Basic Security Allego's Laptop Security Config 2025

Last updated
Apr 29, 2025
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
BitLocker Device Encryption for Windows
Log-in security
    • Basic account password (insecure)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Access Control
Notify me only when programs try to make changes to my computer
Smart App Control
Off
Network firewall
Enabled
About WiFi router
Provided by XFinity
Real-time security
Microsoft Defender
VS CyberLock
Firewall security
Microsoft Defender Firewall with Advanced Security
About custom security
DefenderUI with Aggressive Profile
CyberLock Always On mode Aggressive
Periodic malware scanners
None
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
Microsoft Edge
Secure DNS
Cloudflare Gateway
Desktop VPN
ProtonVPN
Password manager
ProtonPass
Maintenance tools
Windows Built-in tools
File and Photo backup
Flash Drive
Subscriptions
    • Google One AI Premium 2TB
System recovery
Using WIndows Create a recovery drive into my flash drive
Risk factors
    • Browsing to popular websites
    • Working from home
    • Buying from online stores, entering banks card details
    • Downloading software and files from reputable sites
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Coding and development
Computer specs
Acer Predator
Intel i7-10750H
NVIDIA RTX 2060
16GB
SSD 512GB
What I'm looking for?

Looking for minimum feedback.

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
I posted my first security config in 2019. I'm unable to edit/update it because it was already in archived due for not updating it for 5 years lol so I need to make a new one. Any suggestions are welcome. Thank you!
 

Kongo

Level 37
Verified
Top Poster
Well-known
Feb 25, 2017
2,639
Nice config! Tho you don't need to enable LOLBins + recommended as H_c recommended is just a smaller collection of all the LOLBins.
 
  • Like
Reactions: Nevi and Allego

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
Nice config! Tho you don't need to enable LOLBins + recommended as H_c recommended is just a smaller collection of all the LOLBins.
Okay thanks for letting me know. Though I did clicked both so far no problems. Anyway, I don't use MS Office but I use LibreOffice. Do I need to "add rule" all of its .exe files or just leave it?
 
  • Like
Reactions: Nevi

Kongo

Level 37
Verified
Top Poster
Well-known
Feb 25, 2017
2,639
Okay thanks for letting me know. Though I did clicked both so far no problems. Anyway, I don't use MS Office but I use LibreOffice. Do I need to "add rule" all of its .exe files or just leave it?
Simply click on "add LOLBins" and you are good to go. The rest like Adobe, MS Office rules are only necessary if you actually use the software
 

harlan4096

Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
9,082
I would:

* Set UAC to Always Notify.
* Periodic malware scanners: add any 3rd party second Opinion Scanner would be welcome.
* System recovery: a full image system backup solution would be welcome also here.

Thanks for sharing :)
 

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
I would:

* Set UAC to Always Notify.
* Periodic malware scanners: add any 3rd party second Opinion Scanner would be welcome.
* System recovery: a full image system backup solution would be welcome also here.

Thanks for sharing :)
I will just leave the UAC to its default and won't add a second opinion scanner because I won't add anymore apps in this system. Just the browser, real-time security, password manager, vpn, firewall hardening tool, o&o shutup, and Libre Office. If my curiosity kicks in, I'll just fire up the Windows Sandbox or Hyper-V and visit the website there. I did make a system recovery though using the Windows create recovery drive feature into my flash drive (y)
 

Kongo

Level 37
Verified
Top Poster
Well-known
Feb 25, 2017
2,639
I will just leave the UAC to its default and won't add a second opinion scanner because I won't add anymore apps in this system. Just the browser, real-time security, password manager, vpn, firewall hardening tool, o&o shutup, and Libre Office. If my curiosity kicks in, I'll just fire up the Windows Sandbox or Hyper-V and visit the website there. I did make a system recovery though using the Windows create recovery drive feature into my flash drive (y)
May I ask how you managed to get Crowdstrike? And how is it running on your system?
 

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
May I ask how you managed to get Crowdstrike? And how is it running on your system?
I got it through Amazon for $39 per license. It feels light in the system. Even though I turned all the settings and put the protection level to Aggressive/Moderate. It reminds of Panda Cloud when I used it years ago.
 

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
Some small changes
Changed Adware & PUP Prevention Level to Aggressive
Changed USB Policy for Mass Storage from read, write, and execute to read and write.
Used AppLocker to block .exe, msi, and script files in Downloads folder from executing
 

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
Okay so after some testing, I changed all the prevention levels from moderate to aggressive and I didn't feel any performance impact. So it's all good (y)
This probably the last time I'll mess with the settings until they introduce new features or until I discover some again 'cause I'm still exploring and learning about their console 😅
 
  • Like
Reactions: oldschool and Kongo

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
NextDNS subscription was up and went to ControlD. Almost the same speed at least in my area. So far so good
 
  • Like
Reactions: oldschool

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
Done dealing with False Positives. Changed my DNS to Cloudflare Gateway.
 

Allego

Level 3
Thread author
Verified
Well-known
Jan 25, 2016
127
My Crowdstrike Falcon Go subscription almost expire and won't renew since they started now to require business email to buy from Amazon. My plan right now is to limit the use of 3rd party apps as possible and use the built-in features of Windows 11 Pro.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top