What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,944
    Nope. They simply keep their IT infrastructure religiously up to date.
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I'm afraid that this won't protect against zero days. You can't patch holes that you are not aware of, and here's where security tools come into play.
     
  3. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,944
    I tend to agree, but even the most sophisticated security tools are not capable of patching each and every hole that might exist in a company's IT infrastructure. There will always be some sort of a residual risk level.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    No correct, but they don't try to patch anything, they are simply monitoring for suspicious behavior which eventually all malware will trigger.
     
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    If not for 3rd party security tools and some of those oddly enough from freelancer's, I dare say my machines would have been an endless stream of constantly restoring clean images OR at the very least keeping Shadow Defender always ON which I refuse to do. If my front line, mid zones can't fully prevent, the last line of defense always does, luckily. A lot more sharp pencils out there and many of them never receive as much credit for their assistance than commercial one's do.
     
  6. pvsurfer

    pvsurfer Registered Member

    Joined:
    Sep 1, 2004
    Posts:
    1,618
    Location:
    USA
    I just replaced WiseVector Stop-X (way too many FPs) with Kaspersky Free.
     
  7. Jo Ann

    Jo Ann Registered Member

    Joined:
    Jan 6, 2007
    Posts:
    619
    I am also annoyed with too many WVSX's real-time behavior FPs. The problem is compounded due to inoperative reporting within the real-time alerts as well as receiving the very same FP alert no matter how many time I exclude the FP! :mad:
     
  8. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Worth posting in WiseVector thread?
     
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Quad9 DOH
    • Share browsing data with other Windows features - disabled
    • 4 Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL Appcontainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • GPU rasterization
    • Zero-copy rasterizer
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    Extensions:
    • (MS Store) - Decentraleyes
    • (Chrome Store) - UBO - Hard Mode
    • (Chrome Store) - Don't add custom search engines
    • (Chrome Store) - JShelter
     
  10. The Seeker

    The Seeker Registered Member

    Joined:
    Oct 24, 2005
    Posts:
    1,339
    Location:
    Adelaide
    Unless it is still causing you issues, I'd recommend enabling this.
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Unfortunately, it causes me problems.
     
  12. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    Bitdefender Free. All good so far.
    Brave browser | Brave Adblock | Emsisoft Browser Security
    Startpage
    Brave:Flags -
    Code:
    Enable CNAME uncloaking
    Enable domain blocking
    Enable debouncing
    Enable extension network blocking
    Reduce language identifiability
    Enable ephemeral storage
    Smooth scrolling
    Block scripts via document,write
    Block insecure private network requests
    Strict Origin Isolation
    Reduce user-agent request header
    Partitioned cookies
    Isolated sandboxed iframes
    
     
  13. SeriousHoax

    SeriousHoax Registered Member

    Joined:
    Mar 27, 2019
    Posts:
    101
    Location:
    Bangladesh
    You can avoid using YogaDNS in Windows 11 for using NextDNS or any other DNS.
    Try this after running CMD with admin rights or create a .BAT file.
    netsh dns add encryption server=x.x.x.x dohtemplate=https://dns.nextdns.io/xxxxxx autoupgrade=yes udpfallback=no
    You can also add your device name in the end if you wish to identify your device in NextDNS logs.
    netsh dns add encryption server=x.x.x.x dohtemplate=https://dns.nextdns.io/xxxxx/Nightwalker-PC autoupgrade=yes udpfallback=no
    After this, edit DNS in the Network and Internet section with your NextDNS IP and choose Encrypted only.
    I've been using like this since Windows 11 came out in the dev builds with no issues.
    Similarly for Adguard DNS:
    netsh dns add encryption server=94.140.14.14 dohtemplate=https://dns.adguard.com/dns-query autoupgrade=yes udpfallback=no
     
  14. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    I see, I will try it, thanks for the advice.
     
  15. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    I can't really be ***** to look through 1680 pages so can someone tell me what program should i use to allow a certain program to only be able to read its own location? For example right now im using teamviewer and it constantly cries im a commercial user even tho im not (but i got stuff like vs code on the my pc so it thinks i am) and even tho i can circumvent it, that causes some headaches as well so i'd like the problem to be solved once and for all and i need a program to tell teamviewer that it can only read its own directory and not much more. There was smth liket hat pumpernickel or bouncer? But now its gone and even if i would find it it's prob very outdated so i thought this is a good place to ask with all of u knowledgeable and paranoid security folks, what program should i use?
     
  16. noway

    noway Registered Member

    Joined:
    Apr 24, 2005
    Posts:
    461
    OS: Windows 10
    DNS: Quad9
    Modem-Router: CODA-4582-U

    Software: Symantec Endpoint Protection 14.3 (firewall not installed)
    Windows Defender Firewall
    Malwarebytes Windows Firewall Control
    Macrium Reflect 7.3
    Firefox with uBlock Origin for ad blocking
    VirusTotal also used for checking any new software before installing

    This is my favorite config of all time. However I still miss AtGuard 3.22 and Kerio 2.1.5 firewalls a bit even though I haven't used them for years.
     
    Last edited: Jun 24, 2022
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I think it was indeed called Pumpernickel or Bouncer. Isn't is possible to run TeamViewer as an AppContainer app, since those tools can only access their own folder?
     
  18. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    OS: Windows 10 21H2

    Backup: Macrium Reflect Home and IceDrive
    Updates: SUMo, HP Image Assistant, Windows and Office updates
    Anti-malware: Eset Internet Security
    Content blocker: uBlock Origin

    OD scanners: HitmanPro, Norton Power Eraser
    Passwords: Keepass
    Encryption: VeraCrypt
    Privacy: Mullvad, CCleaner, ShutUp10
     
  19. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    How would i do that tho? All I found was some c++ tutorials on how to do it which is outside my area of knowledge (i don't like c and c++)

    Is there a ready program out there that does this?
     
  20. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Quad9 DOH
    • Share browsing data with other Windows features - disabled
    • 4 Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • (MS Store) - Decentraleyes
    • (Chrome Store) - UBO - Hard Mode
    • (Chrome Store) - Don't add custom search engines
    • (Chrome Store) - JShelter
     
    Last edited: Jul 2, 2022
  21. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    What I meant is that perhaps you could search for the UWP version of TeamViewer, see first link. And seems like there is also a portable version, scroll down on the second link.

    https://www.teamviewer.com/en/download/windows-app/
    https://www.teamviewer.com/en/download/windows/
     
  22. vonvon

    vonvon Registered Member

    Joined:
    Apr 30, 2006
    Posts:
    59
    Location:
    European Union - France
    3 computers right now : (all win 11 - built 22621 - 105)

    Main desktop : osarmor - f-secure safe - Nextdns - ublock origin
    17'' laptop : osarmor - f-secure safe - Nextdns - ublock origin
    15'' laptop : osamor - k7 internet security - Nextdns - ublock origin

    easus todo backup home - Kerish doctor resident - f-secure freedome if needed

    Light and enought for me.
     
  23. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    Windows 8.1 Pro.
    Comodo firewall (Cruelsister settings) and Hard Configurator with recommended settings for Win 8.1
    Brave browser with only a couple of adjusted settings and Ublock Origin.
    Macrium Reflect Home, and current backup saved to external HDD.
     
  24. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Stellar settings @Chuck57 and that CFW with Hard Config is solid! Happy 8.1 Safe Computing! :)
     
  25. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    W.10 Home x64 21H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Quad9 DOH
    • Share browsing data with other Windows features - disabled
    • 4 Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • (MS Store) - Decentraleyes
    • (Chrome Store) - UBO - Hard Mode
    • (Chrome Store) - Don't add custom search engines
    • (Chrome Store) - JShelter

     
    Last edited: Jul 23, 2022
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.