Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
No.H_C, CD, and FH default or recommended settings. Windows 11 Pro.
I plan to enable the "Block all incoming connections, including those in the list of allowed apps" Windows Firewall setting on our kids' systems. Would it affect your tools in any way?
I'm testing the stated setting on my system. I've been noticing these entries in "Advanced SRP Logging" since I enabled the setting, but I think they're okay.
Advanced SRP Logging has "filtered" and "all" options. Why not a blocked option? It would be easy to check for blocked ones, or am I missing something?
I mentioned this issue previously. The FH "Blocked Events" is not working; it shows a "Please wait! It will take some time" message. The message disappears, and the log doesn't appear. The "Firewall.log" in the H_C folder opens fine. Does "Blocked Events" require the legacy Notepad? I removed the legacy Notepad from the optional features. What should I check for the issue?
Hard_Configurator(x64).exe (PID = 2784) identified C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2504.62.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe as Unrestricted using path rule, Guid = {6d809377-6af0-444b-8957-a3773f02200e}
Notepad.exe (PID = 11884) identified C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2504.62.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe as Unrestricted using path rule, Guid = {6d809377-6af0-444b-8957-a3773f02200e}
The "All" log option has many entries, so having a separate "Blocked" log would allow users to see only the blocked entries, making it simpler, if feasible.Advanced SRP Logging shows which allow/block rules are applied when the executable is run with admin rights.
I use it rarely to see which block rules will be applied if the executable is going to be run with standard rights. There is some advantage, because one executable can trigger more than one block rule at different moments of running.
The code you posted is there in the logs, but I don't have notepad.exe in the Windows folder.Do you have notepad.exe in Windows folder?
The "All" log option has many entries, so having a separate "Blocked" log would allow users to see only the blocked entries, making it simpler, if feasible.
The code you posted is there in the logs, but I don't have notepad.exe in the Windows folder.
Hard_Configurator runs Notepad by using the command:
@SystemDir & "\notepad.exe " & $ProgramFolder & '\Firewall.log'
This is usually translated to:
C:\Windows\notepad.exe "C:\Windows\Hard_Configurator\Firewall.log"
On Windows 11 the Notepad from Windows folder opens the Notepad located in WindowsApps:
I re-added classic Notepad via optional features. Notepad is present in the Windows folder. Now, the FH log shows a "blocked events for the current blocklist not found" window.That is why the FirewallHardening log does not open automatically.
I re-added classic Notepad via optional features. Notepad is present in the Windows folder. Now, the FH log shows a "blocked events for the current blocklist not found" window.
I'm using GUI Skin 2, as it resembles the ConfigureDefender and FirewallHardening interfaces. There are 16 skins available, some with a light grey color, but none with a dark theme!Updated.![]()
I'm using GUI Skin 2, as it resembles the ConfigureDefender and FirewallHardening interfaces. There are 16 skins available, some with a light grey color, but none with a dark theme!I wish the GUI Skin 2 and CD/FH had a dark theme!
![]()
Hate... the dark mode of emotions!For unknown reasons, I hate dark themes.![]()
@Andy Ful, I removed the H_C entries from the Windows Start Menu but kept the folder on our kids' machine. I understand it shouldn't be a problem, but I just want to make sure.
@Andy Ful, H_C has OS-based configs. I believe it applies the "Windows_11_SAC_ON_Recommended_Settings" config on Windows 11 machines. Why not have an H_C config with WDAC, at least for Windows 11?
Is it correct that WDAC could also block programs (in the reputation database) or executables at a later stage, such as when accessing a program, etc.?
Members who viewed this thread in the last 5 minutes