What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    agree buddy:thumb:
     
  2. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Lite HIPS? Was it ever without weakening security?
     
  3. natsecurity

    natsecurity Registered Member

    Joined:
    Dec 19, 2012
    Posts:
    31
    Location:
    australia
    Please rate my setup since I had to uninstall G-DATA IS 2013 because it was causing me grief like hanging my pc after login.

    sandboxie
    firefox - noscript, lastpass, WOT
    malwarebytes antimalware
    zemana antilogger paid
    MSE and windows firewall (installed after uninstalling G-DATA)
    just installed Truseer Rapport

    so there you have it. I'd probably seek to use something other than windows firewall or MSE, but these seem stable.
     
  4. Easter, I know your preference of hooking every entry of the System Service Dispatch Table at least twice, but with kernel protection of x64 and third Integrity Level trust zone (LOW and UNTRUSTED or Protected Mode and AppContainor) the HIPS function has changed.

    Comodo FW can be adapted to your needs
    1. Add a general security layer for all programs by adopting the default D+ rule (for every program) to allow all except ASK for
    a. Loading a driver
    c. Memory Access
    d. Interproces Memory Access

    2. Add a restriced layer to risky (internet facing programs) programs
    a. Sandbox all internet facing software as partially limited
    b. Add a rule for (drive letters of) your USB drives to run every program as partially limited

    3. Completely sandbox all other binaries
    a) Clear the list of trusted vendors of the Behavioral Blocker
    b) Apply the virtual kiosk regsitry tweak

    ADD UAC and EMET 4.0 Beta to reduce risk of Exploits. Browse with Chrome, use alternative Media Player (e.g. Classic Media Player) and alternative PDF reader (e.g. Evince) to reduce attractiveness/economy of scale for malware writers.

    This is a lite setup with three trust zones to cover all:
    - trust zone = installed programs: better than UAC protection for ALL (memory violations + loading driver)
    - trust zone = Threat gates: run internet facing software as partially limited with additional EMET 4 protection
    - trust zone = Unknown: fully sandbox all other binaries

    Really is strong, not intrusive and light (in combo with kernel protection, UAC and policy sandbox of Chrome)

    Regards Kees (old nick name Kees195:cool:
     
    Last edited by a moderator: May 29, 2013
  5. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Last edited: May 29, 2013
  6. Arcanez

    Arcanez Registered Member

    Joined:
    Oct 5, 2011
    Posts:
    417
    Location:
    Event Horizon
    IE10
    Appguard
    Deepfreeze
    EMET
    OpenDNS
    DriveSnapshot
    GPO Tweaks
    UAC
    VirusTotal Uploader

    best Setup I've ever used.
     
  7. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I love scotty :thumb:
     
  8. Creer

    Creer Registered Member

    Joined:
    Jun 29, 2008
    Posts:
    1,345
    Linksys Router with Norton DNS

    Realtime:
    Look 'n' Stop Firewall 2.07,
    DefenseWall HIPS 3.21,
    EMET

    Encryption:
    Jetico BestCrypt Volume Encryption
    TrueCrypt

    On-demand (scan once per month):
    HitmanPro
    MBAM

    Backup:
    ShadowProtect Desktop (cold imaging to external drive)
    Back to SyncBack Free for sensitive/critical data backup


    Additionally...
    Chrome (built in DNT enabled, no-referrer, geoloc disabled, js disabled globally, no 3rd cookies, http cookies blocked with exceptions for specific websites, java not installed, internal sandboxed pdf reader enabled, flash player for chrome not installed only PAPI in use, browser password manager disabled, autofill feature disabled, check for server certificate revocation enabled).
     
  9. Securon

    Securon Registered Member

    Joined:
    Jan 11, 2009
    Posts:
    1,960
    Location:
    London On
    Good Evening! Just added Exploit Shield 0.9.1Beta...in concert with WSA Security Plus...Ikarus...and Outpost Firewall Pro. Sincerely...Securon
     
  10. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Added WinPatrol :thumb:
     
  11. bberkey1

    bberkey1 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    244
    Location:
    United States
    I've been using it for a few months now and I've liked it's detection, low resources and it even notifies when you uninstall a program. I have yet to upgrade to add the registry monitor, but I may just do so in the near future.

    Have you noticed any negative compatibility with any other programs in your set up? I was looking to play with EXEwatch, being similar in nature and wasn't sure if having two similar programs operating would cause some errors or not?
     
  12. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    MRF71 good job man:thumb:
    are you running the plus version? or free version?
    winpatrol plus is a mini hips:thumb:
     
  13. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I run it at default settings and everything is smooth sailing :thumb:
     
  14. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Plus jmonge
     
  15. Pain of Salvation

    Pain of Salvation Registered Member

    Joined:
    Apr 21, 2005
    Posts:
    399
  16. guest

    guest Guest

    Meh, back to using an AV. I hate it when I have to dumbing down the HIPS protection so I won't get too many popups. Guess I prefer to have bars on my windows. :p

    To those who are using WinPatrol Plus, does Scotty respond quick enough to system changes? *puppy*
     
  17. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    it is slow not like hips that are at the moment the changes want to happen with winpatrol plus is alitle too late as it wants to pull the changes out the system when real time hips will push it out before it enters the system;)
     
  18. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  19. guest

    guest Guest

    Still interesting though, at least you can rollback the changes if I'm not mistaken.
     
  20. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    yes it does:thumb: but just becarefull with the fake antivirus as they defeat winpatrol plus very easilly:) i tested it with some fake antivirus and it fails to pull the changes back:) also i try a rootkit and winpatrol also fail to rollback the system back
     
  21. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I agree it needs to speed up the alerts
     
  22. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  23. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Awesome, but what is WinPcap?
     
  24. Securon

    Securon Registered Member

    Joined:
    Jan 11, 2009
    Posts:
    1,960
    Location:
    London On
    Good Evening! Re-installed Eset S.S.6...WSA Security Plus...and AppGuard...Light...Stealth...Lethal...Sincerely...Securon
     
  25. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    trying tinywall firewall sincerely jmonge
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.