Advanced Plus Security Kongo's PC Security Config

Original forum configuration · expand details
Last updated
Apr 29, 2026
Main use of this computer
For home and private use
Operating system
Windows 11
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Hardware security key
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
On
Network firewall
Enabled
Router and network details
AiProtection Pro by TrendMicro (ASUS ROG Rapture GT-AXE11000)
Real-time protection
Deep Instinct Endpoint Protection
CyberLock (AutoPilot)
Device firewall
Microsoft Defender Firewall with Advanced Security
Custom security settings
Hardening tools:
- Cyberlock with Intelligent Firewall set to "Aggressive"
- Cyberlock with Security Posture set to "Aggressive"
- Run by SmartScreen (forces SmartScreen to scan files of choice)

- O&O ShutUp10 (recommended settings)
- O&O AppBuster (removed unecessary Windows 11 apps)
- Windows Sandbox



System settings:
- Reputation Based Protections (all modules enabled)
- Smart App Control enabled

- Data Execution Prevention set to AlwaysOn
- Core Isolation: Memory Integrity enabled
- Kernel-mode Hardware-enforced Stack Protection enabled
- Local Security Authority Protection enabled
- Microsoft Vulnerable Driver Blocklist enabled
- Memory Access Protection enabled
- Secure Boot enabled
- Drives encrypted via TPM (BitLocker)
- Windows Update Delivery Optimization disabled
- AutoPlay disabled
- Network Discovery disabled (Public Firewall profile)
- PowerShell --> Constrained Language Mode
- Hide extensions for known file types --> disabled
- Show hidden files --> enabled
- Virtualization enabled

‎‎‎ㅤ‎ ‎
Periodic malware scanners
ESET Online Scanner, X-Sec
Malware sample testing
I participate in malware testing; details below
Environment for malware testing
‎‎‎ㅤㅤㅤ
VMware Workstation Player + Mozilla VPN on host machine while connected to the guest network.

Online Malware Analysis Platforms that I use:


- FileScan.iO
- Intenzer Analyze
- Hybrid Analysis
- VirusTotal
- Sophos Intelix
- ANY.RUN
-
Triage
- Kaspersky Threat Intelligence Portal
- UnpacMe
- Qianxin Online Sandbox


--> Currently I am barely testing
Browsers and extensions
ㅤ
Mozilla Firefox

Extensions:
- JShelter

- Ghostery
- Bitwarden

Browser privacy and security settings:
- Tracking protection: Strict (enables Total Cookie Protection)
- Enable secure DNS using: Max Protection (ControlD)
- HTTPS-only-mode enabled
- DuckDuckGo set as search engine
- Clearing browsing data on exit
- Search suggestions disabled
- Websites overview disabled
- Blocking incoming location, camera and microphone requests
- AutoPlay for audio and video disabled
- Firefox telemetry disabled
- Blocking pop-ups and third-party redirects
- Warn when websites try to install addons enabled
- Protection against fraudulent content and dangerous software enabled
- AI features are blocked





ㅤㅤ
Secure DNS
ㅤ
- ControlD with balanced native-blocklists + OISD-big (Network-Wide)
- ControlD with strict native-blocklists + Ai Malware Filter (Aggressive) + Hagezi Ultimate + Hagezi TIFs + Automatic IP redirect over Proxy (Only browser)



ㅤ
Desktop VPN
/
Password and passkey manager
ㅤBitwarden Premium
Maintenance tools
PatchMyPC, UniGetUI, GeekUninstaller, Process Lasso and Windows built in tools for cleaning and optimization
File and photo backups
ㅤbackup to external drive when necessary
Subscriptions
    • Google One Standard 200GB
System recovery
Aomei Backupper
Usage and exposure
    • Visiting familiar websites
    • Visiting unknown or untrusted websites
    • Opening email attachments
    • Online shopping and card payments
    • Downloading software and files from reputable sites
    • Gaming
    • Streaming from untrusted sites
    • Downloading malware samples
Computer specs
GPU: Nvidia Geforce RTX 3060 TI
CPU: Intel I5 12600K
RAM: 16 GB DDR4-3200 Crucial
Hard disks: 500 GB Samsung 970 EVO Plus + 1 TB Western Digital Blue
Notable changes
- Updated for year 2026
Feedback preference

Detailed suggestions and alternatives welcome

Sending referer only on eTLD+1 is the best approach I think.
Had this before, but thought spoofing it completely doesn't have any negative side effects. I personally didn't find any site that broke cause of that entry, but as it can be a security risk according to @qua3k opinion, I will disable it. AdGuard extension actually also has an option to spoof the referrer, so I just might set the about:config entry to default and use their option. :unsure:

Unbenannt.PNG
 
AdGuard extension actually also has an option to spoof the referrer, so I just might set the about:config entry to default and use their option. :unsure:
Or you could try this:
Code:
network.http.referer.trimmingPolicy=2
network.http.referer.XOriginPolicy=2
network.http.referer.XOriginTrimmingPolicy=2
I've had no breakage so far with above combo, but it can vary depending on your browsing behaviour. If you have breakage, a different combo as shown here: Tweaking Referrers For Privacy in Firefox
 
I also refer to these
The last one is quite conservative but shows various options.
I think I stick with AdGuards referrer spoofing as it is enabled by default when enabling Stealth Mode as far as I know. So it would have a lower impact on my fingerprint than also playing in the about:config settings when I am using AdGuard already anyway.
 
Had this before, but thought spoofing it completely doesn't have any negative side effects. I personally didn't find any site that broke cause of that entry, but as it can be a security risk according to @qua3k opinion, I will disable it. AdGuard extension actually also has an option to spoof the referrer, so I just might set the about:config entry to default and use their option. :unsure:

View attachment 259875
Stop spoofing the referrer. There are sites that check referrer as part of CSRF protection and you will break sites by doing so. You should avoid messing with referrer settings in the first place; browsers already default to a sufficiently strict strict-origin-when-cross-origin for requests without an explicit Referrer-Policy. What you’re setting will break sites.
 
- replaced Malwarebytes Browser Guard with uBlock Origin in Medium Mode
- removed ClearURLs as I have the AdGuard URL Tracking blocklist enabled in uBlock Origin
- removed LocalCDN
- removed FirewallHardening, ConfigureDefender and KeyScrambler
+ added Sophos Home Premium
 
Last edited:
I guess I'm in my switching security software every day phase... 😅

- removed Sophos Home Premium
+ added ConfigureDefender, Simple Windows Hardening, Firewall Hardening and KeyScrambler
+ blocking potentially insecure third-party content within uBlock Origin
 
Last edited:
- replaced Malwarebytes Browser Guard with uBlock Origin in Medium Mode
- removed ClearURLs as I have the AdGuard URL Tracking blocklist enabled in uBlock Origin
- removed LocalCDN
- removed FirewallHardening, ConfigureDefender and KeyScrambler
+ added Sophos Home Premium
Hello @SecureKongo

Has SHP still an issue with the ADguard filtering?
 
are you still happy with Immunet? It was a little bit buggy in the past on my system and
with a lot of leftovers after deinstallation.
It was a little buggy. The UI crashed from time to time and I constantly had a CPU usage between 2-4% and a RAM usage of 600mb which shouldn't be the case with my specs. After all the system didn't really feel slow or sluggish in any way. Protection-wise I can't really say much, as I didn't really test it. All I can say is that the signatures Clam+Cloud are acceptable and that Immunet detects malicious scripts (VBS,JS etc.) and other file extensions with static scan which many other AVs don't. If you use HiBit Uninstaller to uninstall Immunet then you should switch to another, as Immunets proactive protection component seems to block some actions performed by HiBit when you uninstall software.

PS:
I saw some videos about Immunet on youtube and they didn't have the CPU and RAM usage problem like on my system.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top