This weekend I replaced the desktop of an aunt from Windows7 to Windows10. Because NVT SysHardener is not maintained I decided to use Hard_Configurator to replace SysHardener with following settings:
Default allow SRP with some hardening:
- blocking scripts sponsors
- protecting Windows folders
- documents Anti-Exploit (VBA)
- protect mail clients
- harden SMB
- elevate only signed programs
- disable Windows Script
- block powershell scripts
Additional manual hardening
Furthermore I disabled command and scripts with registry editor. I also disable mshta.exe by enabling all possible Exploit Protections in MD app& browser control plus I enable code integrity guard for Explorer and Edge. In the Firewall rules I enable blocking all sponsors except explorer.exe (I thought that Explorer needs outbound connection for smart screen?). I also set Configure_Defender on Max.
Question to @Andy Ful
Would you please make disabling commands and scripts an extra option in the MORE ... (right column hardening of H_C). By hiding this in the MORE hardening options, you could set it default to enabled. I know disabling command should only be done on a Vanilla Windows10 install (no need for third party to enable stuff through commands). I have disabled cmd.exe since Microsoft replaced it as default command shell (
link).
P.S.
I always install a cheap digital license Office Home&Student version. MD with the ASR rules enabled by ConfigureDefender is in my opinion the best anti-virus for use with M$Office.