You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser.
Advanced Security Kaffee4Eck's PC Security Config
Original forum configuration · expand details
- Last updated
- Jan 1, 2025
- Main use of this computer
- For work or educational use
- Operating system
- Windows 11
- OS version and support details
- Arch Linux | MacOS
- On-device encryption
- Not applicable
- Device sign-in security
- Security updates
- Check for updates and Notify
- Update channels
- Allow stable updates only
- User Account Control (UAC)
- Notify me only when programs try to make changes to my computer (do not dim my desktop)
- Smart App Control
- Off
- Network firewall
- Enabled
- Router and network details
Fritzbox (as DSL / Fiber Modem)
- Real-time protection
| Service / Tool | Functionality |
|---|
| ESET Smart Security (Hardened) | Signature and behavior-based protection, sample submission disabled, firewall enabled |
- Device firewall
- Other - Next-generation Firewall (NGFW)
- Custom security settings
| Service / Tool | Functionality |
|---|
| ESET Smart Security (Hardened) | Signature and behavior-based protection, sample submission disabled, firewall enabled |
| AdGuard Home + Unbound DNS | Local DNS filtering combined with privacy-focused DNS (DNSSEC, DNS-over-TLS/DoH optional) |
| SearXNG (Docker Instance) | Private, self-hosted meta search engine – anonymous, no telemetry, no tracking |
| TailScale | VLAN-isolated remote access with ACLs and detailed audit logging |
| Sample Testing VLAN | Isolated network segment with virtual machines for malware, phishing, and exploit simulations |
| IP / DNS Blocklists (Threat Feeds) | Includes ThreatFox, AbuseIPDB, FireHOL, MalwareDomains, AdGuard lists, and custom feeds |
- Periodic malware scanners
Nothing right now
- Malware sample testing
- I participate in malware testing; details below
- Environment for malware testing
Virtualization Environment: Malware test VMs are deployed in dedicated, air-gapped VLANs to ensure complete network isolation.
- Browsers and extensions
Brave / Firefox: Bitwarden, AdGuard Assistant, Imagus
- Secure DNS
AdGuard Home + Unbound DNS
- Desktop VPN
ProtonVPN
- Password and passkey manager
Bitwarden / Vaultwarden
- File and photo backups
Nextcloud
Immich
UrBackup
Macrium Reflect
- Subscriptions
- System recovery
Macrium Reflect Backups on Home Server + External Server
UrBackup Home Server + External Server
- Usage and exposure
- Opening email attachments
- Online shopping and card payments
- Downloading software and files from reputable sites
- Downloading files from unknown or untrusted sources
- Gaming with third-party mods
- Streaming audio/video content from trusted sites or paid subscriptions
- Downloading malware samples
- Computer specs
Workstation
| Component | Specification |
|---|
| CPU | Intel Core i9-14900K (planned upgrade: AMD Ryzen 9 9950X3D) |
| GPU | NVIDIA RTX 3080 Ti (planned upgrade: AMD RX 9070 XT) |
| RAM | 128 GB DDR4 |
| Storage | 4 × 2 TB Samsung 990 Pro (NVMe) 1 × 4 TB Transcend SSD |
🖴 Server (Storage & Docker)
| Component | Specification |
|---|
| CPU | Intel Core i5-14500K |
| GPU | Integrated GPU (iGPU ) |
| RAM | 128 GB DDR4 |
| Storage | 16 × 16 TB Toshiba MG08ATA (HDDs) 2 × 2 TB Samsung 970 Evo (NVMe) 2 × 2 TB WD RED NVMe SSDs |
Firewall – OPNsense Appliance
| Component | Specification |
|---|
| CPU | Intel Core i5 (11th Gen) |
| GPU | Integrated GPU (iGPU) |
| RAM | 32 GB DDR4 |
| Storage | 2 × 1 TB Samsung 980 Pro (redundant setup ) |
- Feedback preference
Detailed suggestions and alternatives welcome
Core System & Endpoint Setup
Firewall
- OPNsense (current stable version) with full VLAN segmentation
Endpoints
| Device Type | Usage |
|---|
| Windows | Gaming – hardened ESET Smart Security Premium |
| Arch Linux | Development & system administration |
| Mac Mini M1 | Productivity & software testing |
Virtualization Environment
- Malware testing VMs are hosted in dedicated, air-gapped VLANs, fully isolated from production networks for safe phishing/malware/exploit simulations.
Firewall Components & Protection Layers
| Component | Description |
|---|
| ZenArmor (NGFW) | Layer-7 policy enforcement, app detection, activated per VLAN |
| Suricata IDS/IPS (inline) | Real-time traffic analysis using Emerging Threats and custom local rules |
| GeoIP Filtering | Blocks all incoming traffic from outside the EU, VLAN-specific |
| Firewall Aliases & Segmentation | Fine-grained control over traffic for workstations, IoT, guest devices, test labs, etc. |
Extended Security Services & Features
| Service / Tool | Functionality |
|---|
| ESET Smart Security (hardened) | Signature + behavior-based protection, sample submission disabled, local firewall active |
| AdGuard Home + Unbound DNS | Local DNS filtering with privacy-focused DNS (DNSSEC, DoT/DoH optional) |
| SearXNG (Docker) | Private, self-hosted meta search engine – fully anonymous, no telemetry or tracking |
| TailScale | VLAN-isolated remote access with ACLs and audit logging |
| Sample Testing VLAN | Malware/phishing/exploit simulation VMs in a fully isolated network segment |
| Threat Feeds / IP & DNS Blocklists | Includes ThreatFox, AbuseIPDB, FireHOL, MalwareDomains, AdGuard lists, and custom feeds |
Operating Systems & Per-System Security Strategy
| System | Measures |
|---|
| Windows (Gaming) | Hardened ESET, SmartScreen disabled, telemetry reduced |
| Arch Linux | AppArmor, hardened kernel, firewalld, DNS via DNS-over-HTTPS (DoH) |
| macOS (M1 Mini) | Local firewall, DNS via Unbound, no iCloud, tracker blocking active |
Network Security Goals
- Maximum segmentation & visibility – each device only sees what it’s supposed to
- No third-party cloud analysis (e.g., Microsoft Defender Cloud, Google DNS)
- Isolated, real-world malware testing environment with minimal risk to the rest of the network
- Zero Trust DNS & application enforcement
Protection Focus
- Phishing / Malware / Command & Control (C2) communications
- Telemetry & tracking prevention (both DNS- and IP-based)
- Ransomware & exploit protection (behavioral + signature-based)
Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Forum Veteran
Even having ESET (Hardened), I would set up UAC to Always Notify.
About Periodic malware scanners, I'm sure You know the different ones You could use: NPE, EEK, KVRT...
Thanks for sharing

Recently browsing
Members who viewed this thread in the last 5 minutes