Ozone's config (multiboot)

Status
Not open for further replies.

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
Firefox (portable)
Smart Referer extension (Firefox)
Removed:
Privazer
HMP
Updated:
Avast
WFC
Tweaks:
/

Slowly moving from Chrome (portable) to Firefox (portable).
Trying this extension Chrome Store Foxified almost every chrome extensions I've tried work good or with minor bugs, only ScriptSafe doesn't work :(.

Moved Privazer to USB toolbox, CCleaner is enough and I use Shadow Defender.
Moved HMP to USB toolbox, I use on demand scanners one per 1-2 months or when I find something with Process Explorer (VT) when I am not in shadow mode.

Next week finally I will have some free time to test new insider build.
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
VoodooShield (free)
No Resource URI Leak extension (Firefox)
Removed:
EMET
Glasswire
Updated:
Ccleaner
Tweaks:
UAC set to default

With new VS version I am giving it another chance.
To increase stability I've removed EMET.
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
Process Lasso (free)
Removed:
/
Updated:
VS
SysInternals Suite
Tweaks:
VS set to Always On
ReHIPS – lockdown

Trying Process Lasso
 
Last edited:

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
Autoruns (portable)
Process Explorer (portable)
RequestPolicy Continued extension (Firefox)
Removed:
SysInternals Suite
Updated:
/
Tweaks:
/

Replaced SysInternals Suite with Autoruns (portable) and Process Explorer (portable). Moved SysInternals Suite to usb toolbox.
Added RequestPolicy Continued to increase control over cross-site requests.

Playing with new Windows 10 Insider, Windows Defender Security Center looks good.

Next week I would like to secure Ubuntu 16.04, any tips.
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
Cent browser (portable)
Secure Folders
Removed:
VoodooShield
Chrome (Portable)
Firefox (Portable)
Updated:
Avast
ReHIPS
Tweaks:
Disabled AutoPlay
Disabled Remote Assistance
Disabled Remote Registry Access
Blocked Processes: cscript.exe, wscript.exe, powershell.exe, powershell_ise.exe
UAC set to Always notify
Tweaks in uMatrix and uBO (Cent)

Chrome (Portable) is not true portable apps; profile will always reset on another PC. Firefox (Portable) moved to usb toolbox.
VS has problem with updates for Firefox Nightly. VS is causing delay when turning on shadow mode.
 
  • Like
Reactions: XhenEd

Winizsol

Level 2
Verified
Jan 19, 2017
70
I am multibooting Ubuntu 16.04, Windows 10 Insider and Windows 7
My main OS for work is Windows 7, Ubuntu is for university, and Windows 10 is for fun (testing and gaming).
I am using Firefox (stable) with ReHIPS for work.
Cent (portable) with Sandboxie with container folder in ramdisk is for web browsing.
Firefox Nightly is for testing new functions.
Extensions are tweaked to work together.

Updates are automatic, but they are delayed for 1-3 days to avoid problems.
I am using mainly portable apps and I have USB "toolbox" which contains additional program/tools like scanners, archivers, editors, browsers, ...

Tools in USB "toolbox" won't be in config, only programs I have in PC are there.

Windows 7 Tweaks:
Avast – Hardened mode
VoodooShield – Always On
ReHIPS – Standard, lockdown mode
WFC – Medium filtering, secure boot
DNS only via DNSCrypt or VPN
Chrome can connect only via VPN (firewall rule)
Disabled IPv6
Disabled AutoPlay
Disabled Remote Assistance
Disabled Remote Registry Access
Blocked Processes: cscript.exe, wscript.exe, powershell.exe, powershell_ise.exe

Windows 10 Pro Insider Preview
Operating System: Windows 10
OS Edition: Pro
OS Build: Insider Preview build 15042
OS Architecture: 64-bit
User Access Control: Default
Firewall: Windows Firewall
OS Security Updates: Automatic Updates
OS File Reputation: Smartscreen for Windows 10
Type of User Account: Microsoft Account
Recent Malware Attacks: No
Testing AV's with Malware Samples: No
Real-time Malware Protection:
Windows Defender
Windows Firewall Control (free)
ReHIPS (free)
HitmanPro.Alert ("free")
Sandboxie (free)
Shadow DefenderOn-demand Scanners:
Zemana Antimalware (portable)
Emsisoft Emergency Kit (portable)
Process Explorer (portable)Security Product Settings: Custom
Browsers and Extensions:
Cent (Portable): uBlock Origin, uBlock Origin Extra, uMatrix, ScriptSafe
Firefox: uBlock Origin, uMatrix, noscript, Decentraleyes, Smart Referer, No Resource URI Leak, RequestPolicy Continued
Edge: uBlock OriginPreferred Search Engine: DuckDuckGo
Password Manager: my mind
Content Blocker (Ads, Scripts, Trackers):
Cent (Portable): uBlock Origin, uMatrix
Firefox: uBlock Origin, uMatrix, noscript
Edge: uBlock OriginFrequently used System Utilities:
Autoruns (portable)
Process Explorer (portable)
CCleaner (portable)
Simple DnsCrypt
Process Lasso (free)Frequency of Data Backups: Custom Backups
Frequency of System Image Backups: No Backups
System Image Backup Software: If something went wrong I will do a clean reinstall
Great config, thanks for sharing! :)
 
  • Like
Reactions: XhenEd

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
Adguard
Adguard AdBlocker extension
Removed:
Process Lasso (free)
Updated:
WFC
ReHIPS
Tweaks:
Removed Internet Explorer

I don't need Process Lasso. Trying Adguard desktop, adguard extension is working only as indicator (integration mode).
uBO and uMatrix tweaked or disabled
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
Decentraleyes extension (for chromium-based browser)
Containers extension (Firefox Nightly via Test Pilot add-on)
Removed:
/
Updated:
Simple DnsCrypt
Firefox (stable)
Tweaks:
ReHIPS Lockdown mode set to Without GUI only
Removed Avast unnecessary components

Updating and testing.
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
/
Removed:
/
Updated:
WFC
Avast
HMP.A
Sandboxie
Simple DnsCrypt
Adguard
Firefox (stable)
Cent (Portable)
CCleaner (portable)
Tweaks:
Blocked/Monitored Processes: vssadmin.exe
Removed other legacy windows components

Finally time to do some updates.
 

S3cur1ty 3nthu5145t

Level 6
Verified
May 22, 2017
251
I'm beginning to think you should be sporting my user name ;) Since it is obvious you like playing with and testing different securities, whether out of curiosity or passion, I will not give you the "holy **** that's way to much" speech. :D
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
I'm beginning to think you should be sporting my user name ;) Since it is obvious you like playing with and testing different securities, whether out of curiosity or passion, I will not give you the "holy **** that's way to much" speech. :D

I like to have full control over my PC (removing legacy components and disabling services I don't use) and using apps which are light or portable. And because I don't test malware, I don't test AV so I have to play with something else :D. I usually test apps which are portable, related to net (browsers, firewall, VPN, DNS, ...) or use "signatureless detection" (antiexe, SRP, BB, HIPS, ...).
 
  • Like
Reactions: S3cur1ty 3nthu5145t

S3cur1ty 3nthu5145t

Level 6
Verified
May 22, 2017
251
I like to have full control over my PC (removing legacy components and disabling services I don't use) and using apps which are light or portable. And because I don't test malware, I don't test AV so I have to play with something else :D. I usually test apps which are portable, related to net (browsers, firewall, VPN, DNS, ...) or use "signatureless detection" (antiexe, SRP, BB, HIPS, ...).
Allow me to make a suggestion then. Set up a Virtual Machine, create a snapshot once you have the Guest machine set up, and then you can play all day long with software, and when done, you just simple reset the snapshot and your ready for another round of tinkering again, all without hampering your main system in any way. ;)
 

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Allow me to make a suggestion then. Set up a Virtual Machine, create a snapshot once you have the Guest machine set up, and then you can play all day long with software, and when done, you just simple reset the snapshot and your ready for another round of tinkering again, all without hampering your main system in any way. ;)

I usually play with portable apps and apps which don't require reboot after installing in shadow mode, if they need reboot or if there is some conflict with my current setup(very rare) I test them in VM. Also I prefer to test in shadow mode as I am currently dualbooting win7 and win10.
For VM I have only win7.
 
  • Like
Reactions: S3cur1ty 3nthu5145t

ozone

Level 3
Thread author
Verified
Jan 17, 2017
97
Added:
uBlock Protector extension (Cent browser)
Removed:
Adguard (desktop)
uBlock Origin Extra extension (Cent browser)
Updated:
Everything to latest stable version
Tweaks:
/

I will soon switch to Win 10 Pro as my main OS.
 
  • Like
Reactions: Parsh
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top