What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,438
    Location:
    Slovakia
    Smart App Control is controlled by MS, third party is controlled by the user. So it is just like with Defender, it is for undemanding users.
     
  2. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    W.10 Home x64 22H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Quad9 DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --no-pings --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown,EncryptedClientHello"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Next DNS DOH - (oisd + Easy Privacy)
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed
    • Clipboard permissions - blocked

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Support for HTTPS records in DNS - DNS-over-HTTPS only
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    • Microsoft Edge tracking prevention
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:
    • UBO - Hard Mode with TLD's
    • JShelter
    • Don't add custom search engines

    • ( on/off) - AdGuard MV3 - Hard Mode with TLD's + UBO Lite - only AdGuard URL Tracking Protection List

    Mozilla Firefox - Arkenfox.user.js

    • Tracking protection: Strict (enables Total Cookie Protection)
    • HTTPS-only-mode enabled
    • Clearing browsing data on exit
    • AutoPlay for audio and video disabled
    • DDG Search Engine
    • Hardware acceleration enabled
    • AdGuard DNS DOH (oisd)
    Extensions:
    • UBO - Hard Mode with TLD's
     
    Last edited: Dec 11, 2022
  3. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    For home users and small businesses, its meant to replace AppLocker and SRP which when configured incorrectly, can lock up your PC.

    This is a simple, worry free solution with pre configured rules in place - a set and forget it approach to security like NVT’s OSArmor.

    For power users though it may not be enough because there’s no path offered to exclude false positives.

    Microsoft has created a comprehensive security solution to malware and ransomware threats, which has now reached its apogee in Windows 11 22H2 with SAC.
     
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    W.10 Home x64 22H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Cloudflare DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --no-pings --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown,EncryptedClientHello"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Next DNS DOH - (oisd + Easy Privacy)
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed
    • Clipboard permissions - blocked

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Support for HTTPS records in DNS - DNS-over-HTTPS only
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    • Microsoft Edge tracking prevention
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:

    Microsoft Edge Store:

    • UBO - Hard Mode with TLD's
    Chrome Web Store:
    • JShelter
    • Don't add custom search engines
    • ( on/off) - AdGuard MV3 - Hard Mode with TLD's + UBO Lite - only AdGuard URL Tracking Protection List

    Mozilla Firefox - Arkenfox.user.js

    • Tracking protection: Strict (enables Total Cookie Protection)
    • HTTPS-only-mode enabled
    • Clearing browsing data on exit
    • AutoPlay for audio and video disabled
    • DDG Search Engine
    • Hardware acceleration enabled
    • NEXT DNS (oisd + Easy Privacy)
    Extensions:
    • UBO - Hard Mode with TLD's
     
    Last edited: Dec 26, 2022
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Good little combo there @Sampei Nihira :cool:
     
  6. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
  7. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    2,286
    Location:
    Canada
    Nord, Bitdefender Total, & MBAM, uBlock, FF default & https always

    I also have a machine: Nord, Windows defender + MBAM
     
  8. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    :thumb:
    Thank you.
    Arkenfox is stopped in November.
    I have bookmarked the link.
    As soon as I have some free time today I will check if some rules are already used by me.
    :)

    P.S.
    I entered some FastFox.js settings.
    I did not enter those proposed in Smoothfox.js.
    Many others were already entered.
    ;):)
     
    Last edited: Dec 28, 2022
  10. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,101
    Windows defender antivirus and windows firewall.
    Malwarebytes anti-malware on demand scanner.

    Thats it.
     
  11. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    OS: Windows 11 22H2
    Backup: Macrium Reflect
    Updates: SUMo
    Anti-virus: Eset Nod32 Antivirus
    On demand scanners: Emsisoft Emergency Kit, Norton Power Eraser
    Passwords: KeePass
    Other Tools: CCleaner, ShutUp10, AppBuster
     
  12. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    In Thunderbird I have enabled a custom DNS (DOH) - AdGuard Private DNS.
    I want to check how it works.
     
  13. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    What could be the benefit, running AdGuard DNS?
     
  14. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    • The first advantage is that related to the privacy/security offered by a private DNS over HTTPS:

    https://en.wikipedia.org/wiki/DNS_over_HTTPS

    • The second benefit is that offered by AdGuard's request log:

    1.jpg

    Example in the past I have blocked often,but in the browser with UBO, "googleapis.com".

    See where it says "bloccare" ( means to block in the English language) also in Thunderbird I have this possibility.
    I have to study this opportunity.;)

    P.S. With AdGuard private DNS you can write your own rules to block websites (but in the case of emails,you should get the blocking of emails in the email client that for example are sent from some domains):

    2.jpg

    P.S.1

    If I enter the rule for "googleapis" the authentication of IMAP (Gmail) is blocked.
     
    Last edited: Jan 5, 2023
  15. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    K7 Total Security, VoodooShield, Spyshelter Premium. Boring, wot? Works for me. :rolleyes:
     
  16. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
  17. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    I did a switcheroo:
    From: K7 Total Security w/Firewall (FW) that cannot be disabled by user (the reason I switched)
    To: G-Data Internet Security w/FW that CAN be disabled, or not installed, as user desires
    Ancilliary real-time: VoodooShield (whitelist/anti-exe) & Spyshelter Premium (anti-keylogger & HIPS)
     
  18. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    @bellgamin
    Any conflicts/slow down between G-Data Internet Security:)?
    VoodooShield (whitelist/anti-exe) & Spyshelter Premium (anti-keylogger & HIPS).
    And do you have a password manager with your setup :)?
    Just wondering :)?

    @moredhelfinland,
    What is your current setup :)?
    And do you like about it most:)?

    Always the best,
     
    Last edited: Jan 8, 2023
  19. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    I checked load with 9 apps running, plus 10 other processes, plus browser at work with 17 tabs open. My aging laptop's Sysgauge showed Intel i5 CPU at 4.6% usage. MemReduct showed 51% used of 8GB RAM. My computer laptop stayed zippy at that heavy load. G-data has a large footprint but it executes light & smooth.
     
  20. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    @bellgamin
    Appreciate the details and info! What about, VoodooShield (whitelist/anti-exe) & Spyshelter Premium (anti-keylogger & HIPS:)?

     
  21. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    VoodooShield (VS) plus a good AV (including a firewall component) plus regular imaging are a VERY strong security team. Spyshelter (SS) adds little if anything because its HIPS is limited to 66 default rules & has no learning capability. I will probably uninstall it when my present license expires.

    Both VS & SS are super light on resources.
     
  22. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen

    @bellgamin

    Thank you!! Thumb up with details...
     
  23. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    W.10 Home x64 22H2
    Local Account - Standard user - Limited permissions
    UAC maximum - Always notify
    Cloudflare DNS
    Onedrive,Cortana,Advertising ID,Web Search - disabled
    Usage of location data for Cortana disabled
    Telemetry OFF
    Removed some Windows optional features.

    Microsoft Defender Firewall hardened with H_C.
    Microsoft Defender hardened with Configure Defender (Customized level) - Cloud Block Level

    • Ransomware protection - disabled
    • No run in a sandbox
    • Core Isolation: Memory integrity - disabled
    • Some softwares hardened with maximum AE protection
    • All Windows Exploit Protection options - enabled
    MS Edge --no-pings --time-zone-for-testing --enable-features="GpuAppContainer,IsolateSandboxedIframes,EnableCsrssLockdown,EncryptedClientHello"
    • Enabled Security Mitigations - Strict
    • Detection Protection - Strict
    • Always HTTPS
    • Next DNS DOH - (oisd + Easy Privacy)
    • Share browsing data with other Windows features - disabled
    • 4 Insecure Cipher Suites - 0x002f,0x0035,0xc013,0x009c - disabled
    • TLS_RSA_WITH_AES_256_GCM_SHA384 - enabled
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA - enabled
    • IL AppContainer - enabled
    • Audio Service -sandboxed
    • Network Service - sandboxed
    • Clipboard permissions - blocked

    Edge://flags:

    Enabled:

    • Block scripts loaded via document.write
    • Enables the BrowsingDataLifetimeManager service to run
    • Experimental QUIC protocol
    • Use DNS https alpn
    • Support for HTTPS records in DNS - DNS-over-HTTPS only
    • Enable Back/Forward Cache
    • Project Robin experiment
    • Automatic HTTPS
    • Strict-Origin-Isolation
    • Show block option in autoplay settings
    • Experimental Tracking Prevention Features
    • Block insecure private network requests
    • Enable Digital Signature for PDF
    • Partitioned cookies
    • Microsoft Edge tracking prevention
    • Experimental third-party storage partitioning - Third party cookies blocker enabled
    Disabled:
    • Show feature and workflow recommendations
    • Allow tab-to-search using Microsoft Search with Bing
    • Allow Microsoft Search with Bing for any default search engine
    • Allow preloading of pages by other applications
    • Enable First-Party Sets
    • Consider SameParty cookies to be first-party
    Extensions:

    Microsoft Edge Store:

    • UBO - Hard Mode with TLD's
    Chrome Web Store:
    • JShelter
    • Don't add custom search engines
    • ( on/off) - AdGuard MV3 - Hard Mode with TLD's + UBO Lite - only AdGuard URL Tracking Protection List
     
    Last edited: Jan 16, 2023
  24. JohnMult

    JohnMult Registered Member

    Joined:
    Mar 26, 2012
    Posts:
    133
    Location:
    Greece
    1. Linux Lite
    2. Firewall on
    3. Firejail Firefox with uBlock Origin in Medium mode and Quad9 in Network settings. Enabled Security Mitigations like Edge and block eval through uBlock
     
  25. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    Emsisoft AM ( won a free years subscription)
    Voodoo Shield
    UBO

    All I need.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.