Advanced Plus Security n8chavez's System Configuration 2025

Last updated
Aug 14, 2025
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
VeraCrypt
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Access Control
Notify me only when programs try to make changes to my computer
Smart App Control
Off
Network firewall
Enabled
Real-time security
  1. Sandboxie Plus (via RAM drive)
  2. Cyberlock with SiriusLLM
  3. Windows Security (hardened)
  4. AdGuard for Windows
Firewall security
Microsoft Defender Firewall
About custom security
Binisoft's Windows Firewall Control GUI
Periodic malware scanners
HitmanPro
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
Vivaldi
addons: TamperMonkey, Dark Read, Privacy Badger
Secure DNS
ControlD
Desktop VPN
Mullvad
Password manager
Bitwarden Premium
Maintenance tools
Not much needed, other than winget. Everything that has internet connectivity is configured via sandboxie to clean out cache/changes at close.
File and Photo backup
Changed files are backup up daily via rclone to an encrypted and 2fa Mega.nz; including music, video, documents, installer files, photos, ISOs, ebooks and disk images
Subscriptions
    • None
System recovery
System images (partitions required for my system to boot) are created daily and automatically via scheduled scripts using Terabyte's Image for Windows. Full images are created weekly, and differential images are created daily.
Risk factors
    • Browsing to popular websites
    • Working from home
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Downloading software and files from reputable sites
    • Sharing and receiving files and torrents
    • Gaming
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Streaming audio/video content from shady sites
Computer specs
  • Hardware
    • Motherboard: Asus Prime Z790-P
    • GPU: Nvidia RTX 4070 Super
    • Memory: 64 GBytes @ DDR 5 Kingston Fury 6000MHz
    • Storage: Disk 1 20TB Seagate Enterprise @ 7200RPM,
    • Disk 2 Samsung 990 EVO Pro 1TB @ 5425RPM
    • Disk 3 Samsung 990 EVO Pro 2TB w/Heatsink
    • CPU Brand Name:Intel(R) Core(TM) i7-14700KF CPU @ 5.60GHz
      CPU Vendor:GenuineIntel
      CPU Stepping:B0
      CPU Code Name:Raptor Lake
      CPU Technology:14 nm
      CPU S-Spec:
Notable changes
  1. Replaced Waterfox with Vivaldi
    1. Eliminated jshelter
    2. Eliminated uBo
    3. Eliminated Bitwarden
    4. Added AdGuard for Windows
  2. Added Cyberlock plus SiriusLLM
What I'm looking for?

Looking for medium feedback.

n8chavez

Level 24
Thread author
Well-known
Feb 26, 2021
1,346
2
3,648
2,268
42
Here is my system configuration. I try to automate as much as possible, from imaging my SSD to rcloning data backups to an encrypted GDrive. From a security standpoint, I try to keep things proactive, not reactive. I do not use malware scanners, or any third party anti-malware software.

Let me know what you think!
 
Nice config. Consider setting UAC to "Max" to prevent UAC bypasses. Also consider picking a second additional scanner next to HitmanPro as it can't detect scripting malware for example. :)

Thanks! But that's where VoodooShield comes into play; it detects anything running on my system and prompts me. There's no need for both UAC @ max and VS, since theyr do the same thing.
 
Hi, I am truly impressed, I wish I had the know-how to set up my Laptop similar to yours @n8chavez, real technical & very great Configuration!
Respect!(y):censored:;)

Thanks @ simbatippe1234! I've run variations of this config for over a decade, with no problems. If there's anything I can ever help you configure/setup just ask.
 
Thanks! But that's where VoodooShield comes into play; it detects anything running on my system and prompts me. There's no need for both UAC @ max and VS, since theyr do the same thing.
Oh, my bad. I think last time I tried VoodooShield it even told me to disable UAC if I remember correctly.
 
There's no need for both UAC @ max and VS, since theyr do the same thing.
They do not, but the attacks that could use this difference are rare. So, if one does not like UAC on MAX, then using VS (or similar protection) is a good idea. (y)
 
Either VoodooShield or something like OSArmor. Both are very good.

Any smart default-deny setup. There are many good choices: SRP, anti-EXE, Comodo auto-sandbox, etc.
Simply, if one blocks/contains something by default then it cannot elevate or it is contained in the sandbox.:)(y)

Edit.
OSArmor might have to be highly tweaked if one would like to skip UAC on MAX.
 
Last edited:
  • Like
Reactions: Gandalf_The_Grey
Any smart default-deny setup. There are many good choices: SRP, anti-EXE, Comodo auto-sandbox, etc.
Simply, if one blocks/contains something by default then it cannot elevate or it is contained in the sandbox.:)(y)

Edit.
OSArmor might have to be highly tweaked if one would like to skip UAC on MAX.

Yuuup. But, after all, we are a community of tweakers! :sneaky:
 
  • Like
Reactions: Andy Ful
Any of the mentioned solutions (including VS) will be stronger with UAC MAX in the postinfection stage. But, most users who like such solutions will not be probably infected, at all.
 
  • Like
Reactions: harlan4096
Any of the mentioned solutions (including VS) will be stronger with UAC MAX in the postinfection stage. But, most users who like such solutions will not be probably infected, at all.
Any setup has to balance security with usability. If not why don't we all disconnect and turn off our systems? They would be completely secure then!
 
  • Like
Reactions: Andy Ful