How to set up a security system WITHOUT using AV/AM software?

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Hi, I'm not asking for a software but a combination of non-AV/AM software. Thanks for the reply
It can start with the browser, Google's SafeBrowsing in Chrome can decline malicious downloads, block phishing pages and more, likewise for Edge/IE with Smartscreen in-browser.

Is this something you are looking for as part of your security?
 
  • Like
Reactions: _CyberGhosT_

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
What is the point of using any adblocker without updated filtering rules?

I only replied to that poster and asking for his recommendation of a suitable one that meets my requirements. If adblocker is not suitable can you recommend something for my Chrome/Firefox browser?
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
If adblocker is not suitable can you recommend something for my Chrome/Firefox browser?
Look for a Content Blocker.
In the grand scheme of things, blocking cookies, scripts, etc. doesn't seem to serve any practical purpose. The average user does not do these things and they don't seem to be at a disadvantage to those who are more cautious on the internet. When I set up uMatrix, I'm surprised by all these tracking cookies and unnecessary objects that come with the sites I visit but why should I care?

https://www.reddit.com/r/firefox/comments/3uhy53/what_is_the_practical_purpose_of_things_like/
 
  • Like
Reactions: _CyberGhosT_

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Ok, so you say ReHIPS is a good replacement for all 3 software I mentioned. This is great! But I'm no so sure my low IQ can handle it. I think I'll wait a little longer for the official version to be released. Using SB, SD and NVTERP combined might be a good start for me to get a feel.

With this ReHIPs how far can it protect the system as far as the definition of malware (mentioned in my opening post) is concerned? Will it be adequate to just use this ReHIPs alone or need to combine with others? Any others to make good companionship with ReHIPs?

Thanks
You can combine ReHIPS with most other security softs.
but you don't really need to. It depends on your level of paranoia, and also, how you use ReHIPS.
If you isolate all vulnerable apps, then you don't have any credible security threats to worry about.
Of course, when installing a new app, the burden is primarily on you to decide whether it is safe, because there is no cloud and no malware database. You will only get broad indicators regarding the file's safety rating.

HOWEVER: keep in mind that REHIPS is protecting your file system, but is not protecting you from visiting phishing sites etc. Furthermore, your browser could be exploited, but the exploit will not affect your file system. In this way, it is like Sandboxie.
 

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
Do you know how to lookup which version of Windows that you're running - XP, Vista, 7, 8, 8,1 or 10 ?

Desktop - or - laptop ?

I'm now using Win 10 Pro (64-bit) v1607 Build 14393.222

I'm using MS SP3
 

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
You can combine ReHIPS with most other security softs.
but you don't really need to. It depends on your level of paranoia, and also, how you use ReHIPS.
If you isolate all vulnerable apps, then you don't have any credible security threats to worry about.
Of course, when installing a new app, the burden is primarily on you to decide whether it is safe, because there is no cloud and no malware database. You will only get broad indicators regarding the file's safety rating.

HOWEVER: keep in mind that REHIPS is protecting your file system, but is not protecting you from visiting phishing sites etc. Furthermore, your browser could be exploited, but the exploit will not affect your file system. In this way, it is like Sandboxie.

I'm keeping system protection separate from web protection. I'll tackle system protection first then later come to web protection in a similar manner.

So, if for you, what other software besides ReHIPs would you need to prevent and protect against malwares? Remember the term malware is encompassing all types of malicious attacks. Would using ReHIPs alone be adequate?

This is also a question which I raised in my opening post.
 
  • Like
Reactions: SHvFl

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I'm keeping system protection separate from web protection. I'll tackle system protection first then later come to web protection in a similar manner.

So, if for you, what other software besides ReHIPs would you need to prevent and protect against malwares? Remember the term malware is encompassing all types of malicious attacks. Would using ReHIPs alone be adequate?

This is also a question which I raised in my opening post.
I combo ReHIPS with HMPA.
Others combo it with AppGuard -- this is a real lockdown security setup, which is beyond my needs. Depends on your level of obsessive-compulsive perfectionism, and also what you do on your PC.
 

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
I combo ReHIPS with HMPA.
Others combo it with AppGuard -- this is a real lockdown security setup, which is beyond my needs. Depends on your level of obsessive-compulsive perfectionism, and also what you do on your PC.

You think using HMPA without its scanning portion would be good enough with ReHIPs?

Another question. Would these 2 be adequate for online and offline prevention and protection against malwares.....leaving web protection aside first? That is to say now malwares are coming from the USB ports as well through external devices.
 
  • Like
Reactions: SHvFl
H

hjlbx

He is running Pro - but I don't know which ve
I'm keeping system protection separate from web protection. I'll tackle system protection first then later come to web protection in a similar manner.

So, if for you, what other software besides ReHIPs would you need to prevent and protect against malwares? Remember the term malware is encompassing all types of malicious attacks. Would using ReHIPs alone be adequate?

This is also a question which I raised in my opening post.

ReHIPS utilizes separate user profiles - similar to the Admin and Standard User profiles in Windows. The ReHIPSUser profile isolates processes from the real system. The HIPS blocks execution. Whatever you allow - if it is malicious - will be contained in the isolated ReHIPSUser profile.

The whole point of non-AV security solution is this simple principle:

1. Clean install OS
2. Install desired softs
3. Install\configure default-deny
4. Lock down system
5. Don't change system afterwards - very rarely - if ever

SInce you start with a clean system, it is locked down preventing system changes, it should stay clean unless you put stuff onto your system that is malicious.

There is no network protections from software restriction policy software, anti-executables, etc. So you will need network protection - but if it is a desktop system then you don't really need it. If it is laptop taken to public wifi hotspots then network protection is needed.

As far as adblocker you are not going to find one that does not require filter updates; you can disable the updates and manually update them once in a while. If you don't want to do that then there just aren't any practical solutions.

All you really need is a single primary protection and a good adblocker like Adguard or uBlock Origin.

The same products will be mentioned repeatedly - AppGuard, ReHIPS, Sandboxie, Shadow Defender, NVT ERP, Voodooshield, Drive Vaccine, etc, etc, etc.
 

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
He is running Pro - but I don't know which ve


ReHIPS utilizes separate user profiles - similar to the Admin and Standard User profiles in Windows. The ReHIPSUser profile isolates processes from the real system. The HIPS blocks execution. Whatever you allow - if it is malicious - will be contained in the isolated ReHIPSUser profile.

The whole point of non-AV security solution is this simple principle:

1. Clean install OS
2. Install desired softs
3. Install\configure default-deny
4. Lock down system
5. Don't change system afterwards - very rarely - if ever

SInce you start with a clean system, it is locked down preventing system changes, it should stay clean unless you put stuff onto your system that is malicious.

There is no network protections from software restriction policy software, anti-executables, etc. So you will need network protection - but if it is a desktop system then you don't really need it. If it is laptop taken to public wifi hotspots then network protection is needed.

As far as adblocker you are not going to find one that does not require filter updates; you can disable the updates and manually update them once in a while. If you don't want to do that then there just aren't any practical solutions.

All you really need is a single primary protection and a good adblocker like Adguard or uBlock Origin.

The same products will be mentioned repeatedly - AppGuard, ReHIPS, Sandboxie, Shadow Defender, NVT ERP, Voodooshield, Drive Vaccine, etc, etc, etc.

Hi thanks

System Protection

I know those are the software that are often repeatedly mentioned here and elsewhere. The thing I want to know is which are the ones most suited for a "signature less" protection without unnecessary overlapping protection and similar features. Compatibility and conflict will be there if 2 software are functioning similarly like weird behavior, unnecessary alerts, system slowdown, software competing for system resources resulting in one not working, system crash etc.

Like I said ReHIPs is still in beta. Some moths back I tried ESET beta and it screwed up my system. I need to reformat then. I would like to give SB, SD and NVTERP a try first.

Web Protection

Yes, I'm using my MS SP3 outdoor frequently too. Using SafeScript, Random User Agent, Web Defender etc(for Chrome) and NoScript, BetterPrivacy, RequestPolicy Continued, Random Agent Spoofer, HTTPS etc(for Firefox) will definitely help. These are definition-less if I'm not wrong. I'm using those mentioned except for NoScript and SafeScript for the moment besides those adblockers requiring updates.

I may even need to take the risk of letting malwares and other unwanted web content to be downloaded first and then let the system software to take the necessary preventive and protective actions if I take the approach of having a "sig-less" security system

FYI, my paid AdGuard for desktop expired recently and I'm now using its AdGuard Adblocker extension/add-on for my Chrome/Firefox browsers.
 
Last edited:
  • Like
Reactions: SHvFl

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
You think using HMPA without its scanning portion would be good enough with ReHIPs?

Another question. Would these 2 be adequate for online and offline prevention and protection against malwares.....leaving web protection aside first? That is to say now malwares are coming from the USB ports as well through external devices.
I don't use the scanning portion of HMPA. Just the various anti-exploit/BB features.

the ReHIPS/HMPA combo is more than adequate for me, but I cannot call myself a bona fide expert in these matters.
@hjlbx and @Umbra should please share their opinions. They know these softwares inside out.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,344
@HarborFront I use Rehips daily for about half a year now without any issues. Note that all releases are first tested by devs, then closed beta and then go in release version or beta request from the open forum.
I am one of those in closed beta and every time i found anything even a small bug it was fixed within a few days and sometimes within hours.

Basically the only reason to not use Rehips beta is to wait for gui to get improved, some usability updates and new features(rule manager, folder isolation,more controlled child application.....etc). Anw requesting beta and trying it's easy so give it a try if you wish and decide on your own. Each has different needs and desires from software.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
@HarborFront I use Rehips daily for about half a year now without any issues. Note that all releases are first tested by devs, then closed beta and then go in release version or beta request from the open forum.
I am one of those in closed beta and every time i found anything even a small bug it was fixed within a few days and sometimes within hours.

Basically the only reason to not use Rehips beta is to wait for gui to get improved, some usability updates and new features(rule manager, folder isolation,more controlled child application.....etc). Anw requesting beta and trying it's easy so give it a try if you wish and decide on your own. Each has different needs and desires from software.
@SHvFl said it like it is.

you can join the beta and get the free demo version, which has a limit of 10 isolated processes per session. This is not enough to run chrome freely (because it is multi-process), but it works for firefox just fine. If you want to remove the said limitation, you need to buy a subscription.
 

HarborFront

Level 71
Thread author
Verified
Top Poster
Content Creator
Oct 9, 2016
6,026
uBlock Origin as adblocker.

You can use your OS with no updates (if you understand how updates work you understand this point), the only way to protect is with some type of sandbox because you don't know what you install or what you allow, keep in mind that there are a lot of signed malware and so on.

I know my point of view is not that popular here but with HIPS/Default Deny you need to know what you are doing (else it's useless)

PS: check this post too.

Sorry, too many sudden advises given and I missed your post.

No virtualization technique and its products is 100% bulletproof. SB has its caveats too. SB has no defintion/signature updates nor a prelist of whitelist/blacklist/blocklist by the developer. But program and software vulnerability updates will be required.

For Windows I'm not using Windows Defender so its malware definition updates don't apply. Windows UAC don't use the definitions. As for SmartScreen I'm not sure just like the Windows EMET tool. However, other updates will be required to improve the OS just like any 3rd-party software providing program updates, no? Improvement can come in having new features, plugging of security vulnerabilities, improving its compatibility etc. These are acceptable as far as meeting my intent.

And regarding Default-Deny. All software, even with default-deny (lock-down), cannot 100% shut the system off from connecting to the outside world otherwise there's no chance of the OS to connect out. There'll be some core Windows processes which MUST connect out even with software having default lock-down (default-deny). After that it'll be up to the user to make the right decision to deny/allow the other Windows processes or any software application from connecting out.

Correct me if I'm wrong.

Thanks
 
Last edited:

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
It sounds to me like you are striving for a lock-down security config with 99.999% reliability, that does not rely on a local or a cloud data base.
If that is the case, the best combo for you would probably be ReHIPS+AppGuard, or NVT ERP+AppGuard.
AppGuard is a bit expensive, and takes some getting used to, but it's very strong protection when configured properly. I am the wrong one to ask about how to configure it, but there are threads on MT you can read.
Of course, a user mistake will bypass any security config.
 
  • Like
Reactions: _CyberGhosT_
D

Deleted member 178

If you want a serious lockdown user-friendly combo : NVT ERP + Appguard ; it was my first combo when i decided to ditch AVs and i kept it for very long.

I only moved to ReHIPS + Appguard because ReHIPS gave me an anti-exe + sandbox in one soft , so i could replace Sandboxie and ERP by it.

If you want a free lockdown user-friendly combo : ERP + Vodooshield would do the trick.

I am a big fan of lockdown combos : i actually use ReHIPS + Appguard + HMPA to cover most of the vector attacks ; on top of them i have some registry/network OS tweaks to tighten my system.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top