Advanced Plus Security n8chavez's PC Security Config

Original forum configuration · expand details
Last updated
Aug 14, 2025
Main use of this computer
For home and private use
Operating system
Windows 11
On-device encryption
VeraCrypt
Device sign-in security
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Account Control (UAC)
Notify me only when programs try to make changes to my computer
Smart App Control
Off
Network firewall
Enabled
Real-time protection
  1. Sandboxie Plus (via RAM drive)
  2. Cyberlock with SiriusLLM
  3. Windows Security (hardened)
  4. AdGuard for Windows
Device firewall
Microsoft Defender Firewall
Custom security settings
Binisoft's Windows Firewall Control GUI
Periodic malware scanners
HitmanPro
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browsers and extensions
Vivaldi
addons: TamperMonkey, Dark Read, Privacy Badger
Secure DNS
ControlD
Desktop VPN
Mullvad
Password and passkey manager
Bitwarden Premium
Maintenance tools
Not much needed, other than winget. Everything that has internet connectivity is configured via sandboxie to clean out cache/changes at close.
File and photo backups
Changed files are backup up daily via rclone to an encrypted and 2fa Mega.nz; including music, video, documents, installer files, photos, ISOs, ebooks and disk images
Subscriptions
    • None
System recovery
System images (partitions required for my system to boot) are created daily and automatically via scheduled scripts using Terabyte's Image for Windows. Full images are created weekly, and differential images are created daily.
Usage and exposure
    • Visiting familiar websites
    • Working from home
    • Opening email attachments
    • Online shopping and card payments
    • Downloading software and files from reputable sites
    • Sharing and receiving files and torrents
    • Gaming
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Streaming from untrusted sites
Computer specs
  • Hardware
    • Motherboard: Asus Prime Z790-P
    • GPU: Nvidia RTX 4070 Super
    • Memory: 64 GBytes @ DDR 5 Kingston Fury 6000MHz
    • Storage: Disk 1 20TB Seagate Enterprise @ 7200RPM,
    • Disk 2 Samsung 990 EVO Pro 1TB @ 5425RPM
    • Disk 3 Samsung 990 EVO Pro 2TB w/Heatsink
    • CPU Brand Name:Intel(R) Core(TM) i7-14700KF CPU @ 5.60GHz
      CPU Vendor:GenuineIntel
      CPU Stepping:B0
      CPU Code Name:Raptor Lake
      CPU Technology:14 nm
      CPU S-Spec:
Notable changes
  1. Replaced Waterfox with Vivaldi
    1. Eliminated jshelter
    2. Eliminated uBo
    3. Eliminated Bitwarden
    4. Added AdGuard for Windows
  2. Added Cyberlock plus SiriusLLM
Feedback preference

Suggestions on the main improvements

n8chavez

Level 26
Verified
Well-known
Forum Veteran
Here is my system configuration. I try to automate as much as possible, from imaging my SSD to rcloning data backups to an encrypted GDrive. From a security standpoint, I try to keep things proactive, not reactive. I do not use malware scanners, or any third party anti-malware software.

Let me know what you think!
 
Nice config. Consider setting UAC to "Max" to prevent UAC bypasses. Also consider picking a second additional scanner next to HitmanPro as it can't detect scripting malware for example. :)

Thanks! But that's where VoodooShield comes into play; it detects anything running on my system and prompts me. There's no need for both UAC @ max and VS, since theyr do the same thing.
 
Either VoodooShield or something like OSArmor. Both are very good.

Any smart default-deny setup. There are many good choices: SRP, anti-EXE, Comodo auto-sandbox, etc.
Simply, if one blocks/contains something by default then it cannot elevate or it is contained in the sandbox.:)(y)

Edit.
OSArmor might have to be highly tweaked if one would like to skip UAC on MAX.
 
Last edited:
Any smart default-deny setup. There are many good choices: SRP, anti-EXE, Comodo auto-sandbox, etc.
Simply, if one blocks/contains something by default then it cannot elevate or it is contained in the sandbox.:)(y)

Edit.
OSArmor might have to be highly tweaked if one would like to skip UAC on MAX.

Yuuup. But, after all, we are a community of tweakers! :sneaky:
 
Any of the mentioned solutions (including VS) will be stronger with UAC MAX in the postinfection stage. But, most users who like such solutions will not be probably infected, at all.
 
Any of the mentioned solutions (including VS) will be stronger with UAC MAX in the postinfection stage. But, most users who like such solutions will not be probably infected, at all.
Any setup has to balance security with usability. If not why don't we all disconnect and turn off our systems? They would be completely secure then!
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top