What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I know what you mean, I actually didn't use an AV for I believe 10 years, cause they all sucked. But I must say Win Defender is very light on my system, it doesn't make my system any slower, so why not. I also don't get that many false positives so far.
     
  2. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Quad9 DOH
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • UBO - Hard Mode
    • Don't add custom search engines
    • JShelter
    I decided to remove LocalCDN to make the configuration more like Firefox.
     
    Last edited: Sep 4, 2022
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Had to update Chrome on one of my 8.1 systems- for some reason i still haven't tracked down yet WHY auto update for Chrome throws me an error. My other 8.1's don't do that and when a Chrome Browser update is available it goes thru just peachy.

    The error is this on one single 8.1 system. Update check failed to start (error code 3: 0x80040154). Even after installing the newest just released 105 afresh. :(

    So since i had to uninstall the last version i saved bookmarks and reinstalled it and am also trying JShelter along with uBlock and LocalCDN.

    Chrome Stable Updates is sure keeping me busy either remaking Incremental Backups or Full again. Which isn't no problem since i am always customizing 8.1 and find missed system or other folder file icons i change to have 8.1 appear more advanced or dressy along with adding a program or two as well. Best part of Imaging 8.1 is that i get to reclean the $MFT and such then remake a new Custom Refresh Wim image which serves as a double failsafe backup in case of troubles. The ONLY windows O/S which offers such a great reliable backup feature! And have had zero fails, not a one in years.
     
    Last edited: Sep 2, 2022
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    Last edited: Sep 3, 2022
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Well, my newest conclusion why so many companies get hacked is because many tools, think of MFA and EDR, are simply not good enough to block attacks, just look at the latest attack on Twilio where MFA was bypassed by a phishing attack, and not even a sophisticated one like proxy based MITM.

    And make sure to read about how easy it is to bypass certain EDR's, see link. Just some general info, EDR is what they use in most big companies in case AV's fail to block malware, then behavior blockers should still be able to spot malicious behavior on endpoints. Think of Microsoft Defender ATP and CrowdStrike Falcon.

    https://www.wilderssecurity.com/thr...-malware-defense-thats-easy-to-bypass.447186/
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Then it sounds a bit like crap to me, a smart AV would never thow up so many false positives.
     
  7. tipo

    tipo Registered Member

    Joined:
    Dec 29, 2008
    Posts:
    440
    Location:
    romania
    Formatted all and installed Zorin OS as main and only OS. Updates turned on and set to daily checking.
    Firewall turned on and set to "deny" for inbound connections.
    Google chrome browser with enhanced protection turned on, forced https everywhere turned on, avira extension, mbam extension, cyberghost extension, ubo extension, lastpass extension.
    Google account syncronized with Zorin's apps- mail, calendar, to do's.
    DNS changend to Google's DNS (8.8.8.8, 8.8.4.4)
    Backup when needed on external HDD.
    Everything clean, beautiful, secure and lightining fast!
     
  8. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    It's your call, when Chinese backdoored security softwares actually "bombs".
     
  9. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Agree!!!
    ~~~~~~~~~~~~~~~~~~~~~
    My real-time security:
    EXE Radar Pro (Italy)
    SpyShelter Premium (HIPS, anti-Keylogger) (Poland)
    OSArmor (Behavior Blocker) (Italy)
    K7 Antivirus Premium (includes a firewall) (India)

    I'm still running Win7 so SpyShelter & OSArmor are set at their highest security levels.
     
    Last edited: Sep 5, 2022
  10. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Mine's 'nilla US antivirus--Microsoft though my helper software is mostly from the European area. :thumb:

    Although maybe my machine is "armored" seeing as Micro recently scored a contract with the US Army for combat goggles. Maybe, maybe not.

    Don't forsake us, Microsoft.
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    Hi,:)
    Why use all those extensions in a Linux OS?
     
  12. tipo

    tipo Registered Member

    Joined:
    Dec 29, 2008
    Posts:
    440
    Location:
    romania
    They're synced by chrome through gmail account. Those were the extensions used in chrome when I used windows. It doesn't bother me at all, they're working all together as a team. Plus some safety measures, even on linux, don't think will do any harm. At the end of the day I must admit it's still the chrome browser that I am using.
     
  13. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
  14. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Next DNS DOH
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Support for HTTPS records in DNS - DNS-over-HTTPS only
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • UBO - Hard Mode
    • Don't add custom search engines
    • JShelter
     
  15. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Samsung Laptop
    Windows 10

    Sphinx Firewall Plus
    AppGuard Solo
    OSArmor
    Spyshelter Silent
    DeepFreeze
    Instant Recovery
    Mullvad VPN
    AdGuard

    Not sure if OSArmor is really needed but better to have two bouncers at the door then one.
    I'll see how it goes.
     
    Last edited: Sep 15, 2022
  16. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    F Secure Safe
    Simple Windows Hardening
     
  17. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    Microsoft Defender with ASR rules
    µBO
     
  18. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --no-pings --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown,EncryptedClientHello"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Next DNS DOH *****
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Support for HTTPS records in DNS - DNS-over-HTTPS only
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • UBO - Hard Mode
    • AdGuard MV3 (enabled when necessary)
    • Don't add custom search engines
    • JShelter
    Mozilla Firefox - Arkenfox.user.js

    • Tracking protection: Strict (enables Total Cookie Protection)
    • HTTPS-only-mode enabled
    • Clearing browsing data on exit
    • AutoPlay for audio and video disabled
    • DDG Search Engine
    • Hardware acceleration enabled
    • Quad 9 DNS (DOH)
    Extensions:
    • UBO - Hard Mode
    ***** = I changed the lists used in Next DNS to maximize blocking/tracking performance in anticipation of MV3.
    I want to use as few rules as possible in AdGuard MV3,to have the ability to also use other MV3 extensions that will compete with AdGuard MV3.
    I only included a custom Italian language list (minified) because this language is not available in the default lists.

    My MV3 adblocker feature extension right now is AdGuard,but I may change my choice if the progress of UBO Lite is to my liking.

     
    Last edited: Sep 22, 2022
  19. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --no-pings --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown,EncryptedClientHello"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Next DNS DOH - (oisd + Easy Privacy)
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Support for HTTPS records in DNS - DNS-over-HTTPS only
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • UBO - Hard Mode
    • JShelter
    • Don't add custom search engines
    • AdGuard MV3 (Off/On)
    Restored everything to move MV3 to the year 2024.

    Mozilla Firefox - Arkenfox.user.js

    • Tracking protection: Strict (enables Total Cookie Protection)
    • HTTPS-only-mode enabled
    • Clearing browsing data on exit
    • AutoPlay for audio and video disabled
    • DDG Search Engine
    • Hardware acceleration enabled
    • Next DNS DOH (oisd + Easy Privacy)
    Extensions:
    • UBO - Hard Mode
     
    Last edited: Sep 30, 2022
  20. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,440
    Location:
    Slovakia
    I had no idea, this could be enabled, huge thanks. :thumb:

    I need to check out https://github.com/dreammjow/ChromiumHardening/blob/main/flags/chrome-command-line.md

    Enabled? I myself do not like QUIC, it is made by Google, it uses faster, but less secure UDP instead of TCP. I keep QUIC enabled for Brave though, since I use it for Youtube/Google.
     
  21. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
  22. gery

    gery Registered Member

    Joined:
    Mar 8, 2008
    Posts:
    2,175
    Nortonware :sick::(:):)
     
  23. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
    Current Setup:

    Win11 21H2 (+Core Isolation Off)
    BitLocker On
    DefenderUI (Recommended Profile)
    VoodooShield CyberLock
    AdGuard for Windows (DNS-over-QUIC) +ETags +Protect from DPI
    Glasswire Elite
    Macrium Reflect
    Process Lasso
    Kerish Doctor (+Apps Live Optimization Off +PC Protection Off)
    KeePass 2.52
    + 2nd opinion scanner Malwarebytes/NPE
    + some tweaking/hardening Windows (Optimizer 14.0/Privacy.Sexy/WindowsSpyBlocker/RazerCortex system-booster) & Firefox (standard +privacy.resistFingerprinting & Addons => AdguardAssistant, Flagfox, DarkReader)
     
    Last edited: Oct 6, 2022
  24. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Not much changes on my system.

    OS: Windows 11 21H2
    Backup: Macrium Reflect
    Updates: SUMo
    Anti-Malware: Eset Internet Security
    Content blocker: uBlock Origin
    On-demand scanners: HitmanPro, Norton Power Eraser
     
  25. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    Windows 11 Pro 22H2
    MS Defender
    Edge with µBO Lite
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.