What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    W.10 Home x64 22H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Cloudflare DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled

    MS Edge --disable-webgl --no-pings --enable-features="IsolateSandboxedIframes,EnableCsrssLockdown,EncryptedClientHello"

    • Home page: https://start.duckduckgo.com/
    • Search engine = DDG
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Clipboard permissions - blocked
    • Next DNS DOH - OISD Full + EasyPrivacy
    • Share browsing data with other Windows features - disabled
    Policies:
    • AutomaticHttpsDefault = 2
    • DnsOverHttpsMode = secure
    • DnsOverHttpsTemplates = Next DNS
    • TLSCipherSuiteDenyList = "0x002f","0x0035","0xc013","0x009c","0xc014","0x009d"
    • HubsSidebarEnabled - false
    • CryptoWalletEnabled - false
    • SyncDisabled - true
    • AudioSandboxEnabled - true
    • NetworkServiceSandboxEnabled - true
    • RendererAppContainerEnabled - true
    • SandboxExternalProtocolBlocked - true
    • Edge3PSerpTelemetryEnabled= 0
    • ExtensionManifestV2Availability= 2
    • WebWidgetAllowed - false

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Block insecure private network requests
    • Parallel downloading
    • Enable experimental cookie features
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Enable Back/Forward Cache
    • Back-forward cache - Enabled force caching all page
    • Project Robin experiment
    • Automatic HTTPS
    • Disable opening mhtml in IE mode from web
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Enable Digital Signature for PDF
    • Microsoft Edge tracking prevention
    • Third-party Storage Partitioning
    • New PDF Viewer
    • Origin-keyed Agent Clusters by default
    • Origin-keyed Processes by default
    • TLS 1.3 hybridized Kyber support
    • Enable Kyber768 + NIST-P384 TLS Kyber Confidentiality
    Disabled:

    • FedCmWithoutThirdPartyCookies
    • Show feature and workflow recommendations
    • Enable system notifications
    • Combine sync consent and sign in
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Enable Drop's custom notification
    Extensions:

    Edge Store:

    • UBO - Hard Mode with TLD's
    • Video DownloadHelper
    Chrome Web Store:
    • SwiftDial
    • Stream Recorder - download HLS as MP4
    • Don't add custom search engines
     
    Last edited: Jan 23, 2024
  2. pegas

    pegas Registered Member

    Joined:
    May 22, 2008
    Posts:
    2,972
    @Sampei Nihira
    Absolutely amazed by every one of your detailed descriptions. :thumb:
     
  3. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    410
    Location:
    Finland
    Anyone knows good HTML5 video autoplay blocker for chrome? Im currently using McAfee Web Boost for chrome. Everytime when Chrome gets updated, i have to re-install MWB. And it is not maintained by McAfee any more, recent update was something like 2 years ago.
    Just want to stop those stupid autoplay videos on every website i visit. Eats bandwidth, cpu time etc...
     
  4. Brocke

    Brocke Registered Member

    Joined:
    Mar 16, 2008
    Posts:
    2,311
    Location:
    USA,IA
    Using Checkpoint's Harmony Endpoint.
     
  5. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,595
    That is available for home users?
     
  6. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    ;):)
     
  7. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    410
    Location:
    Finland
    Yeah, their own engine, which you do not see on virustotal, is awesome.
    It uses Kaspersky or Sophos for basic detection's, but when it fails it uses it own detection engine, which is absolutely powerful. I've tried to infect my system with many, many several samples.
    Well..you just can't.
     
  8. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    410
    Location:
    Finland
  9. Brocke

    Brocke Registered Member

    Joined:
    Mar 16, 2008
    Posts:
    2,311
    Location:
    USA,IA
    It is. I bought from a reseller in ebay that sells licenses. It's fully cloud managed.
     
  10. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,595
    Very nice. Did not realize you could do that with them.
     
  11. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    759
    Location:
    Earth
    OS : Windows 10 LTSC 21H2, only IPV4 (**Telemetry enabled to 0, so disabled), Edge erased and never comeback during Patch Thuesday
    Real-time : Microsoft Security + NextDNS system-wide + HitmanPro.Alert
    On-Demand : Norton Power Eraser
    Password manager : KeepassXC (mostly 2FA)
    Browser : Vivaldi (personal settings) + Ublock + KeepassXC
    Vpn Provider : IVPN
    Maintenance : PrivacyEraser Pro + PrivaZer Pro + Dism commands
    Router ISP : Only Modem enabled (no option to run-it in bridge mode) (DMZ enabled)
    Router : Asus with Merlin firmware (Only IPV4 and personal tweaks

    **Only Windows Entreprise version can really disabled telemetry, all others editions NOT (or you'll have to tweaks lot's of things).
     
  12. gery

    gery Registered Member

    Joined:
    Mar 8, 2008
    Posts:
    2,183
    ZoneAlarm Extreme
     
  13. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,277
    Location:
    Canada
    Windows Defender
    Configure Defender
    Windows Hybrid Hardening
    Firewall Hardening
    Quad 9
    Malwarebytes Browser Guard

    I have a lifetime license for Malwarebytes, deciding if I want to use it in this setup or not.
     
  14. kerykeion

    kerykeion Registered Member

    Joined:
    Jun 30, 2010
    Posts:
    286
    Location:
    Philippines
    Windows 11
    • Windows Firewall - Default settings
    • Standard User Account - Default settings
    • User Account Control - Default settings - Always Notify
    Security Solutions
    • Malwarebytes Premium - Real-time, Browser Guard not installed
    • Sophos ScanAndClean - On-Demand
    • SyncBackFree - On-Demand back-up
    • Bitwarden - Free tier, credential/password repository
    • Mozilla Firefox
      • Yokoffing Betterfox - FastFox and SecureFox sections of user.js
      • uBlock Origin - Yokoffing uBlock Origin base filters
    Network Security
    • AX + WPA3 (added separate AP for WPA2 older devices such as PlayStation 4, monitored)
    • Pi-hole
      • Modules - cloudflared for DNS-over-HTTPS - Quad9 DOH
      • Filters - HaGeZi Multi Pro, Threat Intelligence Feeds, Most Abused TLDs
     
  15. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    745
    Location:
    Milan, Italia
    Windows 11 23H2
    MS Defender | Block all unknown executables | ASR rules
    Smart Application Control | On
    Exploit Protection | All system settings On | Custom settings for apps
    Firefox | µBO
    | Malwarebytes Browser Guard | https://search.disroot.org/
     
  16. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    119
    Location:
    europe
    Win11 ReviOS 23.12
    Windows Defender Disabled
    NextDNS (HaGeZi - Multi NORMAL) or ExpressVPN
    BlackFog
    HitmanPro.Alert
    SysHardener (Home User)
    OOSU10 (Recommended)
    Macrium Reflect 8
    NetLimiter Firewall
    Firefox Betterfox (DarkReader, uBlockOrigin)
    Brave (DarkReader, Rabby)
    KeePass 2.56
    Process Lasso
    2nd opinion scanner NPE
    privaZer
    sync.com
     
    Last edited: Feb 8, 2024
  17. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,563
    AtlasOS (debloated/customized windows 10)
    Hard_Configurator (Recommended settings)
    • ConfigureDefender (Max setting)
    • FirewallHardening ( Recommended & LOLBins blacklist enabled)
    Google Chrome (UBlock Orgin)
    SandboxIE Classic (used to isolate multiple Chrome instances for different tasks)
    SecureFolders (All drives except system drive LOCKED)
    • Only Trusted Applications can access locked drives
    • For convenience I use voidtools' Everything (set to trusted) to access files from within my locked drives.
    • Locked Google Chrome directory
    • Downloads Folder (no-execution)
    Macrium Reflect FREE
     
    Last edited: Feb 7, 2024
  18. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    745
    Location:
    Milan, Italia
    Windows Defender | Block unknown executables | ASR Rules | Beta channel platform and engine updates
    Brave | Brave Adblock | Malwarebytes Browser Guard Beta | Brave Search
    Firefox | µBO | Malwarebytes Browser Guard | Brave Search
     
    Last edited: Feb 17, 2024
  19. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,277
    Location:
    Canada
    Microsoft Defender hardened with Configure Defender
    WindowHybridHardeningLight
    Firewall Hardening
     
  20. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,563
    AtlasOS (debloated/customized windows 10)
    WindowsHybridHardening (SWH Only)
    DEFENDERUI (Aggressive Profile, disabled Controlled Folder Access)
    Google Chrome (UBlock Orgin)
    SandboxIE Classic (used to isolate multiple Chrome instances for different tasks)
    SecureFolders (All drives except system drive LOCKED)
    • Only Trusted Applications can access locked drives
    • For convenience I use voidtools' Everything (set to trusted) to access files from within my locked drives.
    • Locked Google Chrome directory
    • Downloads Folder (no-execution)
    Macrium Reflect FREE
     
    Last edited: Feb 25, 2024
  21. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,304
    Location:
    USA
    Firewall & Anti-Virus
    Router NAT/SPI (Password Protected)
    Windows Firewall (Malwarebytes Windows Firewall Control 6.9.9.4)
    Malwarebytes Anti‑Malware Premium 5.0.17.99

    Blocking/Hardening
    AppGuard 6.7.107.1
    HitmanPro.Alert 3.8.26 Build 979
    Quad9 DNS (or Surfshark VPN Browser Extension)
    User Account Control (Always Notify)
     
  22. JoeBlack40

    JoeBlack40 Registered Member

    Joined:
    Apr 1, 2009
    Posts:
    1,584
    Location:
    Romania
    Tryin' to keep it simple....AVG IS and Comodo FW.
     
  23. gery

    gery Registered Member

    Joined:
    Mar 8, 2008
    Posts:
    2,183
    does this work?
     
  24. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    921
    Location:
    U.S. Citizen
    If AVG IS and Comodo FW:)? Working without conflicts!
    * Which one did you install first:)?
    * Also, Comodo FW link, from where:)?
    * And is a beta version of Comodo FW:)?

    Why not Sandboxie Plus:)?
    Just thinking.......
     
  25. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,563
    AME10 (Windows 10 Ameliorated)
    WindowsHybridHardening
    Google Chrome (UBlock Orgin)
    SandboxIE Classic (used to isolate multiple Chrome instances for different tasks)
    Macrium Reflect FREE
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.