Advanced Plus Security markstitovits's Security Configuration 2024

Last updated
Jan 29, 2024
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
N/A
Log-in security
    • Basic account password (insecure)
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Access Control
Always notify
Smart App Control
Off
Network firewall
Enabled
About WiFi router
ZTE
TPLNIK Archer AX10 (software: AX1500)
Real-time security
Avast Premium Security
Firewall security
Other - Internet Security (3rd-party)
About custom security
Keeping everything up-to-date
Avast Driver Updater
Blocking MS telemetry servers
O&O ShutUp
Periodic malware scanners
MS defender, Norton Power Eraser
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
Brave
extensions: Bitwarden; I still don't care about cookies
Secure DNS
System: AdGuard DNS with DoH
Browser: DNS0 Zero with DoH
Desktop VPN
ProtonVPN (only used if needeed)
Password manager
Bitwarden Free
Maintenance tools
BleachBit, WinDirStat, TCPView, Autoruns, OpenHardwareMonitor, Avast Driver Updater, command line tools (sfc, chkdsk, dism.exe)
File and Photo backup
Primary: iCloud
Others: ProtonDrive, Mega
(All End-to-End encrypted)
System recovery
Windows restore point
AOMEI Backupper
Risk factors
    • Browsing to popular websites
    • Browsing to unknown / untrusted / shady sites
    • Making audio/video calls
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Gaming
    • Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
ASUS TUF Gaming B650M-PLUS
AMD Ryzen 5 7600X
G.SKILL Flare X5 32GB (2x16GB) DDR5 5600MHz
GIGABYTE NVIDIA GTX 1050Ti
Corsair MP600 CORE XT 1TB
Kingston NV2 2TB
Notable changes
2022/09/13
+ Took a few community suggestions after making this thread.
2022/09/30
+ Bitdefender Total Security
- Microsoft Defender(DefenderUI)
2022/10/14
- Cookie AutoDelete from Firefox
- Facebook container from Firefox
2023/04/1
+ Eset Internet Security
2024/01/29
+ Updated the page to the current setup and security configuration
What I'm looking for?

Looking for medium feedback.

Kongo

Level 35
Verified
Top Poster
Well-known
Feb 25, 2017
2,498
I am currently testing 3rd party firewall software. I've tested a few before, I'll be accepting recommendations happily.
Solid config but I'd recommend you to set UAC to Always Notify to prevent UAC bypasses.
Also, there is no need for using Sophos Scan & Clean + HitmanPro as both are basically the same, while HitmanPro uses Sophos and Bitdefender engine and Sophos Scan & Clean only uses the Sophos engine. If you paid for HitmanPro then you should get rid of Sophos Scan & Clean.
And lastly you should think about wether you really need the Facebook Container extension when there is Total Cookie Protection enabled by default for all users nowadays:
 

markstitovits

Level 2
Thread author
Sep 13, 2022
54
Solid config but I'd recommend you to set UAC to Always Notify to prevent UAC bypasses.
Also, there is no need for using Sophos Scan & Clean + HitmanPro as both are basically the same, while HitmanPro uses Sophos and Bitdefender engine and Sophos Scan & Clean only uses the Sophos engine. If you paid for HitmanPro then you should get rid of Sophos Scan & Clean.
And lastly you should think about wether you really need the Facebook Container extension when there is Total Cookie Protection enabled by default for all users nowadays:
Thank you for your feedback! :)
 

markstitovits

Level 2
Thread author
Sep 13, 2022
54
All the recent changes listed:
9/13/2022
+ Took a few community suggestions after making this thread.
9/30/2022
+ Bitdefender Total Security
- Microsoft Defender(DefenderUI)
10/14/2022
- Cookie AutoDelete from Firefox
- Facebook container from Firefox
10/18/2022
+Librewolf
10/21/2022
+ProtonVPN(always on)
 

markstitovits

Level 2
Thread author
Sep 13, 2022
54
+ Added NoScript to LibreWolf.
Switched to Adguard DNS + Quad9 DoH


I have been thinking a lot between Adguard DNS and Quad9 DNS a lot recently. So I have Adguard in my router settings and Quad9 DoH in LibreWolf. Adguard has pretty good ad and tracking protection while quad9 have great malware protection. I'd appreciate some advice or your personal thoughts in terms of DNS providers, thanks. I know that NextDNS would be perfect for me, but I'm trying to avoid paid options, since I'm still a student.
 
Last edited:

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,111
I'd appreciate some advice or your personal thoughts in terms of DNS providers, thanks. I know that NextDNS would be perfect for me, but I'm trying to avoid paid options, since I'm still a student.
You're fine as is, so long as your happy with your setup. I myself use Quad9 DOH in Windows and µBO in Firefox and LibreWolf. Simple and free.
 

markstitovits

Level 2
Thread author
Sep 13, 2022
54
Updated for 2023 config:
Switched to Eset Internet Security
Switched to AdGuard Public DNS + DoH
Added MS defender to periodic scanning (automatic)
Added router configuration
Updated risk factors
Updated default browser settings
Updated custom security settings

I am looking forward for reviews, improvements and tips on my current setup :)
 

Kongo

Level 35
Verified
Top Poster
Well-known
Feb 25, 2017
2,498
Updated for 2023 config:
Switched to Eset Internet Security
Switched to AdGuard Public DNS + DoH
Added MS defender to periodic scanning (automatic)
Added router configuration
Updated risk factors
Updated default browser settings
Updated custom security settings

I am looking forward for reviews, improvements and tips on my current setup :)
You might want to take a look at dns0. It's basically the free version of NextDNS. Might be a better option than Adguard DNS.

 

markstitovits

Level 2
Thread author
Sep 13, 2022
54
You might want to take a look at dns0. It's basically the free version of NextDNS. Might be a better option than Adguard DNS.

I remember reading an article about it when it was still unreleased. I'm definitely trying it out! Thanks <3
 

SeriousHoax

Level 47
Verified
Top Poster
Well-known
Mar 16, 2019
3,635
You might want to take a look at dns0. It's basically the free version of NextDNS. Might be a better option than Adguard DNS.

Looks like dns0 doesn't block ads. So, it depends on what he wants. Ads & tracker blocking or better malware & phishing blocking.
 

TairikuOkami

Level 35
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,487
Windows Backup is deprecated since Windows 7, even MS suggest to use 3rd party software. Try EaseUS Todo, free version has PreOS, so you do not need to create a bootable disc.
WinDirStat was last updated in 2007, you might want to replace it with something newer (WizTree/TreeSize), it has problem displaying system partitions, System & reserved files, etc.
TCPView shows active TCP/UDP connections, but it will not show all connections, try to update time, UDP via 123, thus I am using TCP UDP Watch by Nirsoft, it logs everything.
 

Attachments

  • capture_04022023_122831.jpg
    capture_04022023_122831.jpg
    95.7 KB · Views: 67

markstitovits

Level 2
Thread author
Sep 13, 2022
54
Windows Backup is deprecated since Windows 7, even MS suggest to use 3rd party software. Try EaseUS Todo, free version has PreOS, so you do not need to create a bootable disc.
WinDirStat was last updated in 2007, you might want to replace it with something newer (WizTree/TreeSize), it has problem displaying system partitions, System & reserved files, etc.
TCPView shows active TCP/UDP connections, but it will not show all connections, try to update time, UDP via 123, thus I am using TCP UDP Watch by Nirsoft, it logs everything.
Thank you, I will research on those items and try them out! <3
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top