- Dec 27, 2016
- 1,480
There's this one way of setting up well with simplicity —> Virtualization / Rollback / SRP Restrictions .. and sit back
There's this other way —> the traditional multi-layers and adding some of the above good stuff
Unfortunately, the first approach ain't very practical for many users & use-cases, including my requirements.
An AV is like a bulletproof vest. It won't guarantee protection everywhere. Lockdown.
Feedback welcome
Keep safe, be safe!
There's this other way —> the traditional multi-layers and adding some of the above good stuff
Unfortunately, the first approach ain't very practical for many users & use-cases, including my requirements.
Local AV: Emsisoft Antimalware (disabled "automatically allow programs with good reputation) + Heimdal Pro (limited malware engine)
File Reputation: VoodooShield (VoodooAI + Blacklist scan) + EAM Network + Kerish Doctor
File Reputation: VoodooShield (VoodooAI + Blacklist scan) + EAM Network + Kerish Doctor
Behavior Blocker: Emsisoft
Dedicated HIPS: ____
Application Control: ____
Lockdown: VoodooShield Pro (always ON + max settings)
Dedicated HIPS: ____
Application Control: ____
Lockdown: VoodooShield Pro (always ON + max settings)
Firewall: Sphinx Windows 10 Firewall Control (Basic license) (Zones-based, restrictive, system apps covered, deny-by-default)
Traffic Scanning: Heimdal Pro (VectorN)
MITM check: SSL-Eye
Traffic encryption: DNSCrypt with Yandex (browser only)
Reverse DNS lookup: CrowdInspect
Systemwide DNS: Heimdal Secure DNS
Traffic Scanning: Heimdal Pro (VectorN)
MITM check: SSL-Eye
Traffic encryption: DNSCrypt with Yandex (browser only)
Reverse DNS lookup: CrowdInspect
Systemwide DNS: Heimdal Secure DNS
Dedicated exploit mitigation: ____
Anti-exploit: Emsisoft (limited exploit mitigation) +VoodooShield (web apps exe-based protection)
Exploit prevention: Heimdal Pro (patching + blacklist-based blocking)
Anti-exploit: Emsisoft (limited exploit mitigation) +VoodooShield (web apps exe-based protection)
Exploit prevention: Heimdal Pro (patching + blacklist-based blocking)
Services & Task Scheduler monitor: Kerish Doctor
Disabled: wscript.exe / cscript.exe / powershell / "Allow Remote Assistance" / Remote Registry Service / Autoplay, System Restore / Untrusted Fonts / System Restore / "Hide Extensions of Known File Types" / Execution of 16-bit processes / Installation of unsigned drivers without warning
Alerts: SmartScreen (web + windows store), UAC
System Files Protection: Kerish Doctor
Security Settings protection: Kerish Doctor
Realtime failure detection: Kerish Doctor
Disabled: wscript.exe / cscript.exe / powershell / "Allow Remote Assistance" / Remote Registry Service / Autoplay, System Restore / Untrusted Fonts / System Restore / "Hide Extensions of Known File Types" / Execution of 16-bit processes / Installation of unsigned drivers without warning
Alerts: SmartScreen (web + windows store), UAC
System Files Protection: Kerish Doctor
Security Settings protection: Kerish Doctor
Realtime failure detection: Kerish Doctor
URL blocking: Emsisoft Surf Protection (added Hosts file) + Heimdal Pro + Yandex Protect + Netcraft
Ad blocking: uBlock Origin
Banking protection: Yandex Protect + Zemana Antilogger (identity protection)
Anti-exploit: VoodooShield Pro
Ad blocking: uBlock Origin
Banking protection: Yandex Protect + Zemana Antilogger (identity protection)
Anti-exploit: VoodooShield Pro
Anti-keylogging: Zemana Antilogger
Privacy containment: Covert Pro (occasional use) + Sphinx FW (restricted network communication)
Data leak protection: Heimdal Pro / Covert Pro (occasional) + Sphinx FW (restricted network communication)
Privacy containment: Covert Pro (occasional use) + Sphinx FW (restricted network communication)
Data leak protection: Heimdal Pro / Covert Pro (occasional) + Sphinx FW (restricted network communication)
Rollback S/W: Shadow Defender
Sandbox: Sandboxie
Virtual Machine: VirtualBox
Sandbox: Sandboxie
Virtual Machine: VirtualBox
System Backup / Recovery: Macrium Reflect
Data Backup: Manual + Drive Sync
Data Recovery: MiniTools Power Data Recovery / EaseUS MobiSaver
Data Backup: Manual + Drive Sync
Data Recovery: MiniTools Power Data Recovery / EaseUS MobiSaver
OS patching: PortUp Updater (selective updates)
S/W updater: Heimdal Pro (automatic)
S/W updater: Heimdal Pro (automatic)
File encryption: AxCrypt
VPN: Windscribe VPN
Encrypted mailing: Protonmail
Harden Windows: Hard Configurator / Win10 Security Plus
File details: Pro File Security Tools
DNS switchers: ChrisPC DNS Switcher
Maintenance: ProcessLasso Pro / Kerish Doctor / Complete Internet Repair / Windows Repair Toolbox
Other utilities: MiniTools Partition wizard / RAMDisk / Sardu USB
VPN: Windscribe VPN
Encrypted mailing: Protonmail
Harden Windows: Hard Configurator / Win10 Security Plus
File details: Pro File Security Tools
DNS switchers: ChrisPC DNS Switcher
Maintenance: ProcessLasso Pro / Kerish Doctor / Complete Internet Repair / Windows Repair Toolbox
Other utilities: MiniTools Partition wizard / RAMDisk / Sardu USB
Process Injection / Hollowing / RAT: CrowdInspect / RunPEDetector / Zemana /..
System analysers: Norton PE / McAfee GetSusp / Kaspersky System Checker / SecureAnywhere System Analyser
Rootkit: TDSSKiller / Norton PE / TrendMicro RootkitBuster
Multi-engine: Metadefender client (multi-engine) / HitmanPro / Zemana
Adware / Junkware: AdwCleaner / BC Junkware Removal
Other scanners: Immunet Antivirus (includes Cisco-based cloud protection, community driven) (periodic scanning) / Dr.Web CureIt / Malwarebytes / Panda Cloud Cleaner / ESET Online Scanner
System analysers: Norton PE / McAfee GetSusp / Kaspersky System Checker / SecureAnywhere System Analyser
Rootkit: TDSSKiller / Norton PE / TrendMicro RootkitBuster
Multi-engine: Metadefender client (multi-engine) / HitmanPro / Zemana
Adware / Junkware: AdwCleaner / BC Junkware Removal
Other scanners: Immunet Antivirus (includes Cisco-based cloud protection, community driven) (periodic scanning) / Dr.Web CureIt / Malwarebytes / Panda Cloud Cleaner / ESET Online Scanner
Process Monitor / Scanner: CrowdInspect / KillSwitch / Process Hacker / System Explorer / Rkill / SysInternals suite / ESET SysInspector
Autoruns: Kerish Doctor / System Explorer
System / modules check: SanityCheck / FolderChangesView / ESET HiddenFileSystemReader / RegShot / HiJackThis
All-in-one Tool (SX Kit): Stream Armor / Virus Total Scanner / Windows Autorun Disable / Windows Service Manager / Windows USB Blocker / Autorun File Remover / Hidden File Finder / Net Share Monitor / Remote DLL / Spy BHO Remover / Spy DLL Remover
Autoruns: Kerish Doctor / System Explorer
System / modules check: SanityCheck / FolderChangesView / ESET HiddenFileSystemReader / RegShot / HiJackThis
All-in-one Tool (SX Kit): Stream Armor / Virus Total Scanner / Windows Autorun Disable / Windows Service Manager / Windows USB Blocker / Autorun File Remover / Hidden File Finder / Net Share Monitor / Remote DLL / Spy BHO Remover / Spy DLL Remover
Windows 10: already covered
ElementaryOS: Sophos AV, FireJail, non-GUI Windscribe VPN, VirtualBox for testing (NAT)
ElementaryOS: Sophos AV, FireJail, non-GUI Windscribe VPN, VirtualBox for testing (NAT)
I've been using a bootable rescue-USB using Sardu (highly recommended)
With partitioning, you can add some portable executable scanners too. Write-protect the USB then for On-the-go usage.
- Multiple antivirus rescue discs in-1
- All in One System Rescue Toolkit/ Trinity Rescue Kit
- Ubuntu boot repair tool etc.
With partitioning, you can add some portable executable scanners too. Write-protect the USB then for On-the-go usage.
- The independent AV tests are NOT absolute truth, and experienced users are aware of that. Also, with modified configurations (mostly defaults are tested), these tools can deliver varied level of protection.
- Test the sleepiness of your antivirus here
- Complement your security software. But have no more than 1 real-time AV (some are born incompatible, others may conflict at critical times)
- After uninstalling an antivirus, use their official 'removal tools' for clean removal
- Scan with a bootable-rescue-disc monthly or quarterly (prefer BD, Kaspersky, Avira, ESET & Dr.Web)
- Provide admin-rights with utmost care. Prefer Standard account
- Use lockdown / anti-executables if feasible alongside an AV
- Avoid trying cracks. Those can do more than what's in their name!
- Keep Auto-play always OFF. Write-protect your USB when porting
- Download programs from Vendor sites or trusted downloads sites only
- During potentially risky activities, use sandbox or multi-protection always (AM + URL blocker + anti-exploit + extensions)
- For ransomware protection besides antivirus, WinAntiRansom / Kaspersky AntiRansom Tool / HMPA etc are nice options
- Important tips like low-risk activities, safe browsing, using Windows built-in mechanisms for security are already famous elsewhere. Let me link them here
- Do not share your credentials or personal information with others. These can be misused for hacking your stuff
- Use Sardu to create a Multiboot USB tool to include Multiple AV Rescue Discs, USB repair tools, Linux Distros(s) and some more portable apps. Write protect it then, as needed.
- Install a Linux distro for side-by healthy computing!
Feedback welcome
Keep safe, be safe!
Last edited: