Advanced Plus Security Divine_Barakah's Second Laptop Security Config

Last updated
Jul 10, 2026
Main use of this computer
For work or educational use
Operating system
Windows 11
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
On
Network firewall
Enabled
Router and network details
ISP-provided router.
Real-time protection
Panda Dome Essential
Device firewall
Other - Internet Security (3rd-party)
Custom security settings
- Enabled Application Control
- Enhanced Panda Firewall settings.
- Protected Panda settings with a password
Periodic malware scanners
EEK
Malware sample testing
I do not participate in malware testing
Environment for malware testing
None
Browsers and extensions
Vivaldi (no extensions)
Waterfox (no extensions)
Helium (only the pre-installed unlock)
Secure DNS
Adguard Private DNS systemwide (Win 11 DNS over Https)
Desktop VPN
Adguard VPN
Password and passkey manager
Enpass Desktop synced to my cloud using WebDav.
Maintenance tools
Smarty Uninstaller
Hard Disk Sentinel Pro Portable
Lenovo Vantage (Commercial) deployed not the store version
File and photo backups
Koofr
Filejump
Google Photos
Subscriptions
    • Google AI Pro (formerly Google One AI Premium)
System recovery
AOMEI Backupper Pro
Usage and exposure
    • Visiting familiar websites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Online shopping and card payments
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
Lenovo Thinkpad X13 Gen 3
Notable changes
Reverted to Windows 11 Pro 25H2
- blocked driver updates from Windows Update
- Deferred updates for 14 days.
Feedback preference

Detailed suggestions and alternatives welcome

Has anything changed on your end ? Eg new apps installed, new security etc ?

You can change the thread's security details to say that you're using Cosmic now you know. The very top, right corner of thread, there is a menu.
Nothing new except for Strawberry music player.. The system is very stable. I have not experienced any issues (minor or major). So satisfied.
 
Decided to do the pwn test on a Ubuntu 26 box instead. It was hardened with the same steps excluding Selinux. Preliminary results after 4 hrs - nothing happened. I had asked chatGPT for a monitoring script for this pwn test. And it knows my configuration. So the scripts does a long list of tests for various attack methods, persistence methods, kernel attacks etc. And when I ran the report and submitted it to chat, it asked for further sub reports. But ultimately says the machine is clean.
 
Last edited:
Chatgpt updated itis monitoring script to give a better summary. But no bites through the night and this morning. This method of having chat devise a monitoring script and running a report every now and then and letting chat interpret it is the way to go. There are so many ways to misread the symptoms using just syslog and journalctl. And there are many background tasks that are running that could read like symptoms of adversary tinkering. I think I've now found a good way to run these pwn tests.
 
Last edited:
Chatgpt updated itis monitoring script to give a better summary. But no bites through the night and this morning. This method of having chat devise a monitoring script and running a report every now and then and letting chat interpret it is the way to go. There are so many ways to misread the symptoms using just syslog and journalctl. And there are many background tasks that are running that could read like symptoms of adversary tinkering. I think I've now found a good way to run these pwn tests.
Still using Ubuntu?
 
Never knew that.

Snaps, however, are a different story. Sure, the snapd daemon and certain core packages have their source code publicly available. But the Snap Store (or App Center on newer versions of Ubuntu) – the server with the snap packages – is closed-source.

So a correction the daemon is open source.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top