Advanced Plus Security Ebocious's Yoga 6 New Security Config

Last updated
May 26, 2026
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
BitLocker Device Encryption for Windows
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
    • Basic account password (insecure)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Access Control
Always notify
Smart App Control
Off
Network firewall
Enabled
About WiFi router
Calix GigaSpire BLAST EXOS router
Real-time security
  • Comodo Firewall 12.3.4.8162
  • AppCheck Anti-Ransomware 3.1.45.6 (for automated backup)
  • Hardentools
  • Microsoft Defender
  • ConfigureDefender 4.1.0.0
Firewall security
Other - Internet Security (3rd-party)
About custom security
  • Cruelsister configuration with silent mode and dedicated ignored folder for portable apps
  • ConfigureDefender High protection level
Periodic malware scanners
  • Microsoft Defender
  • HitmanPro
  • HiJackThis Fork
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
  • Chrome 148.0.7778.179
  • Edge 148.0.3967.83
  • Brave 1.90.124
  • Puffin Secure Browser
  • uBlock Origin Lite (default filtering mode complete)
  • Osprey: Browser Security 2.0.0 (excluding family filters, ignore frame navigation unchecked)
Secure DNS
NextDNS
Desktop VPN
  • Proton VPN
  • VPN Unlimited (backup)
Password manager
  • Proton Pass
  • Offline TOTP with Soyes XS15 mini phone (seeds backed up to encrypted .json files, backed up with checksum and tested, not saved in Proton Pass)
Maintenance tools
SFC (I run DISM every month after Patch Tuesday)
File and Photo backup
  • iCloud
  • Google Drive
  • OneDrive
  • Proton Drive
  • External hard drives
Subscriptions
    • Apple iCloud+ 2TB
    • Google One Standard 200GB
System recovery
AOMEI Backupper
Risk factors
    • Browsing to popular websites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
  • Lenovo Yoga 6 13ALC7
  • AMD Ryzen 7 5700U
  • Integrated AMD Radeon Graphics
  • 16GB LPDDR4X
  • 512 GB PCIe NVMe M.2 SSD
Notable changes
  • Standard user account
  • Admin account for installations, owner of Bitlocker encryption key
  • Max UAC
  • Max DEP
What I'm looking for?

Looking for maximum feedback.

ebocious

Level 6
Thread author
Verified
Well-known
Forum Veteran
Oct 25, 2018
260
868
469
This apparatus was recommended by Gemini. I've been using Cruelsister's Comodo configuration for a few years, and asked for companion apps to cover potential gaps in security. NextDNS, Osprey, and uBOL block known malicious domains and exploit tactics, Defender with ConfigureDefender blocks in-memory execution and injection, Hardentools disables common script hosts, and Comodo can catch unknown binaries and scripts that manage to bypass everything else and cripple persistence with Auto-Containment.

I like Proton Pass because, even though it is a cloud-based service, I only have to key the master password once, which I can do on a dedicated iPhone with Lockdown Mode enabled. Afterward, new logins are authorized via QR codes, and a PIN to unlock. I use a Soyes XS15 mini phone for TOTP in Aegis. I downloaded the APK on my computer, copied it to the microSD card, and installed it offline. The phone has no cell service or Wi-Fi passwords, and airplane mode stays on. Whenever I create a TOTP token (including for Proton Pass), I boot into Tails Linux on a Kanguru flash drive with physical write-protect swich, hop online, set up TOTP, kill the connection, and reboot.

After adding/updating a TOTP seed, I back up Aegis to an encrypted .json file, copy it to the microSD card, insert it in the computer's card reader, create a SHA-256 checksum, upload a copy to Proton Drive with a different account, download it again, save copies to a couple of external HDDs, verify the last copy against the checksum, delete all the accounts in Aegis, and restore from the backup to test it.