Advanced Plus Security Lenny_FoX Desktop Config 2021

Last updated
Dec 11, 2020
How it's used?
For home and private use
Operating system
Windows 10
Log-in security
Security updates
Allow security updates and latest features
User Access Control
Notify me only when programs try to make changes to my computer
Real-time security
  1. Microsoft Defender Attack Surface Reduction rules and Anti-Exploit
  2. Kaspersky Cloud Free (no HTTPS scanning)
Firewall security
Microsoft Defender Firewall
About custom security
1. UAC - deny elevation of unsigned binaries
2. Software Restriction Policy (similar to SimpleWindowsHardening)
3. Microsoft Defender ASR rules & Exploit protection hardening
4. Kaspersky Cloud Free (https scanning disabled)
5. Using Quad9 (DNS), Trend Micro Smart Home (router), browser (Smartscreen/Safe Browsing)
Periodic malware scanners
windows malicious software removal tool, Autoruns64, ProcessExplorer
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Edge browser for daily browsing
  • for searching & surfing: strict mode, with @BeerIsGood Edge list
  • for booking & buying: default mode with no-extensions.
Chrome browser with BulletVPN and uMatrix as webrequest firewall
Maintenance tools
ProcessExploreer and Autoruns64
File and Photo backup
Syncback Free and Windows Backup (yes 2x backup)
System recovery
Syncback adhoc, usually three to five times per day, Windows Backup monthly, Syncback to USB offline HD also once a month
Risk factors
    • Browsing to popular websites
    • Logging into my bank account
    • Working from home
    • Streaming audio/video content from shady sites
Computer specs
Intel I7 950 with 8 GB Ram, 2 SSD drives and 2 HDD drives (1TB and 2TB)
Notable changes
Replaced router

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
REPLACED my less alphabet with Adblock for Youtube

Because my own Less Alphabet failed to block in stream advertisements in Youtube, I removed that list from AdGuard and added Adblock for Youtube, but allow it only to run on Youtube by a forum Member who used the bypass-paywals extension only on demand when running into a paywall).

1597576777387.png


REPLACED Application Guard on-demand with uMatrix on-demand

Because Edge launches much faster without the Virtal machine sandbox of Application Guard, I removed Application Guard and added uMatrix again for on-demand usage:

1597577836473.png




Why Adguard and uMatrix instead uBlock Origin with advanced dynamic filtering?

Smart forum users could suggest uBlock Origin, but I like Adguard's stealth mode (is like Clean URL's but I can tweak it) and I like it's additional cookie parameter to block cloud flare cookies. I also like the fact that uMatrix shows all the info (connected domains) while the filtering engine of uMatrix is OFf

___________ My Adguard USER RULES ---------------
1597578111639.png
 
Last edited:
F

ForgottenSeer 85179

.. (inspired by @security123 who used the bypass-paywalsl extension only on demand when running into a paywall).
I never use such extensions. Your quote is corrupt ?

REPLACED Application Guard on-demand with uMatrix on-demand
Because Edge launches much faster without the Virtal machine sandbox of Application Guard, I removed Application Guard and added uMatrix again for on-demand usage
uMatrix doesn't provide that isolation from Application Guard. You reduce your security with that setup.
Also uMatrix doesn't increase your browser security at all. Other stuff is already handled by AdGuard ;)
So without uMatrix (i guess from Google extension store?) you can disable external stores which increase your browser security (y)

I also use AdGuard too :)
 

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
I never use such extensions. Your quote is corrupt ?

Corrected, thanks

uMatrix doesn't provide that isolation from Application Guard. You reduce your security with that setup.
Also uMatrix doesn't increase your browser security at all.

Yep, uMatrix by far does not provide isolation like VM Sandbox of WDAG, you are right about that. I disagree about uMatrix not increasing security.

With my settings, uMatrix blocks scripts, frames and XML HTTP request does the same as NoScript blocking scripts, frames and fetch (well not really because Fetch API sort of provides simular functionality, but works differently). Meaning no javascript can execute, making it a harmless CSS, HTML (text and media) website. I don't now of in the wild examples of payload execution without javascript execution. So when eneabled uMatrix increases security as far as I know
 
Last edited:

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
Got bored with my current security setup, because it seems to do its job perfectly. What is the use of joining a Security Forum and not messing with your security setup. Most MT-members have probably bricked their system more often due to security tweaking as with malware infections. Being a junior member I want to be part of this distinct club who fix things which aint broken.

So here is my new setup which i will be trying out for a while.

First I changed from Standard user to Administrator and temporarily disabled "Validate Admin Sgnatures" to install Defender Control. After disabling Windows Defender I enabled "Validate Admin Signatures" again (meaning unsigned software is blocked by UAC when it wants to elevate to High Integrity Level.

Next I broke my first safehex rule to not use software which is not activily maintained and download and installed OSArmor. Because I want a signature based whitelist I also downloaded NoVirus Thanks Signer Extractor and ran it to find out which (signed) programs I have installed
1597827714353.png



My Security setup will be based on Windows Defender Exploit protection, Andy Ful's Simple Windows Hardening and OSArmor.

First thing I did is taking control of the protection settings, making OSArmor transparent by using my own rules only

1597824612454.png


Next I configured my own block rules [Edited thanks to tip of @Andy Ful (y)]
1597844675006.png


And my own signature based exclusions (whitelist), based on signatures found by Signature Extractor
1597827580242.png


Overall delay of starting of executables increased from 1.5 to 1second for first program launch and repetive starts from 0.6 to 1 second. Which shows that WD is lighter than OSArmor on my PC.


Interesting to know forum members opinions
 
Last edited:
F

ForgottenSeer 85179

Only for first party from block to allow and not on demand from allow to block for first AND third--party
Totally fine. For insecure sites I use application guard edge anyway
As browser is itself sandboxed and JavaScript exploits are rar & fast fixed blocking Javascript only increase security in theory nowadays.
For privacy it doesn't help either as blocking increase uniqueness.

I only block it in my surfing profile because of less annoying sites.
But in the end all depends of own setup, needs, thread Modell, ...
Just my experience after years using uMatrix on deny-all mode ;)
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,514
Next I configured my own block rules
View attachment 245362
...
On Windows 10, you can skip the block rules for MS Office, and simply apply blocking child processes for these applications via Exploit Protection from Microsoft Security Center (does not require Microsoft Defender).(y)

Edit.
"SWH + these OSA custom settings" is an interesting semi-locked setup. The user can install/update the applications on the base of a shortlist of available signers. I suspect that it also allows installing/updating most of the UWP apps from Microsoft Store. By using SWH to Protect the system drive (except user profiles) the setup will not break anything in the system.
Anyway, for most MT members, it would be like living in the exclusive penitentiary.:)
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top