Advanced Plus Security Kongo's Computer Security Config 2026

Last updated
Dec 22, 2025
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
BitLocker Device Encryption for Windows
Log-in security
    • Hardware security key
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Access Control
Always notify
Smart App Control
On
Network firewall
Enabled
About WiFi router
AiProtection Pro by TrendMicro (ASUS ROG Rapture GT-AXE11000)
Real-time security
Deep Instinct Endpoint Protection
CyberLock (Autopilot)
Firewall security
Microsoft Defender Firewall with Advanced Security
About custom security
Hardening tools:
- Cyberlock with Intelligent Firewall set to "Aggressive"
- Cyberlock with Security Posture set to "Aggressive"
- Run by SmartScreen (forces SmartScreen to scan files of choice)

- O&O ShutUp10 (recommended settings)
- O&O AppBuster (removed unecessary Windows 11 apps)
- Windows Sandbox



System settings:
- Reputation Based Protections (all modules enabled)
- Smart App Control enabled

- Data Execution Prevention set to AlwaysOn
- Core Isolation: Memory Integrity enabled
- Kernel-mode Hardware-enforced Stack Protection enabled
- Local Security Authority Protection enabled
- Microsoft Vulnerable Driver Blocklist enabled
- Memory Access Protection enabled
- Secure Boot enabled
- Drives encrypted via TPM (BitLocker)
- Windows Update Delivery Optimization disabled
- AutoPlay disabled
- Network Discovery disabled (Public Firewall profile)
- PowerShell --> Constrained Language Mode
- Hide extensions for known file types --> disabled
- Show hidden files --> enabled
- Virtualization enabled

‎‎‎ㅤ‎ ‎
Periodic malware scanners
Norton Power Eraser
Malware sample testing
I do participate in malware testing. See details about my testing environment below.
Environment for malware testing
‎‎‎ㅤㅤㅤ
VMware Workstation Player + Mozilla VPN on host machine while connected to the guest network.

Online Malware Analysis Platforms that I use:


- FileScan.iO
- Intenzer Analyze
- Hybrid Analysis
- VirusTotal
- Sophos Intelix
- ANY.RUN
-
Triage
- Kaspersky Threat Intelligence Portal
- UnpacMe
- Qianxin Online Sandbox


--> Currently I am barely testing
Browser(s) and extensions
ă…¤
Mozilla Firefox v. 147.0.0

Extensions:
- Ghostery
- Mozilla VPN Extension

- Bitwarden

Browser privacy and security settings:
- Tracking protection: Strict (enables Total Cookie Protection)
- Enable secure DNS using: Max Protection
- HTTPS-only-mode enabled
- DuckDuckGo set as search engine
- Clearing browsing data on exit
- Search suggestions disabled
- Websites overview disabled
- Blocking incoming location, camera and microphone requests
- AutoPlay for audio and video disabled
- Firefox telemetry disabled
- Blocking pop-ups
- Warn when websites try to install addons enabled
- Protection against fraudulent content and dangerous software enabled


about:config tweaks:
- network.dns.echconfig.enabled = true
- pdfjs.enableScripting = false
- network.IDN_show_punycode = true
- security.ssl.require_safe_negotiation = true

- geo.enabled = false
- webgl.disabled = true
- network.lna.blocking = true

- network.lna.block_trackers = true
- network.trr.mode = 3 (NextDNS)
ㅤㅤ
Secure DNS
ă…¤
- NextDNS with DoT + OISD (Network-wide)
- NextDNS with DoH + HaGeZi - Multi Ultimate (only browser)



ă…¤
Desktop VPN
Mozilla VPN
Password manager
ă…¤Bitwarden Premium
Maintenance tools
PatchMyPC, UniGetUI, HiBit Uninstaller, Process Lasso and Windows built in tools for cleaning and optimization
File and Photo backup
ă…¤backup to external drive when necessary
Subscriptions
    • Google One Standard 200GB
System recovery
Aomei Backupper
Risk factors
    • Browsing to popular websites
    • Browsing to unknown / untrusted / shady sites
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Downloading software and files from reputable sites
    • Gaming
    • Streaming audio/video content from shady sites
    • Downloading malware samples
Computer specs
GPU: Nvidia Geforce RTX 3060 TI
CPU: Intel I5 12600K
RAM: 16 GB DDR4-3200 Crucial
Hard disks: 500 GB Samsung 970 EVO Plus + 1 TB Western Digital Blue
Notable changes
- Updated for year 2026
What I'm looking for?

Looking for maximum feedback.

- updated Firefox to v. 102 and disabled AdGuard URL Tracking Filter for now, as Firefox is removing tracking parameters from URLs when ETP is set to strict.
I will wait for more details wether AdGuard's filterlist or the built in one of Firefox is more effective. Didn't find any further information about it yet. If one of you finds out additional info I would appreciate it if you could share the source with me. :)
 
Last edited:
- updated Firefox to v. 102 and disabled AdGuard URL Tracking Filter for now, as Firefox is removing tracking parameters from websites when ETP is set to strict.
I will wait for more details wether AdGuard's filterlist or the built in one of Firefox is more effective. Didn't find any further information about it yet. If one of you finds out additional info I would appreciate it if you could share the source with me. :)
I see that there's separate about:config which control if it will be enabled in Private Browsing mode. But it's disabled by default.
"privacy.query_stripping.enabled.pbmode"
I set it to true now.
 
Shouldn't it be enabled in Strict mode and in private browsing mode? :unsure:
I thought so too, but surprisingly it's not. Tried changing settings a couple of times. If I don't set it in Strict mode, then the normal flag gets disabled and enables if I set it to strict. But the private browsing flag doesn't change. It stays "false" always.
 
Last edited:
I thought so too, but it's surprisingly it's not. Tried changing settings a couple of times. If I don't set it in Strict mode, then the normal flag gets disabled and enables if I set it to strict. But the private browsing flag doesn't change. It stays "false" always.
Can confirm. It's also disabled by default on my system... Thanks for letting me know :) (y)
 
How did you do it? I wasn't able to.
I am using Firefox. Keep that in mind.

Screenshot 2022-09-02 195915.jpg
 
Totally understandable, but Cylance is really light and works well for me at the moment. I also ditched most Iobit products but the Software Updater is the only not bloated software by iobit. Also I'm not using Iobit Uninstaller, I'm using HiBit Uninstaller. Thanks for your tips, might remove Iobit Software Updater in the future as there are better software updaters anyway. :)
Since you are using Kerish Doctor, you don't need Iobit Updater.