Advanced Plus Security Divine_Barakah's PC Security Config

Original forum configuration · expand details
Last updated
Aug 23, 2026
Main use of this computer
For work or educational use
Operating system
Windows 11
OS version and support details
Windows 11 Enterprise IOT LTSC
On-device encryption
Cryptomator (file vaults, not full-disk encryption)
Device sign-in security
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
Evaluation mode
Network firewall
Enabled
Router and network details
ISP-provided router.
Real-time protection
MD (default settings)
NVT OSArmor Personal
Adguard for Windows
Device firewall
Microsoft Defender Firewall
Custom security settings
*OSArmor
- added my rules
Periodic malware scanners
EEK
Malware sample testing
I do not participate in malware testing
Environment for malware testing
I don't do malware testing.
Browsers and extensions
Browsers
1- Vivaldi with multiple profile
2- Waterfox

Extensions
Webroot
Secure DNS
Adguard Windows with my personal Adguard DNS
Desktop VPN
Adguard VPN
Password and passkey manager
Sticky Password
Maintenance tools
Uninstalr
Kerish Doctor
Dell Command Update Universal

Hard Disk Sentinel Pro Portable
Bleachbit
Hibit Uninstaller
File and photo backups
Koofr (Cryptomator)
Filejump (Cryptomator)
Cyberduck
Subscriptions
    • Google AI Pro (formerly Google One AI Premium)
System recovery
O&o Diskimage 21 Premium
Usage and exposure
    • Visiting familiar websites
    • Visiting unknown or untrusted websites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Online shopping and card payments
    • Logging into my bank account
    • Downloading software and files from reputable sites
Computer specs
Dell Latitude 7450
Ultra 7 155U
16 GB DDR5 Ram 6400
1TB Micron nVMe Gen4
Notable changes
The inclusion of OSArmor.
Changed main password manager
Ditched Kerish Doctor
Managing Windows updates through GP.
Feedback preference

Detailed suggestions and alternatives welcome

I diable the whole web guard of Avast during the limited periods I use; I prefer to wait until the malware land safely.
I believe https scanning deployed by vendors undermines security. It causes too many issues. I am restoring a clean system image now and I will test MD for a while. If I do not like it, I will install TM as I still have 3 years in my subscription.
 
Oh Lord forgive me for I have sinned. I installed Webroot 😅

IMG_20260704_123818.jpg
 
So according to this link, Webroot is a blessing in disguise?

Analysing the results shows that Webroot extension accounts for %96.91 of detection. Only %3.09 slipped through and allowed to run only to be detected by Webroot's cloud detection.

It is weird that this is the only testing lab that gives Webroot a favourable rating and awards it "product of the year" 😅
 
The problem I see with AV's is that they weigh several factors before issuing a deny. For example, if script file is obfuscated AND file resides in C:\Users\<YourUsername>\AppData\ AND .... then quarantine it. Whereas you can use HIDS or similar and make a hard rule to say no executables allowed in AppData period. (because you never install per user apps). Then it wouldn't matter if the AV cannot figure out the obfuscation and the other 5 conditions don't match because an AV has to be oh so careful so as to not make a false positive. You know how you use your system. A hard rule is easier to enforce. And you will be safer for it.

Also hackers make discreet actions. Their work may not follow a recognizable malware chain of attack, it may follow a TTP. Thus a hard rule also stops hands on keyboard attacks. Whereas AV's traditionally fail against live human adversaries.
 
Last edited:
The problem I see with AV's is that they weigh several factors before issuing a deny. For example, if script file is obfuscated AND file resides in C:\Users\<YourUsername>\AppData\ AND .... then quarantine it. Whereas you can use HIDS or similar and make a hard rule to say no executables allowed in AppData period. (because you never install per user apps). Then it wouldn't matter if the AV cannot figure out the obfuscation and the other 5 conditions don't match because an AV has to be oh so careful so as to not make a false positive. You know how you use your system. A hard rule is easier to enforce. And you will be safer for it.

Also hackers make discreet actions. Their work may not follow a recognizable malware chain of attack, it may follow a TTP. Thus a hard rule also stops hands on keyboard attacks. Whereas AV's traditionally do not work against live human adversaries.
I believe I will get OS Armor to bridge the gap.
 
So according to this link, Webroot is a blessing in disguise?

You might laugh about this, but I had Webroot running for a week or so and I can actually say that I was enjoying it. Performance-wise it's unbeatable. And even tho the detection rate isn't considered the best out there, the response time to missed samples is awesome. I downloaded a malware pack with relatively fresh samples. Detection rate was about 80%. After rescanning 30 minutes later, quite a few more samples were detected. I even dare to say that Webroot still has a justified place in the antivirus landscape for some cautious users out there. :censored:
 
Under my local user account, I created a folder called (App Data) in which I store the portable apps such as Hard Disk Sentinel.

Now when I tried to run HDS, OSArmor blocked it and adding HDS to exclusions did not fix the block.

The rule that blocked HDS was "Block processes located in suspicious folders"

And the parent process was explorer.exe

To correctly exclude HDS I had to create a manual rule in exclusions [%PROCESSNAME%: HD Sentinel.exe] [%SIGNER% Janis Mathe].

What this rule basically does is add a process to exclusions regardless of its path.

Now step by step I am building my rules and I am experimenting. I am installing my apps and J am monitoring how OSA reacts.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top