Advanced Plus Security Marana’s Security Config 2024

Last updated
Jun 30, 2024
How it's used?
For home and private use
Operating system
Windows 10
On-device encryption
BitLocker Device Encryption for Windows
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Access Control
Always notify
Smart App Control
N/A - Linux / Mac / Other operating system
Network firewall
Enabled
About WiFi router
WiFi by Ubiquiti Unify APs.
Routing, Radius Server and Edge Firewall by pfSense firewall appliance.
Separate VLANs for Home, TV, IoT and Guest use (both wired & wireless).
Home VLAN protected by 802.1X (EAP-TLS) and device certificates. Self-created Root CA.
Real-time security
Windows Defender
Malwarebytes Windows Firewall Control (WFC)
Comodo Firewall
NovirusThanks OSArmor
G DATA USB Keyboard Guard
ConfigureDefender
FirewallHardening
Firewall security
Other - Next-generation Firewall (NGFW)
About custom security
Custom firewall & routing configuration in edge firewall (pfSense appliance)
Outbound network connections blocked by default in Windows Defender Firewall (WFC)
Modified Cruelsister configuration in Comodo Firewall
Modified Microsoft Security baseline for Windows 10 v1809 (I’m using Windows 10 LTSC 2019)
Modified Microsoft Office 2016 Security baseline
Several Windows features turned off
Several Windows services disabled
Some Windows registry tweaks
Some ACL based directory hardenings
Exploit protection enabled for Microsoft Office programs, browsers etc.
Software Restriction Policies (SRP) enabled. Default Deny. Enforcement for all files.
ConfigureDefender in HIGH settings
FirewallHardening with Recommended H_C + LOLBins
BitLocker with dTPM enbled for all relevant internal & external disk partitions
Periodic malware scanners
Emsisoft EEK
Norton NPE
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
Brave as main browser. Three user profiles (Network surfing / Banking & online shopping / Ad hoc & test use)
  • Microsoft Defender Browser Protection
  • Cookie AutoDelete
Firefox 32-bit as secondary browser (some old applications I use are not compatible with 64-bit browsers)
Microsoft Edge installed, but not actively used nowadays
Secure DNS
Quad9
Desktop VPN
Proton VPN
Password manager
KeePass
Maintenance tools
Hard Disk Sentinel Enterprise
Active@Partition Manager
Hex Editor Neo
FileVerifier++
DiskSavvy
WinMerge
Autoruns, Process Explorer, Process Monitor, Process Hacker, PsExec
accesschk, icacls
HardWipe
Self-made nightly script for automatically cleaning temporary files
File and Photo backup
Macrium Reflect Workstation
SecondCopy
Subscriptions
    • Microsoft 365 Family 6TB
System recovery
Macrium Reflect Workstation. GFS-type backups with stepwise decreasing granularity in redundancy. AES-256 encryption enabled for backup files.
Fortnightly semiautomatic backup replication alternating to two external disks stored in remote locations
Annual long-term backups in a third external disk. Includes PAR2 parity archives (“Parchive”) with 1% redundancy to protect backups from latent sector errors and with a simple EMP shield to protect from Carrington events as well as from tactical nuclear bomb EMPs (however not does not protect from the upcoming apocalypse :sneaky:). Disk stored in a burglarproof and fireproof safe.
Risk factors
    • Browsing to popular websites
    • Browsing to unknown / untrusted / shady sites
    • Making audio/video calls
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Coding and development
Computer specs
Motherboard: ASUS AMD X570
CPU: AMD Ryzen 5 3600
GPU: ASUS GeForce GTX 1060-O3G
RAM: 32 GB DDR4
Storage:
  • 2 x 1 TB SSD
  • 1 x 8 TB HDD
  • 1 x 4 TB HDD
  • 1 x 256 GB SSD
3 x SATA hot swap disk docks, 10+TB external disks
What I'm looking for?

Looking for medium feedback.

Marana

Level 1
Thread author
Verified
Jan 21, 2018
48
The Gdata keyboard guard , have you seen any response from it, interesting addition, I never heard of it, sounds good are you willing to elaborate? Thanks, does Microsoft Defender have good or any e- mail protection?
That is an old piece of software, however it has a simple and reliable principle of operation: When it detects a new USB device that identifies itself as a keyboard, it pops up a virtual numeric keyboard window and asks to enter a 4-digit code (that it displays) via mouse clicks, if one wants to enable the new device.

So it effectively blocks possible BADUSB attacks, but it also requires you to do four specific mouse clicks every time you insert a new USB keyboard to your system.

I don't know how effective Microsoft Defender is in e-mail protection (IIRC I have received one or maybe two warnings regarding emails or e-mail attachments, but they have happened several years ago).
OVERKILL?
Well no — not at all. That's what I call layered security :).

And actually it's not even as much layered as one could easily think at first glance. Here is just one example...

One of the "essential eight principles" in cybersecurity is Application Control (aka application whitelisting). The easy way to implement this is to use a standard user account (SUA) along with a default-deny Software restriction policy (SRP) that blocks file execution in the user space.

Unfortunately Microsoft has abandoned its policy to install programs only to system space (\Program Files directories) and nowadays wants to install e.g. Microsoft Teams into user space (...\AppData\Local\Microsoft\Teams). So, to enable the safe execution of Microsoft Teams I use both SRP and NVT OSA:
  • I created custom policies in SRP to enable the execution of programs in Microsoft Teams directories
  • I created a custom block rule in OSA to block the execution of all programs in Microsoft Teams directories
  • I created an exclusion rule in OSA to enable the execution of all Microsoft signed programs in Microsoft Teams directories
This approach can be used to safely allow execution of programs in specific user space directories, provided they are digitally signed by a trustworthy organization. However it needs both SRP and OSA.
 

rashmi

Level 11
Jan 15, 2024
536
That is an old piece of software, however it has a simple and reliable principle of operation: When it detects a new USB device that identifies itself as a keyboard, it pops up a virtual numeric keyboard window and asks to enter a 4-digit code (that it displays) via mouse clicks, if one wants to enable the new device.

So it effectively blocks possible BADUSB attacks, but it also requires you to do four specific mouse clicks every time you insert a new USB keyboard to your system.
You're using Comodo Firewall. Have you explored the Device Control feature in Advanced Protection? It allows you to protect USB devices and add more device types.
 

Marana

Level 1
Thread author
Verified
Jan 21, 2018
48
Why are you using two firewalls at the same time? It won't add to your protection. Disable windows firewall and wfc. With comodo, you don't need it.
Well, first of all I prefer to use primarily native MS products, especially those that are built-in into Windows operating system, and I also had used Windows Firewall and WFC long before starting to play around with CFW, so my software firewall configuration is based on primarily Windows Firewall. I also like WFC's user interface and some of its "bells and whistles" a lot.

However I consider CFW to provide me with some layered security as well as some additional features like containment and script analysis that Windows Firewall does not have. CFW also seems to run smoothly along with Windows Firewall, causing no problems whatsoever. So why not use it?
You're using Comodo Firewall. Have you explored the Device Control feature in Advanced Protection? It allows you to protect USB devices and add more device types.
Hmm... this is interesting! I wasn't aware of this feature, and it doesn't seem to be available in my CFW's user interface. Maybe it's available only in the full CIS? I have installed only the CFW part. Anyway, I'll keep that in mind, and I might give it a try some day.
This is a great setup with multiple automated layers of security. First time seeing a RADIUS server for home use.
Yeah, I actually borrowed the idea of implementing 802.1X from the office where we used device certificates to protect devices on some VLANs. I consider it merely a nuance in home use, where the threat factors are somewhat different from those of businesses.

But anyway, at least I don't have to worry about someone cracking my WiFi password in the home VLAN, since there is no password! :)(y)
 
  • Like
Reactions: SpiderWeb

rashmi

Level 11
Jan 15, 2024
536
Hmm... this is interesting! I wasn't aware of this feature, and it doesn't seem to be available in my CFW's user interface. Maybe it's available only in the full CIS? I have installed only the CFW part. Anyway, I'll keep that in mind, and I might give it a try some day.
Navigate to Settings, then Advanced Protection, and finally Device Control.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top