Advanced Plus Security Kongo's PC Security Config

Original forum configuration · expand details
Last updated
Apr 29, 2026
Main use of this computer
For home and private use
Operating system
Windows 11
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Hardware security key
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
On
Network firewall
Enabled
Router and network details
AiProtection Pro by TrendMicro (ASUS ROG Rapture GT-AXE11000)
Real-time protection
Deep Instinct Endpoint Protection
CyberLock (AutoPilot)
Device firewall
Microsoft Defender Firewall with Advanced Security
Custom security settings
Hardening tools:
- Cyberlock with Intelligent Firewall set to "Aggressive"
- Cyberlock with Security Posture set to "Aggressive"
- Run by SmartScreen (forces SmartScreen to scan files of choice)

- O&O ShutUp10 (recommended settings)
- O&O AppBuster (removed unecessary Windows 11 apps)
- Windows Sandbox



System settings:
- Reputation Based Protections (all modules enabled)
- Smart App Control enabled

- Data Execution Prevention set to AlwaysOn
- Core Isolation: Memory Integrity enabled
- Kernel-mode Hardware-enforced Stack Protection enabled
- Local Security Authority Protection enabled
- Microsoft Vulnerable Driver Blocklist enabled
- Memory Access Protection enabled
- Secure Boot enabled
- Drives encrypted via TPM (BitLocker)
- Windows Update Delivery Optimization disabled
- AutoPlay disabled
- Network Discovery disabled (Public Firewall profile)
- PowerShell --> Constrained Language Mode
- Hide extensions for known file types --> disabled
- Show hidden files --> enabled
- Virtualization enabled

‎‎‎ㅤ‎ ‎
Periodic malware scanners
ESET Online Scanner, X-Sec
Malware sample testing
I participate in malware testing; details below
Environment for malware testing
‎‎‎ㅤㅤㅤ
VMware Workstation Player + Mozilla VPN on host machine while connected to the guest network.

Online Malware Analysis Platforms that I use:


- FileScan.iO
- Intenzer Analyze
- Hybrid Analysis
- VirusTotal
- Sophos Intelix
- ANY.RUN
-
Triage
- Kaspersky Threat Intelligence Portal
- UnpacMe
- Qianxin Online Sandbox


--> Currently I am barely testing
Browsers and extensions
ㅤ
Mozilla Firefox

Extensions:
- JShelter

- Ghostery
- Bitwarden

Browser privacy and security settings:
- Tracking protection: Strict (enables Total Cookie Protection)
- Enable secure DNS using: Max Protection (ControlD)
- HTTPS-only-mode enabled
- DuckDuckGo set as search engine
- Clearing browsing data on exit
- Search suggestions disabled
- Websites overview disabled
- Blocking incoming location, camera and microphone requests
- AutoPlay for audio and video disabled
- Firefox telemetry disabled
- Blocking pop-ups and third-party redirects
- Warn when websites try to install addons enabled
- Protection against fraudulent content and dangerous software enabled
- AI features are blocked





ㅤㅤ
Secure DNS
ㅤ
- ControlD with balanced native-blocklists + OISD-big (Network-Wide)
- ControlD with strict native-blocklists + Ai Malware Filter (Aggressive) + Hagezi Ultimate + Hagezi TIFs + Automatic IP redirect over Proxy (Only browser)



ㅤ
Desktop VPN
/
Password and passkey manager
ㅤBitwarden Premium
Maintenance tools
PatchMyPC, UniGetUI, GeekUninstaller, Process Lasso and Windows built in tools for cleaning and optimization
File and photo backups
ㅤbackup to external drive when necessary
Subscriptions
    • Google One Standard 200GB
System recovery
Aomei Backupper
Usage and exposure
    • Visiting familiar websites
    • Visiting unknown or untrusted websites
    • Opening email attachments
    • Online shopping and card payments
    • Downloading software and files from reputable sites
    • Gaming
    • Streaming from untrusted sites
    • Downloading malware samples
Computer specs
GPU: Nvidia Geforce RTX 3060 TI
CPU: Intel I5 12600K
RAM: 16 GB DDR4-3200 Crucial
Hard disks: 500 GB Samsung 970 EVO Plus + 1 TB Western Digital Blue
Notable changes
- Updated for year 2026
Feedback preference

Detailed suggestions and alternatives welcome

Strange. It's working perfectly fine for me. Did you download it from here?

Yes, not blaming the app, probably user snafu. Will try again a little later tonight. will update. thanks.
 
- decided to go with Netcraft instead of SafeToOpen.

From my personal experience SafeToOpen's performance is really good, but considering the outdated version on Firefox in comparison to the Chrome version, I don't feel comfortable running it at the moment.
 
- decided to go with Netcraft instead of SafeToOpen.

From my personal experience SafeToOpen's performance is really good, but considering the outdated version on Firefox in comparison to the Chrome version, I don't feel comfortable running it at the moment.

Thanks for that heads-up. SafeToOpen on Chrome and Brave is 4.2.8, while FF is 4.0.0.
 
Do you keep it on default settings or make changes? I never used it before.
Screenshot 2023-11-27 170510.png


Those are my settings right now. Basically I activated all the recommended settings. Wonder why they are not active by default tho.
If you decide to give it a try too, then make sure to give it access to your data on all sites under "permissions" in order to make it work correctly (Firefox).
 
@Kongo, Do you truly need a phishing extension? Modern browsers are effective in combating phishing attacks. Have you ever come across a phishing website or failed to recognize one? What's the point of adding an extension that may expand the attack surface but offers little extra protection, particularly for advanced users like yourself?
 
@Kongo, Do you truly need a phishing extension? Modern browsers are effective in combating phishing attacks. Have you ever come across a phishing website or failed to recognize one? What's the point of adding an extension that may expand the attack surface but offers little extra protection, particularly for advanced users like yourself?

Netcraft does offer more than phishing protection, for me personally it's useful to inform about websites data... What's that site running? | Netcraft
In my VM while testing malware, Netcraft was sometimes effective to detect and block malicious Java Scripts, additional the following:

n#1.png

 
Netcraft does offer more than phishing protection, for me personally it's useful to inform about websites data... What's that site running? | Netcraft
In my VM while testing malware, Netcraft was sometimes effective to detect and block malicious Java Scripts, additional the following:
I comprehend Netcraft's offerings. Netcraft blocks certain elements while testing malicious domains. Have any of you advanced users ever encountered or failed to recognize a phishing website during regular browsing? Have such extensions been beneficial enough for advanced users like yourself in regular browsing to justify their presence on your system?
 
Last edited by a moderator:
I comprehend Netcraft's offerings. Netcraft blocks certain elements while testing malicious domains. Have any of you advanced users ever encountered or failed to recognize a phishing website during regular browsing? Have such extensions been beneficial enough in regular browsing to justify their presence on your system?
And what about a mid-tier user as myself, how much (many add-ons) is too much, and will it hinder F-Secure's web browsing filter from being efficient with Brave's, Brave search, Chrome's filters, and then my adding SafeToOpen over the weekend. That was exactly what was on my mind, when is it overkill, or will it diminish the effectiveness of onboard AV filtering/antiphishing capabilities? And as you mentioned above, creating more attack surface?
 
Last edited:
And what about a mid-tier user as myself, how much (many add-ons) is too much, and will it hinder F-Secure's web browsing filter from being efficient with Brave's, Brave search, Chrome's filters, and then my adding SafeToOpen over the weekend. That was exactly what was on my mind, when is it overkill, or will it diminish the effectiveness of onboard AV filtering/antiphishing capabilities? And as you mentioned above, creating more attack surface?
I have experience managing many average or click-happy users over the years. For real-time protection, I installed an ad blocker and an effective security suite. They never experienced malware or phishing issues. A combination of effective security, an ad blocker, and browser built-in security is sufficient, which is what I use and recommend to users I manage.
 
Last edited by a moderator:
Hardening? whh light mabye ;)
Not necessary with Deep Instinct as it already has malicious script protection included.

@Kongo, Do you truly need a phishing extension? Modern browsers are effective in combating phishing attacks. Have you ever come across a phishing website or failed to recognize one? What's the point of adding an extension that may expand the attack surface but offers little extra protection, particularly for advanced users like yourself?
Definitely a valid point, as NextDNS blocks the NRDs that often are associated with phishing attacks. Still phishing is the only way where you can possibly get me with my guard down when i'm not focused. So i'd rather be on the safe side. And as @silversurfer mentioned, phishing protection is just one feature of Netcraft.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top