Advanced Plus Security Kongo's PC Security Config

Original forum configuration · expand details
Last updated
Apr 29, 2026
Main use of this computer
For home and private use
Operating system
Windows 11
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Hardware security key
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
On
Network firewall
Enabled
Router and network details
AiProtection Pro by TrendMicro (ASUS ROG Rapture GT-AXE11000)
Real-time protection
Deep Instinct Endpoint Protection
CyberLock (AutoPilot)
Device firewall
Microsoft Defender Firewall with Advanced Security
Custom security settings
Hardening tools:
- Cyberlock with Intelligent Firewall set to "Aggressive"
- Cyberlock with Security Posture set to "Aggressive"
- Run by SmartScreen (forces SmartScreen to scan files of choice)

- O&O ShutUp10 (recommended settings)
- O&O AppBuster (removed unecessary Windows 11 apps)
- Windows Sandbox



System settings:
- Reputation Based Protections (all modules enabled)
- Smart App Control enabled

- Data Execution Prevention set to AlwaysOn
- Core Isolation: Memory Integrity enabled
- Kernel-mode Hardware-enforced Stack Protection enabled
- Local Security Authority Protection enabled
- Microsoft Vulnerable Driver Blocklist enabled
- Memory Access Protection enabled
- Secure Boot enabled
- Drives encrypted via TPM (BitLocker)
- Windows Update Delivery Optimization disabled
- AutoPlay disabled
- Network Discovery disabled (Public Firewall profile)
- PowerShell --> Constrained Language Mode
- Hide extensions for known file types --> disabled
- Show hidden files --> enabled
- Virtualization enabled

‎‎‎ㅤ‎ ‎
Periodic malware scanners
ESET Online Scanner, X-Sec
Malware sample testing
I participate in malware testing; details below
Environment for malware testing
‎‎‎ㅤㅤㅤ
VMware Workstation Player + Mozilla VPN on host machine while connected to the guest network.

Online Malware Analysis Platforms that I use:


- FileScan.iO
- Intenzer Analyze
- Hybrid Analysis
- VirusTotal
- Sophos Intelix
- ANY.RUN
-
Triage
- Kaspersky Threat Intelligence Portal
- UnpacMe
- Qianxin Online Sandbox


--> Currently I am barely testing
Browsers and extensions
ㅤ
Mozilla Firefox

Extensions:
- JShelter

- Ghostery
- Bitwarden

Browser privacy and security settings:
- Tracking protection: Strict (enables Total Cookie Protection)
- Enable secure DNS using: Max Protection (ControlD)
- HTTPS-only-mode enabled
- DuckDuckGo set as search engine
- Clearing browsing data on exit
- Search suggestions disabled
- Websites overview disabled
- Blocking incoming location, camera and microphone requests
- AutoPlay for audio and video disabled
- Firefox telemetry disabled
- Blocking pop-ups and third-party redirects
- Warn when websites try to install addons enabled
- Protection against fraudulent content and dangerous software enabled
- AI features are blocked





ㅤㅤ
Secure DNS
ㅤ
- ControlD with balanced native-blocklists + OISD-big (Network-Wide)
- ControlD with strict native-blocklists + Ai Malware Filter (Aggressive) + Hagezi Ultimate + Hagezi TIFs + Automatic IP redirect over Proxy (Only browser)



ㅤ
Desktop VPN
/
Password and passkey manager
ㅤBitwarden Premium
Maintenance tools
PatchMyPC, UniGetUI, GeekUninstaller, Process Lasso and Windows built in tools for cleaning and optimization
File and photo backups
ㅤbackup to external drive when necessary
Subscriptions
    • Google One Standard 200GB
System recovery
Aomei Backupper
Usage and exposure
    • Visiting familiar websites
    • Visiting unknown or untrusted websites
    • Opening email attachments
    • Online shopping and card payments
    • Downloading software and files from reputable sites
    • Gaming
    • Streaming from untrusted sites
    • Downloading malware samples
Computer specs
GPU: Nvidia Geforce RTX 3060 TI
CPU: Intel I5 12600K
RAM: 16 GB DDR4-3200 Crucial
Hard disks: 500 GB Samsung 970 EVO Plus + 1 TB Western Digital Blue
Notable changes
- Updated for year 2026
Feedback preference

Detailed suggestions and alternatives welcome

+ added .zip and .mov to NextDNS blocked TLDs
FYI LennyFox on github published three TLD blocklists (which I have blocked in NextDNS)

I will browse the list in NextDNS again. Do you have a list of which TLDs you block in NextDNS?
 
FYI LennyFox on github published three TLD blocklists (which I have blocked in NextDNS)

I will browse the list in NextDNS again. Do you have a list of which TLDs you block in NextDNS?
Most abused TLD and .zip + .mov

Nothing special
 
Will test it in the coming days. It's using Rising Antivirus engine + its own engine for scanning. To be fair I didn't test it enough to make any assesments. But unlike HitmanPro it can also detect malicious scripts (vbs,js,jar etc.)
Keep us posted 👍
One thing I noticed is that scans take pretty long. It took 17:36 min for only 30400 files (quick scan). And nothing was bottlenecked in the system (CPU, RAM or SSD).
 
Little update:

Made a little test with a few malicious samples with various file types (ps1, js, html, xls)
I intentionally skipped PE-files as those are the easiest to detect for most scanners:

24 samples in total:

- HitmanPro detected as expected 0
- Norton Power Eraser detected 16
- X-Sec detected 13

Even tho Norton performed better, I think X-Sec performed pretty good considering how unknown it is.

Edit: I forgot to remove those shortcuts from the sample folder. So there would be only 22 actual malicious files. But doesn't matter as I just wanted to demonstrate that is also quite effective when you throw malicious scripts at it.

Screenshot 2023-08-14 000123.png
 
Will test it in the coming days. It's using Rising Antivirus engine + its own engine for scanning. To be fair I didn't test it enough to make any assesments. But unlike HitmanPro it can also detect malicious scripts (vbs,js,jar etc.)
You running X-Sec on same machine as DeepInstinct? :unsure: (I did not dig into the details fo your security config)
 
I knew the name sounded familiar. Lol, I tried this before in 2017 and had same feedback for the dev.
View attachment 277822
For slow scan speed, based on these reasons:
- I only use 2 threads for scan
- UI is written in .NET Core, but both X-Sec Antivirus Engine and Rising Antivirus Engine are written in C++, use P/Invoke may lose some performance
- Some modules of X-Sec Antivirus are protected by VMProtect(don't worry, it's genuine version, I renew license every year)
- Some design in scan logic and engine are not good enough, it could be better
 
fwiw, I downloaded and "ran
UpdateHub-x64.exe sha256 80A081B63FAC71E96930C24C342ED51A184E9BCA964633D7D898B07B82F90B92
as administrator" from sua, but it would not install... now I have to hammer & bend it in... :oops:
Strange. It's working perfectly fine for me. Did you download it from here?

 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top