Question Firewall Hardening: Should i block all lolbins or just use H_C Recommended?

Please provide comments and solutions that are helpful to the author of this topic.

ScandinavianFish

Level 7
Verified
Dec 12, 2021
319
FYI: FirewallHardening doesn't include all LOLbins that is abused by malware in it's presets. I have personally manually added every single one and has so far not encountered a single false positive.
 
  • Like
Reactions: simmerskool

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,158
Will there be any false positives if I block them all?

Most users should apply only H_C Recommended. In this way, you can get 95% of the protection available via FirewallHardening with 5% of the required effort. Of course, you can fight for the last 5% if you like, but your effort can increase to 100%.:)
I know people who have many blocks related to explorer.exe.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top