to me — and here’s how I fixed it. The Problem My server load was pinned at ... <a title="How I Stopped Bots from Crashing My cPanel Server" class="read-more" href="https://tristanpoulsen.com/how-i-stopped-bots-from-crashing-my-cpanel-server/" aria-label="Read more about How I Stopped Bots from Crashing My cPanel Server">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">If you&#8217;re managing a cPanel + WHM server (mine runs on AlmaLinux) and notice CPU usage spiking to 100%, there&#8217;s a good chance that <strong>aggressive bots</strong> or <strong>inefficient PHP processes</strong> are hammering your server. That’s exactly what happened to me — and here’s how I fixed it.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">The Problem</h2>



<p class="wp-block-paragraph">My server load was pinned at 100%, with <code>php-fpm</code> processes consuming the bulk of the CPU. Using tools like <code>htop</code> and <code>ps</code>, I traced the activity back to a few specific WordPress sites hosted on the server.</p>



<p class="wp-block-paragraph">The common culprit? <strong>Bot traffic</strong> hammering uncached pages and XML-RPC endpoints.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">The Fix (3-Part Solution)</h2>



<h3 class="wp-block-heading">1. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9f1.png" alt="🧱" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Block Bots with <code>.htaccess</code></h3>



<p class="wp-block-paragraph">I edited the <code>.htaccess</code> file for each affected site and added rules to block known abusive bots by user agent:</p>



<pre class="wp-block-preformatted"><code># Block bad bots by user-agent<br>&lt;IfModule mod_rewrite.c><br>RewriteEngine On<br>RewriteCond %{HTTP_USER_AGENT} ^$ [OR]<br>RewriteCond %{HTTP_USER_AGENT} (semrush|ahrefs|mj12bot|dotbot|python-requests|curl|wget|masscan|sqlmap|fimap|nmap|nikto) [NC]<br>RewriteRule .* - [F,L]<br>&lt;/IfModule><br></code></pre>



<p class="wp-block-paragraph">This simple change started deflecting unnecessary load <strong>before</strong> it could hit WordPress or PHP.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">2. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e1.png" alt="🛡" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Install and Configure Fail2Ban</h3>



<p class="wp-block-paragraph">I installed <strong>Fail2Ban</strong> to automatically block IPs that triggered suspicious patterns in my Apache logs (like repeated bot-like requests):</p>



<pre class="wp-block-preformatted"><code>sudo yum install epel-release -y<br>sudo yum install fail2ban -y<br>sudo systemctl enable fail2ban<br>sudo systemctl start fail2ban<br></code></pre>



<p class="wp-block-paragraph">Then, I created a jail to detect and ban bad bots:</p>



<p class="wp-block-paragraph"><strong><code>/etc/fail2ban/jail.d/apache-badbots.conf</code></strong></p>



<pre class="wp-block-preformatted"><code>[apache-badbots]<br>enabled = true<br>port    = http,https<br>filter  = apache-badbots<br>logpath = /usr/local/apache/logs/access_log<br>maxretry = 10<br>findtime = 300<br>bantime = 3600<br></code></pre>



<p class="wp-block-paragraph"><strong><code>/etc/fail2ban/filter.d/apache-badbots.conf</code></strong></p>



<pre class="wp-block-preformatted"><code>[Definition]<br>failregex = ^&lt;HOST> -.*"(GET|POST).*(crawler|bot|spider|python|curl|wget).*HTTP.*"<br></code></pre>



<p class="wp-block-paragraph">With this in place, the server now proactively bans repeat offenders and malicious bots.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">3. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f504.png" alt="🔄" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Restart PHP-FPM and Apache to Flush Load</h3>



<p class="wp-block-paragraph">Once the defenses were in place, I restarted the two main services to clear out any bloated or stuck processes:</p>



<pre class="wp-block-preformatted"><code>systemctl restart ea-php81-php-fpm<br>systemctl restart httpd<br></code></pre>



<p class="wp-block-paragraph">This dropped my CPU usage almost instantly and gave the server a clean slate to work with.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Summary</h2>



<p class="wp-block-paragraph">After these changes:</p>



<ul class="wp-block-list">
<li>CPU usage dropped from 100% to &lt;10%</li>



<li>PHP-FPM processes normalized</li>



<li>The server has stayed stable under load, even with continued traffic</li>
</ul>



<p class="wp-block-paragraph">If you&#8217;re running cPanel/WHM and notice unexplained high load:</p>



<ul class="wp-block-list">
<li><strong>Check your access logs</strong></li>



<li><strong>Filter bots at the .htaccess level</strong></li>



<li><strong>Set up Fail2Ban to auto-ban bad actors</strong></li>



<li>And always <strong>restart PHP-FPM/Apache</strong> after config changes</li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Recommended Switch for Small Business with No Yearly Licensing</title>
		<link>https://tristanpoulsen.com/recommended-switch-for-small-business-with-no-yearly-licensing/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 30 Oct 2024 20:30:26 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=833</guid>

					<description><![CDATA[If you&#8217;re in need of a business grade switch, my recommendation as of recent, has been this Cisco Business switch. My favorite aspect is there&#8217;s no need to pay for a recurring cloud license with this switch. This makes it perfect for smaller businesses with less than 10 offices or stations (each with a VOIP ... <a title="Recommended Switch for Small Business with No Yearly Licensing" class="read-more" href="https://tristanpoulsen.com/recommended-switch-for-small-business-with-no-yearly-licensing/" aria-label="Read more about Recommended Switch for Small Business with No Yearly Licensing">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">If you&#8217;re in need of a business grade switch, my recommendation as of recent, has been this Cisco Business switch. My favorite aspect is there&#8217;s no need to pay for a recurring cloud license with this switch. This makes it perfect for smaller businesses with less than 10 offices or stations (each with a VOIP device and workstation).</p>



<h2 class="wp-block-heading">CISCO DESIGNED Business CBS220-24P-4G Smart Switch | 24 Port GE | PoE | 4x1G SFP | 3-Year Limited Hardware Warranty</h2>



<div class="wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex">
<div class="wp-block-button has-custom-width wp-block-button__width-25"><a class="wp-block-button__link has-contrast-color has-text-color has-background has-link-color wp-element-button" href="https://amzn.to/4fgHaPg" style="background-color:#f7ca00">Amazon</a></div>
</div>



<div style="height:52px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph">The <strong>CISCO CBS220-24P-4G Smart Switch</strong> is a versatile network switch designed for small to medium-sized businesses. Here’s a quick breakdown:</p>



<ul class="wp-block-list">
<li><strong>Ports:</strong> 24 Gigabit Ethernet (GE) ports</li>



<li><strong>Power over Ethernet (PoE):</strong> Supports PoE, allowing it to power compatible devices like IP cameras, phones, and access points directly through Ethernet cables.</li>



<li><strong>Uplink Ports:</strong> 4 SFP (Small Form-factor Pluggable) ports at 1G each for high-speed uplinks to other network devices or the internet.</li>



<li><strong>Smart Features:</strong> Designed to offer easy configuration and monitoring, providing essential Layer 2 network features that support efficient traffic management without complexity.</li>



<li><strong>Warranty:</strong> Comes with a 3-year limited hardware warranty.</li>
</ul>



<p class="wp-block-paragraph">This switch is suited for businesses needing a reliable, secure, and simple solution to expand their network and support PoE devices.</p>



<figure class="wp-block-image size-medium"><img decoding="async" width="300" height="169" src="http://3.239.168.193/wp-content/uploads/2024/10/CISCO-DESIGNED-Business-CBS220-24P-4G-300x169.png" alt="" class="wp-image-836" srcset="https://tristanpoulsen.com/wp-content/uploads/2024/10/CISCO-DESIGNED-Business-CBS220-24P-4G-300x169.png 300w, https://tristanpoulsen.com/wp-content/uploads/2024/10/CISCO-DESIGNED-Business-CBS220-24P-4G-1024x578.png 1024w, https://tristanpoulsen.com/wp-content/uploads/2024/10/CISCO-DESIGNED-Business-CBS220-24P-4G-768x434.png 768w, https://tristanpoulsen.com/wp-content/uploads/2024/10/CISCO-DESIGNED-Business-CBS220-24P-4G-1536x867.png 1536w, https://tristanpoulsen.com/wp-content/uploads/2024/10/CISCO-DESIGNED-Business-CBS220-24P-4G.png 1580w" sizes="(max-width: 300px) 100vw, 300px" /></figure>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Auto Email Filter Script Python</title>
		<link>https://tristanpoulsen.com/auto-email-filter-script-python/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 21 Aug 2024 01:19:41 +0000</pubDate>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Random Tech Posts]]></category>
		<category><![CDATA[Tech]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=715</guid>

					<description><![CDATA[Today I built a python script that takes a csv file with a list of emails and using the Gmail API, moves the emails to the corresponding folder I&#8217;d like to move them to. Then it archives them. Now obviously you can do this in Gmail with an automated filter for incoming emails, so the ... <a title="Auto Email Filter Script Python" class="read-more" href="https://tristanpoulsen.com/auto-email-filter-script-python/" aria-label="Read more about Auto Email Filter Script Python">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="has-medium-font-size wp-block-paragraph">Today I built a python script that takes a csv file with a list of emails and using the Gmail API, moves the emails to the corresponding folder I&#8217;d like to move them to. Then it archives them.<br><br>Now obviously you can do this in Gmail with an automated filter for incoming emails, so the reason I&#8217;ve done this is so occasionally, probably once every other week, I&#8217;ll check all the emails in my inbox and I move emails (99% of the time to the same folders). <br>I wanted to automate this cleaning process without using <a href="https://www.sanebox.com/">SaneBox</a> and I did try to use <a href="http://make.com">Make.com</a> to do the same thing, but this was honestly simpler and I can run it without the additional operations cost.</p>



<p class="has-medium-font-size wp-block-paragraph">Here&#8217;s the csv format for the headers and for the Folders &#8211; I couldn&#8217;t get it to link via the name so I have it cross-reference the Label ID to match the folders:<br>email, label<br>example_email@yahoo.com, Label_55<br><br>This is what the output looks like:</p>



<figure class="wp-block-image size-full"><img decoding="async" width="630" height="320" src="http://3.239.168.193/wp-content/uploads/2024/08/email_filter_python_script_image-e1724203635699.png" class="wp-image-719" alt="Python script output showing no emails found for filtering." srcset="https://tristanpoulsen.com/wp-content/uploads/2024/08/email_filter_python_script_image-e1724203635699.png 630w, https://tristanpoulsen.com/wp-content/uploads/2024/08/email_filter_python_script_image-e1724203635699-300x152.png 300w" sizes="(max-width: 630px) 100vw, 630px" /> </figure>



<div style="height:100px" aria-hidden="true" class="wp-block-spacer"></div>



<h3 class="wp-block-heading"><strong>Here&#8217;s my code if anyone wants to make their own python script:</strong></h3>



<pre class="wp-block-code"><code>import os
import pickle
import pandas as pd
import base64
from google.oauth2.credentials import Credentials
from google.auth.transport.requests import Request
from googleapiclient.discovery import build
from googleapiclient.errors import HttpError
from google_auth_oauthlib.flow import InstalledAppFlow
from email.mime.text import MIMEText
from email.mime.multipart import MIMEMultipart

# Step 1: Authentication and Service Initialization
def authenticate_gmail_api():
    SCOPES = &#91;'https://www.googleapis.com/auth/gmail.modify']
    creds = None

    if os.path.exists('token.pickle'):
        with open('token.pickle', 'rb') as token:
            creds = pickle.load(token)
    
    if not creds or not creds.valid:
        if creds and creds.expired and creds.refresh_token:
            creds.refresh(Request())
        else:
            flow = InstalledAppFlow.from_client_secrets_file(
                'credentials.json', SCOPES)
            creds = flow.run_local_server(port=0)
        with open('token.pickle', 'wb') as token:
            pickle.dump(creds, token)

    service = build('gmail', 'v1', credentials=creds)
    return service

# Step 2: Read Filters from CSV File
def read_filters_from_csv(csv_file):
    filters_df = pd.read_csv(csv_file)
    return filters_df

# Step 3: Search for Matching Emails
# Step 3: Search for Matching Emails
def search_emails(service, query):
    try:
        # Modify the query to explicitly search only within the INBOX
        query = f'label:inbox {query}'
        results = service.users().messages().list(userId='me', q=query).execute()
        messages = results.get('messages', &#91;])
        return messages
    except HttpError as error:
        print(f'An error occurred: {error}')
        return &#91;]


# Step 4: Apply Filters and Move Emails
def apply_filters(service, filters_df):
    for index, row in filters_df.iterrows():
        email_filter = row&#91;'email']
        label = row&#91;'label']

        query = f'from:{email_filter}'
        messages = search_emails(service, query)

        if not messages:
            print(f'No emails found for {email_filter}')
            continue

        for message in messages:
            msg_id = message&#91;'id']
            # Move email to the specified folder (label)
            service.users().messages().modify(
                userId='me',
                id=msg_id,
                body={'addLabelIds': &#91;label], 'removeLabelIds': &#91;'INBOX']}
            ).execute()
            print(f'Email from {email_filter} moved to {label} and archived.')

# Step 5: Retrieve and List Label IDs
def list_labels(service):
    results = service.users().labels().list(userId='me').execute()
    labels = results.get('labels', &#91;])

    if not labels:
        print('No labels found.')
    else:
        print('Labels:')
        for label in labels:
            print(f"{label&#91;'name']} - {label&#91;'id']}")

# Step 6: Main Function
def main():
    # Authenticate and create the Gmail API service
    service = authenticate_gmail_api()

    # Uncomment the line below to list all labels and their IDs
    list_labels(service)

    # Load filter rules from CSV
    csv_file = 'filters.csv'  # Replace with your CSV file
    filters_df = read_filters_from_csv(csv_file)

    # Apply filters to emails
    apply_filters(service, filters_df)

if __name__ == '__main__':
    main()
</code></pre>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New TFP logo</title>
		<link>https://tristanpoulsen.com/new-tfp-logo/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 31 Jul 2024 19:42:42 +0000</pubDate>
				<category><![CDATA[Random Tech Posts]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Updates]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=705</guid>

					<description><![CDATA[TFP new vs. Old I decided to add some additions to this portfolio website like the &#8220;App Ecosystems I Work With&#8221; &#38; I updated my personal logo &#8211; honestly it looks 300% better than the previous one I made over 10 years ago.. My graphic design skills have gotten better even though I&#8217;m more analytical ... <a title="New TFP logo" class="read-more" href="https://tristanpoulsen.com/new-tfp-logo/" aria-label="Read more about New TFP logo">Read more</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="705" class="elementor elementor-705" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-45ea10d6 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="45ea10d6" data-element_type="section" data-e-type="section">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1b708328" data-id="1b708328" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-04268a3 elementor-widget elementor-widget-heading" data-id="04268a3" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">TFP new vs. Old</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-5eaa389 elementor-widget elementor-widget-text-editor" data-id="5eaa389" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									
<p class="wp-block-paragraph">I decided to add some additions to this portfolio website like the <a href="http://3.239.168.193/app-ecosystems-i-work-with/" data-type="page" data-id="593">&#8220;App Ecosystems I Work With&#8221;</a></p>

<p class="wp-block-paragraph">&amp;</p>

<p class="wp-block-paragraph">I updated my personal logo &#8211; honestly it looks 300% better than the previous one I made over 10 years ago.. My graphic design skills have gotten better even though I&#8217;m more analytical than creative..<br /><br />Also needed to update some image links to be served locally as the reference links I had for facebook and twitter (now X) expired or were removed.</p>
								</div>
				</div>
				<div class="elementor-element elementor-element-91d9042 uael-ba-label-hover uael-ba-halign-flex-start elementor-widget elementor-widget-uael-ba-slider" data-id="91d9042" data-element_type="widget" data-e-type="widget" data-widget_type="uael-ba-slider.default">
				<div class="elementor-widget-container">
							<div class="uael-before-after-slider">
			<div class="uael-ba-container" data-move-on-hover="yes" data-orientation="horizontal" data-offset="0.5">
				<img decoding="async" class="uael-before-img" style="position: absolute" src="https://tristanpoulsen.com/wp-content/uploads/2024/07/tfp_before_comparison-1024x1024.png" alt="Before" />
				<img decoding="async" class="uael-after-img" src="https://tristanpoulsen.com/wp-content/uploads/2024/07/Tristan-Forryst-Poulsen-initials-logo-with-buffer-1024x1024.png" alt="After" />
			</div>
		</div>
						</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Remedy for Flying</title>
		<link>https://tristanpoulsen.com/remedy-for-flying/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Tue, 16 May 2023 15:16:54 +0000</pubDate>
				<category><![CDATA[Random Other Posts]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=564</guid>

					<description><![CDATA[I was talking with a client of mine and he mentioned a few things that one can do to help prevent myself from getting sick after flying on an airplane &#8211; being jetlagged of course. I&#8217;m making this post mostly for my own collection so I can look back and read the quick remedies I&#8217;ve ... <a title="Remedy for Flying" class="read-more" href="https://tristanpoulsen.com/remedy-for-flying/" aria-label="Read more about Remedy for Flying">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I was talking with a client of mine and he mentioned a few things that one can do to help prevent myself from getting sick after flying on an airplane &#8211; being jetlagged of course. I&#8217;m making this post mostly for my own collection so I can look back and read the quick remedies I&#8217;ve heard work. I&#8217;ll update this after I&#8217;ve done further testing myself.</p>



<ol class="wp-block-list">
<li>Most importantly drink water or if already feeling meh, mix 2/3 water with 1/3 Gatorade or some other electrolyte and sugar drink.
<ul class="wp-block-list">
<li>If already feeling meh after flying &#8211; drink some warm bone broth</li>
</ul>
</li>



<li>Dark chocolate prior to flying helps? Not sure why but chocolate in general is good before a flight</li>



<li>Lysine or L-lysine &#8211; is an essential amino acid protein block. It&#8217;s used for building proteins and it&#8217;ll help boost your immune system. It can be found in meat fish, dairy, eggs, and supplements. Take 500mg before flying.</li>



<li>Glutathione &#8211; is a Master anti-oxidant that is capable of preventing damage to important cellular components caused by sources such as reactive oxygen species, free radicals, peroxides, lipid peroxides, and heavy metals.</li>
</ol>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Having a Maximum Security Mindset is Important</title>
		<link>https://tristanpoulsen.com/having-a-maximum-security-mindset-is-important/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Fri, 10 Mar 2023 16:53:17 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=549</guid>

					<description><![CDATA[I’ve always tried to have the most secure mindset when it comes to my passwords. Unfortunately with the news of the recent LastPass hacks, I’ve had to migrate away from it (over a year ago at this point) but now with the more serious breach that occurred, I decided to update ALL of my passwords, ... <a title="Having a Maximum Security Mindset is Important" class="read-more" href="https://tristanpoulsen.com/having-a-maximum-security-mindset-is-important/" aria-label="Read more about Having a Maximum Security Mindset is Important">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I’ve always tried to have the most secure mindset when it comes to my passwords. Unfortunately with the news of the recent LastPass hacks, I’ve had to migrate away from it (over a year ago at this point) but now with the more serious breach that occurred, I decided to update ALL of my passwords, quite literally over 1000 passwords, in order to maintain that maximum personal and business security mentality. I’ve probably spent 8 hours already, just updating passwords, usernames, and 2FA where available.</p>



<h3 class="wp-block-heading"><strong>2FA Availability</strong></h3>



<p class="wp-block-paragraph">That’s the thing that I’m frustrated with at the moment, not all major companies offer Two Factor Authentication via a true 2FA App or even better a YubiKey physical key. Banks are the biggest offender of this. They might offer 2FA via your phone or email verification token, but as we all should know, your phone and your email ARE NOT SECURE EITHER. What do I have to do to get USBank and other major Banks to offer the best of the best in security for access to our digital currency?</p>



<p class="wp-block-paragraph">All it takes is a hacker taking control of an email, or SIM jacking your phone number, and presto – they have access to the remainder of your personal information and money. Quite scary if you ask me.</p>



<p class="wp-block-paragraph">Now that I’m looking into this I’m finding that Bank of America – BOA has the highest online security including support for YubiKey. That might be everyone’s best bet, especially large targets like Whales.</p>



<p class="wp-block-paragraph">[insert picture of a whale]</p>



<p class="wp-block-paragraph">“Whaling is a highly targeted phishing attack &#8211; aimed at senior executives &#8211; masquerading as a legitimate email. Whaling is digitally enabled fraud through social engineering, designed to encourage victims to perform a secondary action, such as initiating a wire transfer of funds.”</p>



<h3 class="wp-block-heading"><strong>SIM Jacking</strong></h3>



<p class="wp-block-paragraph">Okay so I don’t have a solution for this, unfortunately, most carriers allow for a sim lock but that has its flaws, as someone with enough information could bypass that over the phone with a telecom customer service rep.</p>



<p class="wp-block-paragraph">It would be cool if a startup or a current telecom company just made a High-security mode for your account/phone numbers linked to the account, which locks the phone number from being replicated to a different SIM without an In-Person double identity verification process. Possibly with fingerprint verification, again in-person to add a barrier to socially engineered methods like SIM jacking.</p>



<p class="wp-block-paragraph">I think this is essential for everyone as our lives now live on our phones, and realistically I’ve noticed most people are less secure with their mobile devices than they are with their desktop computers. When in the real world your phone/phone number should be more important to protection as it ends up being that 2FA step that malicious entities would have to overcome, and currently it’s doable with the right attack vectors. No seriously how are these multi-millionaires not terrified that with their mindset in cyber-security and when they are targeted, they would be hacked in a matter of hours, not days or weeks? Leaving massive financial risk based on one of 3 attack vectors, compromised email, compromised mobile device, or a socially engineered SIM jacking.</p>



<h4 class="wp-block-heading">Get a Yubico Key for your personal or business cyber-security.</h4>



<script type="text/javascript">
amzn_assoc_tracking_id = "tristanp0c-20";
amzn_assoc_ad_mode = "manual";
amzn_assoc_ad_type = "smart";
amzn_assoc_marketplace = "amazon";
amzn_assoc_region = "US";
amzn_assoc_design = "enhanced_links";
amzn_assoc_asins = "B07HBD71HL";
amzn_assoc_placement = "adunit";
amzn_assoc_linkid = "fbe1ff348681137ee16615f55ceec90a";
</script>
<script src="//z-na.amazon-adsystem.com/widgets/onejs?MarketPlace=US"></script>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
