Advanced Plus Security Divine_Barakah's PC Security Config

Original forum configuration · expand details
Last updated
Aug 23, 2026
Main use of this computer
For work or educational use
Operating system
Windows 11
OS version and support details
Windows 11 Enterprise IOT LTSC
On-device encryption
Cryptomator (file vaults, not full-disk encryption)
Device sign-in security
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
Evaluation mode
Network firewall
Enabled
Router and network details
ISP-provided router.
Real-time protection
MD (default settings)
NVT OSArmor Personal
Adguard for Windows
Device firewall
Microsoft Defender Firewall
Custom security settings
*OSArmor
- added my rules
Periodic malware scanners
EEK
Malware sample testing
I do not participate in malware testing
Environment for malware testing
I don't do malware testing.
Browsers and extensions
Browsers
1- Vivaldi with multiple profile
2- Waterfox

Extensions
Webroot
Secure DNS
Adguard Windows with my personal Adguard DNS
Desktop VPN
Adguard VPN
Password and passkey manager
Sticky Password
Maintenance tools
Uninstalr
Kerish Doctor
Dell Command Update Universal

Hard Disk Sentinel Pro Portable
Bleachbit
Hibit Uninstaller
File and photo backups
Koofr (Cryptomator)
Filejump (Cryptomator)
Cyberduck
Subscriptions
    • Google AI Pro (formerly Google One AI Premium)
System recovery
O&o Diskimage 21 Premium
Usage and exposure
    • Visiting familiar websites
    • Visiting unknown or untrusted websites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Online shopping and card payments
    • Logging into my bank account
    • Downloading software and files from reputable sites
Computer specs
Dell Latitude 7450
Ultra 7 155U
16 GB DDR5 Ram 6400
1TB Micron nVMe Gen4
Notable changes
The inclusion of OSArmor.
Changed main password manager
Ditched Kerish Doctor
Managing Windows updates through GP.
Feedback preference

Detailed suggestions and alternatives welcome

Under my local user account, I created a folder called (App Data) in which I store the portable apps such as Hard Disk Sentinel.

Now when I tried to run HDS, OSArmor blocked it and adding HDS to exclusions did not fix the block.

The rule that blocked HDS was "Block processes located in suspicious folders"

And the parent process was explorer.exe

To correctly exclude HDS I had to create a manual rule in exclusions [%PROCESSNAME%: HD Sentinel.exe] [%SIGNER% Janis Mathe].

What this rule basically does is add a process to exclusions regardless of its path.

Now step by step I am building my rules and I am experimenting. I am installing my apps and J am monitoring how OSA reacts.
Now I realised that I should not use to rule to exclude an app if it is not digitally signed. The absence of %SIGNER% creates a vulnerability.

Instead, one should use the %PROCESS% followed by the app storage path to add it to exclusions.

I am using ABDownloadManager which is an open source download manager that is not digitally signed. It was blockes by OSA and I added it to exclusions using the %PROCESS% rule.
 
I am using Peazip as the main archiver. Whenever I unzip a file using Peazip, it triggers a block in OSA.

When you extract and archive using Peazip, it creates a temporary working directory inside your user profile. Once it finishes processing, PeaZip attempts to quietly clean up after itself.

To wipe out those temporary folders, PeaZip spawns a native Windows command string:

cmd /c rmdir "C:\Users\USER\AppData\Local\Temp\peazip-tmp\.pztmp\" /s /q
 
Ditched Floorp and Zen Browser and installed Waterfox. Neither Floorp nor Zen offer mobile apps, but Waterfox does.

In my opinion, Waterfox is the most stable, highly-maintained Firefox fork out there.
 
Updated list of installed Applications:

***Security***
- Webroot Internet Security Plus
- OSA Personal
- Cryptomator
- Adguard VPN

***Productivity***
- Microsoft Office 2024 Standard LAST
- Betterbird
- Onlyoffice
- Swifdoo PDF
- Wondershare PDFelement 11
- ABDownloadManager
- Xyplorer
- Cyberduck
- Koofr

***Browsers***
- Vivaldi
- Helium
- Waterfox

***System Maintenance***
- Bleachbit
- Hard Disk Sentinel Pro Portable
- Smarty Uninstaller
- Patch My PC
- AOMEI Backupper

***Password Managers***
- Password Boss
- Enpass Pro

***Other Tools***
- Musicbee
- Peazip

***Extensions***
- Webroot Web Shield
- Password Boss
 
Been watching the WRData folder closely and its size grew to 700 MB. I opened the WRlog.log and found the culprit. The PDFEngine.exe process (part of Swifdoo PDF) was monitored by Webroot. I changed the process status from monitored to allowed and everything is running as intended now.
 
Removed the extension of Password Boss after reading the following link.

Now I manually copy and paste my credentials from within Enpass Desktop app

 
OSA can provide different degrees of security based on your settings. Go through the setting and trusted vendors and decide on your balance of usability and security.
Yes I indeed did enable many rules. Over the last day I have been experimenting with rules and I believe I managed to achieve the perfect balance between securrity and usability.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top