Advanced Plus Security Brambedkar59's Security Config 2024

Last updated
Nov 5, 2024
How it's used?
For home and private use
Operating system
Windows 11
Other operating system
2 older laptops running Win 10 (one with F-secure and other Kaspersky Free)
On-device encryption
N/A
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
    • Basic account password (insecure)
Security updates
Check for updates and Notify
Update channels
Allow stable updates only
User Access Control
Notify me only when programs try to make changes to my computer
Smart App Control
Off
Network firewall
Enabled
Real-time security
Kaspersky Free
Malwarebytes WFC
Firewall security
Other - Internet Security (3rd-party)
About custom security
Idle scan disabled
Periodic malware scanners
Norton Power Eraser
EEK
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
Common extension/Search in all browsers: Bitwarden, Bing Search
Edge (Default): uBlock Origin (MV2), Shazam (enabled only on usage), Bypass Paywalls Clean ( (enabled only on usage))
Firefox (Secondary): uBlock Origin
Secure DNS
NextDNS
Desktop VPN
AVG Secure VPN
Password manager
Bitwarden
Maintenance tools
Biweekly run: Windows Built-in, CCleaner, WiseCare 365 (Rarely used), Driver Store Explorer [RAPR] (for deleting old drivers not needed)
For finding program updates: UCheck & RuckZuck
HiBit Uninstaller
File and Photo backup
Google Drive, OneDrive
Subscriptions
    • None
System recovery
Hasleo Backup Suite
Risk factors
    • Browsing to popular websites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Sharing and receiving files and torrents
    • Gaming
    • Gaming with third-party mods
    • Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
11400H (UV via ThrottleStop), 3050Ti (UV via G-Helper), 16 GB, 0.5TB + 1 TB NVMe, 1 TB & 4 TB HDD (for image backup and downloads)
Notable changes
Kaspersky Free to AVG IS
AVG IS to Kaspersky Free
What I'm looking for?

Looking for medium feedback.

Notes by Staff Team
  1. This setup configuration may put you and your device at risk!
    We do not recommend that other members use this setup. We cannot be held responsible for problems that may occur to your device by using this security setup.

bazang

Level 9
Jul 3, 2024
430
It's a mess. MS can't be bothered to make proper documentations. Like Why Group policies have no effect on Defender service?
Because even the people at Microsoft do not know or understand how Windows GPO works. This is an accurate statement.

The people that write Microsoft documentation are not Windows internals gurus at Mark Russinovich's level. They're most just technical writers.

The vast majority of Windows internals is uncharted and undiscovered territory - changing as Microsoft changes the OS with every update.
 

bazang

Level 9
Jul 3, 2024
430
I have already disabled defender service with DControl.
There for a while, Sordum's DControl stopped working; it no longer prevented Microsoft Defender from starting/it did not block it.

So it is good to know that it is working again for at least one person.

Just so you are aware, Microsoft knows about the method that Sordum uses. So it could close that ability to block Defender whenever it decides.
 
  • Like
Reactions: brambedkar59

Vitali Ortzi

Level 28
Verified
Top Poster
Well-known
Dec 12, 2016
1,764
There for a while, Sordum's DControl stopped working; it no longer prevented Microsoft Defender from starting/it did not block it.

So it is good to know that it is working again for at least one person.

Just so you are aware, Microsoft knows about the method that Sordum uses. So it could close that ability to block Defender whenever it decides.
Disabling a few components and then a registry edit worked for me to disable defender and I just followed a guide from Microsoft fourm
 
  • Like
Reactions: brambedkar59

bazang

Level 9
Jul 3, 2024
430
Disabling a few components and then a registry edit worked for me to disable defender and I just followed a guide from Microsoft fourm
Officially and ultimately, Microsoft wants to remove any unmanaged user's ability to block Defender.

Microsoft uses the term unmanaged to mean 1) any system not connected to a Microsoft Account (a local account, for example) or 2) any system not managed by an Administrator (not a home Administrator but an enterprise or government IT administrator).

Sooner or later M$ will "patch" the various ways that users can block Defender. When I cannot say, but it has been on their bucket hit list for quite a while.

M$ is OK with the whack-a-user game.

One thing about Microsoft is that for the most part they don't care about what users can and cannot do on older builds of Windows. So if a system is not Windows 11 latest build then M$ will rarely release a patch for an older build to address what it considers to be a security gap or hole that results not from a bug or feature, but some unintended or unwanted way that Windows internals create the hole.
 
Last edited:

Vitali Ortzi

Level 28
Verified
Top Poster
Well-known
Dec 12, 2016
1,764
Officially and ultimately, Microsoft wants to remove any unmanaged user's ability to block Defender.

Microsoft uses the term unmanaged to mean 1) any system not connected to a Microsoft Account (a local account, for example) or 2) any system not managed by an Administrator (not a home Administrator but an enterprise or government IT administrator).

Sooner or later M$ will "patch" the various ways that users can block Defender. When I cannot say, but it has been on their bucket hit list for quite a while.

M$ is OK with the whack-a-user game.

One thing about Microsoft is that for the most part they don't care about what users can and cannot do on older builds of Windows. So if a system is not Windows 11 latest build then M$ will rarely release a patch for an older build to address what it considers to be a security gap or hole that results not from a bug or feature, but some unintended or unwanted way that Windows internals create the hole.
With all the low level security they have been pushing they could make it impossible for a user to do that if they wanted
Eh would definitely be a weird ride in the security by default where everyone will be adminless with low level firmware checks
Unless they pay for some administration license to unlock paid enterprise features with the cloud

Not sure if it will happen but it's always a possibility with their security by default agenda

Only good thing is that every PC will be as secure as their Xbox
 

bazang

Level 9
Jul 3, 2024
430
With all the low level security they have been pushing they could make it impossible for a user to do that if they wanted
Eh would definitely be a weird ride in the security by default where everyone will be adminless with low level firmware checks
Unless they pay for some administration license to unlock paid enterprise features with the cloud

Not sure if it will happen but it's always a possibility with their security by default agenda

Only good thing is that every PC will be as secure as their Xbox
Over the years Microsoft has slowly been wearing-down users and making a strong attempt to manage their devices for them (at least the basics such as applying security patches):

1. Forced updates
2. Forced use of a Microsoft Account
3. Forced Windows S Mode on certain devices

However, to a very large extent, Microsoft wants no parts of home users and all the stuff that they bring.

The entire "users want to use stuff and they should be able to do what they want" is dinosaur thinking. That model has never worked and is the cause of everything that you read about in the daily cybersecurity news.

Do not blame Microsoft or any other company for terrible user security. Blame the users because they are 90% of the cause of device insecurity. Microsoft and OEMs could make extremely secure devices for consumers, but those consumers will not let them. The consumers want what they want when they want it. Well that is just like catering to a 4 year old child that throws temper tantrums and giving them what they want every single time because that is what makes the child stop carrying on like the little obnoxious thug that it is.

I do not think humanity is smart enough to be secure (or prevent catastrophic climate change or fix any other major problems such as the coming world war). Too many soft people. Too many people that want what they want when they want it.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top